Section 6(9) (verifiable parental consent) and section 27(1)(d) (publication duty) commence one year from notification — November 2026.
Source: DPDP Rules 2025 (phased commencement) · last verified 2026-08-01
We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.
The dated obligations from the India Compliance Registry in one timeline — each verified against the Gazette, the regulator or the standards body, never a blog. Governed by our editorial policy.
Section 6(9) (verifiable parental consent) and section 27(1)(d) (publication duty) commence one year from notification — November 2026.
Source: DPDP Rules 2025 (phased commencement) · last verified 2026-08-01
Notice and consent standards, data fiduciary duties, children's data and data principal rights commence eighteen months from notification — May 2027. Published analyses split on 12 vs 13 May; confirm the exact day with counsel before relying on it.
Source: DPDP Rules 2025 (phased commencement) · last verified 2026-08-01
The Schedule to the Act caps monetary penalties at up to ₹250 crore per instance for the highest tier (failure to take reasonable security safeguards to prevent a personal data breach), with lower tiers at ₹200 crore, ₹150 crore and below; the Data Protection Board determines penalties on the facts.
Source: DPDP Act 2023, the Schedule (official Gazette text) · last verified 2026-08-01
Under Rule 7 of the DPDP Rules 2025, a data fiduciary must intimate the Data Protection Board of a personal data breach without delay on becoming aware, follow with a detailed report within 72 hours (extendable by the Board), and notify affected data principals of the breach in plain language.
Source: DPDP Rules 2025, Rule 7 · last verified 2026-08-01
Every consent request must be accompanied or preceded by a notice informing the data principal of: (i) the personal data and the purpose of processing; (ii) the manner of exercising rights under s.6(4) (withdrawal) and s.13 (grievance redressal); and (iii) the manner of making a complaint to the Data Protection Board. For consents given before commencement, notice must follow as soon as reasonably practicable.
Source: DPDP Act 2023, section 5 (official Gazette text) · last verified 2026-08-01
Provisions constituting and empowering the Data Protection Board (ss.18–26), definitions, and procedural rules took effect on 13 November 2025.
Source: DPDP Rules 2025 (phased commencement) · last verified 2026-08-01
Digital Personal Data Protection Rules, 2025 notified 13 November 2025 as G.S.R. 843(E), Gazette of India Extraordinary Part II s.3(i).
Source: MeitY / PIB — DPDP Rules 2025 · last verified 2026-08-01
The CMMC Program rule (32 CFR Part 170) was published 15 October 2024 and took effect 16 December 2024. The acquisition rule (48 CFR) took effect 10 November 2025, starting a phased rollout that adds CMMC requirements to DoD contracts in four annual phases.
Source: US Federal Register — CMMC Program rule (32 CFR 170) · last verified 2026-08-01
The IAF three-year transition window for ISO/IEC 27001:2013 certificates ended 31 October 2025 — certificates not transitioned to the 2022 revision by that date lapsed.
Source: ISO/IEC 27001 (iso.org) · last verified 2026-08-01
Regulation (EU) 2024/1689 entered into force on 1 August 2024. Governance rules and obligations for general-purpose AI (GPAI) model providers apply from 2 August 2025 (with transition for models already on the market).
Source: EU AI Act — official text (EUR-Lex 2024/1689) · last verified 2026-08-01
OWASP Application Security Verification Standard v5.0.0 (May 2025): ~350 requirements across 17 chapters, three verification levels (L1–L3).
Source: OWASP ASVS project · last verified 2026-08-01
PCI DSS v3.2.1 retired 31 March 2024. v4.0.1 (a limited revision — no requirements added or removed) was published 11 June 2024, and v4.0 retired 31 December 2024, leaving v4.0.1 the only active version. The 51 future-dated v4.x requirements became mandatory in assessments from 31 March 2025.
Source: PCI Security Standards Council (official blog) · last verified 2026-08-01
SEBI issued the Cybersecurity and Cyber Resilience Framework circular on 20 August 2024. Compliance timelines were extended more than once; for most regulated entities (excluding MIIs, KRAs and QRTAs) the final compliance date became 31 August 2025, with recurring half-yearly cyber-audit and reporting cycles thereafter.
Source: SEBI — CSCRF FAQs (official PDF, June 2025) · last verified 2026-08-01
Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (RBI/DoS/2023-24/107) issued 7 November 2023; effective 1 April 2024. Requires an IT governance framework, information/cyber security policies and periodic IT risk assurance for regulated entities.
Source: Reserve Bank of India (Master Direction RBI/DoS/2023-24/107) · last verified 2026-08-01
NIST released Cybersecurity Framework 2.0 on 26 February 2024 — the first major revision since 2014, adding the Govern function and broadening applicability beyond critical infrastructure.
Source: NIST (official release announcement) · last verified 2026-08-01
Saudi Arabia's National Cybersecurity Authority first issued the Essential Cybersecurity Controls as ECC-1:2018; the updated ECC-2:2024 restructures the framework into 4 domains, 28 subdomains and 108 main controls, binding government entities and critical-infrastructure operators.
