Blog · Compliance

DPDP Rules 2025 don't take effect on one date - they take effect on three

MeitY notified the DPDP Rules with a staggered, three-date implementation schedule, not a single "compliance day." Where you actually are on that timeline right now changes what's urgent and what isn't - and as of today, the biggest date is still about three months out.

The three dates

Phase 1 - live now
13-14 November 2025

Rules 1, 2, and 17-21 came into force. The Data Protection Board of India was constituted, the definitions and procedural framework became operative, and complaints can already be filed.

Phase 2 - next, ~3 months out
13-14 November 2026

Rule 4 comes into force, Consent Manager registration opens, and the enforcement and penalty machinery becomes operative. Widely read as the end of the initial "soft enforcement" window.

Phase 3 - the big one
13-14 May 2027

Rules 3, 5-16, 22, and 23 come into force - including Rule 6's security-safeguards obligations. This is the "hard enforcement" date most compliance teams are actually planning around, closing an 18-month transition window.

Where that leaves a firm today

As of this post, we're in the gap between Phase 1 and Phase 2 - the procedural machinery exists and complaints can be filed, but the bulk of substantive obligations (including the security-safeguards requirements under Rule 6) don't formally bite until May 2027. That's not a reason to wait. It's exactly why "build and test" is the right way to spend late 2026: the obligations are known in advance, and firms that wait until the Phase 3 deadline to start are compressing 18 months of work into whatever's left.

What to actually do with this timeline

Where Custelis fits: the mechanics this timeline calls for now - a self-service data-principal rights portal, a timed 72-hour breach workflow, classification-driven DLP, and access logging - are built and running today, not scheduled for a future release timed to the deadline. See the full DPDP-readiness guide or score us directly on the 20-point vendor checklist.

This post reflects our understanding of the DPDP Rules, 2025 and the MeitY notification schedule as publicly reported, and is not legal advice. Confirm applicability and specific obligations for your organization with your own counsel.

Get the mechanics in place before the deadline pressure hits

No credit card to start. Intrusive features stay off until your own DPIA is recorded.

Try for free

← Back to the blog