DPDP Rules, 2025
Next deadline:
13 May 2027
Applies to: All Data Fiduciaries processing digital personal data connected to India (extraterritorial)
India's first comprehensive personal-data regime. The DPDP Rules were notified on 14 November 2025 and roll out over an 18-month window. Phase 1 (Nov 2025) established the Data Protection Board of India. Phase 2 (13 Nov 2026) brings the Consent Manager framework into force — registration, obligations and DPBI penalty powers; Consent Managers require a minimum net worth of INR 2 crore and must be incorporated in India. Phase 3 (13 May 2027) activates all remaining substantive obligations: notice, consent, data-principal rights, breach intimation, children's data, cross-border processing and the additional Significant Data Fiduciary duties (DPIAs, independent audits, DPO, algorithmic due-diligence). Breach notification to the Board is required within 72 hours. Penalties run up to INR 250 crore per contravention.
Why it matters
Treat 2026 as the build year, not a grace period — the Q1 2026 enforcement actions against app developers show the Board will act before the May 2027 hard date. For a CII CISO the live work is legacy-data revalidation: historical datasets without demonstrable lawful consent are the first exposure the Board has tested. Put two dates on the board calendar now — 13 Nov 2026 (Consent Manager integration readiness) and 13 May 2027 (full liability). Watch one moving variable closely: MeitY proposed in January 2026 to compress the Significant Data Fiduciary compliance window from 18 to 12 months — if gazetted, SDF obligations (DPIAs, independent audits, algorithmic auditing, DPO) could fall due around November 2026 rather than May 2027. If you are anywhere near the SDF thresholds, plan to the earlier date; that machinery takes a year to stand up, so starting in 2027 is starting late.