India's DPDP Rules 2025: A Compliance Timeline for Technology Projects
The DPDP Rules were notified on 14 November 2025 with an eighteen-month phased window. The era of treating India's data law as 'an Act awaiting rules' is over — here is what technology buyers need to do before May 2027.

For years, India's Digital Personal Data Protection Act, 2023 was, in practice, a law without an operating manual — enacted, but not enforceable in the way GDPR or comparable regimes are, because the implementing rules hadn't been notified. That changed on 14 November 2025.
What actually happened
The DPDP Rules, 2025 were notified on 14 November 2025, introducing an eighteen-month phased compliance period — meaning the substantive Data Fiduciary obligations become fully operative around mid-May 2027. This activates the Act's own penalty structure: up to ₹250 crore for failure to maintain reasonable security safeguards, up to ₹200 crore each for breach-notification failures and children's-data violations, and up to ₹50 crore for other contraventions. (PIB / MeitY)
If your compliance planning still treats DPDP as "an Act awaiting rules," that planning is now roughly a year out of date.
What the Rules actually require
A Data Protection Board of India, fully digital, with appeals routed to the TDSAT. This gives the law a functioning enforcement body, which is what was missing before November 2025.
Consent Managers must be India-incorporated companies. If your technology stack routes consent management through an overseas entity, that arrangement needs review.
A ninety-day response window for data principals' access, correction and erasure requests. This is a hard operational deadline, not a best-effort target — your systems need to be able to locate, correct and delete personal data on request within that window.
Independent audits and impact assessments for Significant Data Fiduciaries — a designation likely to capture larger technology platforms and any organisation processing data at scale, though the specific criteria bear watching as guidance develops.
A separate, clear consent notice — bundled or implied consent inside a general terms-of-service document will not satisfy the standard.
What to do before May 2027
Map where personal data actually lives. You cannot respond to an access request within ninety days for data you cannot locate. This is the single most common gap in early compliance assessments, and it is purely an engineering and documentation problem, not a legal one.
Review every third-party data processor in your stack, particularly Consent Managers and any offshore processing arrangement, against the India-incorporation requirement.
Build the deletion and correction pathway now, not in month seventeen. Retrofitting data lifecycle controls into a system that wasn't designed for them is materially more expensive than building them in from the start — the same principle that applies to every other software cost decision covered elsewhere on this blog applies here too.
Read MeitY's India AI Governance Guidelines alongside the Rules if you're building or buying AI systems. Released 5 November 2025, they expect suppliers to maintain grievance redressal, publish transparency reports evaluating risk of harm in the Indian context, and demonstrate compliance on demand to regulators. (PIB backgrounder)
The honest risk assessment
Eighteen months sounds generous until you map it against how long data architecture changes actually take. A system that needs meaningful rework to support ninety-day data-subject requests is not a project you start in month sixteen.
Kaizen Spark Tech designs and delivers software, AI, automation and digital infrastructure for businesses and institutions. Every statistic here is linked to its original published source. This guide is reviewed quarterly as further DPDP guidance is published.
