Skip to content
TruPriv
DPDP hub

The Act, the Rules,and the deadline.

A working reference for the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, written for the person who has to implement them, not for a court. Every claim here names the section it comes from.

Time to full enforcement ·
--Days
--Hours
--Minutes
--Seconds
Phased commencement

Three dates decide how much time you actually have.

  1. 13 November 2025Passed

    DPDP Rules, 2025 notified; Data Protection Board constituted

    The Rules gave the Act operational shape and the Board came into existence. From this point the enforcement machinery exists.

  2. November 2026Next

    Consent Manager registration framework opens

    Registration opens for Consent Managers, the Board-registered intermediaries defined at Sec 6(7)–(9) and Rule 4. TruPriv is not one of them.

  3. 13 May 2027Enforcement

    All substantive obligations in force

    Consent, notice, rights, breach notification, children's data and Significant Data Fiduciary obligations all become enforceable, with penalties attached.

Penalty exposure

Maximum penalties, enforced by the Data Protection Board of India.

These are ceilings, not tariffs. The Board determines the amount on the facts. The point is the order of magnitude, and that each figure attaches to a specific obligation you can either evidence or not.

  • up to ₹250 croreFailure to take reasonable security safeguardsSec 8(5)
  • up to ₹200 croreFailure to notify a personal data breachSec 8(6)
  • up to ₹200 croreBreach of obligations relating to childrenSec 9
  • up to ₹150 croreBreach of additional Significant Data Fiduciary obligationsSec 10

This is informational and is not legal advice. Liability under the DPDP Act, 2023 remains with the Data Fiduciary.

Two things people get wrong

Precision matters more than urgency.

Records of processing

The DPDP Act contains no Article 30-style obligation to maintain records of processing activities. Anyone telling you otherwise is selling from a GDPR script. What is true: Sec 11(1)(a)–(b) gives every Data Principal the right to a summary of their personal data and the identities of everyone it has been shared with, and Sec 10 imposes audits on Significant Data Fiduciaries. Neither is answerable without a maintained record.

Data Protection Impact Assessments

A DPIA is not mandatory for every business. It is mandatory for those notified as Significant Data Fiduciaries under Sec 10. If you have not been notified, a DPIA is good practice and a useful way to find out what you actually process — but it is not an obligation the Act places on you.