Skip to main content

Aspect Tech Knowledge IES

The DPDP Act Countdown: What Businesses Must Secure Before 13 November 2026

If you have been treating India’s Digital Personal Data Protection Act as a “2027 problem,” the calendar has other ideas. The DPDP Rules, 2025, were notified in November 2025, and the second of three commencement dates—the Consent Manager framework—goes live on 13 November 2026. The rest of the law, including its penalty regime, follows on 13 May 2027. And the government has openly discussed bringing that final date forward.

Most of the advice circulating right now focuses on consent banners and privacy notices. Those matter. But the single largest penalty in the Act — up to ₹250 crore — is not about consent at all. It is about security. At Aspect, we put it simply: compliance is the lock, and security is the key. You need both, and the key is the part most businesses are missing.

01. DPDP is not one deadline—it is three

The phased rollout confuses a lot of teams. Here is the timeline in plain terms:

Date What it means for you
November 2025 Rules notified. The Data Protection Board of India is live and can receive complaints.
13 November 2026 The Consent Manager framework activates. Registered consent managers can begin helping individuals give, review, and withdraw consent across services. Your systems should be ready to honor consent—and withdrawals—coming through these channels.
13 May 2027 Everything else becomes enforceable: notices, consent, security safeguards, breach reporting, data principal rights, and penalties.

A word of caution: in January 2026, MeitY discussed shortening the compliance window from 18 months to 12, which would move full compliance to November 2026 for some or all organizations. At the time of writing this has not been confirmed as final, but it is a clear signal. Plan as if the earlier date could apply to you.

02. Why security is the heart of DPDP

Section 8(5) of the Act requires every organization that handles personal data—a “Data Fiduciary”—to take reasonable security safeguards to prevent a breach. Rule 6 turns that phrase into a concrete minimum:

  • Protect the data itself with encryption, masking, obfuscation, or tokenization.
  • Control access to systems and data, so only the right people see the right information.
  • Log and monitor access so unauthorised activity can be detected, investigated, and remediated—and keep those logs for at least one year.
  • Keep backups and continuity measures so a ransomware attack or outage does not become a data loss event.
  • Bind your vendors—every processor handling data on your behalf must be contractually required to apply the same safeguards.

Failing here carries the Act’s highest ceiling: ₹250 crore. And penalties can stack. A breach caused by weak safeguards, followed by late notification, can attract up to ₹250 crore plus up to ₹200 crore under separate heads.

03. The real cost of a breach is already rising

Regulatory fines are only part of the picture. IBM’s 2026 Cost of a Data Breach Report found that the average breach in India now costs a record ₹25.5 crore—up 15.9% in a single year. Financial services were hit hardest at ₹40.9 crore per incident. The same report offers a useful lesson: offensive security testing, such as penetration testing and red teaming, was the single largest cost-reducing factor for Indian organizations, saving an average of ₹2.47 crore per breach.

In other words, the controls DPDP asks for are the same controls that reduce real-world losses. Compliance and security are not two budgets; they are one investment.

04. Two clocks start the moment you detect a breach

Incident response in India now runs on two timers:

  • CERT-In: reportable cyber incidents must be reported within 6 hours.
  • DPDP Rule 7: affected individuals and the Data Protection Board must be informed without delay, with a detailed report to the Board within 72 hours covering what happened, its extent and impact, and the steps taken.

You cannot meet either deadline if you only discover the breach weeks later, or if nobody knows who makes the call. That is why detection (logging and monitoring) and a rehearsed response plan are compliance requirements, not nice-to-haves.

05. Your 45-day plan to get ahead of 13 November

You do not need to finish everything in six weeks. You do need to know where you stand and have the high-risk gaps moving. Here is a practical sequence:

Weeks 1–2: Find your personal data

  • Map where personal data is collected, stored, and shared—applications, databases, file servers, cloud, email, backups, and third parties.
  • Identify the most sensitive sets: customer identity data, financial data, employee records, and any data about children.

Weeks 2–4: Test the key—your security safeguards

  • Run a gap assessment against Rule 6: encryption at rest and in transit, access controls and privileged accounts, logging coverage, and backup integrity.
  • Commission vulnerability assessment and penetration testing (VAPT) on systems that hold personal data.
  • Confirm logs are centrally collected and retained for at least one year.

Weeks 3–5: Fit the lock—notice and consent

  • Review privacy notices and consent flows for clear, specific, itemized purposes.
  • Make sure consent withdrawal actually stops processing across your systems—including when it arrives through a Consent Manager.

Weeks 5–6: Prepare for the bad day

  • Write a dual-track incident response plan covering CERT-In’s 6-hour and DPDP’s 72-hour obligations, with named owners.
  • Run a tabletop exercise with IT, legal, and leadership.
  • Update vendor and processor contracts with security and breach-notification clauses.

06. Common myths we hear

“We’re too small for DPDP.”

The Act applies to any organization processing digital personal data in India. Size affects which extra obligations apply, not whether the law applies.

“We have ISO 27001, so we’re covered.”

ISO 27001 overlaps heavily with Rule 6 and is an excellent foundation, but it does not cover DPDP-specific duties such as notices, consent withdrawal, data-principal rights, and 72-hour reporting to the Board.

“Our cloud provider handles security.”

Your provider secures its infrastructure. You remain the Data Fiduciary, accountable for how your data is configured, accessed, and protected.

07. Frequently asked questions

What happens on 13 November 2026?

The Consent Manager registration framework under Rule 4 becomes operational. Registered consent managers can then help individuals manage their consent across multiple services.

When do DPDP penalties apply?

Under the notified rules, the substantive obligations and penalty provisions come into force on 13 May 2027. A proposal to shorten this to November 2026 has been discussed but was not final at the time of writing.

What is the maximum penalty under the DPDP Act?

Up to ₹250 crore for failing to take reasonable security safeguards. Other heads include up to ₹200 crore for failing to report a breach and up to ₹200 crore for breaching children’s data obligations.

How quickly must a data breach be reported?

Without delay to affected individuals and the Data Protection Board, with a detailed report to the Board within 72 hours. CERT-In separately requires reportable incidents within 6 hours.

08. Turn the key before the lock is tested

The organizations that will handle DPDP calmly are the ones that start now—with a clear view of their data, tested security controls, and a plan that people have actually rehearsed. Consent notices can be rewritten in a week. Encryption, access control, logging, and a working incident response process take longer.

Aspect Tech Knowledge IES helps organizations understand their gaps and build the security foundation DPDP expects. Speak to our team about a DPDP security gap assessment.

Talk to us at connect@aspect-tech-knowledge-ies.com .
Deeper Understanding. Better Solutions.