DPDPA Compliance Deadlines: What's Due in Nov 2026 vs May 2027
Last verified: 22 July 2026. Timelines shift as MeitY issues clarifications — this page is re-checked against the Act and Rules when they change.
India's Digital Personal Data Protection Act becomes fully enforceable on 13 May 2027 — the end of the 18-month transition that began when the DPDP Rules were notified on 13 November 2025. That is the date when notice, consent, security safeguards, data-principal rights, breach notification, and the associated penalties all bite. A separate milestone falls at 13 November 2026 (12 months), when the Consent Manager registration regime arrives. Through 2026 the Board is expected to focus on guidance and awareness — soft enforcement — with active supervision from May 2027.
The three dates that matter
Rules notified
The Digital Personal Data Protection Rules were notified, taking immediate effect for the constitution of the Data Protection Board of India.
12-month milestone
Consent Manager provisions arrive — organisations intending to operate as registered Consent Managers must complete registration with the Board by this date.
Full enforcement
The 18-month transition ends. All substantive obligations come into force: notice, consent, security safeguards, data-principal rights, breach notification — and the penalties that back them.
If you're a Significant Data Fiduciary, watch Nov 2026
In January 2026, MeitY proposed compressing the compliance window for Significant Data Fiduciaries from 18 months to 12 — which would move large-volume data processors to a November 2026 deadline rather than May 2027. Treat this as a proposal to track, not settled law: confirm its status before planning against it. If your organisation is likely to be designated an SDF, the prudent assumption is the earlier date.
SDF status also brings additional duties under S.10 — appointing a Data Protection Officer in India, commissioning independent data audits, and running Data Protection Impact Assessments — which carry their own penalty ceiling of up to ₹150 crore.
What becomes enforceable on 13 May 2027
| Section | Obligation | Enforceable |
|---|---|---|
| S.5 | Give every data principal a clear notice of what personal data is processed and why | 13 May 2027 |
| S.6 | Obtain free, specific, informed, and withdrawable consent | 13 May 2027 |
| S.8(5) | Take reasonable security safeguards to prevent a personal data breach | 13 May 2027 |
| S.8(6) | Notify the Board and affected individuals of a breach | 13 May 2027 |
| S.11–S.13 | Honour access, correction/erasure, and grievance-redressal rights | 13 May 2027 |
For the penalty ceilings attached to each of these, see the DPDPA penalty guide.
Why "we'll start in 2027" doesn't work
The obligations that take longest to build are the evidentiary ones. Proving you served a S.5 notice, captured valid S.6 consent, or honoured a S.12 erasure request requires a durable, auditable record produced at the time — you cannot retroactively manufacture a consent trail in May 2027. The same is true of the AI tools your employees have already connected to company data: discovering them is the prerequisite to every other obligation, because you cannot give notice about processing you haven't inventoried.
Know what you'd have to disclose today.
A free Pyroniq scan inventories every OAuth-consented AI tool in about six minutes.
Sources
- India Briefing — India DPDP compliance timeline and enforcement 2026–27
- Lakshmikumaran & Sridharan — DPDP Act and Rules: a ticking compliance timeline
- DPDPA.com — Compliance deadline May 2027: 12-month implementation roadmap
- DPDPA Schedule (penalties, referenced by S.33(1))
This guide summarises statutory timelines under the DPDPA 2023 and the DPDP Rules 2025 for awareness only and does not constitute legal advice. Confirm current dates and any MeitY clarifications with qualified counsel before relying on them.