Knowledge centre · Data privacy

DPDP Rules 2025 Timeline: Every Deadline Up to 13 May 2027

The Digital Personal Data Protection Rules, 2025 come into force in three phases. Here is what applies on each date, rule by rule, and a practical plan for startups working back from the main deadline.

Notified 13 Nov 2025 Consent Managers 13 Nov 2026 Main duties 13 May 2027
When does the DPDP Act come into force? The DPDP Rules, 2025 were notified on 13 November 2025 and apply in three phases. The rules on the Data Protection Board applied at once. The rule on Consent Managers applies from 13 November 2026. Everything that businesses must do day to day (notice, security, breach reporting, retention, children's data and rights) applies from 13 May 2027.
At a glance

The three phases of the DPDP Rules

Phase 1 · 13 November 2025

The regulator is set up

Rules 1 and 2 (title and definitions) and rules 17 to 21 on the Data Protection Board: how members are selected, their terms of service, how the Board meets and how it works as a digital office.

Phase 2 · 13 November 2026

Consent Managers can register

Rule 4 and the First Schedule: the conditions a Consent Manager must meet to register with the Board, and its obligations once registered.

Phase 3 · 13 May 2027

Every Data Fiduciary's duties apply

Rules 3, 5 to 16, 22 and 23: notice, security safeguards, breach intimation, retention and erasure, privacy contact, children's data, Significant Data Fiduciaries, rights, cross-border transfers, appeals and calls for information.

Rule by rule

What each rule covers and when it applies

RuleSubjectIn force from
1 and 2Short title, commencement and definitions13 Nov 2025
3Notice given by a Data Fiduciary to a Data Principal13 May 2027
4Registration and obligations of Consent Managers13 Nov 2026
5Processing by the State for subsidies, benefits, services, certificates, licences and permits13 May 2027
6Reasonable security safeguards13 May 2027
7Intimation of a personal data breach (72-hour detailed report to the Board)13 May 2027
8When a purpose is treated as served, erasure, and one-year log retention13 May 2027
9Contact information of the person who answers questions about processing13 May 2027
10 and 11Verifiable consent for children and for persons with disability who have a lawful guardian13 May 2027
12Exemptions from certain obligations for children's data13 May 2027
13Additional obligations of Significant Data Fiduciaries (annual DPIA and audit)13 May 2027
14Rights of Data Principals and grievance redressal within 90 days13 May 2027
15Transfer of personal data outside India13 May 2027
16Exemption for research, archiving and statistical purposes13 May 2027
17 to 21The Data Protection Board: appointments, service conditions, meetings, digital office, staff13 Nov 2025
22Appeal to the Appellate Tribunal13 May 2027
23Calling for information from a Data Fiduciary or intermediary13 May 2027

Source: Digital Personal Data Protection Rules, 2025, rule 1(2) to 1(4), Gazette notification G.S.R. 846(E) dated 13 November 2025, published by the Ministry of Electronics and Information Technology.

Plan

A startup plan, working back from 13 May 2027

Most of the work is not legal drafting but product and vendor changes, which take longer than expected. This is the order we recommend.

Now to December 2026

Map and assess

List the personal data you hold, where it comes from and which vendors receive it. Run a gap assessment and put the fixes in next year's budget.

January to March 2027

Draft and build

Write the notices, consent wording, policies and vendor terms. Change sign-up, consent and settings screens, and set up the rights request route.

April 2027

Test and train

Run a breach drill on paper against the 72-hour clock, test erasure and log retention, and train everyone who handles customer data.

By 13 May 2027

Go live

Publish the notices and the privacy contact, switch on the new consent flows, and keep a record of what you did and when.

After May 2027

Keep it current

Review every new feature, vendor and market for its privacy impact, and handle requests and grievances within the time limits.

Want this done for you? Our DPDP Readiness Check (from ₹25,000) covers the first step in 7 to 10 working days, and the DPDP Compliance Pack covers the rest. See all DPDP compliance services.
FAQs

DPDP Rules 2025 timeline: common questions

The Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025 by Gazette notification G.S.R. 846(E) dated 13 November 2025.

13 May 2027. That is when rules 3, 5 to 16, 22 and 23 come into force, eighteen months after notification, covering notice, security, breach reporting, retention, children's data and the rights of Data Principals.

Rules 1 and 2 and rules 17 to 21, which deal with the Data Protection Board, came into force on 13 November 2025, the date of publication.

Rule 4, on the registration and obligations of Consent Managers, comes into force one year after publication, on 13 November 2026.

You can, but it is risky. Changing consent flows, vendor contracts and data retention takes months of product and engineering time, so most startups need to start their gap assessment in 2026 to be ready by 13 May 2027.

Plan your DPDP compliance before the deadline.

Tell us what your product does and roughly how many users you have. We will reply within 24 hours with a fixed-fee quote for a readiness check.

    Send Us Your Enquiry

    Fill in the form below and our team will respond within 24 hours.

    Prefer chat? WhatsApp us.

    General information on the DPDP Act, 2023 and the DPDP Rules, 2025, current to 30 September 2026. Not legal advice for your specific situation.

    Scroll to Top