DPDP Act Compliance Countdown: Data Protection Board Constituted, 18-Month Runway to Full Enforcement

Data Protection Board of India notification and DPDP Rules 2025 official gazette document analyzed by Adv Shoeb Hakim

Key Facts

  • Date of Notification: 13 November 2025 — the Digital Personal Data Protection Rules, 2025 were formally notified alongside the Act .
  • Immediate Effect (13 November 2025) : Data Protection Board of India constituted with powers to investigate, issue directions, and impose penalties .
  • 12-Month Milestone (13 November 2026) : Consent Manager registration framework becomes operational for India-incorporated entities .
  • 18-Month Deadline (13 May 2027) : Full compliance obligations apply — notice requirements, security safeguards, breach notification, and Data Principal rights .
  • Maximum Penalty: Up to ₹250 crore for failure to implement reasonable security safeguards .

Direct Answer

India’s Digital Personal Data Protection (DPDP) framework officially entered its enforcement phase on 13 November 2025, when the Government notified the Digital Personal Data Protection Rules, 2025 and constituted the Data Protection Board of India .

The framework provides an 18-month phased implementation timeline, with core compliance obligations becoming fully enforceable on 13 May 2027, at which point Data Fiduciaries must demonstrate demonstrable compliance with notice requirements, security safeguards, breach notification obligations, and Data Principal rights . A ₹250 crore penalty cap applies for certain violations, including failure to implement reasonable security safeguards .


In this article:

  • The DPDP Framework: Structure and Scope
  • Phased Implementation Timeline
    • Phase 1: Immediate Effect (13 November 2025)
    • Phase 2: 12-Month Milestone (13 November 2026)
    • Phase 3: 18-Month Deadline (13 May 2027)
  • Penalty Regime
  • Compliance Costs
  • Simplified Compliance for Startups
  • The Five Questions the Board Will Ask
  • FAQ

By Adv. Shoeb Hakim — Criminal defence, AML, digital forensics, and cybercrime specialist; former General Counsel, Credit Suisse; training police and judiciary since 1996.


The DPDP Framework: Structure and Scope

The Digital Personal Data Protection Act, 2023, together with the DPDP Rules, 2025, establishes India’s first comprehensive framework for the processing of digital personal data . The Act traces its origin to the Supreme Court’s 2017 Puttaswamy judgment, which mandated a statutory framework for data protection in India .

The DPDP Act applies to the processing of digital personal data within India and extraterritorially to entities offering goods or services to individuals in India . It operates primarily on a foundation of explicit consent, requiring Data Fiduciaries to process personal data only for lawful purposes with free, informed, specific, and unambiguous consent .


Phased Implementation Timeline

The DPDP Rules implement a staggered approach to commencement, giving organisations time to build governance capacity before full-scale compliance begins .

Phase 1: Immediate Effect (13 November 2025)

The following provisions became operational upon notification:

  • The Data Protection Board of India was formally constituted .
  • The Board is empowered to investigate breaches, issue corrective directions, and impose penalties .
  • The Board’s head office is located in the National Capital Region, with an initial four-member composition .
  • Rule 4 of the DPDP Rules relating to appointment, functioning, meetings, and digital office operations took effect .

Phase 2: 12-Month Milestone (13 November 2026)

The framework for registration and oversight of Consent Managers becomes operational .

Consent Manager registration requirements include:

  • Incorporation in India
  • Minimum net worth of ₹2 crore (approximately USD 200,000)
  • Demonstration of sufficient technical, operational, and financial capacity
  • Certification that the platform is interoperable and adheres to data protection standards

Consent Manager obligations:

  • Act in a fiduciary capacity toward the Data Principal
  • Prohibition on sub-contracting their obligations
  • Avoid conflicts of interest with Data Fiduciaries
  • Retain records of consents, notices, and data sharing activities for at least seven years
  • Cannot read the contents of personal data being shared

Phase 3: 18-Month Deadline (13 May 2027)

Core compliance duties apply, including :

  • Notice requirements for data collection
  • Implementation of reasonable security safeguards
  • Breach intimation obligations
  • Significant Data Fiduciary (SDF) obligations
  • Data Principal rights (access, correction, erasure)
  • Data erasure upon withdrawal of consent unless retention is legally required

Penalty Regime

The Data Protection Board is empowered to impose monetary penalties for violations. Penalties are determined based on factors including the nature and gravity of the breach, the volume and sensitivity of data involved, the harm caused to Data Principals, whether the fiduciary acted wilfully or negligently, the duration of the violation, cooperation during investigation, and steps taken to mitigate damage .

Penalty Categories :

Breach CategoryMaximum Penalty
Failure to implement reasonable security safeguards₹250 crore
Failure to notify personal data breach to Board and affected individuals₹200 crore
Failure to fulfil obligations regarding children’s data (parental consent, profiling restrictions)₹200 crore
Violation of duties by Significant Data Fiduciaries (DPIAs, DPO appointments, audits)₹150 crore
Non-fulfilment of Data Principal rights (access, correction, erasure)₹50 crore
Breach of cross-border transfer restrictionsQuantum at Board’s discretion

Compliance Costs

A recent analysis estimates significant compliance investment requirements :

One-time costs (by May 2027) :

  • Large enterprises: ₹2.5 crore to ₹18 crore
  • Mid-size enterprises: ₹1.5 crore to ₹2.5 crore
  • Smaller companies: ₹1 crore to ₹1.5 crore

Annual recurring costs :

  • ₹50 lakh to ₹10 crore depending on organisational size

These costs include data mapping and inventory, consent management infrastructure, Data Subject Access Request (DSAR) system development, security hardening, and Data Protection Officer hiring .


Simplified Compliance for Startups

The DPDP framework provides exemptions for certain Data Fiduciaries, including startups, from obligations such as providing notices, maintaining accurate personal data, erasing personal data, and supplying summaries of personal data processed . These exemptions are determined based on the volume and nature of personal data processed .


The Five Questions the Board Will Ask

  1. Why are we collecting this data? — The principle of purpose limitation requires Data Fiduciaries to identify and document every processing purpose before collection .
  2. Is it necessary for the stated purpose? — Data minimisation requires justification for each data field collected and an assessment of whether less intrusive alternatives are feasible .
  3. Do we have valid, demonstrable consent where required? — Consent must be free, specific, informed, and unambiguous, preceded by proper notice . Organisations must maintain audit trails demonstrating valid consent for each processing activity.
  4. Who owns and safeguards this data? — Data Fiduciaries must implement appropriate technical and organisational measures to ensure compliance, with breach notification obligations within 72 hours of becoming aware of a breach .
  5. When and how will it be securely deleted? — Data must be erased upon withdrawal of consent or when the purpose is fulfilled, unless retention is legally required . Retention schedules must be documented and consistently enforced.

FREQUENTLY ASKED QUESTIONS (FAQ)

When was the Data Protection Board of India constituted?
The Data Protection Board of India was formally constituted on 13 November 2025, when the Digital Personal Data Protection Rules, 2025 were notified .

What is the maximum penalty under the DPDP Act?
The maximum penalty is ₹250 crore for failure to implement reasonable security safeguards . Failure to report data breaches can attract penalties up to ₹200 crore

When do DPDP compliance obligations become fully enforceable?
Core compliance obligations, including notice requirements, security safeguards, breach notification, and Data Principal rights, become fully enforceable on 13 May 2027 — 18 months from the notification date .

What is a Consent Manager under the DPDP framework?
A Consent Manager is an entity registered with the Data Protection Board that acts as an intermediary to enable Data Principals to give, manage, review, and withdraw consent for processing their personal data . The registration framework becomes operational on 13 November 2026 .

What are the Consent Manager registration requirements?
Consent Managers must be incorporated in India, have a minimum net worth of ₹2 crore, demonstrate sufficient technical and financial capacity, and maintain interoperable platforms meeting data protection standards .

Does the DPDP Act apply to foreign companies?
Yes, the DPDP Act applies extraterritorially to entities processing digital personal data outside India in connection with offering goods or services to individuals in India .

Are startups subject to full DPDP compliance obligations?
The framework provides exemptions for certain Data Fiduciaries, including startups, from obligations such as providing notices, maintaining accurate personal data, erasing personal data, and supplying summaries of personal data processed — subject to conditions based on data volume and nature .

What is the timeline for compliance preparation?
Organisations have 18 months from 13 November 2025 to achieve compliance, with the deadline of 13 May 2027 for full obligations .

What factors determine the quantum of penalty?
The Data Protection Board considers the nature, gravity, and duration of the breach; sensitivity of data; volume of individuals affected; whether the breach was wilful or negligent; cooperation during investigation; and steps taken to mitigate damage .

What are the cost estimates for DPDP compliance?
One-time compliance costs range from ₹1 crore to ₹18 crore depending on organisational size, with annual recurring costs of ₹50 lakh to ₹10 crore .

Q: What is a Consent Manager?
Ans: A registered intermediary that enables Data Principals to give, manage, review, and withdraw consent for data processing.

Q: Are foreign companies subject to the DPDP Act?
Ans: Yes. The Act applies extraterritorially to any entity processing digital personal data in connection with offering goods or services to individuals in India.

Q: What factors determine the penalty imposed by the Board?
Ans: Factors include the nature, gravity, and duration of the breach, the sensitivity of the data, the volume of individuals affected, whether the act was willful or negligent, and the steps taken to mitigate damage.

Q: Can data be retained indefinitely if it is encrypted?
Ans: No. Data must be erased upon the withdrawal of consent or when the stated purpose of processing is fulfilled, unless retention is explicitly required by law.


Adv. Shoeb Hakim
Data Protection & Governance Advisor | shoebhakim.com

https://www.linkedin.com/in/shoebhakim

📌 Visit my website for more articles: https://www.shoebhakim.com
📌 Visit my website for legal knowledge: https://www.vakilverse.com
📌 Visit my website for research fellowship: https://www.legalcomplaince.in
📌 Connect: https://www.linkedin.com/in/shoebhakim | https://shoebhakim.com/shoeb-hakim-blog/ 

#AdvShoebHakim #DPDPAct #DataProtection #IndiaPrivacy #ComplianceCountdown #DataGovernance #CyberLaw #RegulatoryCompliance #PrivacyByDesign #DataProtectionBoard #Vakilverse #LegalComplianceIN

Disclaimer: This content is for informational purposes only and does not constitute legal advice. Readers should consult qualified legal counsel for advice on their specific circumstances.

Leave a Reply

Your email address will not be published. Required fields are marked *

Find