Key points
- The penalty provisions of the DPDP Act are not in force, and do not commence in November 2026. Section 33 falls in the eighteen-month tranche under G.S.R. 843(E).
- The Data Protection Board is constituted, but Section 27 — its powers and functions — is itself deferred to the eighteen-month mark, save one clause.
- The only obligations commencing at twelve months are the Consent Manager package: Section 6(9), Section 27(1)(d), and Rule 4.
- Consent Manager registration is conditioned on a certification against standards the Board has not yet published.
- Substantive duties on every Data Fiduciary — notice, security safeguards, breach reporting, retention, children’s data, cross-border transfer — commence eighteen months from 13 November 2025.
Two separate gazette notifications of 13 November 2025 do different jobs. G.S.R. 843(E) brings provisions of the Act into force in three tranches. G.S.R. 846(E) notifies the Rules, which carry their own staggered commencement in Rule 1. Citing one without the other produces the wrong answer, which is the origin of most of the confusion presently in circulation.
What is actually in force
Tranche 1
13 November 2025
In force
Institutional framework only
Under G.S.R. 843(E)(a): Section 1(2), Section 2 (definitions), Sections 18 to 26 (constitution of the Data Protection Board), Sections 35, 38 to 43, and Sections 44(1) and 44(3). Under Rule 1(2) of the Rules: Rules 1, 2 and 17 to 21.
What this means in practice is narrower than it is often described. The Board exists as a body. Its powers and functions under Section 27 — including the power to inquire into a complaint or a breach and to impose a penalty — are not among the provisions brought into force on this date.
Tranche 2
Twelve months
Consent Managers only
Section 6(9), Section 27(1)(d) and Rule 4
That is the whole of it. Nothing else commences at the twelve-month mark. Rule 4 opens registration of Consent Managers with the Board and sets out the conditions in Part A of the First Schedule and the obligations in Part B.
The commencement language is “one year from the date of publication of this gazette”. Whether that falls on 13 or 14 November 2026 turns on the computation rule in Section 9 of the General Clauses Act, 1897, and published sources differ. For any matter where the date is operative, it should be settled on the facts rather than assumed.
Tranche 3
13 May 2027
Substantive obligations
Everything that bites
Under G.S.R. 843(E)(c): Sections 3 to 5, Section 6(1) to (8) and (10), Sections 7 to 10, Sections 11 to 17, Section 27 other than clause (d) of sub-section (1), Sections 28 to 34, Sections 36 and 37, and Section 44(2). Under Rule 1(4): Rules 3, 5 to 16, 22 and 23.
Section 33, which carries the penalty framework, sits inside this tranche. So does Section 27 generally, which is what confers the Board’s adjudicatory function. Until this date, the Information Technology Act, 2000 and the rules made under it continue to do the work they have always done.
On the November 2026 penalty claim
A number of published timelines state that enforcement powers and penalties activate at the twelve-month mark. That is not what either notification says. Section 33 is within Sections 28 to 34, which G.S.R. 843(E) places at eighteen months, and Rule 22 — appeal to the Appellate Tribunal — is likewise in the eighteen-month tranche under Rule 1(4). Any compliance plan built on a November 2026 penalty date is working from a misreading.
Whether the Act applies at all
The threshold question is rarely as obvious as it looks, and it is the question most often asked before anything else. The Act reaches the processing of digital personal data within India, and processing outside India where it is in connection with offering goods or services to Data Principals within India. A company with no Indian establishment can therefore be a Data Fiduciary.
Three distinctions do most of the work in practice. Whether an organisation is a Data Fiduciary, a Data Processor, or both in respect of different processing, since the obligations differ and the contractual consequences differ more. Whether any of the legitimate uses in Section 7 are engaged, which removes the consent requirement for that processing but not the other duties. And whether the organisation is likely to be notified as a Significant Data Fiduciary, which brings the additional obligations in Rule 13 — a data protection impact assessment and audit once in every period of twelve months, a report of significant observations furnished to the Board, due diligence on algorithmic software, and a restriction on transferring specified personal data and its traffic data outside India.
This is an opinion question rather than a software question. It is also the answer an auditor, an acquirer or a customer’s vendor questionnaire will ask to see in writing.
