Updated October 2026. Dates below follow the phased schedule in the DPDP Rules, 2025. Confirm official notifications from MeitY.
When the government notified the Digital Personal Data Protection (DPDP) Rules in November 2025, it chose a phased rollout over 18 months. The next milestone is close.
The phased timeline
| When | What applies |
|---|---|
| November 2025 | Definitions, the Data Protection Board of India, and rule-making provisions came into force. The Board was set up as a digital-first regulator. |
| Around mid-November 2026 (about 12 months later) | Consent Manager framework: registration of Consent Managers with the Board |
| Around mid-May 2027 (about 18 months later) | Core obligations for Data Fiduciaries: notices, consent, security safeguards, breach notification, data principal rights, children’s data, and so on |
What is a Consent Manager?
A Consent Manager is a registered entity that gives individuals a single interface to give, manage, review and withdraw consent across many companies. It is somewhat like the Account Aggregator model in finance. Under the Rules, Consent Managers must be Indian companies that meet the eligibility conditions, including financial and technical requirements.
Seven months to May 2027: a company checklist
- Data inventory: what personal data you collect, where it lives, who can access it, and the purpose for each item.
- Notices and consent flows: clear, standalone notices, and a way to withdraw consent that is as easy as giving it.
- Retention and deletion: delete data once its purpose ends, as the Rules require.
- Security safeguards: encryption, access control, logging and monitoring.
- Breach response: processes to notify the Board and affected individuals. Align these with CERT-In’s 6-hour incident reporting.
- Rights handling: processes for access, correction and erasure requests within the prescribed time.
- Vendor contracts: data processing terms with processors and cloud providers.
- Children’s data: verifiable parental consent mechanisms where relevant.
Penalties under the Act can reach ₹250 crore for failing to take reasonable security safeguards.
Jobs angle
Privacy engineering, DPO and privacy-ops roles, consent and identity engineering, and GRC are growing fast. Our DPDP explainer in the Legal section covers your rights as an individual.
Sources
This article is general information, not legal advice.
Leave a Reply