Erasure

Blog

Written by the Erasure product and engineering team

DPDP Timeline 2026-27: Every Enforcement Date You Need

Every material DPDP Act date: assent August 2023, Rules notified November 13 2025, Consent Manager registration November 2026, penalty enforcement expected May 2027.

The DPDP Act is not a future concern. It received presidential assent on August 11, 2023, the DPDP Rules were notified on November 13, 2025, and the enforcement machinery is now being stood up in phases. Companies that treat the timeline as a distant event will be in remediation mode when enforcement begins.

This post collects every material date in the DPDP enforcement roadmap in one place, with what each one means operationally. It is not legal advice; it is a calendar.

The complete DPDP timeline

| Date | Milestone | What it means for you | |------|-----------|-----------------------| | August 11, 2023 | DPDP Act receives presidential assent and is gazetted | The law exists; compliance obligations begin in principle | | 2024 | MeitY drafts the DPDP Rules (no public draft) | Planning window; no operational specifics available | | January 3, 2025 | Draft DPDP Rules released for public consultation | First look at the operational requirements | | November 13, 2025 | DPDP Rules, 2025 notified (G.S.R. 846(E)) | The Act gets operational teeth: notice, consent, security, breach reporting rules | | November 13, 2026 | Consent Manager registration window opens | The consent manager ecosystem becomes regulated | | ~May 2027 | Full penalty enforcement expected to begin | The Data Protection Board starts exercising its enforcement powers |

The gap between November 2025 and May 2027 is the compliance runway. It is also the window where companies either build the machinery or bet that enforcement will slip. GDPR's history suggests the bet is a bad one.

Why the November 2025 notification matters

The Act itself, from 2023, was a framework. It said consent must be free, specific, informed, unconditional and unambiguous. It created the Data Protection Board and the ₹250 crore penalty ceiling. What it did not do is say how.

The Rules filled that in: notice content and language requirements, consent mechanics, security safeguard standards (encryption, access controls, a one-year log retention floor), breach notification within 72 hours to the Board, and the Significant Data Fiduciary framework with DPIAs, audits, and an India-based DPO.

If you have not read the Rules because you thought the Act was still in a transition period, that is the single biggest gap in your planning. The transition period is over.

What happens between now and enforcement

Three things are happening in parallel through 2026 and into 2027:

  1. Board constitution and staffing. The Data Protection Board is being set up and will need to be functional before enforcement begins. Expect its early work to focus on building process, not on mass enforcement.

  2. Consent Manager ecosystem. Registration for Consent Managers opens November 2026. This creates the regulated layer through which data principals can manage consent across fiduciaries. If you are building consent infrastructure, the Consent Manager rules are directly relevant to how your architecture should think about portability and withdrawal.

  3. Fiduciary remediation. This is the part that is on you. Companies are using 2026 to rebuild notice, consent, inventory, and deletion machinery. The ones that started in early 2026 will be done by enforcement; the ones that start in early 2027 will be racing it.

How the enforcement will likely roll out

Looking at how GDPR enforcement began in Europe, and at the structure of the DPDP Act, a few patterns are probable:

  • The Board will start with the largest, highest-volume fiduciaries and the most serious breaches
  • Significant Data Fiduciaries (SDFs) are the natural first targets; the Rules give them extra obligations precisely because they are high-risk
  • The early enforcement cases will be about systemic failure: no security safeguards, mass unlawful processing, no breach notification
  • Smaller companies that have built defensible operations are unlikely to be early targets

None of that is a reason to delay. It is a reason to sequence: build the operational core now, while the enforcement machinery is still being stood up, so that when scrutiny arrives you are not scrambling.

Building on the runway

The practical work for the runway is:

  1. Notice with versioning and multi-language support
  2. Consent with per-purpose granularity, withdrawal parity, and receipts
  3. A data inventory: systems, identifiers, deletion keys
  4. A deletion workflow with verification, fulfilment, and audit
  5. Security safeguards: encryption, access control, one-year logs
  6. A breach runbook covering both the DPB 72-hour clock and CERT-In

That list is exactly what our DPDP compliance checklist itemizes, and the Rules explainer goes into what each Rule requires. If you want the consent-specific deep dive, the consent requirements post covers Section 6 in detail.

The calendar in one line

The Act is law, the Rules are notified, Consent Manager registration opens in November 2026, and penalty enforcement is expected from around May 2027. Everything between now and then is runway. How you use it is the only variable left.

Erasure is built to cover the operational core of that work: notice and consent in Accord, deletion and evidence in Rights, inventory in Data Maps, and fulfilment across Postgres, MySQL, HTTP, and Webhook systems. It is invite-only in beta; request access or read the product docs.

About this post

Written by the Erasure product and engineering team

Published 29 July 2026

This article is grounded in Erasure's product documentation and explains engineering and operational implications. Where it discusses regulation, it is not legal advice. See our editorial policy.

← All posts · Docs