The Consent Manager window, and the difficulty underneath it
Rule 4 permits a person satisfying the conditions in Part A of the First Schedule to apply to the Board for registration. The conditions are specific: incorporation as a company in India; sufficient technical, operational and financial capacity; sound financial condition and general character of management; net worth of not less than two crore rupees; adequate volume of likely business, capital structure and earning prospects; directors, key managerial personnel and senior management of general reputation and record of fairness and integrity; and provisions in the memorandum and articles requiring adherence to items 9 and 10 of Part B, amendable only with the prior approval of the Board.
The ninth condition is the one that repays attention. It requires independent certification that the applicant’s interoperable platform is consistent with such data protection standards and assurance framework as may be published by the Board on its website from time to time.
No such standards or assurance framework have been published. On the position reported through 2026, no Chairperson and no Members of the Board have been appointed, the Search-cum-Selection Committees under Rule 17 having sought nominations in May and June 2026 without appointments following. A condition of registration is therefore contingent on a document that only a constituted Board can issue.
The obligations in Part B are equally concrete and worth reading before a business model is fixed: the sharing mechanism must be such that the Consent Manager cannot read the contents; records of consents given, denied and withdrawn must be retained for at least seven years; no obligation may be sub-contracted or assigned; the Consent Manager acts in a fiduciary capacity toward the Data Principal; conflicts of interest with Data Fiduciaries, including through directorships, financial interests, employment or beneficial ownership, must be actively excluded; shareholdings above two per cent must be published; and control of the company cannot be transferred by sale, merger or otherwise without the Board’s prior approval.
If you are planning to register
The corporate and constitutional-document work — incorporation, net worth, memorandum and articles amendments, conflict-of-interest structuring — can be completed now and does not depend on the Board. The certification cannot. Sequencing the two is the practical question.
Discuss a Consent Manager registration →
What the substantive obligations require
These commence at eighteen months. The work of meeting them does not compress into the final quarter, which is the reason for setting them out now rather than in 2027.
Notice
Rule 3 requires the notice to be presented and understandable independently of any other information the Data Fiduciary makes available — which is to say, not folded into terms of service. It must give, in clear and plain language, an itemised description of the personal data and the specified purposes, together with the communication link and other means by which the Data Principal may withdraw consent with an ease comparable to that with which it was given, exercise rights, and complain to the Board.
Security safeguards
Rule 6 sets a minimum rather than a standard of reasonableness at large: encryption, obfuscation, masking or virtual tokens; access control over computer resources; logs, monitoring and review sufficient to detect and investigate unauthorised access; measures for continued processing such as backups; retention of those logs and the personal data for one year; appropriate provision in the contract with any Data Processor; and technical and organisational measures to ensure the safeguards are observed.
Breach reporting
Rule 7 is two-stage and is frequently described as a single seventy-two hour rule, which understates it. Each affected Data Principal must be intimated without delay, with a description of the breach, the consequences relevant to her, the mitigation measures taken, the safety measures she may take, and a business contact who can answer questions. The Board must be intimated without delay with a description including nature, extent, timing, location and likely impact; and then, within seventy-two hours of becoming aware, with updated and detailed information, the broad facts and circumstances, mitigation measures, any findings regarding the person who caused the breach, remedial measures, and a report on the intimations given to Data Principals.
The judgment of whether an incident is a reportable personal data breach at all, and how the sequence sits alongside the CERT-In directions, is where the legal exposure actually lies.
Retention and erasure
Rule 8 and the Third Schedule apply defined erasure periods to three classes: an e-commerce entity with not less than two crore registered users in India, an online gaming intermediary with not less than fifty lakh, and a social media intermediary with not less than two crore. The period is three years from the date the Data Principal last approached the Data Fiduciary or last exercised her rights, or the commencement of the Rules, whichever is latest. At least forty-eight hours before erasure the Data Principal must be told. Separately, Rule 8(3) requires personal data, associated traffic data and processing logs to be retained for a minimum of one year.
Children and persons with disability
Rule 10 requires verifiable parental consent before processing a child’s personal data, with due diligence to check that the person identifying herself as the parent is an identifiable adult, by reference to reliable identity and age details held by the Data Fiduciary or provided voluntarily, including through a virtual token issued by an authorised entity or a Digital Locker service provider. Rule 11 makes parallel provision for persons with disability who have a lawful guardian. Rule 12 and the Fourth Schedule carve out defined classes — clinical and mental health establishments, healthcare and allied healthcare professionals, educational institutions, crΓ¨ches and child care centres, and transport providers engaged by them — and defined purposes, each on stated conditions.
