Skip to main content
Compliance Guides
DPDPA
DPDP Rules 2025
Compliance Deadline
2027
Implementation Timeline
India

The DPDP Act Deadline Calendar: Every Date Between Now and 13 May 2027

The DPDP Rules 2025 set two hard dates: 13 November 2026 for the Consent Manager framework and 13 May 2027 for every core obligation. MeitY has proposed compressing that further. Here is the month-by-month readiness calendar Indian businesses should be working to — with what to finish in each quarter.

Consently Team
10 June 2026
10 min read

Short answer: The DPDP Rules 2025 were notified on 13 November 2025 and phase in over 18 months. The Consent Manager framework becomes operational on 13 November 2026. Every core obligation — notice, consent, security safeguards, breach reporting, and Data Principal rights — becomes enforceable on 13 May 2027. There is no grace period after that date.

The Two Dates That Matter

Most DPDP coverage in India collapses into a single vague statement: "compliance is due in 2027." That is not how the Rules are structured. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 with a deliberately staggered commencement, and different obligations switch on at different times.

PhaseEffective dateWhat switches on
Phase I13 November 2025Rules notified. Data Protection Board of India (DPBI) constituted; definitions and Board machinery in force.
Phase II13 November 2026Consent Manager framework under Rule 4 becomes operational. Registration with the DPBI opens and the eligibility bar applies.
Phase III13 May 2027All substantive obligations: itemised notice, valid consent, security safeguards, 72-hour breach notification, Data Principal rights, retention limits, children's data rules.

Eighteen months sounds generous. It is not, because the work is sequential — you cannot build a rights-request workflow before you know what data you hold, and you cannot write an itemised notice before you have mapped your processing purposes. Organisations that start the data-mapping step in early 2027 will not finish.

The Timeline May Get Shorter, Not Longer

Key insight: planning to the 2027 date assumes the 2027 date holds. On 23 January 2026, MeitY held stakeholder consultations proposing to compress the compliance window from 18 months to 12, which would move the final deadline from 13 May 2027 to 13 November 2026, with Significant Data Fiduciaries expected to comply first. Industry feedback was sought by 4 February 2026.

Two things follow from that. First, the conservative planning date for a large or regulated organisation is November 2026, not May 2027. Second, even if the compression is not adopted, the direction of travel is clear: the regulator wants faster, not slower. In May 2026, MeitY invited applications for the DPBI Chairperson and four Members — the step that converts the Board from a statutory entity on paper into an operating regulator with the staff to act on complaints.

The practical reading for 2026 is soft enforcement: guidance, warnings, and correspondence rather than penalty orders. November 2026 is widely expected to mark the shift toward active supervision.

The Month-by-Month Readiness Calendar

Work backwards from 13 May 2027. Each quarter below assumes the previous quarter's output exists.

Q3 2026 (Jul–Sep): Know What You Hold

Nothing downstream works without this. The deliverable is a written record of processing, not a feeling.

  • Data inventory — every system that touches personal data: CRM, marketing automation, support desk, payroll, analytics, ad pixels, WhatsApp, spreadsheets on someone's laptop.
  • Purpose mapping — for each dataset, the specific purpose it is processed for. "Business operations" is not a purpose. "Sending order-status SMS" is.
  • Processor register — every third party that processes personal data on your behalf, with the contract clause that binds them.
  • Legal-basis triage — separate what runs on consent from what runs on the legitimate-uses grounds in Section 7, especially employment data.

Q4 2026 (Oct–Dec): Notice and Consent Machinery

This is the quarter that overlaps the 13 November 2026 Consent Manager date, and the quarter where technology decisions get locked in.

  • Rebuild the consent notice to be itemised and standalone — one purpose, one toggle, no bundling. See our Rule 3 itemised notice guide for the exact requirements.
  • Ship multilingual notices. The Act requires the notice to be available in English or any of the 22 languages in the Eighth Schedule, at the Data Principal's option.
  • Deploy consent capture and withdrawal — withdrawal must be as easy as giving consent. A one-click banner with a five-email withdrawal process fails.
  • Start recording consent artefacts — which purpose, which notice version, what timestamp. If you cannot reproduce the notice a user saw on the day they consented, you cannot prove consent.

Q1 2027 (Jan–Mar): Rights, Retention, and Breach

  • Data Principal rights workflow — access, correction, erasure, grievance redressal, and nomination. Publish the contact channel and staff it.
  • Retention and erasure — implement the Rule 8 clocks, including the three-year inactivity rule for the specified classes of data fiduciary. See our retention and erasure guide.
  • Breach response — the notification obligation runs on a very short clock. Rehearse it before you need it; our 72-hour breach notification guide covers the mechanics.
  • Security safeguards — encryption, access control, logging, and retention of logs. This is the obligation carrying the ₹250 crore maximum penalty.

Q2 2027 (Apr–May): Evidence and Dry Runs

The last quarter is not for building. It is for proving the build works.

  • End-to-end DSAR dry run — a real request, answered inside your stated SLA, with the evidence trail retained.
  • Consent-record audit — pick ten users at random and reconstruct their full consent history against notice versions.
  • Breach tabletop — simulate a breach and time the notification.
  • Vendor attestations — confirm every processor contract carries the required obligations.

What Non-Compliance Costs

The penalty schedule under the DPDP Act 2023 is set in absolute rupee terms rather than a percentage of turnover, which makes it unusually punishing for mid-size businesses.

FailureMaximum penalty
Failure to take reasonable security safeguards₹250 crore
Failure to notify a personal data breach₹200 crore
Breach of obligations relating to children's data₹200 crore
Breach of additional obligations of a Significant Data Fiduciary₹150 crore
Breach of any other provision₹50 crore

A ₹50 crore residual category is worth reading twice. It means an obligation with no specific entry — a defective notice, an ignored rights request — still carries an eight-figure exposure. Our penalties breakdown covers how the Board is directed to determine quantum.

Who Is Actually in Scope

Two scoping questions come up in every readiness conversation, and both have short answers that surprise people.

Does it apply to businesses outside India?

Yes, where the processing relates to offering goods or services to Data Principals within India. A Singapore SaaS company with Indian customers, a US e-commerce site shipping to India, a UK analytics vendor processing Indian user data — all in scope. The Act's extraterritorial reach mirrors the GDPR's, and it does not depend on having an Indian entity, office, or bank account.

The practical consequence for foreign businesses is uncomfortable: you need Indian-language notice capability, an India-facing grievance channel, and consent records that survive scrutiny by a regulator you have never dealt with. Most global CMPs treat all of this as a configuration afterthought.

Does it apply to offline and paper data?

No. The Act governs digital personal data — data in digital form, or non-digital data that is subsequently digitised. A paper form in a filing cabinet is out of scope until someone scans it or types it into a system. In practice this exclusion is narrower than it sounds, because almost everything gets digitised eventually, and the moment it does the Act applies to it in full.

What This Costs

Budget conversations stall because nobody has a number. Rough shape of a mid-size Indian company's programme, assuming no existing privacy function:

WorkstreamTypical effortWho does it
Data inventory and purpose mapping6–10 weeksInternal, cross-functional
Legal review and notice drafting3–5 weeksExternal counsel
Consent platform deployment2–6 weeksVendor plus engineering
Rights workflow build4–8 weeksEngineering plus support ops
Retention and erasure automation4–8 weeksEngineering
Ongoing operationContinuousNamed owner, part- or full-time

Roughly six months of calendar time for an organisation that starts clean and does not stall. That is why a start date in Q3 2026 is comfortable, Q4 2026 is tight, and Q1 2027 means shipping something incomplete. Our DPDP compliance cost breakdown goes into the numbers.

The Three Mistakes That Blow the Deadline

1. Treating It as a Banner Project

A cookie banner addresses one narrow slice of one obligation. The DPDP Act governs all digital personal data — your CRM, your HR records, your support tickets, your WhatsApp broadcasts. Organisations that scope the project as "install a banner" discover in Q1 2027 that they have no rights workflow, no retention policy, and no processor register.

