The final DPDP Rules are here. Here's your actual deadline — and your plan.
MeitY notified the final DPDP Rules in November 2025, starting a phased 18-month clock. The Data Protection Board is already operating; Consent Manager provisions switch on around November 2026; and everything else — consent, notice, rights requests, grievance redressal — must be fully working by 13 May 2027. The Rules also added teeth: retain logs for at least a year, answer grievances within 90 days, and report breaches to the Board within 72 hours.
For two years, "DPDP compliance" was something Indian businesses could postpone because the detailed rules weren't final. That excuse ended in November 2025. The law of the land now has dates, procedures and a functioning regulator — and if your business handles personal data of people in India, the 18-month runway is already burning.
What actually happened
The DPDP Act passed in 2023 but left the operating detail — how consent notices must look, how breaches are reported, how the Data Protection Board works — to Rules. A draft was published in January 2025, industry feedback followed, and the final Rules were notified in the Gazette in November 2025. Notification means this is no longer a proposal: it is enforceable law rolling out on a fixed schedule.
The timeline that matters
| When | What takes effect |
|---|---|
| Nov 2025 | Immediately on notification: the Data Protection Board of India framework — the Board has been constituted and can act. |
| ~Nov 2026 | 12 months in: Consent Manager provisions — the registration framework for the new class of consent-management intermediaries. (What a Consent Manager actually is — most MSMEs don't need to become one.) |
| 13 May 2027 | 18 months in — full compliance: consent and notice requirements, data-principal rights (access, correction, erasure), grievance redressal, children's-data safeguards, and the rest of the Act and Rules. |
Read that last row carefully: 13 May 2027 is not the day to start. Consent flows, a data inventory, request-handling processes and vendor agreements realistically take months to build — the deadline is when they must already be running.
The three new obligations that surprise people
1. Keep your logs for a year
The Rules require businesses to retain personal data, traffic logs and related records for at least one year (subject to narrow exceptions). Many businesses delete logs after 30 or 90 days to save storage — that default is now non-compliant. Review your log retention settings and set a 12-month hold.
2. Answer grievances within 90 days
Data-principal grievances now carry a hard 90-day response cap. If you don't have a tracked process — a mailbox someone owns, a log of what came in and when it was closed — you can't prove you met it. This is exactly the machinery a grievance officer runs.
3. Report breaches fast
On a personal data breach, affected individuals must be informed promptly with what happened and what you're doing about it — and the Data Protection Board must receive a detailed notification within 72 hours. Nobody drafts a breach notice well at 2 a.m. during an incident; write the playbook now.
What didn't change
The fundamentals of the Act stand: consent must be free, specific, informed and as easy to withdraw as to give (what valid consent looks like); people keep their rights to access, correction and erasure; children's data needs verifiable parental consent; and the penalty schedule still tops out at ₹250 crore per instance for failing security safeguards. Sectoral regulators (RBI, SEBI, IRDAI) still sit on top — where they demand longer retention, the longer rule wins.
Your next-90-days plan
- Map your data — every system, sheet and vendor. Our 5-step discovery method.
- Fix log retention — set the 12-month hold on personal data and traffic logs.
- Stand up the grievance channel — published contact, tracked mailbox, 90-day SLA.
- Rebuild your consent flow — plain-language notice, granular purposes, one-tap withdrawal.
- Write the breach playbook — detect, contain, notify users, notify the Board within 72 hours.
- Paper your vendors — data-processing agreements with everyone who touches personal data for you.
Where do you stand today?
Take the free, 2-minute DPDP Readiness Scorecard — 12 questions, a per-area gap report, and exactly what to fix first before 13 May 2027.
How Ronin Works helps
We run the whole readiness programme — data discovery, cleansing, consent and grievance processes, breach playbooks, records — and we're building Ronin Consent, a simple consent-collection tool for MSMEs, so the consent log the Rules demand exists from day one rather than being reconstructed for an audit.
Keep reading
- What makes consent valid under the DPDP Act
- Consent Managers, explained — and why your MSME probably doesn't need to become one
- The full DPDP compliance checklist
The DPDP Act gives individuals rights too. Saaph.in — a Ronin Works product — finds where your personal data is exposed across the open web and gets it removed under the Act, then keeps watch.
Scan your exposure at Saaph.in →Need help with the 18-month runway?
Send us a note — we reply within one working day.
This article is general information, not legal advice. Dates and obligations summarise the DPDP Act, 2023 and the DPDP Rules as notified in November 2025; consult the Gazette notifications or a qualified professional for the authoritative text, or talk to Ronin Works.