The Digital Personal Data Protection Rules, 2025 were notified as G.S.R. 846(E) on 13 November 2025 and published in the Gazette of India the following day. Publication started three clocks at once. The rules that constitute the Data Protection Board of India took effect immediately. The consent manager regime follows on 14 November 2026. And everything a compliance team must actually operationalise arrives on 14 May 2027: consent notices, breach reporting, security safeguards, retention limits, the rights machinery.
Eighteen months sounded generous when the gazette landed. From the middle of 2026 it reads differently. Roughly ten months remain, and most of what the operative rules require is engineering work with lead times: consent flows rebuilt so withdrawal is as easy as agreement, breach runbooks that can produce a detailed report inside seventy-two hours, retention logic wired into production systems. None of that ships in a sprint.
This explainer walks through the commencement schedule as the gazette sets it out, the obligations that deserve the earliest start, and a practical sequence for the quarter ahead. Every date and rule number below comes from the instrument itself.
Three dates, one gazette
Rule 1 splits commencement into three sub-rules. Rules 1(2) to 1(4) tie each phase to the date of publication in the Official Gazette, which was 14 November 2025; the notification itself is dated 13 November. The Ministry of Electronics and Information Technology brought the corresponding sections of the parent Act into force on the same three dates through companion notifications.
| In force from | Provisions | What they cover |
|---|---|---|
| 14 November 2025 | Rules 1, 2, 17 to 21 | Definitions and the Data Protection Board: appointments, service terms, digital-office functioning |
| 14 November 2026 | Rule 4, First Schedule | Registration and obligations of Consent Managers, which must be companies incorporated in India |
| 14 May 2027 | Rules 3, 5 to 16, 22, 23 | Notices, security safeguards, breach reporting, children's data, SDF duties, rights, cross-border rules |
The sequencing follows the dependency chain: Board machinery first, consent infrastructure second, data fiduciary obligations last. Each phase assumes the previous one exists, which is why the final date is the one to plan against rather than the one to wait for.
Consent notices become standalone documents
Rule 3 ends the practice of burying consent language inside a privacy policy. The notice must be presented and be understandable independently of any other information the data fiduciary provides, and it must give, in clear and plain language, a fair account sufficient for specific and informed consent. At a minimum, that account covers four things.
An itemised data description
The personal data being collected, itemised. Categories named, not gestured at.
Purpose, tied to outcome
The specified purpose of the processing and a specific description of the goods, services or uses it enables.
A withdrawal route
A communication link to the website or app where consent can be withdrawn, with ease comparable to the ease of giving it.
Rights and complaint paths
The means for the data principal to exercise rights under the Act and to make a complaint to the Data Protection Board.
The comparable-ease standard for withdrawal is the item teams most often underestimate. It is a product requirement rather than a drafting requirement: a one-tap consent paired with a write-to-support withdrawal sits squarely at odds with the rule's language.
Breach reporting runs on two tracks
Rule 7 carries no materiality threshold: on becoming aware of any personal data breach, the data fiduciary must act on two tracks at once. The first runs to affected individuals. Each affected data principal must be told without delay, in concise, clear and plain language, through her user account or a registered mode of communication: what happened, the likely consequences for her, the mitigation under way, the safety steps she can take, and a contact who can answer questions.
The second track runs to the Data Protection Board. A description of the breach, covering its nature, extent, timing, location and likely impact, goes to the Board without delay. Within seventy-two hours of becoming aware, unless the Board allows longer on a written request, the fiduciary must follow with updated detail: the facts and circumstances, mitigation, any findings about who caused the breach, remedial measures, and a report of the intimations sent to data principals.
These duties sit on top of Rule 6, which fixes the minimum security safeguards: encryption, obfuscation, masking or virtual tokens; access control; logging, monitoring and review, with logs retained for at least a year; backups; and safeguard provisions in every data processor contract. Breach response is a test of infrastructure built earlier. If the year of logs does not exist, the seventy-two-hour report cannot be written.
Significant Data Fiduciaries carry an annual cadence
Section 10 of the Act lets the Central Government notify a data fiduciary, or a class of them, as a Significant Data Fiduciary on factors that include the volume and sensitivity of personal data processed. Rule 13 attaches the recurring obligations, and the cycle runs from the date of designation, not from a calendar year.
A Significant Data Fiduciary shall, once in every period of twelve months … undertake a Data Protection Impact Assessment and an audit to ensure effective observance of the provisions of this Act and the rules made thereunder. Rule 13(1), Digital Personal Data Protection Rules, 2025
The person carrying out that assessment and audit must furnish a report of significant observations to the Board. Rule 13 adds two duties with long lead times: due diligence that algorithmic software used in processing is not likely to pose a risk to data principals' rights, and a restriction, for categories of personal data the government specifies on a committee's recommendation, against transferring that data or its traffic data outside India. An organisation that plausibly meets the designation criteria should not wait for the notification to begin its first assessment.
What to do this quarter
With roughly ten months to 14 May 2027, sequencing matters more than volume. The items below front-load the longest lead times, and each produces evidence a future audit or Board inquiry would ask to see.
Map the data estate
Inventory personal data, purposes, systems and processor relationships. Every obligation that follows assumes this map exists.
Rebuild consent flows
Draft Rule 3 notices per purpose, and design withdrawal journeys as easy as the consent journeys they undo.
Write the breach runbook
Templates for principal notices and Board reports, a named owner for the seventy-two-hour clock, and a tested escalation path.
Baseline against Rule 6
Encryption or tokenisation, access control, one-year log retention, backups, and safeguard clauses in every processor contract.
Check the retention triggers
E-commerce and social media platforms with two crore registered users, and gaming platforms with fifty lakh, must erase data three years after a user last engaged, with forty-eight hours' notice.
Assess SDF exposure
If scale or sensitivity makes designation plausible, stand up the impact-assessment and audit cadence before it becomes mandatory.
Two smaller items round out the quarter: publish the business contact of a data protection officer or a person able to answer questions about processing, as Rule 9 requires, and confirm the grievance process can respond within the ninety-day outer limit set under Rule 14. Neither is difficult, but both are publicly visible, and visible gaps invite complaints. The instrument itself runs to a few pages. Read it, diarise the dates, and treat 14 May 2027 as a delivery deadline, because the gazette does.