Skip to content

Current status and deadlines

The DPDP framework is partly in force. Treating the whole Act as either effective or ineffective is wrong. G.S.R. 843(E) starts provisions in three cohorts; Rule 1 of G.S.R. 846(E) does the same for the Rules.

DateWhat changesProduct decision
13 November 2025Act sections 1(2), 2, 18–26, 35, 38–43 and section 44(1), (3); Rules 1, 2 and 17–21; Board establishedTrack the live machinery and legal changes
13 November 2026Act section 6(9), section 27(1)(d); Rule 4 and First ScheduleA statutory Consent Manager track must be legally separate and registration-ready
13 May 2027Main scope, processing, fiduciary duty, rights, children, SDF, enforcement and penalty cohorts; Rules 3, 5–16, 22, 23Enterprise operating controls must work end to end
DPDP — in force

Foundational and Board machinery.

SRC-DPDP-COMMENCEMENT-2025 DPDP — not yet effective

Main processing obligations. Readiness activity may be contractually or sector-required now, but should not be mislabeled as an already enforceable DPDP duty.

  • G.S.R. 844(E) established the Data Protection Board of India from publication and set its head office in the National Capital Region. Establishment does not prove that the institution is fully staffed or that every digital service is live.
  • MeitY’s 6 May 2026 notice invited applications for one Chairperson and four Members. This research pass did not locate a later primary appointment notification.
  • The Aadhaar Good Governance Portal lists a 20 July 2026 approval for voluntary Yes/No and/or eKYC authentication for login and complaint filing on the proposed DPBI Digital Office Portal. The approval does not make Aadhaar mandatory and does not by itself prove production launch.
  • G.S.R. 892(E), Gazette No. 806 dated 11 December 2025, makes seven textual corrections to the published Rules. MeitY’s listing shows 16 December 2025, while the Gazette carries an 11 December issue date and a 12 December digital publication signature. The source register uses the Gazette date and preserves the listing-date distinction.
  • approve entity/role and system inventory method;
  • assign a legal-source owner and sector reviewers;
  • identify high-volume consent journeys and hard-to-reach downstream processors;
  • baseline incident clocks and current CERT-In/sector duties;
  • choose deployment and connector trust boundaries.
  • if pursuing statutory Consent Manager registration, complete the separate entity, net-worth, governance, conflict and technical-readiness pack;
  • if not pursuing it, make product copy and tenancy controls prevent any registered-status claim;
  • complete a Board-portal adapter boundary without inventing a government API.
  • pilot notice, withdrawal, rights, retention and breach flows in one business line;
  • validate processor propagation and deletion evidence with two real systems using synthetic test subjects;
  • perform an accessibility and dark-pattern review;
  • complete sector counsel review for retention and outsourcing conflicts.
  • put approved production configurations, trained owners, monitoring, evidence and exception processes in place;
  • test a Data Principal request, breach tabletop, restore-time re-deletion and customer exit;
  • retain legal sign-off for all “not yet effective” labels becoming “in force.”

The following must be revalidated at every release:

  1. Board Chairperson/Member appointment and portal launch notifications;
  2. Consent Manager application forms, technical standards, certification bodies and registrations;
  3. Significant Data Fiduciary class notifications;
  4. section 16 restricted-country orders and Rule 15 foreign-State availability requirements;
  5. SDF localisation notifications under Rule 12(4);
  6. startup exemptions, other section 17 notifications and section 44 transition dates;
  7. court decisions or challenges affecting the Act, Rules or notification sequence.

The machine-readable detail is in the legal status ledger.