Infosek
INFOSEK

Is the DPDP Act Already in Force? What Applies Today

Partly, and the honest answer is narrower than most summaries suggest. The machinery is in force; almost none of the obligations are.

Is the DPDP Act Already in Force? What Applies Today

The short answer

Partly, and the part that is in force matters more than most organisations realise.

The Digital Personal Data Protection Act, 2023 was passed and received assent in August 2023. The Rules that operationalise it were notified as G.S.R. 846(E) on 13 November 2025. Under Rule 1(2), Rules 1, 2 and 17 to 21 came into force on that date. Those rules include the constitution and functioning of the Data Protection Board of India.

What is in force right now

Rules 17 to 21 are administrative in character, which is precisely why they were commenced first. The government put the adjudicating machinery in place before the duties it would adjudicate.

What is not yet in force

The obligations that most organisations think of as DPDP compliance are not yet live. Under Rule 1(3) and 1(4):

So can you be penalised today?

This deserves a careful answer rather than a reassuring one.

The duties whose breach attracts the largest penalties — failing to take reasonable security safeguards, failing to notify a breach — sit in rules that commence in May 2027. In that narrow sense, the exposure before that date is limited.

But two things are already true. The Board exists and operates under rules in force. And the Act itself, as distinct from the Rules, has been law since 2023. An organisation treating the period until May 2027 as a compliance holiday is making an assumption about enforcement appetite, not relying on a legal exemption.

There is a difference between an obligation that has not yet commenced and a regulator that does not yet exist. Only the first is true here.

Infosek Team

Why the 2027 assumption is expensive even if it is legally safe

Set enforcement aside entirely. The obligations arriving in May 2027 require system changes, not paperwork. Rule 6 sets out minimum security controls including encryption or equivalent, access control, and logging with a one year retention period for logs. Rule 8 requires erasure against a defined retention clock. Rule 14 requires a working rights request process.

An organisation that begins in 2027 will discover its data map does not exist, its logging does not meet Rule 6(1)(e), and its retention policy has never been enforced in code. None of that is fixable in a quarter.

What is genuinely worth doing before November 2026

Common questions

Is the DPDP Act in force in India?

Partly. The Digital Personal Data Protection Act, 2023 received assent in August 2023, and the DPDP Rules 2025 were notified as G.S.R. 846(E) on 13 November 2025. Rules 1, 2 and 17 to 21 came into force on publication, 14 November 2025, which includes the provisions establishing the Data Protection Board of India. The substantive obligations on Data Fiduciaries commence on 14 November 2026 and 14 May 2027.

Can a company be penalised under DPDP before May 2027?

The Data Protection Board has been constituted and the rules governing its functioning are in force. The substantive duties whose breach attracts most penalties commence later, on 14 November 2026 and 14 May 2027. The risk before those dates is lower but it is not the zero that many organisations assume.

Want to know where you actually stand?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment