India's Digital Personal Data Protection Act was passed in 2023 and then sat, for two years, without a single operational deadline attached to it. That changed when MeitY notified the Digital Personal Data Protection Rules, 2025. The Rules did not merely add detail — they started a clock, and they started it in phases, which is why an organisation can be squarely in scope today and not yet in breach of anything. This is the calendar, what each phase actually binds, and the planning mistake we see most often in readiness engagements.
The dates, and why you will see two of them
The Rules were notified by gazette notification G.S.R. 846(E). The notification bears the date 13 November 2025; it was published in the Official Gazette on 14 November 2025. Both dates are correct and they are not in conflict — one is the date of signing, the other the date of publication. It is worth knowing which is which, because commencement periods are measured from publication, and a plan built on the wrong anchor is a day out at every milestone. A day rarely matters; knowing your source does.
| Phase | Approx. date | What starts applying | Who it binds |
|---|---|---|---|
| On notification | 14 Nov 2025 | Provisions constituting the Data Protection Board of India | The State — it stands the regulator up |
| +12 months | ~14 Nov 2026 | Consent Manager obligations, including registration and the framework around it | Entities operating as Consent Managers |
| +18 months | ~14 May 2027 | Data Fiduciary obligations in substance, with the Board's adjudicatory and penalty powers fully live | Every Data Fiduciary, with extra duties on SDFs |
DPDP Rules, 2025 — phased commencement, measured from publication on 14 November 2025
Eighteen months of runway is not eighteen months of preparation
This is the single most expensive misreading of the calendar, and it is easy to make. “Data Fiduciary obligations apply from around May 2027” gets filed as “we have until May 2027,” and the programme is scheduled backwards from that date with the work finishing on it. But several of the obligations are not states you enter — they are artefacts you must already hold.
A Significant Data Fiduciary owes an independent data audit. An audit is not a switch thrown on a deadline: it needs a defined scope, an appointed independent auditor, fieldwork, evidence, findings, and remediation of whatever the findings surface. Every one of those sits before the date, not on it. The same is true of a Data Protection Impact Assessment, and of the consent and notice architecture the audit will test — you cannot evidence a consent flow you deployed the week before.
Which of these phases is actually about you
The three phases bind three different populations, and conflating them produces either wasted effort or a missed obligation. The first phase is about the regulator existing at all. The second is narrow. The third is the one that reaches almost everyone.
- Every Data Fiduciary — any organisation determining the purpose and means of processing personal data of individuals in India. The eighteen-month phase is your phase. Baseline duties apply: lawful processing on consent or a legitimate use, clear notice, purpose limitation and minimisation, accuracy, reasonable security safeguards, breach notification, erasure on withdrawal, grievance redressal, binding processor contracts, and verifiable parental consent for children's data.
- Significant Data Fiduciaries — a subset the Central Government designates by notification, on factors including volume and sensitivity of data, risk to Data Principals, and effects on sovereignty, electoral democracy, State security and public order. You inherit everything above plus an India-based DPO answerable to the board, an independent data audit, Data Protection Impact Assessments, and algorithmic transparency and fairness assessment.
- Consent Managers — entities that register with the Board to give Data Principals a single point to give, manage, review and withdraw consent. This is the twelve-month phase, and it is a business someone opts into, not a status conferred on ordinary data fiduciaries.
What is actually at risk
Penalties under the DPDP Act reach ₹250 crore for a single instance of failing to take reasonable security safeguards, and the Data Protection Board can adjudicate, demand remediation and restrict cross-border transfers. Two features of that regime are worth internalising because they differ from the GDPR model Indian compliance teams often carry across: the ceiling is per-breach rather than a share of global turnover, and it attaches to specific enumerated failures rather than to a general standard. The full adjudicatory and penalty machinery comes with the eighteen-month phase — which is precisely why the current window is the cheap one.
What to do in each window
- Now, through 2026 — establish the facts. Map data flows end to end: what personal data you hold, where it came from, the lawful basis, who it is shared with, where it leaves India, and how long you keep it. Nothing else in the programme can be evidenced until this exists, and it is the single longest-lead item.
- Now — decide whether you are likely to be designated. SDF status is conferred, not chosen, but the designation factors are public. If you are a large consumer platform, a major BFSI or fintech, a significant health-data or ad-tech processor, or a telecom, plan on the SDF duty set rather than waiting to be told.
- Through 2026 — stand up the DPO function properly. For an SDF the role must be India-based and answerable to the board, and it is the published contact for grievance redressal. That is an appointment with a reporting line and a budget, not a title added to an existing job description.
- Late 2026 — run a readiness audit before the statutory one. The independent data audit produces a written opinion you cannot quietly walk back. Find your gaps in an advisory engagement where the output is a remediation plan, not in the statutory audit where the output is a finding.
- Late 2026 into 2027 — close the technical safeguards duty. Reasonable security safeguards is an obligation you have to demonstrate, not assert: penetration testing, breach detection and response, access control and encryption evidence, and a tested incident workflow that can meet notification timelines.
- Before the applicable date — commission the statutory independent audit and the DPIA, with enough time for findings to be closed rather than merely raised.
How Macksofy helps
Macksofy runs DPDP readiness and audit work for Indian Data Fiduciaries and prospective Significant Data Fiduciaries: data-flow mapping and DPIAs, readiness data audits ahead of the statutory independent audit, DPO-function and grievance-workflow design, and the technical assurance the reasonable-security-safeguards duty demands. See the DPDP readiness audit for the baseline programme, the Significant Data Fiduciary engagement for the Section 10 duty set, what an SDF actually has to do for the obligation map, cross-border transfer rules if you export data, VAPT for the safeguards testing, and DFIR for breach readiness.
