Three commencement dates
G.S.R. 843(E) brought the Act into force in stages. From 13 November 2025: the definitions, the Board provisions (sections 18 to 26), sections 35 and 38 to 43, and sub-sections (1) and (3) of section 44. One year later, in November 2026: Consent Manager registration (section 6(9)) and the Board's power over registration breaches (section 27(1)(d)).
Eighteen months after, around May 2027: everything else. That includes notice, consent, legitimate uses, Fiduciary duties, children, SDFs, rights and duties of people, and cross-border transfers. It also includes exemptions, most Board powers, penalties and appeals, and the omission of IT Act section 43A.
Sources: G.S.R. 843(E)
The Rules follow the same pattern
Rule 1 matches this. Rules 1, 2 and 17 to 21, on the Board, applied from publication, and Rule 4, on Consent Managers, applies one year after. Rules 3, 5 to 16, 22 and 23 apply eighteen months after. A December 2025 corrigendum, G.S.R. 892(E), corrected only wording and typing errors.
Sources: Rules r.1G.S.R. 892(E)
Latest status (28 Sep 2026)
No amendment to the Act or the Rules was located in the Gazette or on MeitY's site; the only later instrument found is the G.S.R. 892(E) corrigendum. MeitY reportedly consulted in January 2026 on cutting 18 months to 12. No notification doing so was located, so the May 2027 date stands.
The Board exists in law, but on 6 May 2026 MeitY was still inviting applications for its Chairperson and four Members. No appointment was confirmed from a primary source by 28 September 2026. Its powers to hear complaints and impose penalties start around May 2027.
No Consent Manager can be registered before Rule 4 starts in November 2026, and no Board registration process was located. No Significant Data Fiduciary, section 16 country restriction, Rule 15 order, startup exemption or official MeitY FAQ was located either. Treat each as not yet issued, and recheck.
Sources: G.S.R. 892(E)MeitY circular 6 May 2026
Sector clocks run alongside DPDP
Sector rules already apply and will keep applying. CERT-In's 2022 Directions require listed cyber incidents, including data breaches and leaks, to be reported within 6 hours of noticing them. RBI's July 2026 Directions require banks and other covered entities to report cyber incidents on its DAKSH portal within 6 hours of detection.
SEBI's CSCRF requires a 6-hour notice to SEBI and CERT-In for serious incidents, with portal details within 24 hours. IRDAI asks insurers to report to CERT-In within 6 hours with a copy to IRDAI. The DPDP Board duty differs: without delay, then a detailed report within 72 hours, from around May 2027.
Sources: CERT-In Directions 2022RBI Cyber Directions 2026SEBI CSCRF 2024IRDAI Guidelines 2026Rules r.7
Getting ready: a sensible order
Most of this work takes months, so start early. Map where personal data sits and why, choose the lawful ground for each purpose, and draft Rule 3 notices and consent records. Set retention and erasure rules, and build breach, rights and grievance processes. Review Processor contracts, and check whether children's data or SDF duties apply.
Key points
- Board provisions since 13 November 2025; most duties around May 2027.
- Consent Manager registration starts in November 2026.
- No amendment or 12-month cut was located by 28 September 2026.
- Board posts were still being advertised in May 2026.
- CERT-In, RBI, SEBI and IRDAI 6-hour clocks apply already.
In practice
A checklist for your organisation.
- Build a compliance plan that finishes well before May 2027.
- Run DPDP breach steps alongside your 6-hour sector reports.
- Check the Gazette and MeitY monthly for new notifications.
- Keep dated evidence of each control you put in place.
Check what you learned
5 questions. Choose an answer to see why it is right.
0 of 5 answered
Question 1 of 5
How long after publication do most duties, such as notice and breach reporting, come into force?
Show the answer
C. 18 months
G.S.R. 843(E) para (c) and Rule 1(4) bring the main duties into force eighteen months after publication.
G.S.R. 843(E); Rules r.1(4)G.S.R. 843(E) para (c) and Rule 1(4) bring the main duties into force eighteen months after publication.
G.S.R. 843(E); Rules r.1(4)Question 2 of 5
Which provisions came into force on publication, 13 November 2025?
Show the answer
D. The Board provisions, sections 18 to 26
G.S.R. 843(E) para (a) brought sections 18 to 26, among others, into force from the date of publication.
G.S.R. 843(E)G.S.R. 843(E) para (a) brought sections 18 to 26, among others, into force from the date of publication.
G.S.R. 843(E)Question 3 of 5
When does Rule 4 on Consent Managers come into force?
Show the answer
B. One year after publication
Rule 1(3) brings Rule 4 into force one year after publication.
Rules r.1(3)Rule 1(3) brings Rule 4 into force one year after publication.
Rules r.1(3)Question 4 of 5
Under CERT-In's 2022 Directions, within how many hours must a listed cyber incident be reported?
Show the answer
B. 6 hours
CERT-In Directions No. 20(3)/2022-CERT-In require reporting within 6 hours of noticing listed incidents, including data breaches and leaks.
CERT-In Directions 2022CERT-In Directions No. 20(3)/2022-CERT-In require reporting within 6 hours of noticing listed incidents, including data breaches and leaks.
CERT-In Directions 2022Question 5 of 5
Where is the Data Protection Board's head office?
Show the answer
B. National Capital Region
G.S.R. 844(E) para 2 places the head office of the Data Protection Board of India in the National Capital Region.
G.S.R. 844(E)G.S.R. 844(E) para 2 places the head office of the Data Protection Board of India in the National Capital Region.
G.S.R. 844(E)
Official sources for this lesson
- Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), MeitY, 13 November 2025 (with Schedules)
- G.S.R. 843(E), 13 November 2025: dates on which provisions of the DPDP Act come into force
- G.S.R. 844(E), 13 November 2025: establishment of the Data Protection Board of India
- G.S.R. 892(E), 10 December 2025: corrigenda to the DPDP Rules, 2025
- MeitY F. No. 2(1)/2026-Pers.I, 6 May 2026: appointment to the posts of Chairperson and Members, Data Protection Board of India
- MeitY advertisement: filling up the posts of Chairman and Members in the Data Protection Board of India (2026)
- CERT-In Directions No. 20(3)/2022-CERT-In under s.70B(6) of the IT Act, 28 April 2022 (sector note)
- RBI Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions for commercial banks, RBI/DoS/2026-27/410, 31 July 2026 (sector note)
- SEBI Cybersecurity and Cyber Resilience Framework, SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113, 20 August 2024 (sector note)
- IRDAI Information and Cyber Security Guidelines 2026, Version 2.0 (sector note; text read from a MediaNama-hosted copy)
A plain-English summary of the DPDP Act 2023 and DPDP Rules 2025, checked on 28 September 2026. It is not legal advice. Words in this lesson are explained in the DPDP dictionary.