Confusion about India’s Digital Personal Data Protection Act usually comes down to one question: is it in force or not? The honest answer is both, depending on which part of it you mean. The Act and its Rules are commencing in phases, and knowing exactly which phase applies right now changes what should be on your roadmap today versus what can wait.
The three-phase rollout
The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, and they set a staggered schedule for bringing both the Act and the Rules into force.
| Phase | Date | What commences |
|---|---|---|
| Phase 1 | 13 November 2025 | The Data Protection Board of India is established. Certain foundational provisions take effect, including the Act’s overriding effect over conflicting laws and a bar on civil courts hearing DPDP matters. |
| Phase 2 | 13 November 2026 | The Act’s second phase commences, alongside Rule 4, which operationalizes the Consent Manager registration framework. |
| Phase 3 | 13 May 2027 | The core substantive compliance framework commences: notice and consent mechanics, data principal rights, breach notification obligations, and the additional duties placed on significant data fiduciaries. |
What that means as of today
If you’re reading this in late 2026, the Data Protection Board exists and the law’s overriding authority is active, but the detailed operational rules that most organizations associate with “DPDP compliance”, how to word a consent notice, how fast a breach must be reported, what a significant data fiduciary must additionally do, are not yet the enforceable standard. Those arrive in the Phase 3 commencement in May 2027.
The Consent Manager framework is the one piece of real machinery landing in November 2026: a system of licensed intermediaries through which individuals can manage, review, and withdraw consent across the organizations holding their data. For businesses relying on consent as a lawful basis for processing, this is the infrastructure that will eventually sit between them and the people whose data they hold.
Why “not yet enforceable” is not the same as “nothing to do”
An 18-month phased rollout is deliberate runway, not a reason to wait. Several things take real time to build and are far easier to do before an enforcement deadline than during one:
- Data mapping and inventory. You cannot honor data principal rights, such as access, correction, or erasure, until you know where personal data actually lives across your systems and vendors.
- Consent architecture. Retrofitting consent capture, logging, and withdrawal into existing products and workflows is a build project, not a policy update.
- Vendor and processor contracts. The Act places obligations on data fiduciaries for how their processors handle data, which means contract terms, due diligence, and ongoing oversight of every third party touching personal data need to be in place before Phase 3, not after.
- Breach response readiness. A breach notification obligation is only meaningful if the organization can actually detect a breach and assemble the required information quickly. That capability needs testing before it’s needed for real.
- Significant data fiduciary assessment. Organizations likely to be designated significant data fiduciaries, based on factors like data volume and sensitivity, face extra obligations: periodic audits, data protection impact assessments, and appointing a data protection officer. Determining likely status now avoids a scramble later.
Where third-party risk fits
A meaningful share of DPDP exposure sits outside an organization’s own walls. A vendor or processor with weak data handling practices creates the same obligation and the same risk as an internal gap, and demonstrating oversight of processors is part of what the Act expects from a data fiduciary. Tracking that across dozens or hundreds of vendors manually, with questionnaires that never quite map to DPDP’s specific requirements, is where most programs fall behind. For how a connected approach to vendor assessment handles this, see What Is AI-Powered TPRM? and the TPRM platform itself.
Common misconceptions
- “The DPDP Act isn’t in force yet, so there’s nothing urgent.” Parts of it already are, and the substantive compliance framework has a fixed commencement date in May 2027, which is closer than an 18-month runway feels.
- “We’re a small company, this doesn’t apply to us.” The Act applies broadly to organizations processing the digital personal data of individuals in India, with extraterritorial reach for foreign entities offering goods or services to people in India.
- “Consent is the only lawful basis we need to think about.” The Act also recognizes certain legitimate uses that don’t require consent, but relying on the wrong basis for the wrong purpose is a common early mistake.
- “Our ISO 27001 or SOC 2 certification covers this.” Those frameworks demonstrate strong security practices, but DPDP has its own specific requirements around consent, data principal rights, and breach notification that general security certifications don’t fully address on their own.
Building a DPDP-ready posture
A practical approach treats the remaining runway as a sequence rather than a single deadline-driven project: map data and vendors first, build or adapt consent and rights-handling mechanisms second, rehearse breach response third, and assess significant data fiduciary status throughout, since that designation changes which of the other steps carry additional weight. For governance, risk, and compliance support across this kind of program, see our practices.
Building a roadmap for DPDP readiness? Talk to Network Intelligence.
