DPDP Rules 2025 Timeline: What Applies When

The short answer
The DPDP Rules 2025 timeline has three stages, all counted from the day the Rules were published in the Gazette of India, 13 November 2025. The Data Protection Board, the definitions and the Board's procedures started that day. The Consent Manager rules start one year later, on 13 November 2026. The main duties for every business, including notices, consent, security safeguards, breach notification, children's data, retention and Data Principal rights, start eighteen months later, on 13 May 2027. Until then, the CERT-In directions of 2022 still require data breaches to be reported within 6 hours, and the older IT Act rules on sensitive personal data still apply.
Dates were checked on 11 October 2026 (October 2026) against the Gazette text of the Rules. A proposal to shorten the timeline was under discussion in 2026, so check the e-Gazette for any amendment before you rely on a date.
Why 13 November 2025, not 14?
You will see both dates online. The Gazette text of the DPDP Rules, G.S.R. 846(E) is dated Thursday 13 November 2025, and rule 1 counts each stage from "the date of publication of this Gazette". The issue was uploaded early on 14 November, and the government's own PIB backgrounder of 17 November 2025 says the Rules were notified on 14 November. Some advisers therefore count each stage one day later. The safe course is to plan for the earlier date, 13 November, and treat the next day as a buffer, not a deadline.
The three stages at a glance
Stage | Date | Rules that start | What it means in practice |
|---|---|---|---|
1. On publication | 13 November 2025 | Rules 1, 2 and 17 to 21 | Definitions; the Data Protection Board, its members, meetings, digital office and staff |
2. After one year | 13 November 2026 | Rule 4 | Consent Managers can register with the Board and must meet their duties |
3. After eighteen months | 13 May 2027 | Rules 3, 5 to 16, 22 and 23 | Main duties for Data Fiduciaries; appeals; government calls for information |
The Act's own sections were brought in by a matching notification, G.S.R. 843(E), in the same three groups. The Data Protection Board of India was established from 13 November 2025, with its head office in the National Capital Region.

What applies now, in October 2026?
Only the first stage is in force. The definitions and the Board exist, and the Board can be set up and run, but the main duties of Data Fiduciaries do not yet apply. That does not mean there are no rules today:
- CERT-In directions. The directions of 28 April 2022 require service providers, intermediaries, data centres, body corporates and government bodies to report listed cyber incidents, including data breaches and data leaks, within 6 hours of noticing them, and to keep ICT logs for a rolling 180 days within India.
- IT Act section 43A and the 2011 rules on sensitive personal data. These keep applying until the DPDP Act's main provisions start, when section 43A is removed.
- Sector rules. RBI, SEBI and IRDAI directions on cyber security and incident reporting apply to regulated entities now, and keep applying alongside the DPDP Act later.
13 November 2026: Consent Managers
A Consent Manager is a registered intermediary that lets a person give, review and withdraw consent across many Data Fiduciaries through one platform. Rule 4 sets out registration with the Board and the Consent Manager's duties, and the First Schedule sets the conditions: among them, it must be a company incorporated in India with a net worth of at least ₹2 crore. Most businesses will not become Consent Managers, but if your customers might use one, your consent system should be able to accept and honour consent given through it.
13 May 2027: the main duties
On this date the rules that most organisations care about start: rule 3 notices, reasonable security safeguards (rule 6), breach intimation to the Board and to people (rule 7), retention and erasure periods (rule 8), the published contact person (rule 9), verifiable parental consent for children (rules 10 to 12), Significant Data Fiduciary duties (rule 13), Data Principal rights (rule 14), transfers outside India (rule 15) and the research exemption (rule 16), together with appeals (rule 22).
Duty from 13 May 2027 | Rule | One-line test |
|---|---|---|
Standalone notice with itemised data and purposes | 3 | Could a person understand it without the terms of service? |
Security safeguards, one-year logs | 6 | Encrypted, access-controlled, logged, backed up? |
Breach: Board without delay, detailed report in 72 hours, people told | 7 | Who files at 3 a.m. on a Sunday? |
Deemed erasure for large platforms, 48-hour warning | 8 | Do inactive accounts expire on schedule? |
Verifiable parental consent for under-18s | 10 | Can you prove the parent is an identifiable adult? |
Rights and grievances, at most 90 days | 14 | Is the response period published and met? |

