Updated August 2026
DPDP deadline timeline: every date that matters
The short answer: the DPDP Rules were notified on 14 November 2025. Consent Manager registration and the Data Protection Board arrive around November 2026, and the core obligations — notices, valid consent, and data-principal request handling — become mandatory around May 2027 (18 months from notification).
14 Nov 2025
DPDP Rules notified
The operational rules under the DPDP Act 2023 were published by MeitY, starting the phased compliance clock.
~Nov 2026
Consent Managers & the Board
Consent Manager registration opens and the Data Protection Board becomes operational — one year from notification. Complaints get a destination.
~May 2027
CORE OBLIGATIONS MANDATORY
Eighteen months from notification: notices, valid purpose-wise consent, withdrawal, and data-principal request handling become enforceable for every data fiduciary.
What to do at each stage
- Now → late 2026: map your purposes and systems, put consent recording and a DSR process in place, and start collecting evidence. Consent collected properly now stays valid at the deadline — retrofitting consent later means re-asking your entire user base under time pressure.
- Nov 2026 onward: the Board exists, which means complaints have an address. Data-principal requests you mishandle from here can become cases.
- May 2027: full enforceability, with penalties up to ₹250 crore per category. Companies that started in 2026 will spend this month running normally; everyone else will be shopping for compliance software in a stampede.
The penalties — exactly as the law writes them
From the Schedule of the DPDP Act, 2023 (see Section 33). The Data Protection Board sets the actual amount within these ceilings, considering the nature, gravity and duration of the breach — and penalties across categories can stack.
| Breach | Maximum penalty |
|---|---|
| Failing to maintain reasonable security safeguards to prevent a personal data breach (Sec 8(5)) | ₹250 crore |
| Failing to notify the Board and affected users of a personal data breach (Sec 8(6)) | ₹200 crore |
| Breaching obligations relating to children's data (Sec 9) | ₹200 crore |
| Breaching Significant Data Fiduciary obligations (Sec 10) | ₹150 crore |
| Any other breach of the Act or the Rules | ₹50 crore |
Beyond fines, the practical risks: enforcement proceedings become public record, enterprise clients now demand DPDP posture in vendor audits, and a mishandled citizen request can become a Board complaint with your company's name on it.
Official government sources
Don't take our word for it — read the law itself:
- Digital Personal Data Protection Act, 2023 — full text (MeitY, official PDF) ↗
- DPDP Act, 2023 as amended — India Code (official statute repository) ↗
- Digital Personal Data Protection Rules, 2025 — notified 13 Nov 2025 (MeitY, official PDF) ↗
- Government press release on the DPDP Rules notification (PIB) ↗
- Ministry of Electronics & IT — data protection updates ↗
Where does your company stand today?
Ten questions, three minutes, your exact gaps — free.
Take the DPDP Readiness Score