May 13, 2026 · DPDP Help Center

One Year to Go: Core DPDP Compliance Obligations Take Effect 13 May 2027

With the 18-month transition underway, organisations have until 13 May 2027 to implement consent notices, security safeguards, breach processes and data-principal rights.

The 18-month transition period under the DPDP Rules, 2025 means the core compliance obligations become enforceable on 13 May 2027. By that date, every Data Fiduciary should have in place:

  • Itemised, plain-language consent notices (Rule 3) in English and Eighth Schedule languages;
  • Reasonable security safeguards including encryption, access control and logging (Rule 6);
  • A personal-data-breach response plan meeting the 72-hour reporting window (Rule 7);
  • Retention and erasure workflows (Rule 8) and published data-principal rights mechanisms (Rule 14).

Significant Data Fiduciaries should additionally prepare for annual DPIAs, independent audits and appointment of an India-based Data Protection Officer.

Read the official source

compliance, deadline, may 2027, transition, checklist, sdf
Back to News List