Skip to content
Macksofy Technologies
India · DPDP Rules, 2025

DPDP Rules 2025 — Every India Compliance Deadline, and What to Do in Each Window

India's Digital Personal Data Protection Rules, 2025 turned a two-year-old Act into a dated compliance programme. Here is the phased commencement calendar, who each phase binds, and why an eighteen-month runway is not eighteen months of preparation time.

DPDP DPDP Act Data Protection Compliance Privacy SDF
Macksofy Audit Team· Compliance & regulatory audit practice30 August 2026 11 min read
DPDP Rules 2025 — Every India Compliance Deadline, and What to Do in Each Window — Regulatory · Macksofy
In short

When is the DPDP compliance deadline in India?

India's DPDP Rules, 2025 were published on 14 November 2025 and commence in phases: provisions constituting the Data Protection Board applied on notification, Consent Manager obligations at twelve months (around November 2026), and Data Fiduciary obligations in substance at eighteen months (around May 2027), when the Board's penalty powers are fully live. Macksofy runs DPDP readiness and independent data audits in India.

India's Digital Personal Data Protection Act was passed in 2023 and then sat, for two years, without a single operational deadline attached to it. That changed when MeitY notified the Digital Personal Data Protection Rules, 2025. The Rules did not merely add detail — they started a clock, and they started it in phases, which is why an organisation can be squarely in scope today and not yet in breach of anything. This is the calendar, what each phase actually binds, and the planning mistake we see most often in readiness engagements.

The dates, and why you will see two of them

The Rules were notified by gazette notification G.S.R. 846(E). The notification bears the date 13 November 2025; it was published in the Official Gazette on 14 November 2025. Both dates are correct and they are not in conflict — one is the date of signing, the other the date of publication. It is worth knowing which is which, because commencement periods are measured from publication, and a plan built on the wrong anchor is a day out at every milestone. A day rarely matters; knowing your source does.

PhaseApprox. dateWhat starts applyingWho it binds
On notification14 Nov 2025Provisions constituting the Data Protection Board of IndiaThe State — it stands the regulator up
+12 months~14 Nov 2026Consent Manager obligations, including registration and the framework around itEntities operating as Consent Managers
+18 months~14 May 2027Data Fiduciary obligations in substance, with the Board's adjudicatory and penalty powers fully liveEvery Data Fiduciary, with extra duties on SDFs

DPDP Rules, 2025 — phased commencement, measured from publication on 14 November 2025

Eighteen months of runway is not eighteen months of preparation

This is the single most expensive misreading of the calendar, and it is easy to make. “Data Fiduciary obligations apply from around May 2027” gets filed as “we have until May 2027,” and the programme is scheduled backwards from that date with the work finishing on it. But several of the obligations are not states you enter — they are artefacts you must already hold.

A Significant Data Fiduciary owes an independent data audit. An audit is not a switch thrown on a deadline: it needs a defined scope, an appointed independent auditor, fieldwork, evidence, findings, and remediation of whatever the findings surface. Every one of those sits before the date, not on it. The same is true of a Data Protection Impact Assessment, and of the consent and notice architecture the audit will test — you cannot evidence a consent flow you deployed the week before.

Which of these phases is actually about you

The three phases bind three different populations, and conflating them produces either wasted effort or a missed obligation. The first phase is about the regulator existing at all. The second is narrow. The third is the one that reaches almost everyone.

  • Every Data Fiduciary — any organisation determining the purpose and means of processing personal data of individuals in India. The eighteen-month phase is your phase. Baseline duties apply: lawful processing on consent or a legitimate use, clear notice, purpose limitation and minimisation, accuracy, reasonable security safeguards, breach notification, erasure on withdrawal, grievance redressal, binding processor contracts, and verifiable parental consent for children's data.
  • Significant Data Fiduciaries — a subset the Central Government designates by notification, on factors including volume and sensitivity of data, risk to Data Principals, and effects on sovereignty, electoral democracy, State security and public order. You inherit everything above plus an India-based DPO answerable to the board, an independent data audit, Data Protection Impact Assessments, and algorithmic transparency and fairness assessment.
  • Consent Managers — entities that register with the Board to give Data Principals a single point to give, manage, review and withdraw consent. This is the twelve-month phase, and it is a business someone opts into, not a status conferred on ordinary data fiduciaries.

What is actually at risk

Penalties under the DPDP Act reach ₹250 crore for a single instance of failing to take reasonable security safeguards, and the Data Protection Board can adjudicate, demand remediation and restrict cross-border transfers. Two features of that regime are worth internalising because they differ from the GDPR model Indian compliance teams often carry across: the ceiling is per-breach rather than a share of global turnover, and it attaches to specific enumerated failures rather than to a general standard. The full adjudicatory and penalty machinery comes with the eighteen-month phase — which is precisely why the current window is the cheap one.

