DPDPA Compliance Deadlines: What's Due in Nov 2026 vs May 2027

Ashish KunalFounder — Pyroniq·

Last verified: 22 July 2026. Timelines shift as MeitY issues clarifications — this page is re-checked against the Act and Rules when they change.

India's Digital Personal Data Protection Act becomes fully enforceable on 13 May 2027 — the end of the 18-month transition that began when the DPDP Rules were notified on 13 November 2025. That is the date when notice, consent, security safeguards, data-principal rights, breach notification, and the associated penalties all bite. A separate milestone falls at 13 November 2026 (12 months), when the Consent Manager registration regime arrives. Through 2026 the Board is expected to focus on guidance and awareness — soft enforcement — with active supervision from May 2027.

The three dates that matter

13 November 2025Done

Rules notified

The Digital Personal Data Protection Rules were notified, taking immediate effect for the constitution of the Data Protection Board of India.

13 November 2026Upcoming

12-month milestone

Consent Manager provisions arrive — organisations intending to operate as registered Consent Managers must complete registration with the Board by this date.

13 May 2027Hard deadline

Full enforcement

The 18-month transition ends. All substantive obligations come into force: notice, consent, security safeguards, data-principal rights, breach notification — and the penalties that back them.

If you're a Significant Data Fiduciary, watch Nov 2026

In January 2026, MeitY proposed compressing the compliance window for Significant Data Fiduciaries from 18 months to 12 — which would move large-volume data processors to a November 2026 deadline rather than May 2027. Treat this as a proposal to track, not settled law: confirm its status before planning against it. If your organisation is likely to be designated an SDF, the prudent assumption is the earlier date.

SDF status also brings additional duties under S.10 — appointing a Data Protection Officer in India, commissioning independent data audits, and running Data Protection Impact Assessments — which carry their own penalty ceiling of up to ₹150 crore.

What becomes enforceable on 13 May 2027

SectionObligationEnforceable
S.5Give every data principal a clear notice of what personal data is processed and why13 May 2027
S.6Obtain free, specific, informed, and withdrawable consent13 May 2027
S.8(5)Take reasonable security safeguards to prevent a personal data breach13 May 2027
S.8(6)Notify the Board and affected individuals of a breach13 May 2027
S.11–S.13Honour access, correction/erasure, and grievance-redressal rights13 May 2027

For the penalty ceilings attached to each of these, see the DPDPA penalty guide.

Why "we'll start in 2027" doesn't work

The obligations that take longest to build are the evidentiary ones. Proving you served a S.5 notice, captured valid S.6 consent, or honoured a S.12 erasure request requires a durable, auditable record produced at the time — you cannot retroactively manufacture a consent trail in May 2027. The same is true of the AI tools your employees have already connected to company data: discovering them is the prerequisite to every other obligation, because you cannot give notice about processing you haven't inventoried.

Know what you'd have to disclose today.

A free Pyroniq scan inventories every OAuth-consented AI tool in about six minutes.

Run Free Scan →

Sources

This guide summarises statutory timelines under the DPDPA 2023 and the DPDP Rules 2025 for awareness only and does not constitute legal advice. Confirm current dates and any MeitY clarifications with qualified counsel before relying on them.