The Digital Personal Data Protection Act, 2023 received assent in August 2023 and then did almost nothing for two years. The DPDP Rules, 2025 set the schedule, and it is a staggered one. Reading the Act alone tells you what is required; it does not tell you when.
13 November 2025 — the Board exists on paper
The Rules were notified and the provisions establishing the Data Protection Board of India commenced. That is the legal basis for the Board, and it is not the same thing as a Board.
The seats were still empty a long time afterwards. MeitY invited applications for the Chairperson and the four Members in May 2026, and legal commentary through the first half of 2026 described the Board as established in law and absent in fact — courts referring matters to an authority that had nobody sitting on it. Until the appointments complete there is no forum hearing complaints, whatever the commencement notification says.
Check the current position before relying on this: it is the part of the timeline most likely to have moved since this page was last updated.
13 November 2026 — Consent Manager registration opens
Rule 4 creates the registered Consent Manager: an entity a Data Principal can use to give, review and withdraw consent across multiple Data Fiduciaries through a single interface. Registration opens on this date. If your product intends to act as a Consent Manager rather than merely to collect consent for itself, this is the date that matters, and the work of meeting the registration conditions has to be finished before it, not after.
13 May 2027 — everything else
The bulk of the Act commences together:
- Notice under Sec. 5, in English or any language in the Eighth Schedule
- Consent under Sec. 6(1), free, specific, informed, unconditional and unambiguous
- Withdrawal under Sec. 6(4), which must be as easy as giving consent was
- Data Principal rights under Sec. 11 to 14 — access, correction, erasure, grievance, nomination
- Reasonable security safeguards and breach reporting under Sec. 8(5) and 8(6)
- Retention limits, children's data, and cross-border transfer under Sec. 16
There is no phase-in after that date. There is a carve-out, but it is conditional: Sec. 17(3) lets the Central Government notify classes of Data Fiduciary, startups among them, to whom Sec. 5, Sec. 8(3), Sec. 8(7), Sec. 10 and Sec. 11 do not apply. It takes a notification to bite, and until one names you the duties apply in full.
What the staging means in practice
The gap between now and May 2027 is the whole of the preparation window, and it is shorter than it reads — though not for the reason usually given.
Consent taken before commencement is not wiped out. Sec. 5(2) is explicit: where consent was given before the Act commenced, the Data Fiduciary must give the Data Principal a notice as soon as it is reasonably practicable, and may continue to process until she withdraws. The existing base does not go dark on 13 May 2027.
What it does create is an obligation to notice that base — every person, every purpose, in a language each of them can read, with the withdrawal route working before the notice goes out, because a notice that invites withdrawal from a system that cannot honour it is worse than no notice at all. That is the work, and it is scheduled against a date that does not move.