Rule 1(2) of the DPDP Rules 2025 sets a three-phase commencement. The three dates are the most important thing in the entire regime. If you remember nothing else from this course, remember these three.
Phase 1. 13 November 2025. Machinery on.
On the date of publication in the Official Gazette, Rules 1, 2 and 17 to 21 came into force [L2-C1]. These are the "machinery" Rules. Rule 1 titles the instrument and sets the phasing. Rule 2 gives definitions. Rules 17 to 21 constitute the Data Protection Board of India: Search-cum-Selection Committees for appointments, service conditions, the digital office, meeting procedure, officers and employees.
What this means in practice: from 13 November 2025 the Board can, in principle, function. Nobody has to comply with anything substantive yet. The regulator is warming up while the industry gets ready.
Phase 2. 13 November 2026. Consent Managers open.
One year from publication, Rule 4 comes into force [L2-C2]. Rule 4 opens the registration window for Consent Managers. Any Indian company that meets the First Schedule Part A conditions (audited net worth ≥ ₹2 crore, technical/operational/financial capability, no conflict of interest with Data Fiduciaries) can apply to the Board for registration. Once registered, the CM operates the consent architecture set out in Section 6(7)-(9) read with Part B of the First Schedule (data-blind pipe, ≥7-year consent-log retention, interoperability standards).
Why Rule 4 has its own phase: the CM ecosystem is India-original. There is no GDPR equivalent. MeitY needed a year of policy design and a Code-for-Consent prototype challenge before the door could open. Six firms were shortlisted from that challenge in mid-2025: Jio Platforms, Baldor Technologies (IDfy), VertexTech Labs (Redacto), Zoop (Quagga Tech), Concur, and Aurelion Future Forge. From 13 November 2026 they can start applying. Practitioners advising a Consent Manager applicant should have audited financials, ISO 27001-class controls and a board-approved conflict-of-interest policy ready by Q3 2026.
Phase 3. 13 May 2027. Substantive obligations bite.
Eighteen months from publication, Rules 3 and 5 to 16 and 22 and 23 come into force [L2-C3]. This is where the DPO's job actually starts.
Rules commencing on 13 May 2027:
- Rule 3 — Notice by Data Fiduciary to Data Principal (Section 5)
- Rule 5 — Processing for State subsidy/benefit/service/licence (Section 7(b))
- Rule 6 — Reasonable security safeguards (Section 8(5))
- Rule 7 — Personal data breach intimation (Section 8(6))
- Rule 8 — Erasure trigger and Third Schedule retention (Section 8(7))
- Rule 9 — Contact information (Section 5(1)(a) / Section 8(9))
- Rule 10 — Verifiable consent for children (Section 9(1))
- Rule 11 — Verifiable consent for persons with disabilities (Section 9(1) proviso)
- Rule 12 — Fourth Schedule exemptions from Section 9(1)/(3)
- Rule 13 — Additional obligations of Significant Data Fiduciary (Section 10)
- Rule 14 — Rights of Data Principals and 90-day cap (Sections 11-14)
- Rule 15 — Cross-border transfer restrictions (Section 16(1))
- Rule 16 — Research/archiving/statistical exemption (Section 17(2)(b))
- Rule 22 — Central Government information calls under Section 36 (Seventh Schedule)
- Rule 23 — Confidentiality of Section 36 calls
Reading the calendar as a project plan
Every substantive obligation you owe under Chapter II of the Act (notice, consent, security, breach, erasure, children, SDF) crystallises on 13 May 2027. Everything you build before then is preparation, not compliance. Everything you build after that is remediation, not preparation. This is why the countdown matters.
A workable programme calendar for an average mid-large Fiduciary starting in August 2026 looks like this:
- Aug 2026 to Nov 2026 (T + 3 months). Data discovery. Draft RoPA. Baseline current notice + consent flows. Identify gaps.
- Nov 2026 to Feb 2027 (T + 6 months). Draft Rule 3-compliant notice. Design consent flows. Pick a Consent Manager (Rule 4 window now open). Begin vendor DPA renegotiations.
- Feb 2027 to May 2027 (T + 9 months). Retention regime rebuild under Rule 8 + Third Schedule. Rights request workflows. Grievance mechanism launch. Rule 7 breach runbook rehearsals.
- Post 13 May 2027. Live operations. Rule 13 SDF programme if designated. First DPB inquiries expected to begin.
What can move earlier
Two things are worth watching for acceleration.
First, MeitY consulted in January 2026 on whether to shorten the 18-month timeline to 12 months [L2-C4]. As of August 2026 no acceleration has been notified, but this is on the manual-verification checklist for anyone acting on the calendar. Second, sectoral overlays are already in force ahead of DPDP substantive commencement: RBI DGF Draft (July 2026), IRDAI Cyber Guidelines (April 2026), SEBI CSCRF (August 2024) and Telecom Cyber Security Rules (November 2024). BFSI, insurance and telecom entities are effectively operating to DPDP-style obligations already, via their sectoral regulators.
The three dates to memorise
13 November 2025. Machinery on. DPB constituted. Rules published. Nothing substantive yet.
13 November 2026. Consent Manager registration opens under Rule 4.
13 May 2027. Substantive obligations bite. Rules 3, 5-16, 22, 23 in force.