Skip to content
    August 23, 2026| Top Floor Team| 12 min read

    India DPDP: What Is in Force Now, and What Lands in 2027

    As of August 2026, not one of the Digital Personal Data Protection Act obligations that applies to your company is in force in India. The commencement notification, G.S.R. 843(E) of 13 November 2025, splits the Act into three tranches: the regulator switched on immediately, two narrow consent-manager provisions switch on at the one-year mark, and sections 3 to 17 and 27 to 34, the entire compliance rulebook and every penalty in it, switch on eighteen months after publication, computing to 13 May 2027. The contrarian part: most vendor pitches and trade headlines since November 2025 have told India-facing companies that DPDP "is now in force," and the gazette says the parts that could actually fine you are not.

    This piece walks the three tranches section by section, then shows where your real 2026 deadlines come from instead.

    Key takeaways

    • Four notifications, not one. 13 November 2025 produced G.S.R. 843(E) (Act commencement), 844(E) (Board established), 845(E) (Board strength) and 846(E) (the Rules). Most coverage collapsed them into "the Rules dropped," which is how the staging got lost.
    • Nothing that binds a Data Fiduciary is on yet. Notice, security safeguards, breach intimation, children's consent, data principal rights and cross-border restrictions all sit in the eighteen-month tranche, and so does every penalty: section 33 and the Schedule carrying the INR 250 crore ceiling are inside sections 28 to 34.
    • India is still governed by the old law meanwhile. Section 44(2), which deletes section 43A of the IT Act, 2000, is itself in the eighteen-month tranche.
    • Your binding 2026 deadline is almost certainly contractual, not statutory.

    Four notifications on one day, and why the difference matters

    On 13 November 2025 the Ministry of Electronics and Information Technology published four instruments in the Gazette of India, Extraordinary, Part II, Section 3(i). Reading them as one announcement is the commonest error in the secondary coverage, because they do four jobs. G.S.R. 844(E) establishes the Data Protection Board of India under section 18, with effect from publication. G.S.R. 845(E) notifies under section 19(1) that the Board shall consist of four members. G.S.R. 846(E) is the Digital Personal Data Protection Rules, 2025 themselves. And G.S.R. 843(E) decides when any of it operates.

    That last one is the document to read, and it is one page long. The Act was never self-executing: section 1(2) of the Act as published on 11 August 2023 says it comes into force on such date as the Central Government appoints, and that different dates may be appointed for different provisions. For twenty-seven months no such date existed. One note on arithmetic: the notifications are dated 13 November 2025 on their face while the e-gazette identifier carries 14112025, so if your counsel computes from the fourteenth, shift every derived date below one day.

    Tranche one: in force since 13 November 2025

    G.S.R. 843(E)(a) brought into force, on publication: section 1(2), section 2, sections 18 to 26, sections 35, 38, 39, 40, 41, 42, 43, and sub-sections (1) and (3) of section 44.

    Notice what that list is. Section 2 is definitions. Sections 18 to 26 are the establishment, composition, appointment and procedure of the Data Protection Board. Section 40 is the rulemaking power that G.S.R. 846(E) was issued under. The rest is machinery: bar of jurisdiction, good-faith protection, laying rules before Parliament. The Rules match at rule 1(2), commencing rules 1, 2 and 17 to 21, which are the selection committee for Board appointments, the Board's terms, its meeting procedure and its functioning as a digital office.

    So the live portion of India's data protection regime today is the regime's own administrative plumbing. It creates a regulator and tells that regulator how to hold meetings. It does not require any company to write a privacy notice, obtain a form of consent, encrypt anything, notify anyone of a breach, or answer an access request under this Act.

    Tranche two: 13 November 2026, narrower than it looks

    G.S.R. 843(E)(b) commences exactly two things one year after publication: section 6(9), which requires every Consent Manager to be registered with the Board on prescribed conditions, and section 27(1)(d), which lets the Board inquire into and penalise a breach of those conditions. Rule 1(3) commences rule 4, the registration and obligations of Consent Managers, on the same date.

    That is the whole tranche. It is a licensing regime for a new category of intermediary, not an obligation on data fiduciaries. If you are an operating company rather than a firm building a consent dashboard for the Indian market, 13 November 2026 is a date you can watch and ignore. The conditions say something about intent, though: Part A of the First Schedule requires a Consent Manager to be a company incorporated in India, with net worth of not less than two crore rupees and independent certification that its interoperable consent platform meets a standards and assurance framework the Board will publish. That is a regulated-entity regime, not a registry.

    Tranche three: 13 May 2027, when everything arrives at once

    G.S.R. 843(E)(c) commences, eighteen months after publication: sections 3 to 5, sub-sections (1) to (8) and (10) of section 6, sections 7 to 10, sections 11 to 17, section 27 except clause (d) of sub-section (1), sections 28 to 34, sections 36 and 37, and sub-section (2) of section 44.

