A printed project timeline on a desk, with milestones marked between November and May
COVER

The Digital Personal Data Protection Rules, 2025 were notified as G.S.R. 846(E) on 13 November 2025 and published in the Gazette of India the following day. Publication started three clocks at once. The rules that constitute the Data Protection Board of India took effect immediately. The consent manager regime follows on 14 November 2026. And everything a compliance team must actually operationalise arrives on 14 May 2027: consent notices, breach reporting, security safeguards, retention limits, the rights machinery.

Eighteen months sounded generous when the gazette landed. From the middle of 2026 it reads differently. Roughly ten months remain, and most of what the operative rules require is engineering work with lead times: consent flows rebuilt so withdrawal is as easy as agreement, breach runbooks that can produce a detailed report inside seventy-two hours, retention logic wired into production systems. None of that ships in a sprint.

This explainer walks through the commencement schedule as the gazette sets it out, the obligations that deserve the earliest start, and a practical sequence for the quarter ahead. Every date and rule number below comes from the instrument itself.


Three dates, one gazette

Rule 1 splits commencement into three sub-rules. Rules 1(2) to 1(4) tie each phase to the date of publication in the Official Gazette, which was 14 November 2025; the notification itself is dated 13 November. The Ministry of Electronics and Information Technology brought the corresponding sections of the parent Act into force on the same three dates through companion notifications.

TABLECommencement schedule under Rule 1, DPDP Rules, 2025
In force from Provisions What they cover
14 November 2025 Rules 1, 2, 17 to 21 Definitions and the Data Protection Board: appointments, service terms, digital-office functioning
14 November 2026 Rule 4, First Schedule Registration and obligations of Consent Managers, which must be companies incorporated in India
14 May 2027 Rules 3, 5 to 16, 22, 23 Notices, security safeguards, breach reporting, children's data, SDF duties, rights, cross-border rules

The sequencing follows the dependency chain: Board machinery first, consent infrastructure second, data fiduciary obligations last. Each phase assumes the previous one exists, which is why the final date is the one to plan against rather than the one to wait for.


Consent notices become standalone documents

Rule 3 ends the practice of burying consent language inside a privacy policy. The notice must be presented and be understandable independently of any other information the data fiduciary provides, and it must give, in clear and plain language, a fair account sufficient for specific and informed consent. At a minimum, that account covers four things.

01

An itemised data description

The personal data being collected, itemised. Categories named, not gestured at.

02

Purpose, tied to outcome

The specified purpose of the processing and a specific description of the goods, services or uses it enables.

03

A withdrawal route

A communication link to the website or app where consent can be withdrawn, with ease comparable to the ease of giving it.

04

Rights and complaint paths

The means for the data principal to exercise rights under the Act and to make a complaint to the Data Protection Board.

The comparable-ease standard for withdrawal is the item teams most often underestimate. It is a product requirement rather than a drafting requirement: a one-tap consent paired with a write-to-support withdrawal sits squarely at odds with the rule's language.


Breach reporting runs on two tracks

Rule 7 carries no materiality threshold: on becoming aware of any personal data breach, the data fiduciary must act on two tracks at once. The first runs to affected individuals. Each affected data principal must be told without delay, in concise, clear and plain language, through her user account or a registered mode of communication: what happened, the likely consequences for her, the mitigation under way, the safety steps she can take, and a contact who can answer questions.

The second track runs to the Data Protection Board. A description of the breach, covering its nature, extent, timing, location and likely impact, goes to the Board without delay. Within seventy-two hours of becoming aware, unless the Board allows longer on a written request, the fiduciary must follow with updated detail: the facts and circumstances, mitigation, any findings about who caused the breach, remedial measures, and a report of the intimations sent to data principals.

72 hours detailed report to the Board Any breach no materiality threshold 1 year minimum retention of security logs ₹250 crore cap for failed security safeguards ₹200 crore cap for failure to notify a breach

These duties sit on top of Rule 6, which fixes the minimum security safeguards: encryption, obfuscation, masking or virtual tokens; access control; logging, monitoring and review, with logs retained for at least a year; backups; and safeguard provisions in every data processor contract. Breach response is a test of infrastructure built earlier. If the year of logs does not exist, the seventy-two-hour report cannot be written.


Significant Data Fiduciaries carry an annual cadence

Section 10 of the Act lets the Central Government notify a data fiduciary, or a class of them, as a Significant Data Fiduciary on factors that include the volume and sensitivity of personal data processed. Rule 13 attaches the recurring obligations, and the cycle runs from the date of designation, not from a calendar year.

A Significant Data Fiduciary shall, once in every period of twelve months … undertake a Data Protection Impact Assessment and an audit to ensure effective observance of the provisions of this Act and the rules made thereunder. Rule 13(1), Digital Personal Data Protection Rules, 2025

The person carrying out that assessment and audit must furnish a report of significant observations to the Board. Rule 13 adds two duties with long lead times: due diligence that algorithmic software used in processing is not likely to pose a risk to data principals' rights, and a restriction, for categories of personal data the government specifies on a committee's recommendation, against transferring that data or its traffic data outside India. An organisation that plausibly meets the designation criteria should not wait for the notification to begin its first assessment.


What to do this quarter

With roughly ten months to 14 May 2027, sequencing matters more than volume. The items below front-load the longest lead times, and each produces evidence a future audit or Board inquiry would ask to see.

01

Map the data estate

Inventory personal data, purposes, systems and processor relationships. Every obligation that follows assumes this map exists.

02

Rebuild consent flows

Draft Rule 3 notices per purpose, and design withdrawal journeys as easy as the consent journeys they undo.

03

Write the breach runbook

Templates for principal notices and Board reports, a named owner for the seventy-two-hour clock, and a tested escalation path.

04

Baseline against Rule 6

Encryption or tokenisation, access control, one-year log retention, backups, and safeguard clauses in every processor contract.

05

Check the retention triggers

E-commerce and social media platforms with two crore registered users, and gaming platforms with fifty lakh, must erase data three years after a user last engaged, with forty-eight hours' notice.

06

Assess SDF exposure

If scale or sensitivity makes designation plausible, stand up the impact-assessment and audit cadence before it becomes mandatory.

Two smaller items round out the quarter: publish the business contact of a data protection officer or a person able to answer questions about processing, as Rule 9 requires, and confirm the grievance process can respond within the ninety-day outer limit set under Rule 14. Neither is difficult, but both are publicly visible, and visible gaps invite complaints. The instrument itself runs to a few pages. Read it, diarise the dates, and treat 14 May 2027 as a delivery deadline, because the gazette does.


Sources