What to do in each window

  1. Now, through 2026 — establish the facts. Map data flows end to end: what personal data you hold, where it came from, the lawful basis, who it is shared with, where it leaves India, and how long you keep it. Nothing else in the programme can be evidenced until this exists, and it is the single longest-lead item.
  2. Now — decide whether you are likely to be designated. SDF status is conferred, not chosen, but the designation factors are public. If you are a large consumer platform, a major BFSI or fintech, a significant health-data or ad-tech processor, or a telecom, plan on the SDF duty set rather than waiting to be told.
  3. Through 2026 — stand up the DPO function properly. For an SDF the role must be India-based and answerable to the board, and it is the published contact for grievance redressal. That is an appointment with a reporting line and a budget, not a title added to an existing job description.
  4. Late 2026 — run a readiness audit before the statutory one. The independent data audit produces a written opinion you cannot quietly walk back. Find your gaps in an advisory engagement where the output is a remediation plan, not in the statutory audit where the output is a finding.
  5. Late 2026 into 2027 — close the technical safeguards duty. Reasonable security safeguards is an obligation you have to demonstrate, not assert: penetration testing, breach detection and response, access control and encryption evidence, and a tested incident workflow that can meet notification timelines.
  6. Before the applicable date — commission the statutory independent audit and the DPIA, with enough time for findings to be closed rather than merely raised.

How Macksofy helps

Macksofy runs DPDP readiness and audit work for Indian Data Fiduciaries and prospective Significant Data Fiduciaries: data-flow mapping and DPIAs, readiness data audits ahead of the statutory independent audit, DPO-function and grievance-workflow design, and the technical assurance the reasonable-security-safeguards duty demands. See the DPDP readiness audit for the baseline programme, the Significant Data Fiduciary engagement for the Section 10 duty set, what an SDF actually has to do for the obligation map, cross-border transfer rules if you export data, VAPT for the safeguards testing, and DFIR for breach readiness.

FAQ

Quick answers.

The DPDP Rules, 2025 were notified by G.S.R. 846(E) dated 13 November 2025 and published on 14 November 2025, and they commence in phases. Provisions constituting the Data Protection Board applied on notification. Consent Manager obligations follow at twelve months, around November 2026. Data Fiduciary obligations apply in substance at eighteen months, around May 2027, when the Board's adjudicatory and penalty powers are fully live.
Because two different events have two different dates. The gazette notification G.S.R. 846(E) bears the date 13 November 2025, and it was published in the Official Gazette on 14 November 2025. Commencement periods run from publication, so 14 November 2025 is the anchor to count phases from.
No, and this is the most common planning error. Several obligations are artefacts you must already hold on the date rather than states you enter on it. An independent data audit needs scoping, an appointed auditor, fieldwork, findings and remediation, all of which precede the deadline. Chained backwards, most organisations need the sequence underway during 2026.
The Data Fiduciary obligations reach any organisation that determines the purpose and means of processing personal data of individuals in India, which is most businesses. The additional Significant Data Fiduciary duties apply only to those the Central Government designates by notification, and Consent Manager obligations apply only to entities that register to operate as Consent Managers.
Annually. The Act frames the SDF's data audit and impact assessment as periodic without fixing a cadence; the Rules set it, and the operative expectation is an annual independent data audit and an annual DPIA alongside algorithmic transparency and fairness assessment. Budget it as a recurring programme rather than a one-off project.
Up to ₹250 crore for a single instance of failing to take reasonable security safeguards. Unlike the GDPR, the ceiling is per-breach rather than a percentage of global turnover, and it attaches to specific enumerated failures. The Board's full adjudicatory and penalty powers come with the eighteen-month phase around May 2027.
Read next

Related articles

Compliance

The CERT-In Empanelment Process (2026): How an Auditing Organisation Actually Gets on the Panel

A step-by-step walkthrough of how CERT-In empanels information security auditing organisations in India — the single three-month application window each year, the eligibility bar, the documentation round, the offline and online practical skill tests and their 90% pass threshold, the Personal Interaction Session, government background verification, what it costs, how long the whole cycle takes, and what an organisation has to keep doing to stay on the panel.

Read article
Compliance

ABDM M1 WASA Audit: The Complete Guide to the Safe-to-Host Certificate (2026)

Everything an Indian digital-health team needs to know about the WASA audit behind ABDM Milestone 1 — what WASA stands for, why the report has to come from a CERT-In empanelled auditor, what functional and security testing it covers for HIPs, HIUs and health lockers, what the safe-to-host certificate must state about the environment tested, realistic timelines, and the failures that send teams back for a re-test.

Read article
Compliance

CERT-In Empanelled Audit: The Complete Guide (2026)

Everything Indian organisations need to know about CERT-In empanelled audits in 2026 — what CERT-In empanelment means, who needs an empanelled audit, what it covers, the CERT-In Directions of 2022 (6-hour reporting, 180-day logs), the report format, timelines, cost drivers, how CERT-In compares to ISO 27001 and SOC 2, and how to verify a provider's empanelment.

Read article
Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • Thousands of professionals trained
  • India + UAE engagements