Privacy

    DPDP 13 November 2026: What Starts, What Doesn't, and What to Do Before May 2027

    By Santhosh K, Chief Operating Officer, CyberWave GRC
    Published
    Last updated
    Privacy

    Reviewed by Santhosh K, Chief Operating Officer, CyberWave GRC · CISA, CISM, CCISO, HITRUST CCSFP, CHQP, ISO/IEC 27001 Lead Auditor

    This article is general information, not legal advice.

    Short answer: DPDP 13 November 2026 is not the general compliance deadline. It is the date the Consent Manager rules start. The main obligations under India's Digital Personal Data Protection Rules, 2025 start on 13 May 2027.

    The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025. They implement the Digital Personal Data Protection Act, 2023 and come into force in stages. Here is what each date means for your organisation and what to do before May 2027.

    The DPDP timeline

    DateWhat takes effect
    13 November 2025The DPDP Rules are notified. The provisions setting up the Data Protection Board of India take effect.
    13 November 2026Rule 4 takes effect, one year after notification. It sets up the framework for registering and operating Consent Managers.
    13 May 2027Rules 3, 5 to 16, 22 and 23 take effect, eighteen months after notification, along with the Act's main obligations.

    What a Consent Manager is and who must register

    A Consent Manager is a platform registered with the Data Protection Board that lets individuals give, manage, review and withdraw their consent. Eligibility to register as a Consent Manager includes being incorporated in India and having a net worth of at least ₹2 crore.

    Who is affected on 13 November 2026, and who is not

    13 November 2026 is not a blanket requirement. Most businesses will not need to register as Consent Managers.

    The date mainly matters to:

    • Organisations that plan to become a Consent Manager.
    • Organisations that plan to connect their consent systems to one.

    If neither applies to you, 13 November 2026 does not create a new duty for you. Your main date is 13 May 2027.

    What starts on 13 May 2027

    On 13 May 2027, Rules 3, 5 to 16, 22 and 23 take effect, along with the Act's main obligations. These cover:

    • Notices
    • Consent
    • Security safeguards
    • Personal data breach notification
    • Children's data
    • Individuals' rights

    What to do between now and May 2027

    Use this checklist to prepare:

    • [ ] Build a personal data inventory.
    • [ ] Review privacy notices and consent flows.
    • [ ] Set up a process for individuals' requests and grievances.
    • [ ] Prepare a breach response plan.
    • [ ] Review contracts with vendors who process personal data.
    • [ ] Decide whether your consent systems need to work with a Consent Manager.
    • [ ] Assess whether you may be designated a Significant Data Fiduciary.
    • [ ] Train staff.

    Our guide to navigating India's DPDP Act explains the Act's wider structure.

    Extra duties for Significant Data Fiduciaries

    Organisations designated as Significant Data Fiduciaries must also:

    • Appoint a Data Protection Officer based in India.
    • Carry out periodic Data Protection Impact Assessments.
    • Undergo independent data audits.

    See our guide to Data Fiduciary obligations under the DPDP Act for more on the role.

    Get ready for May 2027

    We help organisations prepare for the DPDP Rules through our DPDP Act consulting and provide an India-based DPO through DPO as a Service. Book a 30-minute call to discuss your DPDP readiness or DPO needs.

    Frequently asked questions

    No. It is the date Rule 4 takes effect, setting up the framework for registering and operating Consent Managers. The main obligations start on 13 May 2027.

    Most businesses will not. The date mainly matters to organisations that plan to become a Consent Manager or to connect their consent systems to one.

    Eligibility includes being incorporated in India and having a net worth of at least ₹2 crore.

    Rules 3, 5 to 16, 22 and 23, along with the Act's main obligations covering notices, consent, security safeguards, personal data breach notification, children's data and individuals' rights.
    Hi! I'm your AI Assistant 💬