DPDP Compliance Deadlines: What Changes on 14 November 2026 and 14 May 2027
Most companies believe DPDP compliance is a single deadline in 2027. It is not. The Rules commence in three stages, and the stage that activates enforcement is closer than almost anyone realises.
The short answer
The Digital Personal Data Protection Rules, 2025 were notified as G.S.R. 846(E) on 13 November 2025. Rule 1 sets a staggered commencement in three stages rather than a single deadline:
- 13 November 2025 — Rules 1, 2 and 17 to 21 came into force on the date of publication. This is the machinery of the regime, including the Data Protection Board.
- 14 November 2026 — Rule 4 comes into force one year after publication. This governs the registration and obligations of Consent Managers.
- 14 May 2027 — Rules 3, 5 to 16, 22 and 23 come into force eighteen months after publication. This is the bulk of the substantive obligations.
Two notifications, not one
This is the part most summaries miss. The Rules were notified as G.S.R. 846(E), but a separate notification, G.S.R. 843(E), issued the same day under section 1(2) of the Act, commences the Act’s own sections on the same three-stage schedule. You need both to know what actually applies.
- On publication (14 November 2025) — section 1(2), section 2, sections 18 to 26, sections 35 and 38 to 43, and section 44(1) and (3). This constitutes the Data Protection Board and switches on the rule-making powers.
- 14 November 2026 — section 6(9) and section 27(1)(d), alongside Rule 4. This is the Consent Manager layer.
- 14 May 2027 — sections 3 to 5, section 6(1) to (8) and (10), sections 7 to 10, sections 11 to 17, section 27 apart from (1)(d), sections 28 to 34, sections 36 and 37, and section 44(2).
So is there really any urgency?
Yes, but not the kind usually claimed. There is no penalty exposure under the Act before 14 May 2027, and anyone telling you otherwise has not read G.S.R. 843(E). The urgency is that the obligations arriving on that date are engineering changes to live systems: logging with a year of retention under Rule 6, erasure against a retention clock under Rule 8, and a working rights process under Rule 14. Those are not quarter-end tasks.
What is already in force today
Rules 17 to 21 commenced on publication, and G.S.R. 843(E) brought sections 18 to 26 of the Act into force on the same date. Together these constitute the Data Protection Board and govern the appointment of its Chairperson and Members. What did not commence is section 27, which contains the Board’s powers to inquire into a personal data breach or a complaint and to impose penalties. That arrives on 14 May 2027.
What changes on 14 November 2026
Rule 4 commences, bringing the Consent Manager framework into effect. A Consent Manager is a registered intermediary through which a Data Principal can give, manage, review and withdraw consent across multiple Data Fiduciaries from a single interface.
The conditions for registration are set out in Part A of the First Schedule. Among them, the applicant must be a company incorporated in India and must have a net worth of not less than two crore rupees. The Schedule also requires sufficient technical, operational and financial capacity, and sound general character of management.
For most companies, the significance is not that they will become a Consent Manager. It is that the consent infrastructure they are expected to interoperate with begins to exist from this date.
What changes on 14 May 2027
This is the largest commencement, covering Rules 3, 5 to 16, 22 and 23. It includes the obligations most organisations think of as “DPDP compliance”:
- Rule 3 — the form and content of the notice given by a Data Fiduciary to a Data Principal.
- Rule 6 — reasonable security safeguards, which set out a minimum list of technical controls rather than a general standard.
- Rule 7 — intimation of a personal data breach to affected Data Principals and to the Board.
- Rule 8 — erasure of personal data once the specified purpose is no longer being served, read with the Third Schedule.
- Rule 10 — verifiable parental consent before processing a child’s personal data.
- Rule 13 — additional obligations of a Significant Data Fiduciary, including an annual Data Protection Impact Assessment and audit.
- Rule 14 — the mechanism through which Data Principals exercise their rights.
Why eighteen months is shorter than it sounds
The obligations that commence in May 2027 are not policy documents that can be drafted in the final quarter. Rule 6 requires encryption or equivalent protection, access control, logging and monitoring, and backups. Rule 8 requires the ability to identify and erase personal data against a defined retention clock. Rule 14 requires a working process for handling rights requests.
These are engineering changes to live systems. An organisation starting in early 2027 is starting a build with a hard external deadline and no room to discover that its data is spread across systems nobody has mapped.
The eighteen-month runway is not a grace period granted after the obligations began. It is the time the government allowed for the work to be done before they begin. Treating it as slack is the most common planning error we see.
Infosek Team
A realistic sequence for the time remaining
- Now to end of 2026 — data mapping and a record of processing. You cannot apply retention rules or answer a rights request against data you have not inventoried.
- Now to end of 2026 — assess against Rule 6 specifically. It lists minimum controls, so the gap analysis is concrete rather than interpretive.
- Early 2027 — rebuild consent notices for Rule 3, which requires the notice to be understandable independently of any other information the Data Fiduciary provides.
- Early 2027 — build and test the breach procedure required by Rule 7, including the seventy-two hour reporting path to the Board.
- Before May 2027 — confirm whether you are a Significant Data Fiduciary, because Rule 13 adds an annual DPIA and audit obligation that takes time to schedule.
Where to start
The first question is not what to build. It is which obligations actually apply to you, because a Significant Data Fiduciary, an ordinary Data Fiduciary and a Data Processor carry materially different burdens under these Rules.
Common questions
When do the DPDP Rules 2025 come into force?
The DPDP Rules 2025 commence in three stages under Rule 1. Rules 1, 2 and 17 to 21 came into force on 14 November 2025, the date of publication. Rule 4, covering Consent Managers, comes into force one year later on 14 November 2026. Rules 3, 5 to 16, 22 and 23 come into force eighteen months after publication, on 14 May 2027.
Is there a grace period after 14 May 2027?
No grace period has been notified. The eighteen-month runway between publication and the commencement of Rules 3 and 5 to 16 is itself the transition period.
Not sure which obligations apply to you?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment