Reference
Is the DPDP Act in force? Status, dates and deadlines
The short answer, then the full story of how India got its data protection law: every milestone below is verified against a primary official source before it publishes, newest first. Computed future dates are marked as such and treated as interpretation until officially confirmed.
The verdict
In force, but phased. Parts of the DPDP Act 2023 and the DPDP Rules 2025 have been in force since 13 November 2025 under notification G.S.R. 843(E) and Rule 1, and the Data Protection Board was established the same day under notification G.S.R. 844(E). Consent Manager registration is due on the computed date 13 November 2026, and the main obligations, including notice, consent, security safeguards, breach intimation and penalties, are due on the computed date 13 May 2027. Both computed dates are interpretation until officially confirmed.
Last verified on 6 September 2026
Status last checked 28 September 2026 against the MeitY library and India Code. Each milestone above keeps its own citation date; this is a separate, weekly check for a new filing in either collection, not a re reading of the Gazette.

What comes next
ImplementationUpcoming · computed date
The main obligations of the Act and the Rules due to come into force
Eighteen months after publication, the main operational provisions are due to start on both sides: Rules 3, 5 to 16, 22 and 23, and the core of the Act, meaning sections 3 to 5, most of section 6, and sections 7 to 17 (application, grounds, notice, consent, obligations of Data Fiduciaries, children's data and the rights of Data Principals), section 27 other than 27(1)(d), sections 28 to 34, 36 and 37, and section 44(2). Section 6(9) is not in this group; it commences a year earlier. The calendar date shown is computed from the publication dates and is presented as interpretation until officially confirmed.
Why it matters: This is the date most organisations are working towards, per Rule 1(4) and paragraph (c) of notification G.S.R. 843(E).
Status: upcoming; dates derived from Rule 1(4) and G.S.R. 843(E), interpretation until officially confirmed
ImplementationUpcoming · computed date
Rule 4 and the Consent Manager provisions of the Act due to come into force
One year after publication, the registration and obligations framework for Consent Managers is due to start operating: Rule 4 on the Rules side, and section 6(9) and section 27(1)(d) of the Act. The calendar date shown is computed from the publication dates and is presented as interpretation until officially confirmed.
Why it matters: Consent Managers can only be registered once Rule 4 operates, per Rule 1(3). The matching Act provisions commence 1 year from the publication of notification G.S.R. 843(E).
Status: upcoming; dates derived from Rule 1(3) and G.S.R. 843(E), interpretation until officially confirmed
The Rules
Notification
MeitY invites applications for the Data Protection Board's Chairperson and 4 Members
By a circular of 6 May 2026 (F. No. 2(1)/2026-Pers.I), MeitY invited applications for the post of Chairperson (1 post) and Member (4 posts) of the Data Protection Board of India, to prepare a panel for the Search cum Selection Committees constituted under Rule 17 of the DPDP Rules 2025. The Board was established as a body corporate on 13 November 2025, but no appointment of a Chairperson or Member had been located when this event was last verified, a state of affairs legal commentary of August 2026 also records.
Why it matters: The circular starts the Rule 17 appointment machinery moving but makes no appointment: under Rule 17(3) the Central Government appoints after considering the committee's recommendations, and any appointment should surface as an official notification or announcement. Until then the Board has no Members, no quorum under Rule 19(3) and nobody to exercise the Chairperson's powers under section 26, while the first Board dependent deadline, Consent Manager registration under Rule 4, arrives on the computed date of 13 November 2026, which is interpretation until officially confirmed.
Status: selection process ongoing; no appointment notification located as of 28 August 2026
Judgment
Supreme Court issues notice on the constitutional challenge and refuses a stay
A batch of writ petitions led by Venkatesh Nayak v Union of India, W.P.(C) No. 177/2026, challenges parts of the DPDP Act and Rules, centred on section 44(3), which rewrote the RTI Act's privacy exemption, and section 36 read with Rule 23. The court issued notice and refused an interim stay, so the framework operates exactly as notified while the case proceeds. At the latest reported hearing on 7 August 2026, the Union was given 2 weeks to file its reply.
Why it matters: The challenge does not change any obligation or date unless and until a court order says otherwise. No stay or interim direction touching the operation of the Act or the Rules was located as of the 23 August 2026 verification; the stay and interim relief applications were still shown as pending on the 23 March 2026 cause list, with no order on them reported since.
Status: pending before the Supreme Court; notice issued, stay refused, Union reply awaited
Reported, not notified
A proposal to cut the 18 month window to 12 is reported, and never notified
Business Standard reports that MeitY proposed at a stakeholder meeting to shorten the compliance window for Significant Data Fiduciaries from 18 months to 12, to bring the cross border transfer provisions and the power to call for information into force immediately, and to apply the minimum retention requirement in Rule 8(3) within 90 days of an amendment. That report attributes every operative statement to unnamed sources and records that MeitY did not respond to it. Moneycontrol and cadp.in trace back to it on their face; the S.S. Rana commentary of 13 February 2026 footnotes press reports only, including a Financial Express report this site has not obtained. The meeting date is given as 22 January 2026 by one account and 23 January 2026 by another.
