Email WhatsApp
DPDP Rules 2025 — compliance timeline

DPDP timeline and compliance deadlines under the DPDP Rules, 2025.

The DPDP Rules, 2025 did not set one DPDP deadline — they phase commencement across three key dates over 18 months. Here is what happens on each date and what organisations should prepare before 13 May 2027.

DPDP Rules full form and purpose

The full form of the DPDP Rules is the Digital Personal Data Protection Rules, 2025. They provide operational detail for the Digital Personal Data Protection Act, 2023 and specify how important parts of the framework commence and work in practice.

When the Ministry of Electronics and Information Technology notified the DPDP Rules on 13 November 2025, it phased the rollout deliberately rather than switching everything on at once. That design rewards organisations that use the runway to prepare — and quietly penalises the ones that read "May 2027" and relax.

Phase 1 — 13 November 2025: Board legally established

This phase covers the establishment of the Data Protection Board of India (DPB) — the body that will investigate complaints, issue directions, and eventually impose penalties. The Board has been legally established, and its appointments and operational arrangements are being completed. Most substantive compliance obligations aren't enforceable yet, but the enforcement architecture is being assembled — organisations that leave awareness training until the deadline are choosing to prepare against a functioning regulator rather than a nascent one.

Phase 2 — 13 November 2026: Consent Managers

The Consent Manager registration framework opens — independent, interoperable platforms through which Data Principals will be able to manage and withdraw consent across services. Most organisations won't become Consent Managers themselves, but this phase marks the point at which the consent-management architecture becomes available for organisations preparing for the final phase.

The gap between Phase 2 and the final deadline is exactly six months. Data mapping, consent architecture, rights-request workflows, and breach-response processes typically take most mid-size organisations far longer than six months to build properly — which means the honest planning window is really now, not November 2026.

Phase 3 — 13 May 2027: the main DPDP compliance deadline

For most organisations, 13 May 2027 is the main DPDP deadline because this is the operative date for most substantive obligations. Valid consent and notice mechanisms, Data Principal rights infrastructure, the two-stage breach notification framework, and security safeguards under Rule 6 all take effect. After the Board's inquiry and decision process, monetary penalties under the Schedule may be imposed. There is no announced general grace period beyond this date. For the detailed breach report required by Rule 7 within 72 hours, the Board may allow a longer period on a written request from the Data Fiduciary.

DPDP compliance timeline: what to do before each deadline

WindowWhat to be doing
NowMap what personal data you hold, where, and why. Confirm you understand your own obligations.
Before Nov 2026Consent notices drafted, consent capture/withdrawal flows live, employee awareness training completed.
Nov 2026 – May 2027Rights-request handling with clear internal ownership, breach-response runbook tested, retention and erasure practices in place.

Employee awareness training sits early in that list deliberately — it's one of the faster controls to put in place, and many data incidents begin with an employee who simply did not recognise the situation. See how Abhisam's DPDPA training for employees covers Data Principal requests, breaches, everyday handling mistakes and practical workplace decisions.