Source: National Cybersecurity Authority (Saudi Arabia) · last verified 2026-08-01
ISO/IEC 42001:2023 — the first AI management system (AIMS) standard — was published in December 2023 by ISO/IEC.
Source: ISO/IEC 42001 (iso.org) · last verified 2026-08-01
Master Direction on Outsourcing of Information Technology Services (RBI/2023-24/102) issued 10 April 2023; effective 1 October 2023. Governs material IT outsourcing by regulated entities, including vendor risk, audit rights and concentration risk.
Source: Reserve Bank of India (Master Direction RBI/2023-24/102) · last verified 2026-08-01
Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023); Presidential assent 11 August 2023; Gazette ID CG-DL-E-12082023-248045.
Source: Official Gazette text (MeitY PDF) · last verified 2026-07-31
Qatar's National Cyber Security Agency mandates the National Information Assurance Policy for government entities and critical infrastructure; the current revision is v2.1 (May 2023), superseding v2.0.
Source: NCSA Qatar (official portal) · last verified 2026-08-01
IRDAI issued the Information and Cyber Security Guidelines, 2023 on 24 April 2023 — a data-centric, risk-based security framework for insurers and regulated intermediaries, superseding the 2017 guidelines.
Source: IRDAI (official document) · last verified 2026-08-01
Data centres, VPS, cloud and VPN providers must register and retain accurate subscriber/customer records for 5 years after cancellation or withdrawal of service.
Source: CERT-In Directions (official PDF) · last verified 2026-07-31
System clocks must be synchronised to NIC or NPL time sources.
Source: CERT-In Directions (official PDF) · last verified 2026-07-31
ICT system logs must be maintained for a rolling 180 days, within Indian jurisdiction.
Source: CERT-In Directions (official PDF) · last verified 2026-07-31
Specified cyber incidents must be reported to CERT-In within 6 hours of noticing.
Source: CERT-In Directions (official PDF) · last verified 2026-07-31
Directions under Section 70B(6), IT Act 2000 issued 28 April 2022; effective 28 June 2022. Apply to service providers, intermediaries, data centres, body corporates and government organisations.
Source: CERT-In Directions (official PDF) · last verified 2026-07-31
UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data was issued in 2021 and came into effect on 2 January 2022. The DIFC and ADGM financial free zones run their own data-protection regimes in place of the federal law.
Source: UAE legislation portal / official summaries · last verified 2026-08-01
Issued 18 February 2021: minimum security standards for digital payment channels — internet banking, mobile payments and card payments — binding scheduled commercial banks, small finance banks, payments banks and card-issuing NBFCs.
Source: Reserve Bank of India (Master Direction, 18 Feb 2021) · last verified 2026-08-01
SWIFT launched the Customer Security Programme in 2016. Connected organisations attest annually against the Customer Security Controls Framework (CSCF, revised yearly), and from 2021 an independent assessment became mandatory for attestations rather than pure self-attestation.
Source: SWIFT — Customer Security Programme (official) · last verified 2026-08-01
ISO 22301:2019 (business continuity management systems) was published 30 October 2019, replacing the 2012 first edition.
Source: ISO 22301:2019 (iso.org) · last verified 2026-08-01
RBI circular DPSS.CO.OD No.2785/06.08.005/2017-2018 (6 April 2018) requires payment system providers to store the entire data relating to their payment systems only in India, with compliance within six months (by October 2018). End-to-end transaction data is covered.
Source: Reserve Bank of India (circular DPSS.CO.OD No.2785/06.08.005/2017-2018) · last verified 2026-08-01
Regulation (EU) 2016/679 entered into force 24 May 2016 and has applied across all EU member states since 25 May 2018. Breach notification to the supervisory authority is required without undue delay and, where feasible, within 72 hours (Art. 33).
Source: GDPR — official text (EUR-Lex 2016/679) · last verified 2026-08-01
The Saudi Central Bank (SAMA) issued its Cyber Security Framework v1.0 in May 2017, applying to SAMA-regulated banks, insurers and finance companies; principle-based, drawing on ISO, Basel and PCI DSS.
Source: SAMA — Cyber Security Framework (official PDF) · last verified 2026-08-01
RBI’s Cyber Security Framework in Banks (2 June 2016) requires scheduled commercial banks to report cyber incidents to RBI within 2 to 6 hours of detection, alongside board-approved cyber security policy, SOC capability and cyber crisis management plans.
Source: Reserve Bank of India (notification, 2 June 2016) · last verified 2026-08-01
Compliance with the HIPAA Security Rule was required from 20 April 2005 for most covered entities; small health plans had until 20 April 2006.
Source: US HHS — HIPAA Security Rule · last verified 2026-08-01
This tracker regenerates daily from the registry data file; additions and corrections append to the registry changelog and are never silently edited. Machine-readable version: /compliance-registry.json. Spotted an error? Tell us via the contact page.