Timeline

DPDP compliance deadlines & timeline

The DPDP Act compliance timeline explained — the phased rollout, the key dates, and the 13 May 2027 deadline for core obligations.

By DreamyHook Consultancy ServicesUpdated 6 min read

The DPDP Act doesn't switch on all at once. It rolls out in phases, giving organizations a transition period to get ready. This guide lays out the timeline and the key dates — and why starting early is the only sensible strategy.

Accuracy note (dated): Dates below reflect the phased rollout as understood in May 2026. The headline date for full compliance is 13 May 2027. In January 2026 there was public discussion of compressing the transition window (from 18 months to 12). That was proposed and unconfirmed at the time of writing — we'll update this page if it's formalized. Always confirm against the official notifications.

The phased rollout

Phase 1 — Foundations (from notification, late 2025)

The provisions needed to stand up the regime commence first: establishing the Data Protection Board of India, and the framework for Consent Manager registration. This is the machinery, not yet the obligations on your business.

Phase 2 — Build period (~2026)

The transition window where organizations are expected to get ready: mapping data, fixing consent, building rights workflows, and putting security and retention in place. The Consent Manager framework is expected to become operational during this period (around November 2026).

Phase 3 — Full compliance (13 May 2027)

The core obligations on Data Fiduciaries become enforceable. From this date, the Data Protection Board can act on non-compliance, including the penalties of up to ₹250 crore. See Penalties & Enforcement.

The dates at a glance

WhenWhat
11 August 2023DPDP Act received Presidential assent
January 2025Draft DPDP Rules released for consultation
Late 2025Phased notification begins; Board & Consent Manager framework commence
~November 2026Consent Manager framework expected operational
13 May 2027Core compliance obligations enforceable

Why "we have until 2027" is the wrong way to think

Eighteen months sounds like plenty. It isn't, because compliance is sequential: you can't build consent flows before you've mapped your data, you can't automate erasure before retention rules exist, and you can't prove security without controls in place. Each stage depends on the last.

The organizations that struggle are the ones that wait. The earlier you start:

  • the cheaper it is (no rushed, premium-priced scramble),
  • the calmer it is (no firefighting against a hard date),
  • and the stronger your position if the timeline accelerates.

What to do now

  1. Baseline today with a readiness audit.
  2. Sequence the work to the timeline — deadline-critical items first.
  3. Keep watching the Rules with Managed Compliance, so a change in dates never catches you out.

See where you stand in five minutes with the free DPDP Quick Scan.

General information, not legal advice. Dates are subject to official notification.

Frequently asked questions

Core obligations are set to become enforceable on 13 May 2027, following a phased rollout that began after the Rules were notified. Some provisions (like setting up the Board and Consent Manager registration) commence earlier.

It's possible. In early 2026 there was discussion about accelerating the transition period. We treat 13 May 2027 as the working deadline and flag any change as it's confirmed — start early either way.

See how this applies to you

The Quick Scan turns this guide into a personalized snapshot — your risk, your likely SDF status, and your top gaps — in five minutes.

Take the free Quick Scan

The deadline isn't moving. Start today.

Get your free DPDP Quick Scan — no obligation, instant results. See where you stand in five minutes.