---
title: "Timeline and commencement"
url: https://dpdp.myndsolution.com/wiki/faq/timeline-and-commencement/
description: "When the DPDP Act was enacted, what took effect on 13 November 2025, what follows in November 2026 and May 2027, and what binds businesses today."
kind: faq
updated: 2026-09-09
text_type: analysis
publisher: MYND Integrated Solutions
license: Official Government of India texts are reproduced verbatim (public domain / open government data). Interpretation is CC BY 4.0, MYND Integrated Solutions.
disclaimer: Not legal advice. Official text prevails over any interpretation.
html_version: https://dpdp.myndsolution.com/wiki/faq/timeline-and-commencement/
---
# Timeline and commencement

> This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation.

## When was the DPDP Act passed?

The Digital Personal Data Protection Act, 2023 was enacted as Act No. 22 of 2023 and received the President's assent on 11 August 2023, the date of its publication in the Gazette of India. Being on the statute book is not the same as being in force. [Section 1(2)](/wiki/act/section-1/) provides that the Act comes into force on such date as the Central Government may appoint by notification, and that "different dates may be appointed for different provisions". More than two years passed before the first of those dates arrived.

## What came into force on 13 November 2025?

The framework, not the obligations. [G.S.R. 843(E)](/wiki/notifications/gsr-843e-2025/), published that day, appointed the date of its own publication for section 1(2), section 2, sections 18 to 26, sections 35, 38, 39, 40, 41, 42, 43 and sub-sections (1) and (3) of section 44. In plain terms: the definitions, the whole of the chapter creating the Data Protection Board, protection for good faith action, the relationship with other laws, the bar on civil court jurisdiction, the rule-making power, and the amendments to the Telecom Regulatory Authority of India Act, 1997 and to section 8(1)(j) of the Right to Information Act, 2005. On the same day the Board itself was established ([G.S.R. 844(E)](/wiki/notifications/gsr-844e-2025/)) and fixed at four members ([G.S.R. 845(E)](/wiki/notifications/gsr-845e-2025/)).

## What happens on 13 November 2026?

Two narrow provisions, both about Consent Managers. [G.S.R. 843(E)](/wiki/notifications/gsr-843e-2025/) appoints "one year from the date of publication of this gazette" for sub-section (9) of section 6, which requires every Consent Manager to be registered with the Board, and for clause (d) of sub-section (1) of section 27, which lets the Board inquire into a breach of a condition of a Consent Manager's registration and impose a penalty. The Rules keep step: [rule 4](/wiki/rules/rule-4/), covering registration and the obligations of Consent Managers, comes into force one year after publication of the Rules ([rule 1(3)](/wiki/rules/rule-1/)). So the registration regime opens a full six months before the main obligations bite.

## What happens on 13 May 2027?

Almost everything else. [G.S.R. 843(E)](/wiki/notifications/gsr-843e-2025/) appoints "eighteen months from the date of publication of this gazette" for sections 3 to 5, sub-sections (1) to (8) and (10) of section 6, sections 7 to 10, sections 11 to 17, section 27 apart from clause (d) of sub-section (1), sections 28 to 34, 36, 37 and sub-section (2) of section 44. That is the application of the Act, the grounds for processing, notice, consent, legitimate uses, the general obligations of Data Fiduciaries, children's data, Significant Data Fiduciaries, all four rights and the duties, transfers outside India, exemptions, the Board's powers and procedure, penalties and appeals. [Rule 1(4)](/wiki/rules/rule-1/) brings rules 3, 5 to 16, 22 and 23 into force on the same footing.

## What are businesses actually bound by today?

Very little of the operative law. As of 9 September 2026 the provisions in force are those from the first phase: the definitions in [section 2](/wiki/act/section-2/), the Board chapter in [sections 18](/wiki/act/section-18/) to [26](/wiki/act/section-26/), and sections 35 and 38 to 43, plus [rules 1](/wiki/rules/rule-1/), [2](/wiki/rules/rule-2/) and [17](/wiki/rules/rule-17/) to [21](/wiki/rules/rule-21/), which concern the Board's own appointments, salaries, meetings, digital functioning and staff. No duty in Chapter II applies yet. Two changes are live and easy to miss: the Right to Information Act exemption for personal information now reads as substituted by [section 44(3)](/wiki/act/section-44/), and the Telecom Disputes Settlement and Appellate Tribunal is listed as the appellate tribunal under the DPDP Act by section 44(1).

