Infosek
INFOSEK

DPDP Compliance Deadlines: What Changes on 14 November 2026 and 14 May 2027

Most companies believe DPDP compliance is a single deadline in 2027. It is not. The Rules commence in three stages, and the stage that activates enforcement is closer than almost anyone realises.

DPDP Compliance Deadlines: What Changes on 14 November 2026 and 14 May 2027

The short answer

The Digital Personal Data Protection Rules, 2025 were notified as G.S.R. 846(E) on 13 November 2025. Rule 1 sets a staggered commencement in three stages rather than a single deadline:

Two notifications, not one

This is the part most summaries miss. The Rules were notified as G.S.R. 846(E), but a separate notification, G.S.R. 843(E), issued the same day under section 1(2) of the Act, commences the Act’s own sections on the same three-stage schedule. You need both to know what actually applies.

So is there really any urgency?

Yes, but not the kind usually claimed. There is no penalty exposure under the Act before 14 May 2027, and anyone telling you otherwise has not read G.S.R. 843(E). The urgency is that the obligations arriving on that date are engineering changes to live systems: logging with a year of retention under Rule 6, erasure against a retention clock under Rule 8, and a working rights process under Rule 14. Those are not quarter-end tasks.

What is already in force today

Rules 17 to 21 commenced on publication, and G.S.R. 843(E) brought sections 18 to 26 of the Act into force on the same date. Together these constitute the Data Protection Board and govern the appointment of its Chairperson and Members. What did not commence is section 27, which contains the Board’s powers to inquire into a personal data breach or a complaint and to impose penalties. That arrives on 14 May 2027.

What changes on 14 November 2026

Rule 4 commences, bringing the Consent Manager framework into effect. A Consent Manager is a registered intermediary through which a Data Principal can give, manage, review and withdraw consent across multiple Data Fiduciaries from a single interface.

The conditions for registration are set out in Part A of the First Schedule. Among them, the applicant must be a company incorporated in India and must have a net worth of not less than two crore rupees. The Schedule also requires sufficient technical, operational and financial capacity, and sound general character of management.

For most companies, the significance is not that they will become a Consent Manager. It is that the consent infrastructure they are expected to interoperate with begins to exist from this date.

What changes on 14 May 2027

This is the largest commencement, covering Rules 3, 5 to 16, 22 and 23. It includes the obligations most organisations think of as “DPDP compliance”:

Why eighteen months is shorter than it sounds

The obligations that commence in May 2027 are not policy documents that can be drafted in the final quarter. Rule 6 requires encryption or equivalent protection, access control, logging and monitoring, and backups. Rule 8 requires the ability to identify and erase personal data against a defined retention clock. Rule 14 requires a working process for handling rights requests.

These are engineering changes to live systems. An organisation starting in early 2027 is starting a build with a hard external deadline and no room to discover that its data is spread across systems nobody has mapped.

The eighteen-month runway is not a grace period granted after the obligations began. It is the time the government allowed for the work to be done before they begin. Treating it as slack is the most common planning error we see.

Infosek Team

A realistic sequence for the time remaining

Where to start

The first question is not what to build. It is which obligations actually apply to you, because a Significant Data Fiduciary, an ordinary Data Fiduciary and a Data Processor carry materially different burdens under these Rules.

Common questions

When do the DPDP Rules 2025 come into force?

The DPDP Rules 2025 commence in three stages under Rule 1. Rules 1, 2 and 17 to 21 came into force on 14 November 2025, the date of publication. Rule 4, covering Consent Managers, comes into force one year later on 14 November 2026. Rules 3, 5 to 16, 22 and 23 come into force eighteen months after publication, on 14 May 2027.

Is there a grace period after 14 May 2027?

No grace period has been notified. The eighteen-month runway between publication and the commencement of Rules 3 and 5 to 16 is itself the transition period.

Not sure which obligations apply to you?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment