KryptoMindz Technologies

KryptoMindz Insight · DPDP Act

DPDP Act Timeline and Compliance Deadlines

The DPDP Rules 2025 were notified in November 2025 with an 18-month, three-phase rollout. Here is what each deadline means for your compliance program — and why planning starts now.

By 12 min read Reviewed August 7, 2026

Key takeaways

  • The DPDP Rules 2025 phase in over 18 months: Board functioning from November 2025, Consent Manager and cross-border mechanisms from November 2026, full fiduciary enforcement from May 2027.
  • Phase 3 (May 2027) is the hard deadline for notices, consent, security safeguards, rights workflows, retention and breach reporting.
  • Programs started in 2026 should be in assessment or core-controls phase now; 72-hour breach reporting and 22-language notices are design requirements, not later add-ons.

Why the timeline matters more than the Act text

The DPDP Act, 2023 sets the framework, but the enforceable detail lives in the DPDP Rules, 2025, notified by MeitY in November 2025. The Rules deliberately phase obligations so that institutions and industry can stand up infrastructure — the Data Protection Board, Consent Managers, cross-border mechanisms — before full enforcement begins.

For most organizations the operational question is simple: by May 2027 you must be processing personal data under valid notices, lawful consent or permitted grounds, with safeguards, retention limits, rights workflows and a working breach response. Everything before that date is runway.

The three phases of the DPDP Rules 2025

PhaseEffectiveWhat applies
Phase 1November 2025Data Protection Board of India established, its composition and digital-first procedural functioning.
Phase 2November 2026Consent Manager framework, cross-border data transfer mechanisms and Significant Data Fiduciary obligations.
Phase 3May 2027Full enforcement of substantive Data Fiduciary obligations: notices, consent, security safeguards, retention, rights, breach notification and penalties.

Phase 1 (November 2025): the Board is live

Phase 1 stood up the Data Protection Board of India as an independent adjudicatory body. The Board investigates breaches, inquires into complaints and imposes penalties — and under the Rules its proceedings are digital-first, with electronic filings and virtual hearings.

Practical implication: the regulator exists and is operational now. Organizations should treat breach-response readiness, evidence capture and digital record keeping as live requirements rather than future work, because inquiries and penalty proceedings will be built on written, digital evidence.

Phase 2 (November 2026): Consent Managers and cross-border mechanisms

Phase 2 brings the Consent Manager framework into force. Consent Managers are registered digital intermediaries through which Data Principals can give, review and withdraw consent across multiple Data Fiduciaries. If your products serve Indian residents, your consent architecture should anticipate honoring consent states managed through such platforms.

This phase also activates the cross-border transfer mechanisms. The Act uses a blacklist model — transfers are permitted unless the Government restricts a territory — so the mechanisms are about how restrictions are notified and how fiduciaries demonstrate compliance when they apply.

Phase 3 (May 2027): full enforcement

Phase 3 is the deadline that matters most for most teams. From May 2027, the substantive obligations are enforceable: itemized notices in English and the scheduled languages, free and specific consent with easy withdrawal, reasonable security safeguards, purpose-based retention, data principal rights workflows, grievance redressal and breach notification without delay plus a detailed report within 72 hours.

Penalties under the Schedule become practically relevant at this point — up to ₹250 crore for safeguard failures leading to a breach and up to ₹200 crore for breach-notification failure or violations of children's data obligations.

What to do in each window

Now to November 2026

November 2026 to May 2027

Build your DPDP roadmap before Phase 3

KryptoMindz helps global and India-facing teams assess readiness, redesign consent and notices, build breach response and set up evidence that survives Board inquiries.

Discuss Your DPDP Program

Go deeper