Digital Personal Data Protection Act, 2023 was passed on 11 August 2023, and its Rules were notified on 13 November 2025. However, the notification did not make the entire framework immediately enforceable. The law’s citizen-rights provisions and penalty powers are subject to a staggered rollout: only a limited set of institutional and procedural rules take effect immediately. At the same time, core obligations and Data Principal rights only begin after an 18-month window. In practice, this means that as of mid-2026, the DPDP framework is incomplete. This gap is essential to understanding what the DPDP Act does and does not deliver today.
Overview
When the government notified the DPDP Rules on 13 November 2025, it described the move as the activation of India’s data protection regime. That description is accurate and incomplete in equal measure. What activated on that date was the law’s institutional skeleton — the Data Protection Board of India came into existence, procedural provisions took effect, and the compliance clock started running.
The six rights examined in Article 1 — access, correction, erasure, withdrawal of consent, grievance redressal, and nomination are legally recognised but not yet fully enforceable. The obligations on organisations to handle data responsibly, notify breaches, and honour citizen requests have not yet taken legal effect. The penalties designed to enforce those obligations will not apply until May 2027.
The DPDP Act took India almost five years to produce; understanding why enforcement is phased requires understanding how long that journey took. The first data protection bill was proposed in 2018. The Justice Srikrishna Committee draft attracted significant expert attention. Subsequent iterations in 2022 and 2023 drew criticism from civil society. Parliament passed the final Act in August 2023, and rules were drafted and consulted on through 2024 and early 2025. The rules were notified twenty-seven months after the Act. Full enforcement arrives eighteen months after the rules. By the time citizens can fully exercise and enforce their rights under the DPDP framework, nearly a decade will have passed since the Supreme Court recognised privacy as a fundamental right in the Puttaswamy judgment (2017).
The Three-Phase Rollout: What Each Date Actually Means
The Ministry of Electronics and Information Technology (MeitY) structured implementation across three dates. The table below maps each phase precisely against what is legally operative today.
| Phase | Date | What Activates | What It Delivers and what it does not |
| Phase 1Partially operative | 14 Nov 2025 | DPBI legally established (Sections 18–26). Definitions operative (Section 2). Administrative and procedural rules in force (Rules 1, 2, 17–21). RTI amendment operative (Section 44(3)). | What it delivers: The Board has legal existence. The RTI Act’s public interest override for personal data disclosures has already been curtailed. What it does not deliver: No complaint adjudication. No citizen rights. No Data Fiduciary obligations. No penalties. Substantive enforcement is entirely deferred. |
| Phase 2Scheduled | 14 Nov 2026 | Consent Manager registration framework operative (Rule 4 / Section 6(9)). One DPBI function activates (Section 27(1)(d)). What is a Consent Manager? A registered entity that allows citizens to manage all their data consents across multiple platforms through a single interface — a centralised on/off switch for data permissions, rather than hunting for settings across dozens of apps. | What it delivers: First hard compliance deadline for organisations using third-party consent infrastructure. One narrow DPBI function activates. What it does not deliver: Citizen rights, Fiduciary obligations, penalties, SDF requirements, cross-border rules, and full DPBI adjudication remain deferred. |
| Phase 3Deferred | 14 May 2027 | All remaining substantive provisions. Key provisions by section: Section 5 (Data Fiduciary consent-notice obligations- not legally required until this date); Section 6 (lawful bases for processing, including consent); Section 8 (Data Fiduciary general obligations, including breach notification); Section 10 (Significant Data Fiduciary designation obligations); Sections 11–14 (Data Principal rights: access, correction, erasure, withdrawal of consent, nomination); Section 13 (citizen’s right to grievance redressal- deferred to this date); Section 16 (cross-border transfer restrictions);Section 17 (Central Government exemptions from compliance); Sections 27–34 (DPBI’s full complaint adjudication, inquiry, penalty, and appeals powers); Section 36 (government’s power to demand data from fiduciaries). Rules 3, 5–16, 22–23, including Rule 23 (non-disclosure obligation on fiduciaries receiving government data demands). | What it delivers: Everything. This is the only date that transforms the DPDP Act from a framework statute into a fully enforceable regulatory regime with operative citizen rights and penalties. The rights exist in law today. They become enforceable in practice here. |
The real asymmetry: Section 44(3) of the Act, which amends the RTI Act to replace a qualified personal data exemption with a near-categorical one, restricting citizens’ ability to obtain information about public officials through RTI, came into force on 14 November 2025. It is already operative. The six new citizen rights the DPDP Act creates are deferred to May 2027. A provision that curtails an existing citizen right is activated on day one. The provisions that create new citizen rights activate in eight months. Section 17 (government exemptions from the DPDP Act) and Rule 23 (the non-disclosure obligation on Data Fiduciaries when served government demands) are both deferred to May 2027 — they are not currently operative.
