DPDP Rules 2025 don't take effect on one date - they take effect on three
MeitY notified the DPDP Rules with a staggered, three-date implementation schedule, not a single "compliance day." Where you actually are on that timeline right now changes what's urgent and what isn't - and as of today, the biggest date is still about three months out.
The three dates
Rules 1, 2, and 17-21 came into force. The Data Protection Board of India was constituted, the definitions and procedural framework became operative, and complaints can already be filed.
Rule 4 comes into force, Consent Manager registration opens, and the enforcement and penalty machinery becomes operative. Widely read as the end of the initial "soft enforcement" window.
Rules 3, 5-16, 22, and 23 come into force - including Rule 6's security-safeguards obligations. This is the "hard enforcement" date most compliance teams are actually planning around, closing an 18-month transition window.
Where that leaves a firm today
As of this post, we're in the gap between Phase 1 and Phase 2 - the procedural machinery exists and complaints can be filed, but the bulk of substantive obligations (including the security-safeguards requirements under Rule 6) don't formally bite until May 2027. That's not a reason to wait. It's exactly why "build and test" is the right way to spend late 2026: the obligations are known in advance, and firms that wait until the Phase 3 deadline to start are compressing 18 months of work into whatever's left.
What to actually do with this timeline
- Now - Nov 2026: get the mechanics in place while there's no penalty pressure yet - a data-principal rights process, a breach workflow, DLP rules for your most sensitive record types. This is the cheapest possible time to find and fix gaps.
- Nov 2026: watch for Consent Manager registration opening and the enforcement/penalty machinery activating - this is when the DPDP Act stops being mostly theoretical for most organizations.
- Before May 2027: have Rule 6 security safeguards - encryption, access controls, audit logging, backups appropriate to the data you hold - not just documented, but actually running and tested.
Where Custelis fits: the mechanics this timeline calls for now - a self-service data-principal rights portal, a timed 72-hour breach workflow, classification-driven DLP, and access logging - are built and running today, not scheduled for a future release timed to the deadline. See the full DPDP-readiness guide or score us directly on the 20-point vendor checklist.
This post reflects our understanding of the DPDP Rules, 2025 and the MeitY notification schedule as publicly reported, and is not legal advice. Confirm applicability and specific obligations for your organization with your own counsel.
Get the mechanics in place before the deadline pressure hits
No credit card to start. Intrusive features stay off until your own DPIA is recorded.
Try for free