DPDP Rules, 2025, Are Here.
With the Digital Personal Data Protection Rules, 2025 now in force, India’s data protection regime is fully operational — and the 18-month countdown to full compliance by May 2027 has begun.
Start Early. Don’t Race the May 2027 Deadline.
- Build Phase: Nov 2025 – Nov 2026: Establish foundations — policies, inventories, governance, and core privacy processes.
- Implement Phase: Nov 2026 – May 2027: Deploy, integrate, and test operational controls across the organization.
- Operational Phase: From May 2027: Run, monitor, and continually mature your end-to-end DPDP compliance programme.
Those who wait will be racing against penalties. Privacy done early is privacy done right.
Why this matters?
Why DPDPA Compliance Can’t Wait
- Applies to most organizations handling digital personal data in India.
- Full compliance + penalties kick in from 13 May 2027.
- Security failures alone can attract penalties up to INR 250 crore.
ACTIONS TO BE TAKEN FROM NOW
Phase 1: Regulatory Setup
Foundations Are Being Laid
- The Data Protection Board of India is notified and set up.
- Definitions, rule-making powers, and appeal mechanisms come into force.
Action for you: Start gap assessment and readiness planning now.
Immediate Implementation Checklist (For All Organizations)
Non-Negotiables for All Data Fiduciaries
- Gap assessment
- Updated privacy notices & policies
- Data inventory + purpose & retention mapping
- Incident & breach workflows
- Grievance redressal with SLAs
- Rights-handling processes
- DPAs & vendor alignment
- Awareness & role-based training
Note : These obligations take effect immediately and become fully enforceable as of 13 May 2027.
ACTIONS TO BE TAKEN FROM NOV 2026 TO May 2027
Phase 2: Consent Manager Ecosystem (From Nov 2026)
- Assess if a Consent Manager suits your business
- Evaluate service providers
- Plan technical & process integration
Example: An e-commerce platform integrates a Consent Manager to centralize marketing opt-ins and withdrawals across website, app, and CRM systems.
ACTIONS BEYOND MAY 2027
Phase 3: Full Obligations (From May 2027)
Full DPDPA Compliance Becomes Mandatory
- Valid legal basis (consent/legitimate use)
- Clear, accessible privacy notices
- Full Data Principal rights enablement
- Strong security, retention & deletion controls
- Children’s data safeguards
- Vendor/processor oversight
- Follow notified cross-border transfer rule
Action for you: Ensure that all controls designed in earlier phases are fully operational, thoroughly tested, and closely monitored.
If you’re a Significant Data Fiduciary (SDF)
SDFs are high-impact data fiduciaries designated based on:

Additional Duties (Before May 2027):
- India-based DPO
- Independent data auditor
- DPIAs for high-risk processing
- Board-level governance
- Structured oversight & reporting
Other Mandatory Requirements
72-Hour Breach Rule
- Notify DPB without undue delay
- Submit detailed report within 72 hours
- Inform affected users when risk of harm exists
- Maintain evidence & justification for each breach response
Consent Manager Requirements
- India-incorporated; net worth ≥ ₹2 crore
- Board-certified interoperable platform
- Plays the role of Fiduciary toward Data Principals
- Maintain consent/notice records for 7 years
Penalties You Should Be Aware Of
Upto INR 250 crore : Failure to implement reasonable security safeguards.
Upto INR 2o0 crore : Failure to notify personal data breaches
Upto INR 200 crore : Violations in children’s data processing.
Upto INR 150 crore : Non-compliance by SDFs.
Upto INR 50 crore : Other violations
Note : Data Protection Board will assess penalties based on the severity and duration of the violation, the type and volume of data involved, the impact on individuals, organisational intent and cooperation, remediation efforts, and any unfair gain or repeat non-compliance.