## What are businesses not yet bound by?

Every obligation that costs money to build. Consent and notice ([sections 5](/wiki/act/section-5/) and [6](/wiki/act/section-6/), other than section 6(9)), the general obligations including accuracy, security safeguards, breach intimation, erasure and grievance redressal ([section 8](/wiki/act/section-8/)), children's data ([section 9](/wiki/act/section-9/)), the extra duties of Significant Data Fiduciaries ([section 10](/wiki/act/section-10/)), the rights of Data Principals ([sections 11](/wiki/act/section-11/) to [14](/wiki/act/section-14/)), restrictions on transfers ([section 16](/wiki/act/section-16/)) and the penalty regime ([section 33](/wiki/act/section-33/)) all commence eighteen months after 13 November 2025. Section 43A of the Information Technology Act, 2000, which the Act omits, stays on the books until section 44(2) commences on the same date.

## Does the Data Protection Board have powers today?

It exists but cannot yet adjudicate. Sections 18 to 26, which establish the Board and govern its composition, appointments, resignation, proceedings, officers and the Chairperson's powers, have been in force since 13 November 2025 ([G.S.R. 843(E)](/wiki/notifications/gsr-843e-2025/)), and the Board was established with its head office in the National Capital Region ([G.S.R. 844(E)](/wiki/notifications/gsr-844e-2025/)). But [section 27](/wiki/act/section-27/), which confers its powers and functions, and [section 28](/wiki/act/section-28/), which sets out its procedure, are not yet in force, except for section 27(1)(d) from November 2026. Until then there is no live route for a Data Principal's complaint or a breach intimation to reach it.

## Do the Rules commence on the same dates as the Act?

They mirror it, with one small difference in shape. [Rule 1(2)](/wiki/rules/rule-1/) brings rules 1, 2 and 17 to 21 into force on the date of publication in the Official Gazette, matching the Act's first phase, which is why the machinery for appointing and paying the Board was ready from day one. [Rule 1(3)](/wiki/rules/rule-1/) sets rule 4 at one year after publication, matching section 6(9). [Rule 1(4)](/wiki/rules/rule-1/) sets rules 3, 5 to 16, 22 and 23 at eighteen months after publication, matching the Act's third phase. The Rules count from the date of publication of their own gazette; the Act counts from the date of publication of the commencement notification. Both were published on 13 November 2025.

## Why does the Third Schedule mention the commencement of the Rules?

Because the erasure clock has a floor. For the three classes of large platforms in the [Third Schedule](/wiki/rules/schedule-3/), personal data must be erased three years from the date on which the Data Principal last approached the Data Fiduciary for performance of the specified purpose or exercise of her rights, "or the commencement of the Digital Personal Data Protection Rules, 2025, whichever is latest". Long dormant accounts therefore do not fall due for erasure the moment the rule switches on. The Rules do not say which of their three commencement dates this phrase points to, and the Schedule as printed leaves the question open.

## What has the Government not yet notified?

Several powers in the Act are unused in the official sources this wiki mirrors. No Data Fiduciary or class of Data Fiduciaries has been notified as a Significant Data Fiduciary under [section 10(1)](/wiki/act/section-10/). No country or territory has been notified under [section 16(1)](/wiki/act/section-16/) as one to which transfers are restricted, and no general or special order has been issued under [rule 15](/wiki/rules/rule-15/). No categories of personal data have been specified for local storage under [rule 13(4)](/wiki/rules/rule-13/). No exemption has been notified under [section 17(2)](/wiki/act/section-17/), [section 17(3)](/wiki/act/section-17/) or [section 17(5)](/wiki/act/section-17/), and no age has been notified under [section 9(5)](/wiki/act/section-9/). The Rules also leave section 11(1)(c) unprescribed, so the access right lists only what section 11(1)(a) and (b) set out.
