India's Digital Personal Data Protection Act, 2023 (DPDP Act) received presidential assent in August 2023, but "the Act is in force" is not a single on/off switch. It is being rolled out in phases, and a lot of the confusion we hear from founders and compliance teams comes from treating it as one event rather than a timeline.
What is live today
The Data Protection Board of India, the body that will hear complaints and impose penalties under the Act, was formally established on 14 November 2025. Its existence does not by itself create new compliance obligations for businesses, but it means the enforcement machinery is no longer theoretical - the Board can begin hearing matters as other provisions come into force.
What comes next
Registration for Consent Managers - the intermediaries the Act allows individuals to route their consent through - opens on 14 November 2026. This matters more for platforms and aggregators that intend to operate as Consent Managers than for most ordinary businesses, but it is the next concrete milestone on the calendar.
The substantive obligations that apply to most data fiduciaries - notice requirements, consent standards, data breach reporting, and the penalty provisions that go with them - are expected to become enforceable around May 2027, once the Government notifies the remaining sections and the transition period built into the Act runs its course.
What this means in practice
"We have time" is true, but it is not the same as "we can wait." The obligations that take effect in 2027 depend on internal work that realistically takes months to do properly: mapping what personal data you collect and why, rebuilding consent flows so they meet the Act's standard rather than a generic cookie banner, and putting a breach-response process in place before you need one. Waiting until the deadline is close tends to compress all of that into a rushed few weeks.
- Map your data flows now - most businesses are surprised by how much personal data moves through vendors and marketing tools they had not thought of as "data processing."
- Review consent language against the Act's specific requirements, not just general privacy-policy best practice.
- Identify who your Data Protection Officer or equivalent contact will be, even before it is strictly mandatory for your organisation's size.
We track this timeline closely because it sits at the centre of our data protection advisory practice. If you want a structured view of where your organisation stands against these requirements, our DPDP Act compliance page has a free readiness self-assessment that takes a few minutes.

