DPDP Rules 2025 timeline: what applies when
3 min read · Updated 30 September 2026
The Digital Personal Data Protection Act, 2023 became law in August 2023, but most of it could not operate until the Government notified the rules that fill in the details. The Digital Personal Data Protection Rules, 2025 were notified in November 2025, and they come into force in three phases.
The three phases
| Phase | When | What takes effect |
|---|---|---|
| 1. Immediately | November 2025 | Setting up and running the Data Protection Board of India (Rules 1, 2 and 17–21) |
| 2. After 12 months | November 2026 | Registration and obligations of Consent Managers (Rule 4) |
| 3. After 18 months | May 2027 | The core obligations on Data Fiduciaries: notices, security safeguards, breach notification, retention and erasure, children's data, rights of Data Principals, Significant Data Fiduciary duties and more (Rules 3, 5–16, 22 and 23) |
For most organisations, May 2027 is the date that matters. It is when the notice, consent, security, breach and rights obligations become enforceable.
What comes into force in May 2027
- Notices (Rule 3): stand-alone, plain-language notices with an itemised description of the data and purposes, plus a link to withdraw consent, exercise rights and complain to the Board. See the consent notice checklist.
- Security safeguards (Rule 6): reasonable measures such as encryption, access control, monitoring and logs, and keeping those logs for at least one year.
- Breach notification (Rule 7): inform affected Data Principals without delay, and send the Board a detailed report within 72 hours of becoming aware of a breach.
- Retention and erasure (Rule 8): certain large e-commerce, online-gaming and social-media platforms must erase data after a set period of inactivity, with 48 hours' notice to the person before erasure.
- Children's data (Rule 10): verifiable consent of a parent or lawful guardian before processing data of anyone under 18.
- Rights of Data Principals (Rule 14): publish how people can exercise their rights, and respond to grievances within 90 days at most.
- Significant Data Fiduciaries (Rule 13): yearly data protection impact assessments and audits.
A realistic plan for the transition
Now to November 2026
- Map personal data, purposes and processors across every product.
- Decide which processing needs consent and which relies on a legitimate use.
- Choose how you will collect, record and prove consent.
November 2026 to early 2027
- Draft and translate notices; build consent collection into web and mobile apps.
- Build withdrawal that is as easy as giving consent, and connect it to your processors.
- Set up rights-request and grievance handling with deadlines.
- Prepare a breach response plan that can meet the 72-hour report.
Before May 2027
- Re-notify existing users as Section 5(2) requires for data collected before the Act.
- Run an end-to-end test: notice, consent, withdrawal, rights request, audit evidence.
- Train the teams that will handle grievances and breaches.
Why start early
Consent touches every signup flow, marketing tool and data pipeline. Integration, translation and testing across products usually take longer than the legal analysis. Teams that leave it to the final months risk launching rushed notices and incomplete records, and under Section 6(10) the burden of proving consent sits with you.
Consentrio is built for this transition: versioned notices, consent SDKs, withdrawal that reaches your processors, rights and grievance workflows, and an audit trail you can hand to an auditor.
This guide is general information, not legal advice. Check the Act and the Rules, or ask your counsel, for decisions about your organisation.