    Out of section numbers: section 3, the application clause including the extraterritorial limb that catches processing outside India connected to offering goods or services to data principals in India; sections 4 to 7, grounds for processing, notice and consent; section 8, the general obligations of a Data Fiduciary, including security safeguards under 8(5) and breach intimation under 8(6); sections 9 and 10, children's data and Significant Data Fiduciary duties; sections 11 to 16, data principal rights and transfer restrictions; and sections 28 to 34, the inquiry, penalty and appeal machinery.

    Rule 1(4) mirrors it, commencing the rules with operational content. Rule 6 lists the minimum security safeguards: encryption, masking or virtual tokens, access control, logs and monitoring, backups and one-year log retention. Rule 7 sets the breach procedure, which is intimate each affected data principal without delay, intimate the Board without delay, then within seventy-two hours of becoming aware supply the broad facts, mitigation, findings on who caused it and a report on the intimations given. Rule 8 and the Third Schedule set three-year erasure clocks for e-commerce entities and social media intermediaries above two crore registered users in India. Rule 13 gives Significant Data Fiduciaries an annual impact assessment and audit. All of it lands on one day, with no ramp.

    The penalties land with it. The Schedule to the Act, read with section 33(1), sets the ceilings everyone quotes: up to INR 250 crore for breaching the section 8(5) security obligation, up to INR 200 crore for failing to give breach notice under 8(6) and again for the children's obligations, up to INR 150 crore for Significant Data Fiduciary obligations, and up to INR 50 crore for any other breach. Section 33 sits inside sections 28 to 34, and so does the Board's inquiry power over data fiduciaries in section 27, so the Board exists today and can hold meetings but cannot fine you until the tranche commences. A vendor telling you INR 250 crore is at risk today is either not reading the one-page notification or hoping you will not.

    The law that actually governs Indian personal data right now

    Here is the detail that almost never appears in DPDP coverage, and it changes what a 2026 programme should look like. Section 44(2) of the DPDP Act amends the Information Technology Act, 2000: it omits section 43A, and it omits clause (ob) of section 87(2), the rulemaking power under which the 2011 sensitive personal data rules were framed. Section 44(2) is in the eighteen-month tranche. Sections 44(1) and 44(3), which amend the TRAI Act and the Right to Information Act, are in force now; 44(2) is not.

    So until the tranche commences, section 43A and the rules made under 87(2)(ob) remain the operative Indian obligation. Section 43A makes a body corporate that is negligent in implementing and maintaining reasonable security practices, and thereby causes wrongful loss or gain, liable to pay compensation to the person affected. A company processing Indian personal data in August 2026 is not in a regulatory vacuum. It is in the old regime, and it will move to the new one in a single step.

    The honest framing of the eighteen-month gap is therefore not "nothing applies until 2027." It is "the old thing applies until 2027, then it is replaced overnight by a much larger thing." Those imply very different projects.

    What is binding on you in 2026, and where it comes from

    If the statute is not your 2026 deadline, something else usually is. We see three.

    Contracts. Indian subsidiaries, BPO and GCC delivery centres, and SaaS vendors serving Indian enterprises are already receiving DPDP clauses in master services agreements and data processing addenda. Those bind on signature, not on commencement, and they routinely import obligations the Act has not switched on, including seventy-two hour breach windows drawn from rule 7. A contractual seventy-two hours in 2026 is a real deadline in a way the statutory one is not. Our vendor risk management guide covers answering an obligation before the law requires it.

    Other regulators. Sectoral Indian regulators have their own incident and data rules that owe nothing to DPDP commencement, and CERT-In directions bind on their own terms.

    Everyone else's law. If you process Indian data you usually process other people's too, and those clocks are running. Our breach notification deadlines crosswalk and state privacy law guide lay them out. A programme built to the strictest clock you are already on will absorb DPDP in 2027 with far less work than one built for it alone.

    How to use eighteen months without wasting them

    The temptation with a distant date is to do nothing; the opposite temptation, which vendors will encourage, is a full readiness programme now against rules that could still be amended. Neither is right. What holds its value regardless is inventory work: you cannot write a notice under section 5, answer a rights request under sections 11 to 14, or run a rule 8 erasure clock without knowing what personal data you hold, where it sits, which entity is the fiduciary and which processors touch it. What does not hold its value is tooling configured to draft rules, or declaring yourself a Significant Data Fiduciary, a classification the Central Government makes under section 10 and which these instruments do not settle.