Why it matters: None on the framework. No amending instrument has been located, so Rule 1, as corrected by corrigenda G.S.R. 892(E), and G.S.R. 843(E) still run on the periods they set. Enumerating MeitY's whole document library on 1 September 2026 returned no consultation note, office memorandum or draft amendment answering to the proposal, and no record of the meeting, and diffing that enumeration again on 4 September 2026 and on 6 September 2026 reported 28 archived, 28 live, 0 added and 0 removed on both runs.
Status: reported only; no amending instrument located as at 6 September 2026
Draft
MeitY publishes its summary of submissions on the draft DPDP Rules
MeitY publishes a 12 page summary of the feedback it received on the draft DPDP Rules of 3 January 2025. It records that the comment window ran to 18 February 2025 and was extended to 5 March 2025, that 6,951 comments and submissions were processed through the MyGov portal, and that physical consultations ran from Delhi on 14 January 2025 to Guwahati on 4 March 2025. The rest of the document lists the feedback rule by rule. Its rule numbers follow the DRAFT Rules, which run 1 behind the notified numbering from rule 11 onward.
Why it matters: A record of a consultation, not an instrument: it proposes nothing and requires nothing. On an enumeration of MeitY's whole document library on 1 September 2026 it was the most recent document there about the Rules themselves, the only 2 later substantive documents being the Data Protection Board appointment papers of 6 May 2026, and its Rule 1 entry records stakeholders asking for a defined implementation period, phased rollouts and additional time for Significant Data Fiduciaries once designated.
Status: published record; no legal effect
Correction
Corrigenda to the DPDP Rules 2025 issued
Eight textual corrections to the Rules are notified as G.S.R. 892(E), published in Gazette issue No. 806 of 11 December 2025. Two of them fix the wording of the commencement rule itself.
Why it matters: The corrected wording is the operative text. Anyone quoting the Rules must apply these corrections.
Status: in effect
Implementation
Rules 1, 2 and 17 to 21 come into force
On the day of publication, the definitions and the provisions relating to the Data Protection Board start to operate. The obligations with operational lead time follow later.
Why it matters: The first slice of the Rules to take legal effect, per Rule 1(2).
Status: in force
Rule
The DPDP Rules 2025 are notified
The final Digital Personal Data Protection Rules 2025 are notified as G.S.R. 846(E) in Gazette of India Extraordinary issue No. 760, after considering the public comments on the draft.
Why it matters: The Rules operationalise the Act: notices, consent managers, security safeguards, breach intimation, retention and erasure, children's data, and the Data Protection Board's functioning.
Status: published; text subject to corrigenda G.S.R. 892(E)
Implementation
First provisions of the Act come into force
Sections 1(2) and 2, sections 18 to 26, sections 35 and 38 to 43, and section 44(1) and (3) of the Act take effect on the date of publication of the commencement notification. These cover the definitions, the Data Protection Board and its machinery, rule making powers, and amendments to 2 other laws.
Why it matters: The Act moves from enacted to partially operating. The obligations of Data Fiduciaries and the rights of Data Principals follow in the later phases.
Status: in force
Notification
Data Protection Board of India established
Notification G.S.R. 844(E) establishes the Data Protection Board of India under section 18, with its head office in the National Capital Region of India. A companion notification, G.S.R. 845(E), fixes the Board at 4 members under section 19(1).
Why it matters: The Board is the body that will receive breach intimations, hear complaints and impose penalties once the corresponding provisions operate.
Status: in effect
Notification
Act commencement notified in 3 phases
Notification G.S.R. 843(E) appoints commencement dates for the Act in 3 groups: the definitions, the Data Protection Board provisions and related machinery from the date of publication; the Consent Manager registration provisions 1 year later; and the main obligations and rights 18 months later.
Why it matters: This is the notification under section 1(2) that actually brings the Act into force. Until commencement was notified, the Act's provisions did not operate.
Status: in effect; the later phases are due 1 year and 18 months from publication
Draft
Draft DPDP Rules published for public consultation
The Government publishes draft rules under section 40 of the Act as G.S.R. 02(E) and invites objections and suggestions from the public through the MyGov platform, for consideration after 18 February 2025.
Why it matters: The consultation round required before the final Rules could be made. The final Rules record that these comments were considered.
Status: superseded by the final Rules
The Act
Act
The Digital Personal Data Protection Act 2023 is enacted
India's law for digital personal data becomes Act No. 22 of 2023. It recognises both the right of individuals to protect their personal data and the need to process personal data for lawful purposes.
