If you have been treating India’s Digital Personal Data Protection Act as a “2027 problem,” the calendar has other ideas. The DPDP Rules, 2025, were notified in November 2025, and the second of three commencement dates—the Consent Manager framework—goes live on 13 November 2026. The rest of the law, including its penalty regime, follows on 13 May 2027. And the government has openly discussed bringing that final date forward.
Most of the advice circulating right now focuses on consent banners and privacy notices. Those matter. But the single largest penalty in the Act — up to ₹250 crore — is not about consent at all. It is about security. At Aspect, we put it simply: compliance is the lock, and security is the key. You need both, and the key is the part most businesses are missing.
The phased rollout confuses a lot of teams. Here is the timeline in plain terms:
| Date | What it means for you |
|---|---|
| November 2025 | Rules notified. The Data Protection Board of India is live and can receive complaints. |
| 13 November 2026 | The Consent Manager framework activates. Registered consent managers can begin helping individuals give, review, and withdraw consent across services. Your systems should be ready to honor consent—and withdrawals—coming through these channels. |
| 13 May 2027 | Everything else becomes enforceable: notices, consent, security safeguards, breach reporting, data principal rights, and penalties. |
A word of caution: in January 2026, MeitY discussed shortening the compliance window from 18 months to 12, which would move full compliance to November 2026 for some or all organizations. At the time of writing this has not been confirmed as final, but it is a clear signal. Plan as if the earlier date could apply to you.
Section 8(5) of the Act requires every organization that handles personal data—a “Data Fiduciary”—to take reasonable security safeguards to prevent a breach. Rule 6 turns that phrase into a concrete minimum:
Failing here carries the Act’s highest ceiling: ₹250 crore. And penalties can stack. A breach caused by weak safeguards, followed by late notification, can attract up to ₹250 crore plus up to ₹200 crore under separate heads.
Regulatory fines are only part of the picture. IBM’s 2026 Cost of a Data Breach Report found that the average breach in India now costs a record ₹25.5 crore—up 15.9% in a single year. Financial services were hit hardest at ₹40.9 crore per incident. The same report offers a useful lesson: offensive security testing, such as penetration testing and red teaming, was the single largest cost-reducing factor for Indian organizations, saving an average of ₹2.47 crore per breach.
In other words, the controls DPDP asks for are the same controls that reduce real-world losses. Compliance and security are not two budgets; they are one investment.
Incident response in India now runs on two timers:
You cannot meet either deadline if you only discover the breach weeks later, or if nobody knows who makes the call. That is why detection (logging and monitoring) and a rehearsed response plan are compliance requirements, not nice-to-haves.
You do not need to finish everything in six weeks. You do need to know where you stand and have the high-risk gaps moving. Here is a practical sequence:
The Act applies to any organization processing digital personal data in India. Size affects which extra obligations apply, not whether the law applies.
ISO 27001 overlaps heavily with Rule 6 and is an excellent foundation, but it does not cover DPDP-specific duties such as notices, consent withdrawal, data-principal rights, and 72-hour reporting to the Board.
Your provider secures its infrastructure. You remain the Data Fiduciary, accountable for how your data is configured, accessed, and protected.
The Consent Manager registration framework under Rule 4 becomes operational. Registered consent managers can then help individuals manage their consent across multiple services.
Under the notified rules, the substantive obligations and penalty provisions come into force on 13 May 2027. A proposal to shorten this to November 2026 has been discussed but was not final at the time of writing.
Up to ₹250 crore for failing to take reasonable security safeguards. Other heads include up to ₹200 crore for failing to report a breach and up to ₹200 crore for breaching children’s data obligations.
Without delay to affected individuals and the Data Protection Board, with a detailed report to the Board within 72 hours. CERT-In separately requires reportable incidents within 6 hours.
The organizations that will handle DPDP calmly are the ones that start now—with a clear view of their data, tested security controls, and a plan that people have actually rehearsed. Consent notices can be rewritten in a week. Encryption, access control, logging, and a working incident response process take longer.
Aspect Tech Knowledge IES helps organizations understand their gaps and build the security foundation DPDP expects. Speak to our team about a DPDP security gap assessment.
Talk to us at
connect@aspect-tech-knowledge-ies.com
.
Deeper Understanding. Better Solutions.