India
DPDP Act Implementation Status: What Is Actually Live (2026 Tracker)

Status as of July 23, 2026. This page tracks the real-world commencement status of India's Digital Personal Data Protection Act, 2023 (DPDPA) as it happens. It is a status tracker, not a one-time explainer, and it will be updated as the government issues new notifications. For an analysis of what the law will mean once it fully applies, see our India DPDP Act vs GDPR comparison. For India's complete privacy picture, see our India data privacy laws guide.
What Is In Force Today
This is the section to check first, because it changes how everything else on this page should be read. India's DPDP Act does not work like a switch that flips on all at once. It commences in stages, and as of today, most of it has not yet happened.
| Component | Status as of July 23, 2026 |
|---|---|
| DPDP Act, overall commencement | Stage 1 only (since November 13, 2025) |
| Data Protection Board of India | Constituted as an entity; not staffed |
| Consent and notice duties | Not yet in force (Stage 3, May 13, 2027) |
| Significant Data Fiduciary obligations | Not yet in force (Stage 3) |
| Children's-data / parental-consent rules | Not yet in force (Stage 3) |
| Cross-border transfer rules (Section 16) | Not yet in force (Stage 3) |
| DPDP breach-notification duty (Rule 7) | Not yet in force (Stage 3) |
| Consent Manager registration | Not yet operative (expected around Stage 2, ~November 13, 2026) |
| CERT-In 6-hour cyber-incident reporting | In force (separate statute, unaffected by DPDP's timeline) |
| DPDP enforcement actions, fines, or Board orders to date | None reported |
The plain-language version: an organization handling personal data in India today is not yet legally bound by DPDP's consent rules, its children's-data protections, its Significant Data Fiduciary duties, its cross-border transfer regime, or its breach-notification duty to the Data Protection Board. Only the Board's existence and a small set of procedural, definitional, and rule-making provisions are currently in force. The one mandatory breach-reporting clock actually running in India today comes from a different statute entirely, covered below.

The Staged Commencement Timeline
The DPDPA received presidential assent in August 2023 and then sat un-commenced for more than two years. Commencement finally began through a gazette notification dated November 13, 2025 (Gazette of India, Extraordinary, Part II-Section 3(i), No. 757), issued by the Ministry of Electronics and Information Technology (MeitY) alongside the Digital Personal Data Protection Rules, 2025 and a companion document titled "Enforcement Timeline for the DPDP Act."
| Stage | Date | Status | What it covers |
|---|---|---|---|
| Stage 1 | November 13, 2025 | Done | The Data Protection Board's establishment, composition, and procedural powers; the Central Government's general rule-making authority; a set of definitional and procedural provisions. Of the DPDP Rules, 2025, only the short-title/definitions rule and the Board's own operating rules took effect. |
| Stage 2 | Expected around November 13, 2026 | Not yet | A further slice of the Act's provisions, roughly one year after Stage 1, per the notified enforcement timeline. |
| Stage 3 | May 13, 2027 | Not yet | The bulk of the Act's substantive machinery: consent and notice duties, the Section 7 list of enumerated "certain legitimate uses," children's-data protections, core data-principal rights, Significant Data Fiduciary obligations, cross-border transfer rules, and the corresponding DPDP Rules covering Consent Managers, breach notification, and SDF audits. |
A deliberate note on precision: this page does not attempt to list which exact section numbers activate on the Stage 2 date specifically, because the precise section-by-section mapping for Stage 2 has not been independently verified against the primary gazette and Rules text. The framing above, staged, not yet fully live, with the substantive provisions concentrated in Stage 3, is well-supported and safe to rely on. A specific section citation for Stage 2 is not. Anyone who needs an exact section list for a specific compliance decision should check MeitY's own "Enforcement Timeline for the DPDP Act" notification directly rather than relying on a secondary summary, including this one.
By contrast, the GDPR was adopted with a fixed two-year transition period and became directly applicable across the EEA on a single date, May 25, 2018. There was no skeleton-first phase and no multi-year rollout. That structural difference between a hard cutover and a staged phase-in is the reason a status tracker like this one is necessary for DPDP in a way it never was for GDPR. See our DPDP vs GDPR comparison for the full substantive comparison once the Act is fully in force.

