India flag

India

DPDP Act Implementation Status: What Is Actually Live (2026 Tracker)

By Recording Law Editorial Team12 min read
DPDP Act Implementation Status: What Is Actually Live (2026 Tracker)

Frequently Asked Questions

Is India's DPDP Act fully in force right now?

No. Only Stage 1 is in force, effective November 13, 2025, covering the Data Protection Board's establishment and basic rule-making machinery. The Act's substantive consent, children's-data, cross-border, and Significant Data Fiduciary provisions are scheduled for Stage 3 on May 13, 2027, and are not yet legally binding.

Has the Data Protection Board of India started enforcing the DPDP Act?

No. The Board has been formally constituted as an entity, but as of this review it has not been staffed with a Chairperson or Members, and there has been no DPDP enforcement action, fine, or published order to date.

What actually happened on November 13, 2025?

The government issued the commencement notification for Stage 1 of the DPDPA, published as Gazette of India, Extraordinary, Part II-Section 3(i), No. 757, alongside the Digital Personal Data Protection Rules, 2025. This brought the Data Protection Board's establishment and a small set of procedural and definitional provisions into force. It did not activate the Act's substantive consent or data-principal-rights provisions.

When do DPDP's consent and notice rules actually take effect?

They are scheduled to commence in Stage 3, on May 13, 2027, along with children's-data protections, Significant Data Fiduciary obligations, cross-border transfer rules, and the DPDP breach-notification duty. Until that date, an organization is not legally bound by these provisions under DPDP itself.

Does India have a breach-notification deadline right now, even though DPDP's own rule is not yet in force?

Yes. The Indian Computer Emergency Response Team (CERT-In) already requires reporting of cybersecurity incidents within 6 hours, in force since June 2022, under a separate statute (the Information Technology Act). DPDP's own breach-notification duty to the Data Protection Board has not yet commenced. As of today, only CERT-In's 6-hour clock actually binds organizations in India on breach reporting.

Can a business register as a Consent Manager under DPDP today?

Not yet. The DPDP Rules define what a Consent Manager must be and do, but the Rule making Consent Manager registration operative is expected to take effect around November 13, 2026, alongside Stage 2 of the Act's commencement. No Consent Manager can be registered under DPDP before then.

Is there a restricted-country list for cross-border data transfers under DPDP?

No. DPDP's Section 16 cross-border transfer provision has not itself commenced, and even once it does, its negative-list design means transfers remain unrestricted by DPDP unless and until the government affirmatively notifies specific countries as restricted, which has not happened as of this review.

What is the maximum DPDP penalty, and has anyone actually been fined?

The Act's Schedule caps the most serious category of contravention at roughly ₹250 crore, with the Data Protection Board able to enhance that up to double in serious cases. No DPDP penalty has actually been assessed against any organization, since Section 33 and the penalty Schedule are part of the Stage 3 provisions that have not yet commenced.

Updates

Page published. The Data Protection Board remains constituted but unstaffed, with no reported Chairperson or Members in office and no DPDP enforcement action to date. Next scheduled milestone: Stage 2 of commencement is expected around November 13, 2026.

The Ministry of Electronics and Information Technology (MeitY) issued a corrigendum to the Digital Personal Data Protection Rules, 2025. Anyone relying on precise Rules text should check it against the corrigendum, not the original November PDF alone.

Stage 1 of the DPDPA's staged commencement took effect, per the Gazette of India, Extraordinary, Part II-Section 3(i), No. 757. The Data Protection Board of India was formally constituted, and the Act's and Rules' skeletal machinery (definitions, the Board's own operating rules, the Central Government's general rule-making powers) went live. Substantive consent, notice, children's-data, and cross-border provisions remain dormant.

Sources and References

  1. Ministry of Electronics and Information Technology (MeitY): Digital Personal Data Protection Rules, 2025 and commencement notifications (Gazette No. 757, Nov 13, 2025)(meity.gov.in).gov
  2. MeitY: Enforcement Timeline for the DPDP Act (notification PDF)(meity.gov.in).gov
  3. CERT-In: Direction under Section 70B of the IT Act on cyber incident reporting(cert-in.org.in).gov
  4. Mondaq: India's Data Protection Board - The Enforcer That Isn't There Yet(mondaq.com)
  5. Internet Freedom Foundation: Statement on the DPDP Rules 2025 notification(internetfreedom.in)
  6. Medianama: Consent Manager rules under the DPDP Rules 2025(medianama.com)
Share: