Skip to main content
DPDP Regulatory Updates and Notifications Tracker 2026 — page loaded
Regulatory tracker

DPDP Regulatory Tracker: Notifications, Rules and Enforcement Signals

A running log with the practitioner implication spelled out.

Phase clock

The DPDP timeline so far — and what's next.

11 Aug 2023Passed

DPDP Act, 2023 receives Presidential assent

Parliament passes the DPDP Bill, 2023; the President gives assent. The Act exists on the books but has no operational force without Rules.

13 Nov 2025Notified

DPDP Rules, 2025 notified by MeitY

MeitY notifies the DPDP Rules, 2025 via G.S.R. 846(E). Twenty-two Rules cover notice content, consent-manager registration, security safeguards, breach intimation, children's consent, retention defaults, SDF obligations and Board procedures. Seven Schedules attach.

13 Nov 2025Phase 1

Phase 1 — procedural provisions commence

A limited set of procedural provisions take immediate effect: DPBI constitution and procedures, appellate rules to TDSAT, certain definitions, rule-making power, and the carriage of breach intimation. Substantive duties remain deferred.

~Nov 2026Phase 2

Phase 2 — Consent Manager framework expected

Rule 4 (Consent Manager registration) and the First Schedule are expected to commence ~12 months from notification, enabling registered intermediaries to manage consent across Fiduciaries.

13 May 2027Phase 3

Phase 3 — substantive obligations crystallise

Notice & consent (S.5–6), legitimate uses (S.7), Fiduciary duties (S.8), children (S.9), SDF obligations (S.10), Data Principal rights (S.11–14) and the full Schedule of Penalties come into force. Real enforcement begins.

Latest signals

Recent developments and what they mean for you.

Rule notificationNOV 2025

DPDP Rules, 2025 — phased commencement confirmed

G.S.R. 846(E) brings 22 Rules into existence but defers commencement to a phased schedule. Procedural provisions take immediate effect; Consent Manager and substantive obligations follow over the next 9 months.

So what?

Plan for substantive duties to be live by 13 May 2027. RoPA, DSAR portal, vendor remediation and security uplift are 9–12 month efforts — start them in Q1 FY26 at the latest.

Penalty signalNOV 2025

Schedule of Penalties — civil-only, ₹250 Cr ceiling per breach

Civil-only enforcement with ceilings of ₹250 Cr (security), ₹200 Cr (breach-notification + children), ₹150 Cr (SDF) and ₹50 Cr (catch-all). Per-instance — multiple events compound. No criminal liability under the Act.

So what?

Board-level risk reporting needs revised exposure modelling. Aggregate exposure can multiply rapidly — quantify it in the next risk-committee meeting.

OperationalNOV 2025

Breach intimation — to Board "without delay" + affected Principals

Rule 7 codifies a two-track breach intimation: to the DPBI "without delay" with prescribed contents, and to affected Data Principals as soon as feasible. Form, contents and channels are prescribed.

So what?

"Without delay" is an unusually tight standard — likely hours, not days. Stand up a 72-hour breach runbook with clear severity gates before Phase 3.

Rule notificationNOV 2025

Children — verifiable parental consent stack required

Rule 10 requires identity-verified parental consent before processing children's data, and verification that the parent is in fact the parent or guardian. Self-declared age gates do not suffice. Behavioural monitoring and targeted ads to children are barred.

So what?

If you have under-18 users at any scale, the engineering to build a real verification stack (DigiLocker, Aadhaar offline, hybrid) is significant. See the Verifiable Parental Consent Flow template.

OperationalNOV 2025

Retention defaults — Third Schedule for high-volume entities

Rule 8 with the Third Schedule sets retention defaults for e-commerce (>2 cr users), online gaming (>50 L users) and social media (>2 cr users): three years from last activity, with 48-hour pre-erasure intimation.

So what?

Cross any threshold and retention is a substantive duty — not policy. Pre-erasure notification infrastructure (email/SMS/in-app) is a real engineering deliverable.

Pipeline · 2026EXPECTED

SDF classifications — most consequential pending notification

Section 10 obliges notified classes to run DPIAs, periodic audits, appoint India-resident DPOs reporting to the Board, and undertake additional measures. The first notifications are expected in 2026 and will materially expand scope for those caught.

So what?

Run an internal SDF-likelihood assessment now. If volume + sensitivity + sector exposure puts you near the line, start sizing the DPIA and audit programme before notification lands.

Watchlist

Six things on our watchlist.

W-01Expected 2026

First SDF list

The Government's first list of classes designated as Significant Data Fiduciaries. Likely: large fintech, e-commerce, social-media and gaming, and entities processing large volumes of children's/sensitive data.

W-02Unscheduled

First cross-border restriction

A Section 16 notification restricting transfer to specified countries would convert the default-permitted regime into a conditional one for some data classes.

W-03Imminent

DPBI Chairperson appointment

Designation of the Chairperson and Members under Rule 16 — a prerequisite for any enforcement action by the Board.

W-04Post Phase 3

First adjudication order

The DPBI's first published order will set the tone for penalty quantum, procedure and enforcement priorities.

W-05Ongoing

Sectoral overlay clarifications

How DPDP reconciles with RBI, IRDAI, SEBI and ABDM sectoral rules — especially on retention and localisation.

W-06~Nov 2026

Consent Manager registry goes live

Registration of the first Consent Managers under Rule 4 and the First Schedule, and the technical standards they must meet.

Authoritative sources

Where we watch.

MeitY

Primary publisher of DPDP rules, schedules and notifications.

meity.gov.in

The Gazette of India

Official Gazette where every formal notification is published, including G.S.R. 846(E).

egazette.nic.in

India Code

Authoritative repository of central Acts, including the DPDP Act, 2023 (Act No. 22 of 2023).

indiacode.nic.in

TDSAT

Appellate forum for DPBI orders under Section 29. Watch for bench designation and first appeals.

tdsat.gov.in

PRS Legislative Research

Independent analysis of Indian legislation, debates and commentary on the Act.

prsindia.org

CERT-In

Separate cyber-incident reporting regime under the IT Act 2000. DPDP breach intimation runs in parallel.

cert-in.org.in

Get The DPDP Update — fortnightly, no marketing.

A short note every other Friday: Gazette notifications, DPBI orders once they land, sectoral guidance, and the implementation implication. No upsell — just the regulatory signal.