The Data Protection Board of India: Constituted, Not Staffed
The Data Protection Board of India (DPBI) is DPDP's central enforcement body, and its current status is the clearest illustration of the gap between a law existing on paper and a law actually operating.
The Board was formally constituted as an entity on November 13, 2025, through the same wave of notifications that brought Stage 1 into force, including separate MeitY notifications titled "Establishment of the Data Protection Board of India" and "Decision Regarding Number of Members in the Data Protection Board of India." The Board's own operating rules are among the very few DPDP Rules currently in force.
What has not happened is staffing. As of this review, the Board's Chairperson and Members have not been appointed and have not assumed office. The Cabinet-Secretary-led Search-cum-Selection Committee responsible for those appointments has faced reported delays. Some Indian courts have reportedly directed complainants toward the Board even though it cannot yet act on a complaint. There is no reported DPDP enforcement action, fine, or published Board order to date, consistent with a body that exists but is not yet functioning as an adjudicator.
On paper, once operational, the Board will have real teeth. Section 33's penalty Schedule caps the most serious contraventions, such as a failure to implement reasonable security safeguards resulting in a breach, at roughly ₹250 crore, with the Board able to weigh statutory aggravating factors and enhance a penalty up to double in serious cases. That figure is worth knowing as the eventual ceiling, but it describes future exposure, not a current one: Section 33 sits within the group of provisions still awaiting Stage 3 commencement, so no DPDP penalty has actually been assessed against anyone. This page does not state a specific number of Board members, since MeitY's own notification fixing that figure has not been independently confirmed here.

What Compliance Work Is Worth Doing Now vs Later
The staged timeline changes the right sequencing for compliance work. Building a full DPDP program today, on the assumption the law already applies in full, is premature. Waiting until May 2027 to start is also a mistake, since the underlying operational changes (data mapping, consent architecture, vendor contracts) take real time to build.
Worth doing now, regardless of the timeline:
- CERT-In readiness. The 6-hour cyber-incident reporting clock is live today and unrelated to DPDP's schedule. If an incident-response plan does not already account for it, that is the most urgent gap on this list.
- Data mapping and inventory. Knowing what personal data is collected, where it is stored, and who it is shared with is foundational work that has value under any eventual DPDP rule set and does not depend on which stage is currently in force.
- Tracking, not building, Consent Manager and Significant Data Fiduciary developments. Watching whether an organization's activities are likely to attract an eventual SDF designation, or whether its consent flows will need to integrate with a Consent Manager once that Rule is operative, is useful now. Building the actual integration is premature until the relevant Rules are in force and, ideally, until the Consent Manager ecosystem itself is operating with real registered participants.
Can reasonably wait, but should be tracked closely as Stage 2 and Stage 3 approach:
- Consent-notice redesign for DPDP-specific language. The Rules that would give this legal weight are not yet in force, and the corrigendum issued in December 2025 is a reminder that rule text can still change before it takes effect. Draft directionally, but avoid over-investing in a specific implementation until the operative Rules text is settled.
- Cross-border transfer mechanism buildout. DPDP's Section 16 has not commenced, and even once it does, its negative-list design means no restriction exists in practice unless and until the government actually notifies a restricted country. There is no adequacy assessment, SCC-equivalent, or transfer-impact-assessment obligation to build toward yet.
- Children's-data age-gating deployment specific to DPDP's 18-year threshold. This sits inside Stage 3.
- Significant Data Fiduciary-specific obligations, such as appointing an India-resident Data Protection Officer or standing up an annual DPIA and audit cycle, since SDF status itself is a government designation that has not yet been made against anyone and the underlying Section 10 duties are not yet in force.

Consent Managers: Registered, Not Yet Operating
A Consent Manager is a registered intermediary, unique to DPDP with no GDPR equivalent, through which an individual can grant, review, and withdraw consent to multiple organizations from a single interoperable dashboard rather than negotiating separately with each one.
The DPDP Rules set defined obligations for a Consent Manager: it must incorporate as an Indian company, demonstrate technical, operational, and financial capacity, and obtain independent certification of its consent-management platform. Structurally, a Consent Manager cannot simultaneously act as a data fiduciary or processor for the same individual, so it cannot both broker consent and profit from the data it manages, and it cannot monetize consent flows or favor one fiduciary over another. It is required to operate on a transparent, fee-based model instead. This page does not state the specific minimum net-worth figure sometimes quoted for Consent Managers, since that figure has not been independently verified against the primary Rules text.
Consent Managers are not operating yet. The Rule that makes registration operative is expected to take effect around November 13, 2026, alongside Stage 2. Until then, no Consent Manager can be registered or relied on under DPDP, and any vendor claiming current DPDP Consent Manager status should be treated with caution.
The CERT-In Overlay: What's Actually Required Today
This is the point most guides get backwards, and it is the reason this section exists on a status tracker rather than a comparison page: India already has a mandatory, currently-enforceable breach reporting deadline, and it has nothing to do with DPDP.
The Indian Computer Emergency Response Team (CERT-In), operating under Section 70B of the Information Technology Act, requires reporting of cybersecurity incidents within 6 hours of an organization noting or being notified of the incident. This direction has been in force since June 2022, applies broadly to service providers, intermediaries, data centers, body corporates, and government organizations, carries no size threshold, and covers 20 listed categories of cyber incident, of which a data breach is only one.
DPDP's own breach-notification duty, under Rule 7, is different in design: an initial alert to the Data Protection Board "without delay," followed by a detailed report within 72 hours (or longer if the Board permits), with no minimum-size threshold once it applies. But Rule 7 sits inside the group of Rules delayed to Stage 3, so it is not live today. Only CERT-In's clock currently binds an organization that experiences a breach in India. A breach-response plan built solely around a future 72-hour DPDP figure, without accounting for the 6-hour clock that is actually running now, would be incomplete. See our broader data breach notification deadlines by country guide for how this compares across the region.
What to Watch Next
The following are the specific, concrete triggers that would change the picture described on this page. None of these are predictions; they are the events this tracker is watching for, and each will move a status row above from "not yet" to "in force" or from "unstaffed" to "operational" when it happens.
- Data Protection Board appointments. A Chairperson and Members actually assuming office would be the first sign the Board can begin adjudicating complaints rather than only existing as an entity.
- Stage 2 notification, expected around November 13, 2026. Confirming both that it was actually issued on schedule and exactly which provisions it activates.
- Any advance signal ahead of the May 13, 2027 Stage 3 date, including draft guidance, public consultations, or implementation timelines MeitY publishes in the run-up.
- Consent Manager registrations actually opening and the first Consent Managers being certified, which would make that institution real rather than a Rule waiting on its own commencement.
- A restricted-country cross-border transfer list being notified for the first time, since none exists today and Section 16 has not itself commenced.
- The first DPDP enforcement order, fine, or published Board decision, which would be the first real test of how the Board actually applies the Act once it is functioning.
- The first Significant Data Fiduciary designations, since SDF status is government-assigned rather than self-declared and none have been made yet.
Disclaimer
This page presents general legal information about the implementation status of India's Digital Personal Data Protection Act, 2023. It does not constitute legal advice. DPDP's commencement is an active, staged process, and specific dates, section mappings, and figures described above are subject to further government notification. This is a living status page maintained on an ongoing basis; readers relying on any date here for a compliance decision should confirm it against MeitY's official notifications directly. This page reflects information available as of July 23, 2026.
Status as of July 23, 2026. This is a living tracker; check back for updates as India's Data Protection Board is staffed, Stage 2 and Stage 3 notifications are issued, and Consent Manager registration becomes operative.
Frequently Asked Questions
Is India's DPDP Act fully in force right now?
