The Rules don’t take effect all at once. They roll out in stages — which sounds like breathing room, but works differently in practice than it first appears.
THE ROLLOUT, IN THREE STAGES
IMMEDIATE
Nov 2025
Provisions setting up the Data Protection Board of India take effect straight away.
+12 MONTHS
Nov 2026
Rules governing Consent Manager registration and operation come into force.
+18 MONTHS
May 2027
Most Data Fiduciary obligations — verifiable parental consent, breach notification, security safeguards — become fully enforceable.
Eighteen months sounds generous until you map out what actually has to happen inside it: mapping every place personal data lives, rewriting notices and consent flows, renegotiating vendor contracts, and building a breach-response process that’s never been tested. Organisations that treat the phased timeline as permission to wait are the ones most likely to still be scrambling when it closes.
Common misconception — That because enforcement is phased, there’s no urgency yet. Building the actual systems — data maps, consent flows, vendor contracts — takes most of that runway on its own.
Phased enforcement isn’t a delay. It’s a countdown.
SOURCES India’s DPDP Regime Takes Effect — S&R Associates — https://www.snrlaw.in/indias-digital-personal-data-protection-regime-takes-effect/ · The DPDP Rules, 2025 — official text, MeitY — https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf