Pillaraxis Cyber law, privacy & security — read plainly
Vol. 2 · 2026
Kochi, India
Brief No. 007
Law & Policy

India's DPDP Rules Are Finally Here — and the Clock to May 2027 Is Running

After two years of waiting since the Act received presidential assent, the Digital Personal Data Protection Rules were notified in November 2025. Here is what actually starts, and when.

There has been a persistent confusion in Indian compliance circles about whether 2025 produced a new law. It did not. The Digital Personal Data Protection Act received presidential assent in August 2023 and has been in force, in a limited sense, since then. What arrived in November 2025 was the Rules — the operational detail that turns the Act's broad principles into something a compliance officer can actually implement: consent notice formats, breach notification timelines, children's data safeguards, and the machinery for cross-border transfers.

The compliance clock the Rules set running is an 18-month phase ending on 13 May 2027. That single date now anchors almost every DPDP planning document in the country. Along the way, 13 November 2026 activates the Consent Manager registration framework — a new category of registered intermediary that will sit between individuals and the organisations processing their data, managing and revoking consent on the individual's behalf. It is a structure with no close precedent in Indian law, closer to the account-aggregator model in financial services than to anything GDPR has attempted.

There is no sign of an extended grace period once May 2027 arrives — early Data Protection Board activity suggests full compliance means full compliance from day one.

The Act also introduces something genuinely new for India: a functioning Data Protection Board with the power to receive complaints and impose penalties, which is already operational and already receiving complaints even though most substantive obligations are not yet enforceable. Unlike previous Indian regulatory rollouts, there is no sign of an extended grace period once May 2027 arrives — the Board's early activity suggests the government intends full compliance to mean full compliance from day one, not a soft landing.

For a consultancy advising SME clients through this transition, the practical trap is treating 13 May 2027 as a distant deadline. Consent flows, breach response protocols, and data principal rights mechanisms take most organisations nine to twelve months to build properly once you include testing. Treat 2026 as the year the actual implementation work has to happen — because 2027 is when the deadline, not the grace period, arrives.

← OlderThe Children's Data Problem: What Instagram and TikTok's Fines Actually Found