No. Only Stage 1 is in force, effective November 13, 2025, covering the Data Protection Board's establishment and basic rule-making machinery. The Act's substantive consent, children's-data, cross-border, and Significant Data Fiduciary provisions are scheduled for Stage 3 on May 13, 2027, and are not yet legally binding.
Has the Data Protection Board of India started enforcing the DPDP Act?
No. The Board has been formally constituted as an entity, but as of this review it has not been staffed with a Chairperson or Members, and there has been no DPDP enforcement action, fine, or published order to date.
What actually happened on November 13, 2025?
The government issued the commencement notification for Stage 1 of the DPDPA, published as Gazette of India, Extraordinary, Part II-Section 3(i), No. 757, alongside the Digital Personal Data Protection Rules, 2025. This brought the Data Protection Board's establishment and a small set of procedural and definitional provisions into force. It did not activate the Act's substantive consent or data-principal-rights provisions.
When do DPDP's consent and notice rules actually take effect?
They are scheduled to commence in Stage 3, on May 13, 2027, along with children's-data protections, Significant Data Fiduciary obligations, cross-border transfer rules, and the DPDP breach-notification duty. Until that date, an organization is not legally bound by these provisions under DPDP itself.
Does India have a breach-notification deadline right now, even though DPDP's own rule is not yet in force?
Yes. The Indian Computer Emergency Response Team (CERT-In) already requires reporting of cybersecurity incidents within 6 hours, in force since June 2022, under a separate statute (the Information Technology Act). DPDP's own breach-notification duty to the Data Protection Board has not yet commenced. As of today, only CERT-In's 6-hour clock actually binds organizations in India on breach reporting.
Can a business register as a Consent Manager under DPDP today?
Not yet. The DPDP Rules define what a Consent Manager must be and do, but the Rule making Consent Manager registration operative is expected to take effect around November 13, 2026, alongside Stage 2 of the Act's commencement. No Consent Manager can be registered under DPDP before then.
Is there a restricted-country list for cross-border data transfers under DPDP?
No. DPDP's Section 16 cross-border transfer provision has not itself commenced, and even once it does, its negative-list design means transfers remain unrestricted by DPDP unless and until the government affirmatively notifies specific countries as restricted, which has not happened as of this review.
What is the maximum DPDP penalty, and has anyone actually been fined?
The Act's Schedule caps the most serious category of contravention at roughly ₹250 crore, with the Data Protection Board able to enhance that up to double in serious cases. No DPDP penalty has actually been assessed against any organization, since Section 33 and the penalty Schedule are part of the Stage 3 provisions that have not yet commenced.
Updates
Stage 1 of the DPDPA's staged commencement took effect, per the Gazette of India, Extraordinary, Part II-Section 3(i), No. 757. The Data Protection Board of India was formally constituted, and the Act's and Rules' skeletal machinery (definitions, the Board's own operating rules, the Central Government's general rule-making powers) went live. Substantive consent, notice, children's-data, and cross-border provisions remain dormant.
The Ministry of Electronics and Information Technology (MeitY) issued a corrigendum to the Digital Personal Data Protection Rules, 2025. Anyone relying on precise Rules text should check it against the corrigendum, not the original November PDF alone.
Page published. The Data Protection Board remains constituted but unstaffed, with no reported Chairperson or Members in office and no DPDP enforcement action to date. Next scheduled milestone: Stage 2 of commencement is expected around November 13, 2026.
Sources and References
- Ministry of Electronics and Information Technology (MeitY): Digital Personal Data Protection Rules, 2025 and commencement notifications (Gazette No. 757, Nov 13, 2025)(meity.gov.in).gov
- MeitY: Enforcement Timeline for the DPDP Act (notification PDF)(meity.gov.in).gov
- CERT-In: Direction under Section 70B of the IT Act on cyber incident reporting(cert-in.org.in).gov
- Mondaq: India's Data Protection Board - The Enforcer That Isn't There Yet(mondaq.com)
- Internet Freedom Foundation: Statement on the DPDP Rules 2025 notification(internetfreedom.in)
- Medianama: Consent Manager rules under the DPDP Rules 2025(medianama.com)