On 13 May 2027, almost everything in the Digital Personal Data Protection Act, 2023 becomes enforceable on the same day. Notice, consent, Data Principal rights, security safeguards, breach reporting, retention, children's data and the duties of Significant Data Fiduciaries all switch on together. The Rules that carry the operational detail, Rules 3, 5 to 16, 22 and 23, commence on that date as well.
There is no further phase after it. No obligation arrives later to give an organisation breathing room.
As of 1 October 2026, that leaves about thirty-two weeks. This article sets out how to use them, in the order the work actually has to be done.
Where things stand
The DPDP Rules were notified on 13 November 2025. That notification started an eighteen-month clock and brought the Act's definitions and the provisions establishing the Data Protection Board into force immediately.
Three developments since then matter for planning.
First, the government has been clear that the date will hold. In August, reporting on remarks by the MeitY Secretary said there would be no extension for startups. Around the same time, the Cabinet Secretary put ministries and state governments on compliance timelines of their own.
Second, large organisations are moving early. In September, Business Standard reported that the State Bank of India has procured the software and hardware it needs and expects to be compliant by the end of December 2026, well before the statutory date.
Third, the Data Protection Board exists in law but, on the public record as of September 2026, still has no appointed Chairperson or Members. MeitY began the appointment process in May. It is tempting to read this as a reason to wait. It isn't one. The obligations apply on 13 May 2027 whether or not the Board is fully staffed by then. Anything that happens after that date can still be the subject of a complaint later.
What 13 November 2026 means
The intermediate milestone in November is narrower than many summaries suggest. From 13 November 2026, the provisions on Consent Managers apply. Companies that want to act as Consent Managers can register with the Board under the conditions set in the Rules.
For most Data Fiduciaries, November is a planning marker rather than a deadline. It matters in two ways. If you intend to accept consent through a registered Consent Manager, you need an integration plan once the first registrations are known. And if you were waiting for November to begin, you have used most of the time between the Rules and the enforcement date.
Why thirty-two weeks is shorter than it sounds
A DPDP programme is a chain. Each link depends on the one before it, and most of the elapsed time sits in the dependencies, not in the individual tasks.
You cannot write an accurate notice until you know every purpose for which data is used. You cannot design consent until you know which purposes need consent and which rest on a legitimate use under Section 7. You cannot answer an access request properly until you know which systems hold a person's data and who it has been shared with. You cannot erase data on request until you know which law requires you to keep some of it.
Then come the constraints that belong to Indian enterprises in particular. The financial year closes on 31 March, and many organisations freeze production changes in the weeks before and after it. Statutory audits take up finance and IT teams in the same window. Procurement for new tools often runs through committees that meet monthly. Vendor contracts renew on their own cycles. Branch and field staff need training before any new consent step reaches a counter.
Once those are mapped onto a calendar, the usable build window between now and May is closer to five months than seven.

Set up the programme before the work
Most delays in DPDP programmes trace back to the first month, when nobody was quite sure who decides what. Before the four stages begin, four things need to be in place.
A sponsor with authority. Someone at executive level who can make decisions across business lines, settle disputes over budget, and take the Board through progress. In most organisations that is the Chief Risk Officer, the General Counsel or the Chief Operating Officer. It shouldn't be the person doing the day-to-day work.
Named owners in each function. Every business line that processes personal data needs an owner who answers for its processing activities: retail banking, HR, marketing, operations, technology. Owners don't need to be privacy experts. They need to know their processes and have the standing to change them.
A decision rhythm. A steering group that meets every fortnight, with a short list of decisions to make each time and a record of what was decided. Decisions that wait a month for a committee add a month to the programme.
An agreed reading of the law. Legal and compliance should settle the interpretive questions early, in writing. Which activities rely on consent and which on a legitimate use? What is the retention period for each class of record? Which sector rules override erasure? Teams that argue about these points in February lose time they don't have.
With those four in place, the work itself can move at the speed the dependencies allow.
The plan, in four stages
The stages below run from October 2026 to May 2027. Each ends with a test that shows the stage is genuinely done, so progress can be measured by evidence rather than by activity.
| Stage | When | What happens | Done when |
|---|---|---|---|
| 1. Know | October to November | Discover where personal data sits. Build the processing record. List every processor and partner. Assess whether you are likely to be a Significant Data Fiduciary. | Every processing activity has an owner, its purposes, its populations and its systems recorded |
| 2. Decide | December to January | Assign one lawful basis to each activity. Design notices per purpose. Set the rights process and publish its timeline. Draft the retention schedule and the breach playbook. Draft DPDP clauses for processor contracts. | Legal has signed off the lawful-basis register, the notices and the clauses |
| 3. Build | February to March | Put consent into web, app, branch and call-centre journeys. Stand up the rights and grievance channel. Route requests to data owners. Send contract updates to vendors. Begin legacy re-notice campaigns. | A consent withdrawal is traced through to every connected system, and a test request of each type closes end to end |
| 4. Rehearse | April to mid-May | Run a breach tabletop on both clocks. Close remaining vendor contracts. Train front-line staff. Brief the Board. Assemble the evidence file. | Leadership has walked through a simulated incident, and the evidence for each obligation is recorded |
Stage 1: Know (October to November)
Start with the systems that hold the most personal data and touch the most people: core platforms, CRM, customer apps, HR and payroll, and anything that stores identity documents. Scan them for personal data rather than relying on interviews alone. Interviews tell you what people believe the systems contain. Scans tell you what they actually contain, including copies in exports, backups and shared drives.
