DPDP Act 2023 and Rules 2025: what is in force in 2026?
By Abhijeet Singh · Primary sources verified by dpdprules.orgPublished · Last reviewed 8 min read
What is in force under the DPDP framework in 2026?
The short answer
The DPDP Act 2023 was enacted on 11 August 2023 and its commencement was notified as G.S.R. 843(E) on 13 November 2025: the definitions, the sections establishing and constituting the Data Protection Board (sections 18 to 26) and certain other sections, including the rule making power, operate now, while the main obligations, the rights and the Board's inquiry and penalty powers follow 18 months after publication. The DPDP Rules 2025 were notified the same day, and Rules 1, 2 and 17 to 21 took effect at once. The main operational obligations in Rules 3, 5 to 16, 22 and 23 and the core Act sections follow 18 months after publication, which computes to 13 May 2027, and Rule 4 on Consent Manager registration and obligations, and sections 6(9) and 27(1)(d) of the Act, follow 1 year after publication, which computes to 13 November 2026. The computed dates are interpretation until officially confirmed.

India has a data protection law, but not all of it operates yet. Here is the position as of 5 September 2026, with every date traced to its official source.
The Act exists and the Rules are notified
The Digital Personal Data Protection Act, 2023 became Act No. 22 of 2023 on 11 August 2023. The Digital Personal Data Protection Rules, 2025 were notified as G.S.R. 846(E) on 13 November 2025 in Gazette of India Extraordinary issue No. 760, and a corrigenda notification, G.S.R. 892(E), corrected 8 points of the text in December 2025. A constitutional challenge is pending in the Supreme Court, but the court refused a stay, so nothing on this page changes because of it.
What operates today
Rule 1 of the Rules sets 3 commencement groups.
"Rules 1, 2 and 17 to 21 shall come into force on the date of their publication in the Official Gazette."
That means the short title, the definitions and the provisions about the Data Protection Board have operated since 13 November 2025. On the same day, the Government established the Data Protection Board of India under notification G.S.R. 844(E), with its head office in the National Capital Region, and fixed it at 4 members under G.S.R. 845(E).
Which provisions are in force today, one by one
These are the provisions themselves, with the heading each one carries in the Gazette, so you can read any of them rather than take the summary on trust. Paragraph (a) of notification G.S.R. 843(E) puts these 19 entries of the Act in force from the date of publication, counting section 44(1) and (3) as 1 entry. The heading is the marginal note printed against the section, which identifies it rather than forming part of what it enacts.
| Act provision | Heading in the Gazette |
|---|---|
| Section 1(2) | Short title and commencement |
| Section 2 | Definitions |
| Section 18 | Establishment of Board |
| Section 19 | Composition and qualifications for appointment of Chairperson and Members |
| Section 20 | Salary, allowances payable to and term of office |
| Section 21 | Disqualifications for appointment and continuation as Chairperson and Members of Board |
| Section 22 | Resignation by Members and filling of vacancy |
| Section 23 | Proceedings of Board |
| Section 24 | Officers and employees of Board |
| Section 25 | Members and officers to be public servants |
| Section 26 | Powers of Chairperson |
| Section 35 | Protection of action taken in good faith |
| Section 38 | Consistency with other laws |
| Section 39 | Bar of jurisdiction |
| Section 40 | Power to make rules |
| Section 41 | Laying of rules and certain notifications |
| Section 42 | Power to amend Schedule |
| Section 43 | Power to remove difficulties |
| Section 44(1) and (3) | Amendments to certain Acts |
Sections 18 to 26 are the Board's constitution, and section 40 is the power the DPDP Rules 2025 recite as the power they were made under, and it was brought into force on the day the Rules were notified. Sections 38 to 43 are the general machinery provisions, and nothing in this group places a duty on a business.
