Most coverage of India's Digital Personal Data Protection regime quotes one date: May 2027, when the 18-month transition ends and full enforcement begins. That is accurate and it is the wrong date to be planning around.
The date that should be on the wall is 13 November 2026. That is three months away, and it is when the comfortable part ends.
The actual timeline
The DPDP Rules were notified by MeitY on 14 November 2025, starting an 18-month phased window.
| When | What happens |
|---|---|
| Jun–Aug 2026 | Consent Manager framework operationalised |
| 13–14 Nov 2026 | Soft enforcement ends. Legacy data revalidation deadline. Board shifts from awareness to supervision |
| Q1 2027 | First mandatory independent audits and DPIAs for Significant Data Fiduciaries |
| 13–14 May 2027 | Transition complete. Full adjudicatory and penalty powers |
The Data Protection Board of India was established by notification dated 13 November 2025. It exists. It has spent the first year building awareness rather than issuing penalties, which is a policy choice, not a limitation — and it is a choice with an expiry date.
The November deadline has teeth the May one doesn't
Two things land in November, and the second is the expensive one.
The Board changes posture. It moves from awareness-building to active regulatory supervision. That is not the same as penalty authority, which arrives in May 2027, but it is the point at which enquiries start.
Legacy data must be revalidated with valid notice and consent. This is the requirement people underestimate, and it is worth being precise about what it means.
Every personal data record you already hold — collected before the DPDP framework, under whatever terms applied at the time — needs to sit on a lawful basis under the new regime. In practice that means going back to the people whose data you hold, issuing a compliant notice, and obtaining consent that meets the standard.
That is not a policy document you write in a fortnight. It is a data inventory exercise, a notice-drafting exercise, a consent-capture mechanism, and an outreach campaign to an existing user base — running in sequence, against a fixed date, on data you may not have catalogued.
If you have not started, three months is tight. If you do not know what personal data you hold or where it sits, three months is not enough.
What the Consent Manager framework changes
The mid-2026 milestone gets less attention than it deserves because it sounds administrative.
Consent Managers are interoperable platforms through which individuals manage, review or withdraw consent across multiple services from one place. The word doing the work is withdraw.
Today, withdrawing consent means finding the setting in each service, one at a time, and most people never do. A functioning Consent Manager collapses that into a single interface. Withdrawal stops being a friction-limited act.
For anyone whose data practices depend on consent that was technically granted but practically never revisited, that is a structural change to the base rate — and it arrives before the enforcement date, not after.
Are you a Significant Data Fiduciary?
The SDF classification carries materially heavier obligations, and the thresholds are lower than many assume. An entity qualifies on any of:
- personal data of 5 million or more Indian residents
- annual turnover of ₹250 crore or more
- processing of sensitive data — health or finance — or use of AI for significant decision-making
That third clause is the one to read twice. It is not scoped by size. A company well under both numeric thresholds that uses a model to make consequential decisions about people — lending, hiring, eligibility, pricing — can land in the SDF category on that basis alone.
Given how many products now route a decision through a model somewhere, this is a wider net than the headline "5 million users" framing suggests.
SDF obligations, operational by Q1 2027:
- an India-based Data Protection Officer reporting to the board
- an independent data auditor engaged for compliance review
- Data Protection Impact Assessments for high-risk processing
A DPO who reports to the board is a hiring decision with a lead time. An independent auditor is a procurement cycle. Neither is arranged in the quarter they are due.
The penalties
The Board can impose penalties of up to ₹250 crore — roughly US$26 million — for major violations.
Two things about that number. It is large enough that it is not a cost-of-doing-business line for most Indian companies. And it becomes available in May 2027, which is why the temptation is to treat everything before that as optional.
The flaw in that reasoning is that the work required to comply cannot be compressed into the gap between the Board acquiring penalty powers and using them. The audits are Q1 2027. The legacy revalidation is November 2026. By the time penalties are live, the evidence of whether you did the work already exists.
How this sits next to the EU
Worth noting for anyone operating in both, because the instinct is to assume GDPR compliance carries over.
It partly does — the concepts rhyme. But India layers sectoral regulators on top: SEBI, the RBI, IRDAI and TRAI each impose additional obligations on customer data processing in their domains. A fintech in India is answerable to the DPDP framework and to the RBI's requirements, which are not harmonised into it.
And as we covered with the EU AI Act, European deadlines have proven movable — the high-risk obligations slipped to December 2027 six days before they were due. Indian deadlines have so far held. Planning on the assumption that a deferral will arrive is planning on a pattern that has not been established here.
What to do in the next three months
- Inventory first. You cannot revalidate consent for data you have not located. This is the step that determines whether November is achievable, and it is usually the one deferred because it is unglamorous.
- Check the SDF thresholds honestly, especially the AI clause. Being an SDF and discovering it in Q1 2027 means missing the audit requirement by definition.
- Design the withdrawal path now. Consent Managers make withdrawal easy. Systems that cannot cleanly honour a withdrawal will fail visibly and at volume rather than quietly.
- Do not wait for the Board to act first. Supervision starts in November. The organisations that get attention early are the ones with nothing to show.
The May 2027 date is real. It is also the deadline for having finished, not for starting.