Is the DPDP Act Already in Force? What Applies Today
Partly, and the honest answer is narrower than most summaries suggest. The machinery is in force; almost none of the obligations are.
The short answer
Partly, and the part that is in force matters more than most organisations realise.
The Digital Personal Data Protection Act, 2023 was passed and received assent in August 2023. The Rules that operationalise it were notified as G.S.R. 846(E) on 13 November 2025. Under Rule 1(2), Rules 1, 2 and 17 to 21 came into force on that date. Those rules include the constitution and functioning of the Data Protection Board of India.
What is in force right now
- Rules 1 and 2 — short title, commencement and definitions.
- Rules 17 to 21 — the provisions concerning the Data Protection Board, including how it deals with matters before it.
Rules 17 to 21 are administrative in character, which is precisely why they were commenced first. The government put the adjudicating machinery in place before the duties it would adjudicate.
What is not yet in force
The obligations that most organisations think of as DPDP compliance are not yet live. Under Rule 1(3) and 1(4):
- Rule 4, on Consent Managers, commences 14 November 2026.
- Rules 3, 5 to 16, 22 and 23 commence 14 May 2027. This includes notice requirements, security safeguards, breach intimation, erasure, children’s data and Significant Data Fiduciary obligations.
So can you be penalised today?
This deserves a careful answer rather than a reassuring one.
The duties whose breach attracts the largest penalties — failing to take reasonable security safeguards, failing to notify a breach — sit in rules that commence in May 2027. In that narrow sense, the exposure before that date is limited.
But two things are already true. The Board exists and operates under rules in force. And the Act itself, as distinct from the Rules, has been law since 2023. An organisation treating the period until May 2027 as a compliance holiday is making an assumption about enforcement appetite, not relying on a legal exemption.
There is a difference between an obligation that has not yet commenced and a regulator that does not yet exist. Only the first is true here.
Infosek Team
Why the 2027 assumption is expensive even if it is legally safe
Set enforcement aside entirely. The obligations arriving in May 2027 require system changes, not paperwork. Rule 6 sets out minimum security controls including encryption or equivalent, access control, and logging with a one year retention period for logs. Rule 8 requires erasure against a defined retention clock. Rule 14 requires a working rights request process.
An organisation that begins in 2027 will discover its data map does not exist, its logging does not meet Rule 6(1)(e), and its retention policy has never been enforced in code. None of that is fixable in a quarter.
What is genuinely worth doing before November 2026
- Map where personal data lives. Every later obligation depends on this and nothing else can proceed without it.
- Read Rule 6 against your current controls. It is a list, not a principle, so the gap analysis is concrete.
- Determine whether you are likely to be notified as a Significant Data Fiduciary, since Rule 13 adds an annual DPIA and audit.
- Fix your notice. Rule 3 requires it to be understandable independently of any other information you provide, which most privacy policies fail.
Common questions
Is the DPDP Act in force in India?
Partly. The Digital Personal Data Protection Act, 2023 received assent in August 2023, and the DPDP Rules 2025 were notified as G.S.R. 846(E) on 13 November 2025. Rules 1, 2 and 17 to 21 came into force on publication, 14 November 2025, which includes the provisions establishing the Data Protection Board of India. The substantive obligations on Data Fiduciaries commence on 14 November 2026 and 14 May 2027.
Can a company be penalised under DPDP before May 2027?
The Data Protection Board has been constituted and the rules governing its functioning are in force. The substantive duties whose breach attracts most penalties commence later, on 14 November 2026 and 14 May 2027. The risk before those dates is lower but it is not the zero that many organisations assume.
Want to know where you actually stand?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment