On this page
The Digital Personal Data Protection Act, 2023 received the President’s assent on 11 August 2023, but its provisions take effect only on dates the Central Government appoints. Section 1(2) allows different dates for different provisions. The government used that power on 13 November 2025, in G.S.R. 843(E). The DPDP Rules, 2025 are dated the same day and carry their own staggered start.
The two notifications
- G.S.R. 843(E) is the commencement notification for the Act, issued under Section 1(2). It sorts the Act’s sections into three groups, in clauses (a), (b) and (c).
- G.S.R. 846(E), dated 13 November 2025, is the Digital Personal Data Protection Rules, 2025, made under Section 40. The notified Rules have 23 rules and seven Schedules. Rule 1 sets their own staggered start, in sub-rules (2), (3) and (4).
(G.S.R. 843(E) and G.S.R. 846(E) are the Gazette reference numbers of the two notifications.) Both instruments use the same three steps: the date of publication, one year after it, and eighteen months after it. The notifications do not print the later two dates. Counted from 13 November 2025 (the publication date of G.S.R. 843(E), and the date the Rules carry), they are 13 November 2026 and 13 May 2027.
What the video shows
- When does the DPDPA clock start for you?
- 13 NOV 2025
- The definitions and the Data Protection Board are in force.
- DAY 0
- 13 NOV 2026
- Consent Manager registration and duties begin.
- +12 MONTHS
- 13 MAY 2027
- Duties, rights and penalty provisions begin.
- +18 MONTHS
- SOME OF WHAT BEGINS ON
- Notice and consent / Security safeguards / Breach reporting / Children's data / Rights of Data Principals / Penalty provisions
- All counted from 13 November 2025.
What switches on when
| Date | Act provisions (G.S.R. 843(E)) | Rules (Rule 1) |
|---|---|---|
| 13 Nov 2025 publication | Section 1(2), Section 2, Sections 18 to 26, Section 35, Sections 38 to 43, Section 44(1) and Section 44(3). Clause (a). | Rules 1, 2 and 17 to 21. Rule 1(2). |
| 13 Nov 2026 + one year | Section 6(9) and Section 27(1)(d). Clause (b). | Rule 4. Rule 1(3). |
| 13 May 2027 + eighteen months | Sections 3 to 5, Section 6(1) to 6(8) and 6(10), Sections 7 to 17, Section 27 except clause (d) of Section 27(1), Sections 28 to 34, Sections 36 and 37, and Section 44(2). Clause (c). | Rules 3, 5 to 16, 22 and 23. Rule 1(4). |
13 November 2025: the machinery
The first group sets up the framework rather than duties on businesses. Section 2 brings the definitions into force. Sections 18 to 26 cover the establishment and composition of the Data Protection Board of India, its members’ terms, and its officers. Sections 38 to 43 cover how the Act sits with other laws, the bar on civil court jurisdiction, and the government’s powers to make rules and amend the Schedule.

On the Rules side, Rules 17 to 21 deal with the Board itself: selecting its Chairperson and Members, their pay, how the Board meets, its working as a digital office, and its staff. Rule 19(9) already sets a time limit for the Board’s future inquiries: six months from receiving an intimation, complaint, reference or direction, extendable by up to three months at a time for recorded reasons.
The Board’s provisions being in force does not by itself mean the Board has been constituted. Check the Gazette for appointment notifications rather than assuming either way.
13 November 2026: Consent Managers
Section 6(9) requires every Consent Manager to be registered with the Board. A Consent Manager is a person registered with the Board who acts as a single point of contact for a Data Principal to give, manage, review and withdraw consent through an interoperable platform (Section 2(g)).
Rule 4 sets out how registration works, and Part A of the First Schedule lists the conditions. They include being a company incorporated in India and having a net worth of not less than two crore rupees. Section 27(1)(d), which lets the Board inquire into a breach of a registration condition, starts the same day.
If you are not planning to become a Consent Manager, this date changes little for you directly.
13 May 2027: the duties on businesses
The third group is the one most businesses need to plan around. From this date:
- the Act starts to apply under Section 3, and processing needs a lawful ground under Section 4;
- notice and consent apply under Sections 5 and 6 (except Section 6(9)), with the notice contents in Rule 3;
- the Data Fiduciary’s general obligations apply under Section 8, with security safeguards in Rule 6, breach intimation in Rule 7, and retention and erasure in Rule 8;
- children’s data rules apply under Section 9 and Rule 10, and Significant Data Fiduciary duties under Section 10 and Rule 13;
- Data Principals’ rights and duties apply under Sections 11 to 15, with Rule 14 on how requests and grievances are handled;
- transfers outside India are governed by Section 16 and Rule 15;
- the Board’s inquiry powers under Section 27 (other than Section 27(1)(d), which starts earlier, on 13 November 2026) and Section 28, appeals under Section 29, and penalties under Section 33 all start.
Section 44(2) also starts on this date. It amends the Information Technology Act, 2000, including omitting its section 43A.
