DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr

Quick Answer

What are the key DPDP Act 2023 compliance deadlines? The DPDP Act 2023 received Presidential assent on 11 August 2023, with most provisions yet to be notified. The Data Protection Rules 2025 were published for public consultation and enforcement is expected to begin by May 2027. Key milestones for organisations include appointing a Grievance Officer (immediately), publishing a compliant Privacy Notice (immediately), conducting a data inventory and gap assessment (within 3 months), and achieving full compliance with consent and data principal rights obligations before the enforcement date.

LIVE COUNTDOWN · UPDATED FOR DPDP RULES 2025

DPDP Compliance Calendar — Key Deadlines & Milestones for 2025–2027

Every deadline that matters, a quarter-by-quarter action plan, and a one-click calendar file so the dates sit in your Outlook — not in a forgotten PDF.

CONSENT MANAGER FRAMEWORK LIVE
13 November 2026
FULL DPDP ENFORCEMENT + PENALTIES
13 May 2027

Works with Google Calendar, Outlook and Apple Calendar. Free, no email needed.

The full timeline

What has happened, and what is coming.

11 AUG 2023 — DONE

DPDP Act receives assent

India's first comprehensive data protection law is on the books.

13 NOV 2025 — DONE

DPDP Rules 2025 notified

The compliance clock starts: Data Protection Board constituted, consent-manager registration framework defined, 18-month runway begins.

THROUGH 2026 — YOU ARE HERE

The build window

Notices, consent flows, security baseline (Rule 6), grievance mechanism, vendor contracts, retention schedules and training all need to be designed, approved and rolled out in this window.

13 NOV 2026

Consent Manager framework operational

Registered Consent Managers go live. Fiduciaries must be able to honour consents given, managed and withdrawn through them — integration work that needs to start well before this date.

13 MAY 2027

Full enforcement

Notice, consent, Data Principal rights, 72-hour breach reporting and erasure duties are all enforceable. Penalties up to ₹250 crore per category are live. The Data Protection Board begins acting on complaints.

Quarter-by-quarter action plan

Working back from May 2027, this is the sane sequencing for a mid-size organisation.

Now – Sep 2026 · Foundations

  • Appoint a compliance owner (board/management minute)
  • Gap assessment vs the Act and Rules
  • Data inventory + RoPA; map vendors and cross-border flows
  • Fix the public basics: privacy notice, grievance officer, consent banner

Oct – Dec 2026 · Build

  • Consent records store + withdrawal workflow
  • Consent Manager integration readiness (13 Nov deadline)
  • 72-hour breach playbook drafted and approved
  • Vendor contract uplift — highest-risk processors first

Jan – Mar 2027 · Prove

  • Rights-request (access/correction/erasure) workflow tested end-to-end
  • Employee training rolled out, attendance evidenced
  • Breach tabletop exercise; fix what breaks
  • DPIA for highest-risk processing; SDF preparations if in scope

Apr – May 2027 · Evidence

  • Internal dry-run audit against the full checklist
  • Close remaining gaps; assemble the evidence pack
  • Board sign-off minute on DPDP readiness
  • 13 May 2027: enforcement begins — you're ready

Want this as a personalised plan for your company?

Tell us your sector and size — we'll send a tailored quarter-by-quarter DPDP plan with effort estimates, plus our monthly deadline reminders so nothing slips.

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
DPDP Compliance Cost CalculatorDPDP Compliance Deadline 2027DPDP Compliance Operations GuideDPDP Internal Audit Report GeneratorSee all Reference & Checklists tools →📝 ICAI Data Breach DPDP📝 What Is Data Fiduciary DPDP