Live Founding Cohort open, limited seats remaining Back to main site →

The three-phase commencement calendar

A single date structure that every compliance decision hangs off. Read this once and every later lesson locates itself against these three dates.

Free preview 8 min read Verified
Legal basis
DPDP Act 2023 (No. 22 of 2023, assented 11 August 2023). DPDP Rules 2025 notified 13 November 2025 via Gazette Notifications G.S.R. 843(E), 844(E), 845(E) and 846(E). Sectoral overlays as in force August 2026: CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); RBI Draft Data Governance Framework (15 July 2026, consultation closed 17 August 2026); SEBI CSCRF (20 August 2024); IRDAI Information and Cyber Security Guidelines 2026 (6 April 2026); Telecom Cyber Security Rules 2024 (21 November 2024); Aadhaar Data Security Regulations 2016. Constitutional context: Puttaswamy v. Union of India (2017) 10 SCC 1.

Rule 1(2) of the DPDP Rules 2025 sets a three-phase commencement. The three dates are the most important thing in the entire regime. If you remember nothing else from this course, remember these three.

Phase 1. 13 November 2025. Machinery on.

On the date of publication in the Official Gazette, Rules 1, 2 and 17 to 21 came into force [L2-C1]. These are the "machinery" Rules. Rule 1 titles the instrument and sets the phasing. Rule 2 gives definitions. Rules 17 to 21 constitute the Data Protection Board of India: Search-cum-Selection Committees for appointments, service conditions, the digital office, meeting procedure, officers and employees.

What this means in practice: from 13 November 2025 the Board can, in principle, function. Nobody has to comply with anything substantive yet. The regulator is warming up while the industry gets ready.

Phase 2. 13 November 2026. Consent Managers open.

One year from publication, Rule 4 comes into force [L2-C2]. Rule 4 opens the registration window for Consent Managers. Any Indian company that meets the First Schedule Part A conditions (audited net worth ≥ ₹2 crore, technical/operational/financial capability, no conflict of interest with Data Fiduciaries) can apply to the Board for registration. Once registered, the CM operates the consent architecture set out in Section 6(7)-(9) read with Part B of the First Schedule (data-blind pipe, ≥7-year consent-log retention, interoperability standards).

Why Rule 4 has its own phase: the CM ecosystem is India-original. There is no GDPR equivalent. MeitY needed a year of policy design and a Code-for-Consent prototype challenge before the door could open. Six firms were shortlisted from that challenge in mid-2025: Jio Platforms, Baldor Technologies (IDfy), VertexTech Labs (Redacto), Zoop (Quagga Tech), Concur, and Aurelion Future Forge. From 13 November 2026 they can start applying. Practitioners advising a Consent Manager applicant should have audited financials, ISO 27001-class controls and a board-approved conflict-of-interest policy ready by Q3 2026.

Phase 3. 13 May 2027. Substantive obligations bite.

Eighteen months from publication, Rules 3 and 5 to 16 and 22 and 23 come into force [L2-C3]. This is where the DPO's job actually starts.

Rules commencing on 13 May 2027:

  • Rule 3 — Notice by Data Fiduciary to Data Principal (Section 5)
  • Rule 5 — Processing for State subsidy/benefit/service/licence (Section 7(b))
  • Rule 6 — Reasonable security safeguards (Section 8(5))
  • Rule 7 — Personal data breach intimation (Section 8(6))
  • Rule 8 — Erasure trigger and Third Schedule retention (Section 8(7))
  • Rule 9 — Contact information (Section 5(1)(a) / Section 8(9))
  • Rule 10 — Verifiable consent for children (Section 9(1))
  • Rule 11 — Verifiable consent for persons with disabilities (Section 9(1) proviso)
  • Rule 12 — Fourth Schedule exemptions from Section 9(1)/(3)
  • Rule 13 — Additional obligations of Significant Data Fiduciary (Section 10)
  • Rule 14 — Rights of Data Principals and 90-day cap (Sections 11-14)
  • Rule 15 — Cross-border transfer restrictions (Section 16(1))
  • Rule 16 — Research/archiving/statistical exemption (Section 17(2)(b))
  • Rule 22 — Central Government information calls under Section 36 (Seventh Schedule)
  • Rule 23 — Confidentiality of Section 36 calls

Reading the calendar as a project plan

Every substantive obligation you owe under Chapter II of the Act (notice, consent, security, breach, erasure, children, SDF) crystallises on 13 May 2027. Everything you build before then is preparation, not compliance. Everything you build after that is remediation, not preparation. This is why the countdown matters.

