The DPDP Act Deadline Nobody's Actually Racing Toward

India's data protection law has a genuinely close deadline hiding behind a reassuringly distant-sounding enforcement date. Most businesses have filed it under "we'll deal with it next year." We think that's a mistake, and here's the actual math on why.

The Digital Personal Data Protection Act, 2023 has been law for a while, but its practical machinery is only now coming online. The government's phased rollout means full, hard enforcement — including the Act's genuinely significant penalties, running into hundreds of crores for serious violations — doesn't land until roughly May 2027. That distant date is exactly why so many businesses have treated the Act as a problem for a future fiscal year rather than this one.

The Date That Actually Matters Isn't the Enforcement Date

The piece getting overlooked is the Consent Manager framework — the registered intermediaries through whom individuals will be able to manage, review, and withdraw consent for how their personal data is used across different platforms. Registration for Consent Managers is expected to open around November 2026, a matter of months away as of this writing. Once that framework is live, businesses that haven't already built proper consent-capture mechanisms, data-processing records, and grievance-redressal infrastructure aren't looking at a distant 2027 problem — they're looking at a live compliance gap the moment the ecosystem around them starts operating on the assumption that this infrastructure exists.

A 2026 industry survey found that 71% of Indian enterprises still don't fully understand what the Act actually requires of them operationally — not a lack of awareness that the law exists, but a genuine gap in translating it into concrete internal processes: how consent is captured and recorded, how a data breach gets reported and to whom, how a "Data Principal" (the individual whose data it is) actually exercises a right to access or erasure, and who inside the organisation is accountable when something goes wrong.

Why the Phased Approach Is Being Misread

We think there's a specific misreading happening here, and it's worth naming directly: a phased, staggered enforcement timeline is being interpreted as "soft" enforcement, when it's actually the opposite. A single hard deadline forces everyone to scramble at once, and regulators historically go easier on genuine, visible good-faith efforts in that scramble. A phased rollout, by contrast, gives a regulator a clean, defensible basis to distinguish between organisations that used the runway to actually build compliant systems and organisations that didn't — and the latter group will have had considerably longer to explain why not.

What to Actually Do in the Next 60-90 Days

The practical priority list is shorter than most businesses assume. First, a genuine data-mapping exercise — knowing exactly what personal data you collect, where it's stored, who has access, and why, is the foundation everything else sits on, and it's the step most organisations skip in favour of jumping straight to a privacy policy update. Second, build (or fix) your actual consent-capture mechanism — a checkbox buried in terms and conditions is unlikely to satisfy the Act's requirement for clear, specific, informed consent. Third, appoint and actually empower a grievance-redressal contact — the Act requires one, and it needs to be a real, responsive function, not a name on a policy document. Fourth, have a data-breach response protocol ready before you need it — the Act's notification timelines are tight enough that improvising one during an actual breach is the worst possible time to start.

None of this requires the Consent Manager ecosystem to exist yet. All of it needs to exist before that ecosystem goes live — which is a matter of months, not years, from where we stand today.


Have a question about this update? Submit a query to our team.