2. Waiting for More Clarity

There is always another clarification coming. Meanwhile the obligations that carry the biggest penalties — security safeguards, breach notification, valid consent — have been clear since the Act passed in August 2023. Nothing about the data-inventory work depends on further guidance.

3. Building Consent Records You Cannot Query

Plenty of businesses will collect consent and store it as a boolean in a user table. When the Board asks for the consent record of one specific person on one specific date against one specific notice version, a boolean is not an answer. Consent evidence has to be immutable, timestamped, versioned against the notice text, and retrievable per Data Principal.

Frequently Asked Questions

What is the final DPDP Act compliance deadline?

13 May 2027. That is when the substantive obligations under the DPDP Rules 2025 — notice, consent, security safeguards, breach notification, Data Principal rights, and retention limits — become enforceable. The earlier date of 13 November 2026 applies specifically to the Consent Manager framework under Rule 4.

Is there a grace period after 13 May 2027?

No. The 18-month phase-in period is itself the grace period. From 13 May 2027 the obligations are enforceable and the Data Protection Board can impose penalties of up to ₹250 crore for security-safeguard failures.

Could the DPDP deadline move earlier than May 2027?

Possibly. MeitY held stakeholder consultations on 23 January 2026 proposing to compress the compliance window from 18 months to 12, which would bring the deadline to 13 November 2026 with Significant Data Fiduciaries complying first. Feedback was sought by 4 February 2026. Planning to November 2026 is the conservative approach for regulated and large organisations.

Does the DPDP Act apply to small businesses and startups?

Yes. The Act has no turnover or headcount threshold. Any entity that determines the purpose and means of processing digital personal data is a Data Fiduciary, whether it has five employees or fifty thousand. Only the additional Significant Data Fiduciary obligations are threshold-based. Our startup guide covers the minimum viable compliance set.

When should we start if we have not begun?

Now, and specifically with the data inventory. The inventory typically takes six to ten weeks in a mid-size organisation because it requires interviewing every team that touches customer data. Every other deliverable — notice, consent design, rights workflow, retention rules — depends on its output, so it sits on the critical path.

What if we already comply with GDPR?

GDPR compliance is a strong head start but not a substitute. The DPDP Act is stricter in some places — it recognises no "legitimate interests" basis for commercial processing, mandates notice availability in 22 Scheduled languages, and imposes verifiable parental consent for all users under 18 rather than a lower age threshold. See our analysis of where DPDPA is stricter than GDPR.

Where Consently Fits

Consently is built natively for the DPDP Act rather than retrofitted from a GDPR product: itemised per-purpose consent, notices in all 22 Scheduled languages, immutable zero-PII consent records with notice versioning, Data Principal rights workflows, verified age consent, breach management, and India-resident infrastructure. If you are working backwards from 13 May 2027, the consent and records layer is the part that takes longest to get right — and the part the Board will ask about first. Talk to us about your readiness plan.

Share this article

Related Articles

Compliance Guides

DPDP Consent Manager Registration: Eligibility, the ₹2 Crore Net Worth Bar, and the Application Checklist

The Consent Manager framework goes live on 13 November 2026. Registration requires incorporation in India, a minimum net worth of ₹2 crore, and demonstrated technical capability to run consent across fiduciaries. Here is who qualifies, what the application needs, and — importantly — why most businesses should not apply.

14 Jul 20269 min
Compliance Guides

Employee Data Under the DPDP Act: What Indian HR Teams Must Fix Before 2027

HR holds more sensitive personal data than marketing ever will — Aadhaar, bank details, medical records, background checks, CCTV, and now productivity monitoring. The DPDP Act covers all of it. The good news: much of it does not need consent. The bad news: most HR teams have no idea which parts do.

10 Jul 20269 min
Compliance Guides

Significant Data Fiduciary Under DPDP: Obligations, DPO Requirements, Audits and Cross-Border Rules

Being designated a Significant Data Fiduciary adds four obligations no ordinary Data Fiduciary has: a resident DPO, an independent data auditor, annual Data Protection Impact Assessments, and algorithmic due diligence. MeitY has also signalled cross-border restrictions for SDFs. Here is what the designation means and how to prepare.

6 Jul 202610 min