Last updated: 9 September 2026
The Digital Personal Data Protection Act, 2023 was enacted on 11 August 2023, but it did not take effect all at once. The Act provided that its provisions would come into force on dates that the Central Government notifies. The operational detail arrived with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025, which give full effect to the Act through a staggered, phased commencement. In broad terms, the framework rolls out over an eighteen-month period.
A first set of provisions took effect immediately on notification, including:
The provisions dealing with Consent Managers — the registered platforms through which individuals can give, manage, review and withdraw consent — and the Board’s associated oversight of them are set to come into force at this stage.
The core substantive obligations — the parts of the framework that most directly affect day-to-day data handling — are due to come into force at this point. These include:
The framework is now settled, even though the substantive compliance obligations are not fully in force until around 13 May 2027. The eighteen-month window is intended to give organisations time to adjust their systems and practices. Because the direction of travel is clear, businesses that process personal data can begin preparing now — mapping the data they hold, reviewing how they obtain consent, and planning for breach response and individual rights requests — rather than waiting for the final commencement date.
This note reflects the position following the notification of the DPDP Rules, 2025 and is for general information only. The commencement schedule is set by government notification and may be supplemented over time; the exact application to any organisation depends on its specific circumstances.