A workable programme calendar for an average mid-large Fiduciary starting in August 2026 looks like this:

  1. Aug 2026 to Nov 2026 (T + 3 months). Data discovery. Draft RoPA. Baseline current notice + consent flows. Identify gaps.
  2. Nov 2026 to Feb 2027 (T + 6 months). Draft Rule 3-compliant notice. Design consent flows. Pick a Consent Manager (Rule 4 window now open). Begin vendor DPA renegotiations.
  3. Feb 2027 to May 2027 (T + 9 months). Retention regime rebuild under Rule 8 + Third Schedule. Rights request workflows. Grievance mechanism launch. Rule 7 breach runbook rehearsals.
  4. Post 13 May 2027. Live operations. Rule 13 SDF programme if designated. First DPB inquiries expected to begin.

What can move earlier

Two things are worth watching for acceleration.

First, MeitY consulted in January 2026 on whether to shorten the 18-month timeline to 12 months [L2-C4]. As of August 2026 no acceleration has been notified, but this is on the manual-verification checklist for anyone acting on the calendar. Second, sectoral overlays are already in force ahead of DPDP substantive commencement: RBI DGF Draft (July 2026), IRDAI Cyber Guidelines (April 2026), SEBI CSCRF (August 2024) and Telecom Cyber Security Rules (November 2024). BFSI, insurance and telecom entities are effectively operating to DPDP-style obligations already, via their sectoral regulators.

The three dates to memorise

13 November 2025. Machinery on. DPB constituted. Rules published. Nothing substantive yet.

13 November 2026. Consent Manager registration opens under Rule 4.

13 May 2027. Substantive obligations bite. Rules 3, 5-16, 22, 23 in force.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 7 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 7 paid modules (24 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹14,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
DPDP Rules 2025, Rule 1 (Short title, commencement) L2-C3
The Rules are called the Digital Personal Data Protection Rules, 2025. Commencement is phased: Rules 1, 2 and 17-21 come into force on publication (13 Nov 2025); Rule 4 (Consent Manager registration) on 13 November 2026; Rules 3, 5-16, 22-23 on 13 May 2027.
DPDP Rules 2025, Rule 4 (Registration and obligations of Consent Manager) L2-C2
A person may apply to the Board for registration as a Consent Manager if it fulfils the conditions in Part A of the First Schedule (Indian company, net worth at least two crore rupees, technical/operational/financial capability, no conflict of interest, etc.). A registered Consent Manager shall comply with the obligations in Part B (data-blind pipe, ≥7-year consent-log retention, interoperability, audit, security). Rule 4 commences 13 November 2026.
DPDP Gazette 2025, G.S.R. 846(E) (Digital Personal Data Protection Rules, 2025) L2-C4
MeitY notification dated 13 November 2025 promulgating the Digital Personal Data Protection Rules, 2025. Rules are structured as 23 Rules plus Seven Schedules with three-phase commencement: 13 Nov 2025 (machinery), 13 Nov 2026 (Consent Managers), 13 May 2027 (substantive obligations).
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: Foundations: The DPDP Act, the 2025 Rules, and the Commencement Calendar
Module 2: Notice, Consent, Cookies and the Consent Manager Ecosystem
  • Notice under Section 5 and Rule 3
  • The Section 6 consent test and withdrawal architecture
  • Cookies and the India grey zone
  • Consent Manager registration under Rule 4 and the MeitY six
Module 3: Data Discovery, RoPA and Retention
  • Data discovery and classification
  • Building a DPDP-fit Record of Processing Activities
  • Rule 8 retention and the Third Schedule
  • Layered retention across DPDP and sectoral rules
Module 4: Data Principal Rights and Grievance Management
  • Section 11 access and Rule 14 workflow
  • Section 12 correction, completion and erasure
  • Section 13 grievance mechanism and escalation to the Board
  • Section 14 nomination and Section 15 Data Principal duties
Module 5: Assessments: DPIA, Independent Audit and Algorithmic Due Diligence
  • SDF designation under Section 10 and the Rule 13 programme
  • Running a DPIA in practice
  • The DPO role in detail: qualifications, salary bands, reporting line
  • DPB adjudication and TDSAT appeal
Module 6: Breach Management: The Rule 7 Two-Stage Clock
  • What counts as a personal data breach
  • Rule 7 Stage 1 and Stage 2 mechanics
  • Parallel clocks: DPDP Rule 7 and CERT-In 6-hour
  • Rule 6 security safeguards
Module 7: Vendor Management, Cross-Border Transfers and Sector Overlays
  • Section 8(2) DPA and the ten non-negotiable clauses
  • Section 16 and Rule 15 cross-border transfer
  • Sector overlays: RBI, SEBI, IRDAI, Telecom, Aadhaar
  • Section 17 exemptions and the constitutional challenge
Module 8: Final Exam and Certificate