Rule 1(2) puts these 7 rules in force on the same terms.
| Rule | Heading in the Gazette |
|---|---|
| Rule 1 | Short title and commencement |
| Rule 2 | Definitions |
| Rule 17 | Appointment of Chairperson and other Members |
| Rule 18 | Salary, allowances and other terms and conditions of service of Chairperson and other Members |
| Rule 19 | Procedure for meetings of Board and authentication of its orders, directions and instruments |
| Rule 20 | Functioning of Board as digital office |
| Rule 21 | Terms and conditions of appointment and service of officers and employees of Board |
Two of the Rules Schedules travel with that group, and this is a reading rather than something Rule 1(2) states. Rule 1(2) names rules and no Schedule. Rule 18 provides that the Chairperson and every other Member shall have such other terms and conditions of service "as are specified in Fifth Schedule", and Rule 21(2) provides that the terms and conditions of service of the Board's officers and employees shall be "such as are specified in Sixth Schedule". Each Schedule points the other way, in a note rather than in its operative text: the Fifth is printed under the headnote "FIFTH SCHEDULE [See rule 18]" and the Sixth under "SIXTH SCHEDULE [See rule 21(2)]". A bracketed reference of that kind names the rule a Schedule serves, in the way a marginal note identifies a section, and it says nothing about when a Schedule commences. This site therefore presents the Fifth Schedule and the Sixth Schedule as commencing with the rules they serve, and labels that as interpretation on each of those pages.
What none of this includes is a Chairperson or a Member. The provisions constituting the Board operate and the appointment machinery in Rule 17 operates, but no appointment to either post has been located in the primary record as at 28 August 2026, with the 1 channel rechecked since, MeitY's published document library, re enumerated on 5 September 2026 and unchanged. That is a statement about what a search of official channels found rather than a certified negative, and the channels and their limits are set out in is the Data Protection Board operational.
What comes next
The other 2 groups follow with lead time. Rule 4, which covers Consent Manager registration, comes into force 1 year after publication. The main operational rules, Rules 3, 5 to 16, 22 and 23, come into force 18 months after publication. Those cover the notice requirements, security safeguards, breach intimation, retention and erasure, children's data and the machinery for exercising rights.
Computed from the publication date, that puts Rule 4 at 13 November 2026 and the main group at 13 May 2027. Treat both computed dates as interpretation until an official confirmation exists: the official text states the periods, not the calendar dates.
Reporting since January 2026 has said this runway is about to be cut from 18 months to 12. It has not been: as at the 1 September 2026 verification no amending instrument and no MeitY consultation document had been located, so the periods above are still the ones in force. What was actually proposed, who reported it and where the accounts contradict each other is set out in the January 2026 proposal to cut the window to 12 months.
The Act's own sections
Section 1(2) of the Act provides that it comes into force on such date as the Central Government notifies, and that different dates may be appointed for different provisions. That notification exists: G.S.R. 843(E), published in Gazette of India Extraordinary issue No. 757 with the printed date 13 November 2025, appoints 3 groups. Some widely read summaries date that notification to 14 November 2025 instead, and every later deadline shifts with it; which date the Gazette actually prints, and what the corrigenda did to the wording, is set out in 13 or 14 November: the DPDP date discrepancy.
From the date of publication, section 1(2), section 2 (the definitions), sections 18 to 26 (the Data Protection Board), sections 35 and 38 to 43, and section 44(1) and (3) operate. 1 year from publication, section 6(9) and section 27(1)(d), which concern Consent Managers, follow. 18 months from publication, the core of the framework arrives: sections 3 to 5, most of section 6, sections 7 to 17 (the grounds for processing, the obligations of Data Fiduciaries and the rights of Data Principals), the rest of section 27, sections 28 to 34, 36 and 37, and section 44(2).
Computed from the printed publication date, the 1 year group lands on 13 November 2026 and the 18 month group on 13 May 2027, matching the Rules dates above. Treat the computed calendar dates as interpretation until officially confirmed: the official text states the periods, not the dates.
Unchanged by the pending Supreme Court challenge
Parts of the framework are under constitutional challenge before the Supreme Court, including the RTI amendment in section 44(3), which has operated since 13 November 2025. Notice has been issued and no stay granted, so every date on this page continues to run as notified. Who is challenging what, hearing by hearing, is tracked in the Supreme Court challenge to the DPDP Act.
What to do
If you are working towards the May 2027 group, the practical reading is that you have a defined runway. Check whether the framework applies to you, then build one company plan against the obligations rather than reacting rule by rule. If you are the person running that plan, the compliance guide sets out which pieces of it usually sit with compliance.
Related tool
Applicability Checker
Find out whether the DPDP framework likely applies to your organisation and processing.
Open
Related tool
Compliance Plan
Generate 1 company level action plan and see the work for your role first.
Open
The verified DPDP timeline →The DPDP Rules 2025 explorer →Why sources disagree by 1 day on the DPDP deadlines →Act to Rules map: which rule sits under which section →