One consequence people miss: consent you already hold
Section 1(2) says that a reference in a provision to “the commencement of this Act” means the date that provision comes into force. Section 5(2) deals with consent given “before the date of commencement of this Act”. Section 5 comes into force on 13 May 2027. On a plain reading of Section 1(2), consents collected before that date fall under Section 5(2).
For those, Section 5(2)(a) requires a notice as soon as reasonably practicable, telling the person what data was processed and for what purpose, how to withdraw consent and use your grievance process (Sections 6(4) and 13), and how to complain to the Board. Section 5(2)(b) lets you keep processing until they withdraw consent. On that reading, every consent you collect before 13 May 2027 adds to the list of people you must notify. See what a consent notice must contain.
Planning backwards from 13 May 2027
The Act’s substantive duties and the penalty regime start on the same day, so there is no grace period after that date written into either notification. A workable plan starts with a data map, then the documents that support the duties: notices, a breach procedure, a retention schedule, a rights process and processor contracts. Each needs an owner and a finish date that leaves time for review before 13 May 2027.
Common questions
When do the main DPDP duties for businesses start?
On 13 May 2027, eighteen months after the notifications published on 13 November 2025. That group covers notice, consent, security safeguards, breach reporting, retention, children’s data, Significant Data Fiduciary duties, the rights of Data Principals, transfers outside India, most of the Board’s inquiry powers, and its power to impose penalties.
What starts on 13 November 2026?
Registration of Consent Managers. A Consent Manager is a person registered with the Board who gives people a single point of contact to give, manage, review and withdraw consent. The Board’s power to inquire into a breach of a registration condition starts the same day.
What took effect on 13 November 2025?
The framework, among other provisions: the definitions, the sections that establish the Data Protection Board of India, and the government’s rule-making powers. The notice, consent and security obligations of businesses were not part of that group.
Do the notifications print the dates 13 November 2026 and 13 May 2027?
No. They say one year and eighteen months after the date of publication. Counted from 13 November 2025, those dates are 13 November 2026 and 13 May 2027.
Is there a grace period after 13 May 2027?
Neither notification gives one. The duties and the Board’s power to impose penalties start on the same day.
Next steps
- Check whether the DPDP Act applies to your business, free, in a few clicks
- How-to 02: Plan the work, in the toolkit
- The free duties list, every duty in plain words
In the news
- DPDP Rules 2025: Fiduciary Duties Phase In Over 18 Months
Clear account of which rules start when; compare it with the dates we set out.
- Government notifies DPDP rules, sets 18-month roadmap for data protection regime
Early broadcast-press report on the phased roll-out of the Rules.
- First DPDP challenge: Knowing where your personal data lives
Recent column on using the run-up to the main duties for practical groundwork.
Sources
Every section, rule and date above was checked against the official text on 6 Oct 2026.
Digital Personal Data Protection Act, 2023 (No. 22 of 2023)
Official text: the Digital Personal Data Protection Act, 2023 (MeitY, PDF)
- Section 1(2)Different dates for different provisions; "commencement" means that provision's date
- Section 2Definitions, in force from 13 November 2025
- Section 2(g)Consent Manager
- Sections 3 to 17 (except 6(9)), 27 (except 27(1)(d)), 28 to 34, 36 and 37Application of the Act, and the other sections listed in clause (c), from 13 May 2027
- Section 5(2)Notice for consent given before commencement
- Section 6(9)Consent Manager registration, from 13 November 2026
- Sections 18 to 26The Board: establishment, composition, terms, officers
- Section 27(1)(d)Board inquiry into breach of a Consent Manager registration condition
- Section 35Protection of action taken in good faith; in force from 13 November 2025
- Sections 38 to 43Relationship with other laws, rule-making, amending the Schedule
- Section 44Section 44(1) and (3) from 13 November 2025; Section 44(2), amending the IT Act, 2000, from 13 May 2027
DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025)
- Rule 1(2), 1(3), 1(4)Staggered commencement of the Rules
- Rule 3Notice contents
- Rule 4Consent Manager registration and obligations, with Part A and Part B of the First Schedule
- Rule 6Security safeguards
- Rule 7Breach intimation
- Rule 8Retention and erasure
- Rule 10Children
- Rule 13Significant Data Fiduciaries
- Rule 14Rights and grievances
- Rule 15Transfers outside India
- Rules 17 to 21Board selection, pay, meetings, digital office and staff
- Rule 19(9)Board inquiries: six months, extendable by up to three months at a time
- First Schedule, Part AConsent Manager registration conditions, including incorporation in India and net worth of at least two crore rupees
Notifications
Official text: commencement notification G.S.R. 843(E) (MeitY, PDF)
- G.S.R. 843(E), clauses (a), (b) and (c)Commencement of the Act in three groups
- G.S.R. 846(E)The DPDP Rules, 2025: 23 rules and seven Schedules
A drafting aid. Get legal advice for your situation. This article explains the published text of the Act and the Rules.


