# DPDP Compliance Timeline

v1.0.0 · updated 2026-08-01 · Licence: CC BY 4.0 — attribution to CyberSigma
Sources: https://cybersigmacs.com/compliance-registry/ (entries dpdp-*)

## Milestones

- **11 Aug 2023 — DPDP Act 2023 enacted.** Act No. 22 of 2023 receives Presidential assent (Gazette CG-DL-E-12082023-248045). (source: compliance-registry#dpdp-act-gazette)
- **13 Nov 2025 — DPDP Rules 2025 notified — Phase I in force.** G.S.R. 843(E). Data Protection Board provisions (ss.18–26), definitions and procedural rules take effect immediately. (source: compliance-registry#dpdp-rules-notified)
- **Nov 2026 — Phase II.** Verifiable parental consent (s.6(9)) and the publication duty (s.27(1)(d)) commence one year from notification. (source: compliance-registry#dpdp-phase-2)
- **May 2027 — Phase III — the substantive framework.** Notice and consent standards, data fiduciary duties, children's data and data principal rights commence at eighteen months. Published analyses split on 12 vs 13 May — confirm the day with counsel. Penalties under the Schedule (up to ₹250 crore for security-safeguard failures) become live exposure. (source: compliance-registry#dpdp-phase-3)

## What to do with the runway

1. Map your processing: what personal data you hold, why, where it sits, who touches it — every later obligation depends on this record existing.
2. Decide your likely Significant Data Fiduciary exposure early: SDF status brings a DPO in India, DPIAs and an independent data audit.
3. Build consent and withdrawal flows against the Rules' standards — withdrawal must be as easy as consent.
4. Join breach response into ONE runbook with CERT-In's six-hour reporting — the same incident triggers both duties on different clocks.
5. Treat the runway as a work period, not a deadline to start: rights processes and retention rebuilds take quarters, not weeks.

---
Maintained by CyberSigma (CERT-In empanelled, PCI QSA): https://cybersigmacs.com/open/dpdp-compliance-timeline/