Why it matters: The Act is the parent framework: it defines Data Fiduciaries, Data Principals and their rights and duties, and it empowers the Central Government to make rules operationalising it.
Status: enacted; provisions commence as notified
Bill
DPDP Bill 2023 introduced and passed by both Houses of Parliament
The Digital Personal Data Protection Bill 2023, Bill No. 113 of 2023, was introduced in the Lok Sabha on 3 August 2023, passed by the Lok Sabha on 7 August 2023 and passed by the Rajya Sabha on 9 August 2023.
Why it matters: Presidential assent followed on 11 August 2023, making it Act No. 22 of 2023, the next event in this timeline.
Status: passed; assented to on 11 August 2023
The road to the Act
Draft
Draft Digital Personal Data Protection Bill 2022 released for public consultation
MeitY released the draft Digital Personal Data Protection Bill 2022 for public consultation, inviting chapter wise feedback through the MyGov platform, first by 17 December 2022 and then, after MeitY extended the window, by 2 January 2023. The draft introduced the structure the Act now follows, including Data Fiduciary obligations and a Data Protection Board.
Why it matters: This consultation draft is the immediate ancestor of the DPDP Act 2023, which kept its digital only scope and its Board centred enforcement design.
Status: consultation closed; enacted with changes as the DPDP Act 2023
Bill
Personal Data Protection Bill 2019 withdrawn in Lok Sabha
The Minister of Electronics and Information Technology moved for leave to withdraw the Personal Data Protection Bill 2019 as reported by the Joint Committee, and the bill was withdrawn. A statement of reasons was circulated to members the same day.
Why it matters: Withdrawal ended the 2018 to 2021 line of bills and cleared the way for the slimmer Digital Personal Data Protection Bill released for consultation 3 months later.
Status: withdrawn
Committee
Joint Committee reports on the Personal Data Protection Bill 2019
The Joint Committee of both Houses presented its report on the Personal Data Protection Bill 2019 to the Lok Sabha and laid it in the Rajya Sabha, annexing a recast bill titled the Data Protection Bill 2021 that widened the coverage beyond personal data.
Why it matters: The scale of the committee's revisions led the government to withdraw the 2019 bill rather than proceed with it, restarting the framework from a shorter draft.
Status: presented; the underlying bill was withdrawn in 2022
Bill
Personal Data Protection Bill 2019 introduced in Lok Sabha
The government introduced the Personal Data Protection Bill 2019, Bill No. 373 of 2019, in the Lok Sabha. The bill proposed a Data Protection Authority and a full personal data protection regime, and was referred to a Joint Committee of both Houses for examination.
Why it matters: This was the first government bill for a general data protection framework to reach Parliament. Its long committee stage and eventual withdrawal shaped the slimmer, digital only structure the DPDP Act adopted.
Status: withdrawn on 3 August 2022
Committee
Srikrishna Committee submits its report with the draft Personal Data Protection Bill 2018
The Committee of Experts submitted its report, A Free and Fair Digital Economy: Protecting Privacy, Empowering Indians, together with a draft Personal Data Protection Bill 2018. The report recommended a fiduciary based framework built on consent, purpose limitation and a Data Protection Authority.
Why it matters: The report supplied the vocabulary the framework still uses, including Data Fiduciary and Data Principal, and its draft bill was the direct ancestor of the Personal Data Protection Bill 2019.
Status: submitted; superseded by later bills
Judgment
Supreme Court holds that privacy is a fundamental right in Puttaswamy
A 9 judge Constitution Bench of the Supreme Court in Justice K.S. Puttaswamy (Retd.) v Union of India, W.P.(C) No. 494 of 2012, unanimously held that the right to privacy is a fundamental right protected under Article 21 and Part III of the Constitution.
Why it matters: The judgment is the constitutional foundation of Indian data protection law. It is the reason a statutory framework for personal data exists, and it supplies the standard against which the DPDP framework is tested in the Supreme Court challenge pending in 2026.
Status: delivered; binding constitutional law
Committee
MeitY constitutes the Justice B.N. Srikrishna expert committee on data protection
The Ministry of Electronics and Information Technology constituted a 10 member Committee of Experts chaired by Justice B.N. Srikrishna, a retired judge of the Supreme Court, to study issues relating to data protection in India and to suggest a draft data protection bill.
Why it matters: The committee's work produced the first government drafted data protection bill and the analytical foundation that every later bill, including the DPDP Act, built on.
Status: completed; report and draft bill submitted on 27 July 2018
How this timeline is built. Every milestone above, from the 2017 expert committee and privacy judgment to the latest notification, cites the original official record: the Supreme Court's own judgment PDF and cause list, MeitY's office memoranda and consultation drafts, the parliamentary bill texts and debate records on Digital Sansad, and the Gazette notifications. Where a pending court matter is still awaiting the formal record, clearly marked news reports sit beside the official cause list; nothing else here rests on news reporting alone.