Worked example: what the dates mean for a product launch
A launch in March 2027. A product team plans to launch an app on 1 March 2027 and says DPDP "does not apply yet". How long until the main duties start?
- Days left in March from 1 March: 30
- April: 30 days
- 1 May to 13 May: 13 days
- Total: 30 + 30 + 13 = 73 days
Ten weeks after launch the app must have rule 3 notices, consent records, breach procedures and retention in place. Building them in before launch costs far less than retrofitting them ten weeks later.
An inactive shopper. An e-commerce platform with 3 crore registered users (above the 2 crore threshold in the Third Schedule) last saw a customer on 20 June 2027. Assume she never returns.
- The three years run from the latest of her last contact (20 June 2027) and commencement (13 May 2027): 20 June 2027
- Three years later: 20 June 2030
- The rule 8 warning must reach her at least 48 hours before: by 18 June 2030
If she logs in after the warning, the period restarts and the account stays.
Could the timeline be shortened?
Possibly. In January 2026, Storyboard18 reported that MeitY had asked industry for views on cutting the eighteen-month period to twelve months, with feedback due by 4 February; officials said no final decision had been made. Twelve months from 13 November 2025 would be 13 November 2026, only weeks after this guide was written. No amending notification had been published when we checked on 11 October 2026.
The practical answer is the same either way: plan to be ready well before 13 May 2027 and fix your highest-risk gaps (security safeguards, breach response, children's data) first. Our DPDP Act compliance checklist turns the duties into twelve jobs with a worked gap assessment.
The penalties start with the duties
The penalty Schedule applies to breaches of the duties as they come into force. The ceilings are ₹250 crore for failing to take reasonable security safeguards, ₹200 crore each for failing to notify a breach and for breaching the children's data duties, ₹150 crore for Significant Data Fiduciary duties and ₹50 crore for other breaches. Breach reporting rules are tightening in other markets too; see how Europe's product rules work in our post on the EU Cyber Resilience Act's 24-hour reporting.
Learn the DPDP Act and Rules, free
The free DPDP Act Compliance: India's Data Protection Law in Practice course starts with exactly this question, which duties are in force on which date, and then covers roles, lawful grounds, notices, rights, children's data, safeguards and breach response with CERT-In's six-hour rule, retention, processors and transfers, Significant Data Fiduciaries, the Board and penalties, sector overlays and a compliance roadmap to 13 May 2027.
It is a free course with a verifiable certificate of completion, and anyone can check a certificate on our verification page. It is not legal advice and not a government certification. Start the DPDP Act compliance course and check each date against the e-Gazette as you go.
To learn this with an instructor in a classroom, see classroom PLC training in Bangalore.
Frequently asked questions
Q: When were the DPDP Rules 2025 notified?
A: The Gazette issue carrying the Rules, G.S.R. 846(E), is dated 13 November 2025. It was uploaded early on 14 November, so some sources give that date; plan your deadlines from 13 November.
Q: When do the main DPDP duties start?
A: On 13 May 2027, eighteen months after publication. Notices, consent, security safeguards, breach notification to the Board and to people, retention, children's data and Data Principal rights all start then, unless an amendment brings the date forward.
Q: What is in force under the DPDP Act today?
A: As of October 2026, only the first stage: the definitions and the Data Protection Board, with rules 1, 2 and 17 to 21. CERT-In's six-hour incident reporting and the IT Act's sensitive personal data rules still apply in the meantime.
Q: When do the Consent Manager rules start?
A: On 13 November 2026, one year after publication. Rule 4 covers registration with the Board and the Consent Manager's duties.
Q: Will the DPDP compliance timeline be shortened to 12 months?
A: MeitY sought industry views on that in January 2026, but no amending notification had been published when we checked on 11 October 2026. Check the e-Gazette and meity.gov.in before relying on 13 May 2027.
Q: Is there a free course on the DPDP Rules 2025?
A: Yes. EDWartens' DPDP Act Compliance course is a free course with a verifiable certificate of completion, covering the Act, the DPDP Rules 2025, the commencement dates and a compliance roadmap.
Learn this, free
The courses that teach this
Every lesson, the written notes and the practice are free with an account. Only the certificate is optional and paid.



