DPDP's staggered commencement dates: what applies when, and why the gap still matters
Need help with dpdp? We can handle it for you.
Some people read DPDP's staggered commencement and conclude nothing applies yet, so there's nothing to do. That's the wrong lesson. The right one is narrower and more useful: know exactly which date turns on which obligation, and use the gap deliberately instead of ignoring it.
Two notifications, same day, three matching tranches
The Digital Personal Data Protection Act 2023 didn't commence in one shot. Two notifications, both dated 13 November 2025, split it into stages. G.S.R. 843(E) commences the Act's own sections. G.S.R. 846(E), the DPDP Rules 2025, commences the Rules in matching tranches under Rule 1(2) to 1(4). Read either notification alone and you'll misjudge what's live. Read them together and the picture is precise down to the sub-clause.
Tranche one: on publication, November 2025
This tranche is pure machinery. No substantive obligation commences here. Rules 1, 2, and 17 to 21 commenced, alongside Act sections 1(2), 2, 18 to 26, 35, 38 to 43, and 44(1) and 44(3). Together these stood up the Data Protection Board of India: its existence, its search-cum-selection committee, its procedure, its status as a digital office. The same tranche carried section 44(3), which amended the Right to Information Act's section 8(1)(j), and that amendment is already in force, separate from everything else in this timeline.
Tranche two: November 2026, one rule and two sections
One year after publication, a narrow second tranche commences: Rule 4 alone, plus section 6(9) and section 27(1)(d) of the Act. This is the Consent Manager registration mechanism switching on, the point at which an entity that wants to operate as a Consent Manager can actually apply to the Board. It does not touch notice, consent standards for ordinary companies, security, breach reporting, or data principal rights. Those wait for tranche three.
Tranche three: May 2027, everything operational
Eighteen months after publication, the substance of the Act arrives. Rules 3, 5 to 16, 22, and 23 commence, alongside Act sections 3 to 5, 6(1) to (8) and (10), 7 to 17, section 27 other than clause (1)(d), and sections 28 to 34, 36, 37, and 44(2). Notice. Consent. The legitimate uses that need no consent. Security safeguards. Breach reporting. Rights for the Data Principal. Significant Data Fiduciary duties. And critically, sections 28 to 34, the inquiry procedure and the penalty regime.
From the blog
Prefer to skip the paperwork?
BuildWright can take this off your plate — done properly, the first time.
Get new templates and compliance updates by email.