Cross-border transfer
Rule 15 is permissive in form. Personal data may be transferred outside India, subject to the Data Fiduciary meeting such requirements as the Central Government may specify by general or special order in respect of making the data available to a foreign State or to a person or entity under its control. The restricted-country model in the January 2025 draft did not survive into the notified Rules, and commentary still describing a blacklist is describing the draft. A separate and narrower restriction applies to Significant Data Fiduciaries under Rule 13(4).
Rights and grievances
Rule 14 requires the means of making a rights request to be published prominently, together with any identifier needed, and requires a grievance redressal system responding within a period not exceeding ninety days, supported by technical and organisational measures sufficient to make that period real.
Where DPDP meets an existing regulator
For a regulated entity the difficult question is not what DPDP requires but how it sits with obligations already in place. Storage-of-payment-data directions and outsourcing norms for entities regulated by the Reserve Bank; cyber security and system audit frameworks in the securities market; insurance-sector record and outsourcing requirements; health data standards; and the CERT-In directions on incident reporting, which run on their own timeline and to their own authority.
Where two instruments require different things of the same dataset, the resolution is a question of construction, not configuration. It is also the area in which the least published guidance exists.
How this practice assists
Written applicability opinions, including capacity as Data Fiduciary or Processor and exposure to Significant Data Fiduciary notification. Consent Manager eligibility assessment and preparation of the application to the Board, together with the corporate and constitutional-document work the conditions require. Data processing agreements, processor and sub-processor terms, and allocation of liability. Notice and consent drafting. Breach response, including the reportability decision and the sequence against sectoral obligations. Children’s data and age-assurance questions. Analysis where DPDP and a sectoral regulator pull in different directions. Representation before the Board and on appeal, once those provisions commence.
No outcome can be promised, and what is required in any matter depends on its facts.
Common questions
Do DPDP penalties start in November 2026?
No. Section 33, which carries the penalty framework, falls within Sections 28 to 34, which G.S.R. 843(E) brings into force eighteen months from 13 November 2025. The only provisions commencing at the twelve-month mark are Section 6(9), Section 27(1)(d) and Rule 4 of the Rules, all of which concern Consent Managers. Several published timelines state otherwise; the notification does not support them.
The Data Protection Board exists. Can a complaint be filed with it now?
Sections 18 to 26, which constitute the Board, are in force. Section 27, which sets out its powers and functions, is in the eighteen-month tranche other than clause (d) of sub-section (1). On the face of the notification the adjudicatory function has not commenced. In addition, no Chairperson or Members have been appointed on the position reported through 2026.
Does the Act apply to a company incorporated outside India?
It can. The Act reaches processing outside India where it is in connection with offering goods or services to Data Principals within India. Absence of an Indian establishment is not by itself an answer, and the analysis usually turns on how the service is offered and to whom.
What is the net worth requirement to register as a Consent Manager?
Not less than two crore rupees, under item 4 of Part A of the First Schedule to the Rules. The applicant must also be a company incorporated in India, and must satisfy eight further conditions, including independent certification of its platform against standards to be published by the Board.
Is there a list of countries to which personal data cannot be transferred?
Not in the notified Rules. Rule 15 permits transfer outside India subject to such requirements as the Central Government may specify by general or special order in relation to making data available to a foreign State or an entity under its control. The restricted-list approach appeared in the January 2025 draft and was not carried into the final text.
What has to be reported within seventy-two hours after a breach?
The seventy-two hours applies to the second stage of the intimation to the Board under Rule 7(2)(b) — updated and detailed information, the broad facts, mitigation and remedial measures, findings regarding the person responsible, and a report on intimations to affected Data Principals. An initial description must go to the Board without delay, and affected Data Principals must be intimated without delay, separately.
What should be done before May 2027?
Discovery and data mapping generally consume more of the runway than expected, and the notice, consent and rights architecture is built on top of it. Contractual work with processors and vendors can proceed immediately, as can the breach response procedure. Where a sectoral regulator is involved, the conflict analysis is better done early, because it constrains design choices.
Law stated as at 16 August 2026, from the notified text of G.S.R. 843(E) and G.S.R. 846(E), both dated 13 November 2025.