The Digital Personal Data Protection Act passed in August 2023 and then did almost nothing for two years. An Act without rules is a statement of intent. Notification of the DPDP Rules in November 2025 turned it into something you have to act on.
The three dates
- 13 November 2025 – the Data Protection Board of India became operational. Complaints can be filed.
- 13 November 2026 – Consent Manager registration opens.
- 13 May 2027 – full compliance, penalty regime live.
The gap between the second and third date is widely misread. Consent Manager registration opening does not mean you must use one. It means the infrastructure exists, and by May 2027 your consent practice has to hold up whether you use one or not.
What the Rules added that the Act did not have
The Act said notices must be clear. The Rules specify contents: an itemised description of the personal data, the purpose, and how to withdraw. Vagueness is no longer available.
The Act said security safeguards. The Rules name them: encryption, access control, logs retained for one year, backups. If you cannot produce logs, you cannot show you had safeguards.
The Act was silent on timelines. The Rules set them. Breach notification to affected individuals without delay, and to the Board within seventy-two hours with detail.
The practical read
Your notice text, consent record schema and log retention are now specified rather than left to judgement. That is good news operationally, because it converts an argument about interpretation into a checklist.
Start with logs. Most teams can rewrite a notice in a week. Almost nobody can produce a year of access logs on a system never configured to keep them.
General information, not legal advice. Rules current as of July 2026.