The phasing is presented as responsible and industry-friendly: giving organisations time to build compliant systems rather than imposing overnight obligations. That framing is not inaccurate, but it obscures an asymmetry. The government’s own exemptions from the law’s requirements under Section 17, which permits the Centre to exempt any of its instrumentalities from compliance on grounds including national security and public order, are not subject to the same phased introduction. The state’s carve-outs from the law took effect immediately. The citizen’s rights to hold the state accountable under the same law did not.
Rights Without Remedies: The Enforcer That Is Not There Yet
The Data Protection Board of India (DPBI) is the centrepiece of the DPDP Act’s enforcement architecture. Under Sections 18-26, it can receive and adjudicate complaints, issue directions to Data Fiduciaries, and impose penalties of up to Rs 250 crore for the most serious violations. Under Rule 20, it is designed as a fully digital institution, with all proceedings conducted without physical presence through technology-enabled hearings.
On paper, the Board has existed since 13 November 2025. In practice, appointing its Chairperson and Members has been a protracted process. Under the DPDP Rules, Rule 17 sets up two separate search-cum-selection committees: one chaired by the Cabinet Secretary for the Chairperson appointment, another chaired by the MeitY Secretary for Members. Both committees include external experts. As of August 2026, the Chairperson and Members had not yet all been appointed and assumed office. The Board exists as a legal entity, but it does not yet function as an institution.
The consequences of this gap are direct. A citizen who experiences a data breach today has a formal right to file a grievance. The DPBI’s digital complaint portal is live. But the body empowered to adjudicate that complaint, issue a remediation direction, and impose a penalty has no Chairperson and, as of this writing, no confirmed Member. Filing a complaint in this period is not meaningless. However, it is, at best, preliminary since the resolution depends on an institution that is still assembling itself, as seen already in April 2026 by the Madhya Pradesh High Court. The limits of what the Board can do today, however, are precisely defined by the commencement schedule. Section 27 of the Act, which governs the DPBI’s complaint adjudication functions, is deferred to May 2027; only Section 27(1)(d), one narrow function (breach of function by Consent Manager), activates in November 2026. Sections 28–34, covering the full appeals mechanism, are similarly deferred. The Board cannot yet formally adjudicate complaints, issue binding directions, or impose penalties. Those powers activate in eight months. The government says the selection process is rigorous by design. A body performing quasi-judicial functions over the personal data of 1.4 billion people requires expertise in law, technology, and public administration. Rushing appointments risks appointing the wrong people. Indeed, these are defensible arguments. But they do not resolve the fact that the interval between the Board’s legal existence and its operational capacity is now measured in months, and citizens in that interval have rights without a functioning remedy.
The Gaps the timeline cannot fix
Three structural problems sit beneath the timeline that the phasing schedule does not resolve, and the government has not publicly addressed them.
1) No Significant Data Fiduciaries have been designated.
Section 10 of the Act empowers the government to classify organisations that process large volumes of sensitive data as Significant Data Fiduciaries (SDFs), triggering heightened obligations: a resident Data Protection Officer, annual audits, algorithmic impact assessments, and data localisation requirements where notified. As of August, 2026, no SDFs have been designated. The platforms that handle the most personal data of the most Indians—major social media companies, health aggregators, fintech providers — face only baseline obligations until they are designated. Designation is supposed to happen in 2026.
2) The cross-border transfer whitelist does not exist.
Unlike the GDPR’s adequacy model, India adopted a negative list (blacklist) approach under Section 16: personal data may be transferred to any country by default, unless the Central Government specifically restricts a destination by notification. No country has been placed on any restricted list. Until May 2027, the Act’s cross-border transfer provisions cannot function. Indian data exported to servers abroad, a standard practice for multinationals, operates without the legal framework which the Act was designed to provide.
3) The government’s exemptions and the citizen’s protections are on the same deferred schedule, but that symmetry has a caveat.
Section 17 (government exemptions from compliance) and Section 36 (government power to demand data from fiduciaries) are both deferred to May 2027. Rule 23, which would prohibit Data Fiduciaries from disclosing government data demands to affected citizens — what the Internet Freedom Foundation has called ‘gag rules’ that ‘prevent the public from ever knowing the extent of state surveillance’- is similarly deferred. The concern about Section 17 and Rule 23 is prospective, not current. Section 44(3) is already operative: the RTI amendment restricting citizens’ existing information rights came into force on day one, while the new rights the DPDP Act creates activate only in May 2027. The Internet Freedom Foundation and digital rights advocates have noted that Section 17 contains no proportionality test, no independent oversight requirement, and no sunset clause. These are structural objections to provisions that, when they activate, will operate without the safeguards that a rights-based framework requires.