    When you should not hire a consultancy like ours

    If your only India exposure is a handful of Indian users on a self-serve product, no Indian entity, no Indian contracts asking about DPDP, and an existing GDPR programme, your marginal DPDP work before early 2027 is close to zero. The overlap is large, the gap is mostly consent record-keeping and the children's provisions, and 2026 is better spent on the regimes that can fine you now. Come back when a customer sends a clause or the tranche is six months out.

    If you have an Indian subsidiary but no privacy function at all, the first thing you need is not a DPDP consultancy. It is a data inventory and someone internal who owns privacy, which is cheaper and more durable than any assessment. And if anyone quotes you a DPDP certification, treat that as disqualifying: the Act provides for Board inquiries, penalties, voluntary undertakings under section 32 and appeals, and for no certificate.

    Where the work is worth buying is narrower: multi-entity groups where fiduciary and processor roles are contested, companies whose Indian delivery centres process other people's data under contracts tightening now, and organisations that will plausibly be notified as Significant Data Fiduciaries.

    Where Top Floor fits

    Our India DPDP practice does the operational half: data mapping and processing inventory, consent framework design, fiduciary and processor role allocation across group entities, processor contract terms, and the breach intimation workflow rule 7 will require. We do not opine on whether an entity is in scope of section 3 or whether a transfer is lawful; that belongs with Indian counsel, and we work alongside them.

    Most of our DPDP work arrives attached to something else, which is usually the right way to buy it. If you already run GDPR compliance, extend the existing inventory and rights processes rather than stand up a parallel Indian programme; the concepts diverge on legitimate interest and cross-border mechanics, but the machinery underneath is shared. If you are managing several regimes at once, our global privacy and international compliance practices keep one control environment answering to all of them at once.

    How to decide this week

    1. Read G.S.R. 843(E) yourself. It is one page. Put it in front of whoever is being asked to fund DPDP work this year.

    2. Search executed MSAs and DPAs for DPDP, Data Fiduciary and Data Principal. If a clause exists, that is your live deadline and it has nothing to do with commencement.

    3. Ask any vendor pitching you what is in force today. If the answer is anything other than the Board machinery plus the definitions, you have learned something about the pitch.

    4. Start the inventory, not the gap assessment. Where personal data lives, which entity controls it, which processors touch it.

    5. Diarise 13 November 2026 and 13 May 2027 with the section lists attached, and re-check the gazette each quarter. Staged schedules have been extended before, and a date table nobody re-reads is how a superseded threshold reaches a board pack.

    Frequently asked questions

    Is India's DPDP Act in force right now?

    Partly, and not the parts that bind companies. G.S.R. 843(E) of 13 November 2025 brought into force the definitions and the Data Protection Board machinery: section 1(2), section 2, sections 18 to 26, sections 35 and 38 to 43, and sub-sections (1) and (3) of section 44. The obligations on Data Fiduciaries in sections 3 to 17 (except section 6(9), which is in the one-year tranche and binds consent managers only), and the Board's power to inquire into and penalise them in sections 27 to 34, commence eighteen months after publication, computing to 13 May 2027. As of August 2026 no Data Fiduciary obligation and no penalty under the Act is operative.

    What actually happens on 13 November 2026?

    Two provisions commence and nothing else: section 6(9), which requires Consent Managers to be registered with the Board, and section 27(1)(d), which lets the Board penalise a breach of a Consent Manager's registration conditions. Rule 4 of the DPDP Rules, 2025 commences the same day under rule 1(3). Unless you intend to operate as a Consent Manager in India this date creates no obligation for you, and the First Schedule conditions, including Indian incorporation and net worth of at least two crore rupees, apply to applicants for that registration only.

    If DPDP is not in force, what law protects Indian personal data today?

    Section 43A of the Information Technology Act, 2000 and the sensitive personal data rules made under section 87(2)(ob), because the DPDP provision repealing them, section 44(2), is itself in the eighteen-month tranche and has not commenced. That regime stays operative until 13 May 2027 and is then replaced in a single step. The gap is a change of regime rather than an absence of one, so an Indian entity with no privacy controls in 2026 is already exposed under the older law rather than waiting to be exposed under the new one.

    Should we do DPDP work now or wait until 2027?

    Do the work that survives a rule change and defer the work that does not. Data inventory, processing records, entity role mapping and processor contract terms are useful under the 2011 rules, under GDPR, and under DPDP when it commences, so there is no wasted spend. Final privacy notices, consent interfaces built to draft text and any Significant Data Fiduciary programme are premature, because those provisions are not in force and the designations are made by the Central Government under section 10 rather than self-assessed. The defensible plan is inventory this year and machinery in the two quarters before the tranche lands.

    Share Share on LinkedIn

    Need help with your compliance program?

    Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.

    Schedule a Free Consultation

    Get insights like this in your inbox

    Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.

    Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.