Digital Personal Data Protection Act Timelines

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Phasellus pharetra tortor eget lacus ullamcorper, posuere fringilla justo convallis.

Digital Personal Data Protection Act Timelines

21, November 2025

DPDP Rules, 2025, Are Here.

With the Digital Personal Data Protection Rules, 2025 now in force, India’s data protection regime is fully operational — and the 18-month countdown to full compliance by May 2027 has begun.

Start Early.  Don’t Race the May 2027 Deadline.
  • Build Phase: Nov 2025 – Nov 2026: Establish foundations — policies, inventories, governance, and core privacy processes.
  • Implement Phase: Nov 2026 – May 2027: Deploy, integrate, and test operational controls across the organization.
  • Operational Phase: From May 2027: Run, monitor, and continually mature your end-to-end DPDP compliance programme.

Those who wait will be racing against penalties. Privacy done early is privacy done right.

Why this matters?

Why DPDPA Compliance Can’t Wait

  • Applies to most organizations handling digital personal data in India.
  • Full compliance + penalties kick in from 13 May 2027.
  • Security failures alone can attract penalties up to INR 250 crore.
ACTIONS TO BE TAKEN FROM NOW

Phase 1: Regulatory Setup

Foundations Are Being Laid

  • The Data Protection Board of India is notified and set up.
  • Definitions, rule-making powers, and appeal mechanisms come into force.

Action for you: Start gap assessment and readiness planning now.

Immediate Implementation Checklist (For All Organizations)

Non-Negotiables for All Data Fiduciaries

  • Gap assessment
  • Updated privacy notices & policies
  • Data inventory + purpose & retention mapping
  • Incident & breach workflows
  • Grievance redressal with SLAs
  • Rights-handling processes
  • DPAs & vendor alignment
  • Awareness & role-based training

Note : These obligations take effect immediately and become fully enforceable as of 13 May 2027.

 

ACTIONS TO BE TAKEN FROM NOV 2026 TO May 2027

Phase 2: Consent Manager Ecosystem (From Nov 2026)

  1. Assess if a Consent Manager suits your business
  2. Evaluate service providers
  3. Plan technical & process integration

Example: An e-commerce platform integrates a Consent Manager to centralize marketing opt-ins and withdrawals across website, app, and CRM systems.

 

ACTIONS BEYOND MAY 2027

Phase 3: Full Obligations (From May 2027)

Full DPDPA Compliance Becomes Mandatory

  • Valid legal basis (consent/legitimate use)
  • Clear, accessible privacy notices
  • Full Data Principal rights enablement
  • Strong security, retention & deletion controls
  • Children’s data safeguards
  • Vendor/processor oversight
  • Follow notified cross-border transfer rule

Action for you: Ensure that all controls designed in earlier phases are fully operational, thoroughly tested, and closely monitored.

 

If you’re a Significant Data Fiduciary (SDF)

SDFs are high-impact data fiduciaries designated based on:

Additional Duties (Before May 2027):

  • India-based DPO
  • Independent data auditor
  • DPIAs for high-risk processing
  • Board-level governance
  • Structured oversight & reporting
Other Mandatory Requirements

72-Hour Breach Rule

  • Notify DPB without undue delay
  • Submit detailed report within 72 hours
  • Inform affected users when risk of harm exists
  • Maintain evidence & justification for each breach response

Consent Manager Requirements

  • India-incorporated; net worth ≥ ₹2 crore
  • Board-certified interoperable platform
  • Plays the role of Fiduciary toward Data Principals
  • Maintain consent/notice records for 7 years

 

Penalties You Should Be Aware Of

Upto INR 250 crore : Failure to implement reasonable security safeguards.

Upto INR 2o0 crore : Failure to notify personal data breaches

Upto INR 200 crore : Violations in children’s data processing.

Upto INR 150 crore : Non-compliance by SDFs.

Upto INR 50 crore : Other violations

Note : Data Protection Board will assess penalties based on the severity and duration of the violation, the type and volume of data involved, the impact on individuals, organisational intent and cooperation, remediation efforts, and any unfair gain or repeat non-compliance.

Topics in this article

Related

Newsletter

FRM Regulatory Pulse- August 2026

Executive Summary The second edition of the Uniqus "Regulatory Pulse" bulletin covers key regulatory developments and supervisory themes observed across India and the Middle East over the quarter ended June 2026. Consistent with the series, this publication focuses on banking...

Newsletter

Sustainability & Climate Pulse- August 2026

In the News Global Record Climate Finance by Multilateral Development Banks Reaches USD 163 Billion in 2025 In a significant boost for global climate action, multilateral development banks (MDBs) achieved a record climate finance total of USD 163 billion in...

Early Impressions

FASB’s Proposed Accounting Standards Update

Executive Summary On June 10, 2026, the FASB issued a proposed Accounting Standards Update that would clarify the discount rate used to measure the benefit obligation under Subtopic 715-30, Compensation—Retirement Benefits—Defined Benefit Plans—Pension, for certain market-return cash balance plans. The...

Ask Uniqus
Your AI Knowledge Assistant
AI
Hi 👋 How can I help you today?

Download the pdf of this publication


This will close in 0 seconds