Current status and deadlines
The DPDP framework is partly in force. Treating the whole Act as either effective or ineffective is wrong. G.S.R. 843(E) starts provisions in three cohorts; Rule 1 of G.S.R. 846(E) does the same for the Rules.
Three dates that drive the programme
Section titled “Three dates that drive the programme”| Date | What changes | Product decision |
|---|---|---|
| 13 November 2025 | Act sections 1(2), 2, 18–26, 35, 38–43 and section 44(1), (3); Rules 1, 2 and 17–21; Board established | Track the live machinery and legal changes |
| 13 November 2026 | Act section 6(9), section 27(1)(d); Rule 4 and First Schedule | A statutory Consent Manager track must be legally separate and registration-ready |
| 13 May 2027 | Main scope, processing, fiduciary duty, rights, children, SDF, enforcement and penalty cohorts; Rules 3, 5–16, 22, 23 | Enterprise operating controls must work end to end |
Foundational and Board machinery.
SRC-DPDP-COMMENCEMENT-2025 DPDP — not yet effectiveMain processing obligations. Readiness activity may be contractually or sector-required now, but should not be mislabeled as an already enforceable DPDP duty.
Verified institutional facts
Section titled “Verified institutional facts”- G.S.R. 844(E) established the Data Protection Board of India from publication and set its head office in the National Capital Region. Establishment does not prove that the institution is fully staffed or that every digital service is live.
- MeitY’s 6 May 2026 notice invited applications for one Chairperson and four Members. This research pass did not locate a later primary appointment notification.
- The Aadhaar Good Governance Portal lists a 20 July 2026 approval for voluntary Yes/No and/or eKYC authentication for login and complaint filing on the proposed DPBI Digital Office Portal. The approval does not make Aadhaar mandatory and does not by itself prove production launch.
- G.S.R. 892(E), Gazette No. 806 dated 11 December 2025, makes seven textual corrections to the published Rules. MeitY’s listing shows 16 December 2025, while the Gazette carries an 11 December issue date and a 12 December digital publication signature. The source register uses the Gazette date and preserves the listing-date distinction.
Executive readiness clock
Section titled “Executive readiness clock”By 30 September 2026
Section titled “By 30 September 2026”- approve entity/role and system inventory method;
- assign a legal-source owner and sector reviewers;
- identify high-volume consent journeys and hard-to-reach downstream processors;
- baseline incident clocks and current CERT-In/sector duties;
- choose deployment and connector trust boundaries.
By 13 November 2026
Section titled “By 13 November 2026”- if pursuing statutory Consent Manager registration, complete the separate entity, net-worth, governance, conflict and technical-readiness pack;
- if not pursuing it, make product copy and tenancy controls prevent any registered-status claim;
- complete a Board-portal adapter boundary without inventing a government API.
By 31 January 2027
Section titled “By 31 January 2027”- pilot notice, withdrawal, rights, retention and breach flows in one business line;
- validate processor propagation and deletion evidence with two real systems using synthetic test subjects;
- perform an accessibility and dark-pattern review;
- complete sector counsel review for retention and outsourcing conflicts.
Before 13 May 2027
Section titled “Before 13 May 2027”- put approved production configurations, trained owners, monitoring, evidence and exception processes in place;
- test a Data Principal request, breach tabletop, restore-time re-deletion and customer exit;
- retain legal sign-off for all “not yet effective” labels becoming “in force.”
Open status checks
Section titled “Open status checks”The following must be revalidated at every release:
- Board Chairperson/Member appointment and portal launch notifications;
- Consent Manager application forms, technical standards, certification bodies and registrations;
- Significant Data Fiduciary class notifications;
- section 16 restricted-country orders and Rule 15 foreign-State availability requirements;
- SDF localisation notifications under Rule 12(4);
- startup exemptions, other section 17 notifications and section 44 transition dates;
- court decisions or challenges affecting the Act, Rules or notification sequence.
The machine-readable detail is in the legal status ledger.