The DPDP compliance clock: every deadline between now and May 2027

India's DPDP Rules were notified in November 2025. Soft enforcement runs through 2026; hard enforcement is widely expected in May 2027. A dated roadmap, and what to do in which order.

THE RECORDISSUE 17
COVER

THE RECORD

THE ALCYONE SECURE FIELD JOURNAL

ISSUE

17

COMPLIANCE · AUG 2026

The DPDP compliance clock: every deadline between now and May 2027

India's DPDP Rules were notified in November 2025. Soft enforcement runs through 2026; hard enforcement is widely expected in May 2027. A dated roadmap, and what to do in which order.

BB-REC-17 · 9 MIN READ

THE RECORD · ISSUE 17 · COMPLIANCE9 MIN READ

COMPLIANCE · ISSUE 17

Most writing about India's Digital Personal Data Protection framework explains the principles. Fewer pieces answer the question businesses actually ask, which is when does this start costing me money, and what do I need finished by then. This is that piece.

The dates

14 November 2025, the Rules are notified

The DPDP Rules 2025 were notified, giving operational shape to the Act passed in 2023. This is the point from which every other date is counted.

Through 2026, soft enforcement

The expectation across compliance practice is that this period is one of guidance and warnings rather than penalties: the Data Protection Board of India building awareness and organisations building programmes. It is a grace period, not an exemption, and it is finite.

June to August 2026, the Consent Manager framework

The central government is expected to operationalise the Consent Manager framework in this window. Consent Managers are interoperable platforms through which individuals can grant, review and withdraw consent across multiple services from one place.

This is the item most organisations underestimate. If people can withdraw consent centrally, your systems have to be able to receive that signal and act on it, which usually means knowing where the relevant personal data actually is. Most organisations discover at this point that they do not.

November 2026, the end of the soft phase

One year after notification. This is widely expected to mark the transition from awareness building to active regulatory supervision.

13-14 May 2027, hard enforcement

The date most commonly cited as the point at which the framework carries real consequences. If your programme is not finished by then, you are relying on not being looked at.

The arithmetic nobody likes

Compliance practice puts a typical enterprise DPDP programme at nine to twelve months for gap assessment, control implementation and audit readiness. Count backwards from May 2027 and the honest conclusion is that an organisation starting after roughly mid-2026 is already compressed.

The other thing to plan for is legacy data. Personal data collected before the framework existed is expected to need valid notice and consent consistent with the Act. For most organisations this is the largest single item, not because it is technically hard, but because nobody knows how much there is or where it sits until they look.

What to do, in order

  1. 01Find the data. A data inventory and flow map. What personal data you hold, where it lives, who it goes to, and why. Everything else depends on this and it always takes longer than planned.
  2. 02Fix the notice and consent path. Clear, plain-language notice at collection, and consent that is specific rather than bundled. Then the harder part: a working mechanism for withdrawal that your systems honour.
  3. 03Name a Grievance Officer. A named individual with authority to resolve complaints, published in your privacy notice. A generic inbox does not satisfy this.
  4. 04Deal with legacy data. Decide, per dataset, whether to re-consent, re-base or delete. Deletion is frequently the cheapest compliant answer and is consistently the last one considered.
  5. 05Write down the security controls. Reasonable security safeguards are an obligation, not a recommendation, and you will be asked what yours were.
  6. 06Rehearse a breach. Notification to the Board and to affected individuals is required. The middle of an incident is a bad time to discover you have no process.
  7. 07Keep evidence. Being compliant and being able to demonstrate compliance are different projects, and only the second one survives an inquiry.

The last point deserves more than a bullet

Almost every obligation above eventually reduces to the same demand: show us. Show us the consent. Show us who accessed that record. Show us that the device the contractor used was not a hole in your controls.

Policies are the cheap half. Records are the half that holds up. And device level accountability is the gap most programmes leave open longest, because it is nobody's obvious job, the security team owns the network, IT owns the endpoints, and what a specific person did on a specific machine during a specific window belongs to neither.

Black Box covers that gap: a tamper evident record of activity on a device, which is one of the technical controls a serious data fiduciary is expected to be able to produce. For organisations that want the whole assessment rather than one control, we run a DPDP compliance service.

When does the DPDP Act become enforceable?+

The Rules were notified on 14 November 2025. Through 2026 the expectation is soft enforcement, guidance and warnings. Hard enforcement is widely expected around 13-14 May 2027, and November 2026 is anticipated as the end of the initial implementation phase. These milestones are the consensus of compliance practice, not fixed statutory dates.

Does DPDP apply to my business if I am not in India?+

It applies to processing of personal data of individuals in India, including by businesses outside India offering goods or services to them. Where you are incorporated is not the test. If you have customers, employees or vendors in India you are very likely a data fiduciary.

What is a Consent Manager?+

An interoperable platform through which individuals can give, review and withdraw consent across multiple services from a single place. The framework is expected to become operational around mid-2026. The practical implication is that your systems need to be able to receive and act on a withdrawal signal you did not originate.

How long does DPDP compliance take?+

Compliance practice puts a typical enterprise programme at nine to twelve months across gap assessment, control implementation and audit readiness. Legacy data is usually the largest single item and the one most often underestimated.

Do I need a Grievance Officer?+

Yes. The Act requires a named individual with authority to address complaints, with contact details published in your privacy notice. A generic support inbox does not meet the requirement.

END OF ISSUE 17

Want a forensic recorder on your machine?

Black Box ships free for individuals, a tamper evident flight recorder for your Windows device. Everything in this issue is the reason it exists.

ALCYONE SECURE · TRUST IS GOOD. PROOF IS BETTER.