DPDP Wiki Talk to us

/Guides · Compliance leads

Key dates: when each part of the DPDP Act and Rules comes into force

The three commencement dates set by G.S.R. 843(E) and rule 1 of the DPDP Rules, 2025, with what is live now and what is still to come.

Interpretation · not legal adviceUpdated 9 September 20266 min read
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation. Every statement links to the official provision it rests on.

The DPDP Act was passed in 2023, but almost none of it took effect then. Two documents published on 13 November 2025 set the actual timetable: G.S.R. 843(E), which appoints commencement dates for the Act, and rule 1 of the DPDP Rules, 2025, which does the same for the Rules. Both work from the same anchor date and produce three cut-off points.

Where the dates come from#

Section 1(2) of the Act says it comes into force "on such date as the Central Government may, by notification in the Official Gazette, appoint and different dates may be appointed for different provisions". G.S.R. 843(E) uses that power. It appoints three moments rather than three calendar dates: the date of publication of the notification, one year from the date of publication of the gazette, and eighteen months from the date of publication of the gazette.

Rule 1 of the Rules is drafted the same way. Rules 1, 2 and 17 to 21 come into force "on the date of their publication in the Official Gazette"; rule 4 "one year after the date of publication of this Gazette"; and rules 3, 5 to 16, 22 and 23 "eighteen months after the date of publication of this Gazette".

The gazette in both cases is dated 13 November 2025. That gives 13 November 2025, 13 November 2026 and 13 May 2027.

The three phases at a glance#

DateBasisProvisions of the ActProvisions of the Rules
13 November 2025G.S.R. 843(E) clause (a); rule 1(2)1(2), 2, 18 to 26, 35, 38, 39, 40, 41, 42, 43, and 44(1) and 44(3)1, 2, 17 to 21
13 November 2026G.S.R. 843(E) clause (b); rule 1(3)6(9) and 27(1)(d)4
13 May 2027G.S.R. 843(E) clause (c); rule 1(4)3 to 5, 6(1) to 6(8) and 6(10), 7 to 10, 11 to 17, 27 except clause (d) of sub-section (1), 28 to 34, 36, 37 and 44(2)3, 5 to 16, 22 and 23

Phase one, 13 November 2025: the machinery, not the duties#

What started on publication day is the plumbing. The definitions in section 2 are in force, so the defined terms have legal meaning. The whole of Chapter V, sections 18 to 26, is in force, which is what allowed the Data Protection Board of India to be established the same day by G.S.R. 844(E), with its head office in the National Capital Region. G.S.R. 845(E) notified under section 19(1) that the Board "shall consist of four members".

The rule-making and housekeeping powers are also live: section 40 (power to make rules), section 41 (laying rules before Parliament), section 42 (power to amend the Schedule of penalties), section 43 (power to remove difficulties), section 35 (protection for acts done in good faith), section 38 (the Act prevails over conflicting laws) and section 39 (no civil court jurisdiction over matters the Board can deal with).

Two of the three consequential amendments in section 44 took effect: the change to the Telecom Regulatory Authority of India Act, 1997, which lists the Appellate Tribunal under the DPDP Act among the tribunals covered by section 14(c) of that Act, and the replacement of clause (j) of section 8(1) of the Right to Information Act, 2005 with the words "information which relates to personal information". The amendments to the Information Technology Act, 2000, which include omitting section 43A, sit in sub-section (2) and wait until 13 May 2027.

On the Rules side, the provisions that let the Board exist and function started: rule 17 on the Search-cum-Selection Committees that recommend the Chairperson and Members, rule 18 on their salary and service conditions, rule 19 on Board meetings and inquiry timelines, rule 20 on the Board functioning as a digital office, and rule 21 on its officers and employees.

One small drafting point: G.S.R. 843(E) appoints "sub-section (2) of section 1" and does not separately mention sub-section (1), the short title.

Only three provisions turn on. Section 6(9) requires every Consent Manager to be registered with the Board on prescribed conditions. Rule 4 supplies the process, pointing to Part A of the First Schedule for the registration conditions and Part B for the obligations that follow. Section 27(1)(d) gives the Board the function of inquiring into a breach of a Consent Manager's registration conditions.

The registration window therefore opens six months before the consent provisions in section 6 take effect, so a Consent Manager can be registered before it has anything to do.

Phase three, 13 May 2027: the operative law#

This is where the Act starts to bite. Section 3, the application provision, comes into force only now, along with the whole of Chapter II except section 6(9): grounds for processing, notice, consent, certain legitimate uses, the general obligations of Data Fiduciaries, children's data and the additional obligations of Significant Data Fiduciaries. Chapter III, the rights and duties of Data Principals, arrives at the same time, as do section 16 and section 17.

So does enforcement. The rest of section 27, the whole of section 28 (Board procedure), Chapter VII on appeals and mediation, and sections 33 and 34 on penalties all commence on 13 May 2027.

The matching rules arrive the same day: rule 3 (notice), rule 5 (State processing for subsidies and benefits), rule 6 (security safeguards), rule 7 (breach reporting), rule 8 (retention and erasure), rule 9 (contact information), rule 10, rule 11 and rule 12 (children and persons with disability), rule 13 (Significant Data Fiduciaries), rule 14 (rights of Data Principals), rule 15 (transfers outside India), rule 16 (research and statistics), rule 22 (appeals) and rule 23 (calling for information).

What this means in practice#

As at 9 September 2026, only the phase one provisions are in force.

No Data Fiduciary obligation under Chapter II is enforceable yet. There is no legally effective notice requirement, no consent standard, no breach reporting duty, no erasure duty and no Significant Data Fiduciary regime, because sections 4 to 10 are not in force. Nor can a Data Principal yet exercise a statutory right of access, correction, erasure, grievance redressal or nomination, because sections 11 to 14 are not in force either.

The Board is established and its size notified, but the parts of section 27 that give it work to do, other than clause (d) of sub-section (1) from November 2026, are not yet in force. Section 33, the penalty provision, does not commence until 13 May 2027, and the Schedule of penalties is read with it. Appeals to the Appellate Tribunal under section 29 also wait until then.

The eighteen-month runway is not a grace period written into the Act. It is simply the date the Central Government appointed, and section 1(2) lets it appoint different dates for different provisions, so any further change would need a fresh notification.

Key provisions#

/MYND · DPDP practice

Want help applying this?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.