Lesson 12 of 12 · 7 min read

Timelines and getting ready

When each part of the Act and Rules starts, the position on 28 September 2026, and how sector clocks run alongside DPDP.

Three commencement dates

G.S.R. 843(E) brought the Act into force in stages. From 13 November 2025: the definitions, the Board provisions (sections 18 to 26), sections 35 and 38 to 43, and sub-sections (1) and (3) of section 44. One year later, in November 2026: Consent Manager registration (section 6(9)) and the Board's power over registration breaches (section 27(1)(d)).

Eighteen months after, around May 2027: everything else. That includes notice, consent, legitimate uses, Fiduciary duties, children, SDFs, rights and duties of people, and cross-border transfers. It also includes exemptions, most Board powers, penalties and appeals, and the omission of IT Act section 43A.

Sources: G.S.R. 843(E)

The Rules follow the same pattern

Rule 1 matches this. Rules 1, 2 and 17 to 21, on the Board, applied from publication, and Rule 4, on Consent Managers, applies one year after. Rules 3, 5 to 16, 22 and 23 apply eighteen months after. A December 2025 corrigendum, G.S.R. 892(E), corrected only wording and typing errors.

Sources: Rules r.1G.S.R. 892(E)

Latest status (28 Sep 2026)

No amendment to the Act or the Rules was located in the Gazette or on MeitY's site; the only later instrument found is the G.S.R. 892(E) corrigendum. MeitY reportedly consulted in January 2026 on cutting 18 months to 12. No notification doing so was located, so the May 2027 date stands.

The Board exists in law, but on 6 May 2026 MeitY was still inviting applications for its Chairperson and four Members. No appointment was confirmed from a primary source by 28 September 2026. Its powers to hear complaints and impose penalties start around May 2027.

No Consent Manager can be registered before Rule 4 starts in November 2026, and no Board registration process was located. No Significant Data Fiduciary, section 16 country restriction, Rule 15 order, startup exemption or official MeitY FAQ was located either. Treat each as not yet issued, and recheck.

Sources: G.S.R. 892(E)MeitY circular 6 May 2026

Sector clocks run alongside DPDP

Sector rules already apply and will keep applying. CERT-In's 2022 Directions require listed cyber incidents, including data breaches and leaks, to be reported within 6 hours of noticing them. RBI's July 2026 Directions require banks and other covered entities to report cyber incidents on its DAKSH portal within 6 hours of detection.

SEBI's CSCRF requires a 6-hour notice to SEBI and CERT-In for serious incidents, with portal details within 24 hours. IRDAI asks insurers to report to CERT-In within 6 hours with a copy to IRDAI. The DPDP Board duty differs: without delay, then a detailed report within 72 hours, from around May 2027.

Sources: CERT-In Directions 2022RBI Cyber Directions 2026SEBI CSCRF 2024IRDAI Guidelines 2026Rules r.7

Getting ready: a sensible order

Most of this work takes months, so start early. Map where personal data sits and why, choose the lawful ground for each purpose, and draft Rule 3 notices and consent records. Set retention and erasure rules, and build breach, rights and grievance processes. Review Processor contracts, and check whether children's data or SDF duties apply.

Key points

  • Board provisions since 13 November 2025; most duties around May 2027.
  • Consent Manager registration starts in November 2026.
  • No amendment or 12-month cut was located by 28 September 2026.
  • Board posts were still being advertised in May 2026.
  • CERT-In, RBI, SEBI and IRDAI 6-hour clocks apply already.

In practice

A checklist for your organisation.

  • Build a compliance plan that finishes well before May 2027.
  • Run DPDP breach steps alongside your 6-hour sector reports.
  • Check the Gazette and MeitY monthly for new notifications.
  • Keep dated evidence of each control you put in place.

Check what you learned

5 questions. Choose an answer to see why it is right.

0 of 5 answered

  1. Question 1 of 5

    How long after publication do most duties, such as notice and breach reporting, come into force?

    Show the answer

    C. 18 months

    G.S.R. 843(E) para (c) and Rule 1(4) bring the main duties into force eighteen months after publication.

    G.S.R. 843(E); Rules r.1(4)
  2. Question 2 of 5

    Which provisions came into force on publication, 13 November 2025?

    Show the answer

    D. The Board provisions, sections 18 to 26

    G.S.R. 843(E) para (a) brought sections 18 to 26, among others, into force from the date of publication.

    G.S.R. 843(E)
  3. Question 3 of 5

    When does Rule 4 on Consent Managers come into force?

    Show the answer

    B. One year after publication

    Rule 1(3) brings Rule 4 into force one year after publication.

    Rules r.1(3)
  4. Question 4 of 5

    Under CERT-In's 2022 Directions, within how many hours must a listed cyber incident be reported?

    Show the answer

    B. 6 hours

    CERT-In Directions No. 20(3)/2022-CERT-In require reporting within 6 hours of noticing listed incidents, including data breaches and leaks.

    CERT-In Directions 2022
  5. Question 5 of 5

    Where is the Data Protection Board's head office?

    Show the answer

    B. National Capital Region

    G.S.R. 844(E) para 2 places the head office of the Data Protection Board of India in the National Capital Region.

    G.S.R. 844(E)

Official sources for this lesson

A plain-English summary of the DPDP Act 2023 and DPDP Rules 2025, checked on 28 September 2026. It is not legal advice. Words in this lesson are explained in the DPDP dictionary.