Every DPO training course starts in the same place: someone reads Section 8 of the DPDP Act 2023 out loud, calls the class to attention, and moves on. That is a mistake. If you do not know where the Act came from, you cannot predict where it is going, and DPDP is a moving target.
The constitutional starting point
The story starts in 2017. A nine-judge Bench of the Supreme Court of India ruled in Justice K.S. Puttaswamy v. Union of India that the right to privacy is a fundamental right under Article 21 of the Constitution [L1-C1]. The Court held that any restriction on privacy must satisfy three tests: legality, legitimate State aim, and proportionality. That ruling created an immediate policy problem. If privacy is a fundamental right, what statute protects it? India had nothing comprehensive.
The eight-year arc
The Central Government constituted the Srikrishna Committee in July 2017. It submitted its report and draft Bill in July 2018. That draft became the Personal Data Protection Bill 2019, which was reworked into the Data Protection Bill 2021, withdrawn from Parliament in August 2022, and finally re-introduced as the Digital Personal Data Protection Bill 2023. The Bill was passed by both Houses in August 2023 and received Presidential assent on 11 August 2023 as Act No. 22 of 2023 [L1-C2].
Then the Act sat. For over two years. Nothing to implement it. The Act was on the statute book but had no rules, no Board, no notified commencement of any substantive provision. Practitioners spoke of DPDP as if it were live, but a lawyer asked to prosecute a breach in early 2025 had nothing to file.
What changed on 13 November 2025
On 13 November 2025 the Ministry of Electronics and Information Technology (MeitY) issued four Gazette Notifications on the same day [L1-C3]:
- G.S.R. 843(E) — commencement of specific Sections of the DPDP Act 2023
- G.S.R. 844(E) — establishment of the Data Protection Board of India
- G.S.R. 845(E) — appointment of officers and preliminary machinery
- G.S.R. 846(E) — the Digital Personal Data Protection Rules, 2025
Together, these four notifications turned DPDP from a paper statute into a working regime. Not fully. Not immediately. But finally.
Why the Rules matter more than the Act right now
Most of the operational obligations live in the Rules, not the Act. The Act says "the Fiduciary shall give notice in such manner as may be prescribed" over and over. The prescribing happens in the Rules. Read the Rules and the Act reads differently.
A concrete example: the Act at Section 8(6) says "in the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed". Read alone, that sentence tells you nothing. Read alongside Rule 7, it tells you: intimate the affected Data Principal without delay in plain language, intimate the Board without delay of the initial description, and file the detailed report within 72 hours of becoming aware [L1-C4]. The Rule is the specification.
Why 13 May 2027 is the date
Rule 1(2) sets out a phased commencement. Machinery Rules (1, 2, 17-21) came into force on notification. Rule 4 on Consent Manager registration comes into force on 13 November 2026. Rules 3, 5-16, 22 and 23 come into force on 13 May 2027 [L1-C5]. That final date is when substantive obligations bite. Every DPO programme in India today is a countdown to 13 May 2027.
Practitioner rule of thumb: if you have not started implementation by August 2026, you are 21 months behind. If you have not started by January 2027, you are running critical path with no slack. The course is designed to close that gap.
The state of play in August 2026
Several things are pending as of the day this lesson was written and need re-checking on the day you act:
- The Data Protection Board is constituted but its Chairperson and Members are not fully appointed
[L1-C6]. There is no active regulator to inquire into a breach today. This will change. - No entity has been formally designated a Significant Data Fiduciary. The Section 10(1) power exists; no notification has issued.
- No Consent Manager has been registered. Rule 4 opens the registration window on 13 November 2026. MeitY has shortlisted six prototype builders (Jio Platforms, IDfy, Redacto, Zoop, Concur, Aurelion Future Forge).
- No country has been notified as restricted under Rule 15 for cross-border transfers. The negative list on paper is empty in practice.
- A batch of writ petitions challenging Section 36, Rules 22-23 and Section 44(3) is pending before the Supreme Court after referral to a larger bench on 16 February 2026. No interim stay
[L1-C7].
Every one of these will change. The course keeps you on the current side of each. In lessons that touch these items, the "as of August 2026" flag appears explicitly.
Why this matters for a DPO career
DPO salary bands in August 2026 already reflect the coming enforcement. SDF-scale DPOs at BFSI and big-tech firms command ₹60 lakh to ₹1.2 crore per year. Mid-size Data Fiduciary DPOs command ₹25 to 50 lakh. Fractional and outsourced DPO retainers are ₹4 to 15 lakh per month. Nobody in the market is being priced this way because they read the DPDP Act. They are being priced this way because they can operate the Rules, run a Rule 13 SDF programme, file a Rule 7 breach report, and reconcile all of it with CERT-In and RBI and SEBI parallel clocks. That is what the next seven modules teach.