The compliance timeline also cannot address a further problem: public awareness. A PwC survey found that nearly 69% of Indian consumers are unaware they can withdraw consent, and 72% do not know that children’s data carries additional protections under the law. Data protection statutes succeed when citizens understand their rights, exercise them, and expect enforcement. Legal architecture and legal literacy must advance together. The former is being assembled; the latter remains almost entirely unaddressed.
This phased implementation is not unusual for complex regulatory legislation; India is not unique in that context. The EU’s General Data Protection Regulation (GDPR) provided approximately two years between enactment in 2016 and application in May 2018, the Data Protection Authorities were operational and staffed before the law applied. India differs in that it separated legislative enactment, institutional establishment, leadership appointment, citizen rights, and penalty powers into distinct implementation tracks, each with its own timeline. The Board was legally established before its leadership was appointed, and both preceded the activation of the rights and penalties the Board is meant to enforce. The sequencing is reversed.
What this means for citizens today
A practical question underlies the institutional analysis: what should a citizen do in the interim period before May 2027?
The DPBI complaint portal is now live and accepting submissions. However, the Board’s full adjudicatory mandate — Section 27, covering the formal complaint process — does not activate until May 2027. Filing a complaint today establishes a documentary record of the grievance and its date, which may be useful when enforcement becomes fully operational.
Consent notice obligations on Data Fiduciaries — the requirement to display clear, multilingual notices before collecting data, in any of India’s 22 scheduled languages, fall under Sections 5 and 6, which are deferred to May 2027. Organisations are not currently legally required to display these notices. Some are doing so voluntarily, as part of early compliance preparation. Citizens may observe these notices as a signal of organisational readiness, but should understand that non-compliance today carries no legal consequence under the DPDP framework.
Outlook
Three developments between now and May 2027 will determine whether the DPDP Act’s enforcement gap closes on schedule or extends further.
1) DPBI leadership appointment
MeitY formally initiated the appointment process in mid-2026. Its Phase 2 function under Section 27(1)(d) activates in November 2026. Full adjudicatory powers activate in May 2027. Appointment before full Phase 3 is the minimum required for the enforcement architecture to be credible. Delay beyond that date would constitute a structural failure of the regulatory framework, not merely an administrative one.
2) Significant Data Fiduciary designations
No designations have been made as of the time of writing. Industry expects major social media platforms and health aggregators to be designated, but the government has given no confirmed timeline for SDFs. Until designations happen, the Act’s most stringent obligations — audits, impact assessments, data localisation remain unactivated for the entities most capable of harm at scale.
3) Supreme Court constitutional ruling
Four petitions before the Supreme Court challenge several provisions of the DPDP Act, including Section 44(3)’s RTI amendment and Section 36’s government information demand power. The Court referred these matters to a larger bench in February 2026 and declined to grant an interim stay. The central question the Court must answer — where the boundary between personal data and public interest information lies — will determine the scope of both the RTI amendment and the citizen’s ability to scrutinise the state. That ruling is the most consequential pending legal development in Indian data protection law, and it may arrive before full enforcement does.
The DPDP Act is meaningful legislation, but it is not a functioning enforcement regime yet. Citizens who understand this distinction are better equipped to manage their expectations, file timely complaints, and monitor the institutional milestones that will determine whether this law becomes a genuine rights-based framework. The critical dates are not August 2023 (when the Act passed) or November 2025 (when the Rules were notified). The date that matters is 14 May 2027. Everything before then is preparation. Citizens, organisations, and the DPBI itself must use the remaining eight months deliberately.
Enforcement delay does not mean compliance delay. The organisations that process your data are accumulating obligations now under timelines that apply regardless of when the DPBI reaches full capacity. Article 3 examines what those obligations mean for startups, and why the eight-month window before May 2027 is not permission to wait.
About DPDP Explained
This is Article 2 in DPDP Explainer, a ten-part series that examines the Digital Personal Data Protection Act from every angle that matters to citizens, firms and constitutional order, healthcare data, comparison with global frameworks, the RTI challenge, and more. The series moves from the accessible to the analytical: it begins with citizen rights, moves through compliance implications for startups and healthcare, examines global comparisons, and closes with the structural and constitutional questions the law has generated.

Leave a Reply