Record every processing activity with its purpose, the categories of data, the people it concerns, the systems involved and the third parties who receive the data. Name the people. The Act protects every natural person whose data you process. That includes employees, rejected job applicants, guarantors, nominees, visitors and the contacts at your business customers, as well as customers.
By the end of November you should also know whether you are a credible candidate for designation as a Significant Data Fiduciary. If you are, the duty to appoint a Data Protection Officer in India, appoint an independent data auditor and carry out periodic impact assessments needs its own workstream from December.
Stage 2: Decide (December to January)
Every activity needs exactly one lawful ground from the Act. Either the person has consented, or the processing falls within one of the legitimate uses listed in Section 7, or an exemption under Section 17 applies. There is no general "legitimate interests" ground in the DPDP Act. Activities that were filed under one in a GDPR-era register need to be looked at again, and marketing almost always needs consent.
Notices follow from the register. Section 5 and the Rules require a notice that stands on its own, itemises the data and the purposes, explains how to withdraw consent and how to exercise rights, and tells the person how to complain to the Board. The notice must be available in English or any of the twenty-two languages in the Eighth Schedule, at the person's choice. Translations take time to produce and longer to review. Start them in December.
Set your rights process in this stage too. The Rules allow up to ninety days to respond to rights requests and grievances. You must publish your own timeline, and once published it binds you. Choose a period you can meet in practice, then design the routing and the owner queues to beat it.
Two more documents belong here. The retention schedule sets out, for each class of record, when the purpose ends and which other law requires it to be kept longer. The breach playbook covers both clocks. CERT-In expects a report within six hours of noticing an incident. The DPDP Rules require notice to the Board and to affected people without delay, followed by a detailed report to the Board within seventy-two hours.
Stage 3: Build (February to March)
This is where most programmes slip, because it depends on engineering capacity and on change windows that close around the financial year end.
Consent has to work inside the journeys people already use. On the web that means a notice and consent screen that blocks tracking until consent is given. In an app it usually means an integration through an SDK or API. At a branch or on a call, staff capture the choice on the person's behalf, and the record must look the same as a digital one. Withdrawal has to be as easy as giving consent, and it has to reach the systems that use the data: marketing tools, CRM, and the processors who act for you.
The rights channel needs identity verification, routing to the owner of each system, clocks that warn before they lapse, and a record of what was done. Requests for erasure need a way to decline where another law requires retention, with the reason given to the person. Section 12(3) allows that, and it is common in regulated sectors.
Begin legacy re-notice campaigns in this stage. Section 5(2) requires a fresh notice to people whose personal data you processed before the Act. For an organisation with a large historical customer base, this is a campaign, with bounced emails, outdated numbers and responses to record. Starting it in March leaves room to follow up before May.
Stage 4: Rehearse (April to mid-May)
Run a tabletop exercise with leadership, built around a realistic personal data breach. Time it against the CERT-In clock and the DPDP clock. Most organisations discover in that exercise that the first six hours depend on decisions nobody has been authorised to make.
Close the remaining processor contracts. Train the people at counters and on phones, since they will meet the new notices first. Brief the Board on the state of each obligation, with the evidence behind it.
Finally, assemble the evidence file. Section 6(10) puts the burden of proving consent on the Data Fiduciary. Section 33(2) lists the factors the Board weighs when it sets a penalty, including what the organisation did to mitigate. A programme that kept its own records, with dates, versions and owners, is far better placed in both situations than one that kept slides.
Five tasks that always take longer than planned
Legacy notices. Old contact data is unreliable. Campaigns need several waves, and every response, including "stop contacting me", has to be recorded.
Vendor contracts. Large vendors negotiate slowly, and some will want to use their own data protection terms. Start with the processors who handle the most sensitive data.
Branch and assisted channels. Paper forms, field agents and call scripts all need to change, along with training and a way to digitise the choice. Data that starts on paper and is later digitised falls within the Act.
Translations. Twenty-two languages are possible, and each notice change triggers a new round. Decide early which languages your customers actually use, and build a review step into every change.
Retention and deletion. Deleting from the system of record is the easy part. Copies in backups, exports, analytics stores and vendor systems are where deletion programmes stall.
If you are starting late
Organisations beginning in late 2026 cannot do everything at once. If you need to prioritise, a sensible order follows the size of the penalties and the likelihood of a complaint.
- Safeguards and breach readiness. Failure to take reasonable security safeguards carries the highest penalty in the Schedule, up to ₹250 crore, and failure to notify a breach up to ₹200 crore. Encrypt or mask identifiers in your highest-volume systems, confirm logging, and agree the breach playbook.
- Notices and consent on the biggest channels. Start with the journeys that collect the most personal data from the most people.
- A working grievance channel. Under Section 13(3), people must use your grievance mechanism before they can complain to the Board. A responsive channel resolves most issues before they become complaints.
- Children's data. If any service may be used by children, verifiable parental consent and the bar on tracking and targeted advertising need attention early, with penalties of up to ₹200 crore.
- Everything else, in the order of the four stages.
Questions for the Board
Directors don't need the detail of each workstream. They need answers to a few questions, backed by evidence.
- Do we know every system that holds personal data, and who owns each one?
- Does every processing activity have a lawful basis from the Act, and has legal signed off the register?
- Can a customer withdraw consent today, and how long does it take to reach every system that uses their data?
- What is our published timeline for rights requests, and what is our current average?
- When did we last rehearse a personal data breach, and what did we change afterwards?
- Are we likely to be designated a Significant Data Fiduciary, and if so, who is our Data Protection Officer?
Thirty-two weeks is enough time to be ready if the work starts now and follows the order the Act imposes. It is not enough time to do it twice.