Tool 13

Which DPDP obligations bind you today, and which do not yet

Check any DPDP obligation against Rule 1 of the Digital Personal Data Protection Rules, 2025 — whether it is in force today, the date it starts, and the sub-clause that commences it.

In short
The DPDP Rules, 2025 commence in three tranches under Rule 1. Rules 1, 2 and 17 to 21 took effect on publication, 13 November 2025. Rule 4, Consent Manager registration, follows on 13 November 2026. Everything a Data Fiduciary must do — notice, security safeguards, breach intimation, retention, Data Principal rights and transfers abroad — commences on 13 May 2027.

Check an obligation

Pick the duty you are asking about. The answer names the rule that imposes it, the sub-clause of Rule 1 that commences it, and the date — because the Rules set commencement as an interval from publication rather than as three printed dates, which is most of the reason the dates get reported wrongly.

It opens on breach notification, which is the obligation most often described as current and is not.

The obligation you are asking about

Every obligation is resolved to the rule that imposes it, and every rule to the sub-clause of Rule 1 that commences it. Dates are computed from publication on 13 November 2025.

Not yet13 May 2027

Notifying a personal data breach is imposed by rule 7, Intimation of personal data breach. Rule 1(4) commences it “eighteen months after the date of publication of this Gazette”, which is 13 May 2027, so it does not bind today and nothing under it is yet enforceable.

Rule 7 requires a Data Fiduciary to intimate every affected Data Principal without delay, with no threshold for size or severity, and to give the Data Protection Board an initial description without delay followed by a full report within seventy-two hours of becoming aware. The seventy-two hours is a second, later clock rather than the whole obligation.

This is the one the web gets wrong. Pages published in 2026 present the seventy-two-hour report to the Data Protection Board as a current obligation. It is not: rule 7 sits in the tranche commenced by Rule 1(4), eighteen months after publication. What does bind today is the CERT-In six-hour report, which is a different duty to a different body under a different statute — and from 13 May 2027 both will run on the same incident, neither discharging the other.

Commencement under Rule 1 of the DPDP Rules, 2025
Sub-clauseFromRulesWhat it covers
Rule 1(2)13 November 20251, 2 and 17 to 21the definitions, and the machinery of the Data Protection Board — its appointment, its terms of service, and its functioning as a digital office
Rule 1(3)13 November 20264the registration and obligations of Consent Managers, and nothing else
Rule 1(4)Yours13 May 20273, 5 to 16, 22 and 23everything a Data Fiduciary has to do — notice, security safeguards, breach intimation, retention limits, Data Principal rights, Significant Data Fiduciary obligations and transfers outside India

Indicative, and not legal advice. Rule 1 of the Digital Personal Data Protection Rules, 2025, notified as G.S.R. 846(E) on 13 November 2025. Whether a given obligation reaches your organisation is a determination for your legal team.

Take this away as a print-ready commencement schedule

Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.

Three tranches, not one date

The Digital Personal Data Protection Rules, 2025 were notified as G.S.R. 846(E) on 13 November 2025. Rule 1 then commences them in three groups, and the grouping is not by subject — the whole of the middle tranche is a single rule.

Sub-clauseIntervalFromRules
Rule 1(2)on the date of their publication in the Official Gazette13 November 20251, 2 and 17 to 21
Rule 1(3)one year after the date of publication of this Gazette13 November 20264
Rule 1(4)eighteen months after the date of publication of this Gazette13 May 20273, 5 to 16, 22 and 23
Commencement under Rule 1 of the DPDP Rules, 2025, with each sub-clause's own wording for the interval it sets.

The seventy-two hours that are not running

Rule 7 requires a Data Fiduciary to intimate affected Data Principals without delay and to give the Data Protection Board a full report within seventy-two hours of becoming aware of a personal data breach. It is the most quoted obligation in the Rules and it is routinely presented as current, including by pages published in 2026 with 2026 in the title.

Rule 1(4) places rule 7 in the eighteen-month tranche. There is no DPDP breach-reporting duty today, of seventy-two hours or of any other length.

The error is worth understanding rather than merely correcting, because it is not random. There is a breach-reporting duty in force in India, it is six hours rather than seventy-two, and it is easy to read the two as one rule inconsistently reported. They are different in every particular that matters: CERT-In’s six-hour report runs under section 70B of the IT Act 2000 to CERT-In rather than to the Data Protection Board, it starts on noticing an incident rather than on becoming aware of a breach, it covers twenty categories of incident rather than personal data alone, and it has bound every organisation in India since June 2022.

From 13 May 2027 both run on the same incident, and neither discharges the other. Until then, an incident plan built on DPDP is late on the clock that is actually running. The CERT-In Directions are the ones to plan against today, and the incident reporting clock resolves them into wall-clock deadlines alongside the sectoral regulators.

What binds while you wait

7 rules are in force today, and every one of them concerns the Data Protection Board rather than the organisations it will regulate:

  • Rule 1Short title and commencement
  • Rule 2Definitions
  • Rule 17Appointment of Chairperson and other Members
  • Rule 18Salary, allowances and other terms and conditions of service of Chairperson and other Members
  • Rule 19Procedure for meetings of Board and authentication of its orders, directions and instruments
  • Rule 20Functioning of Board as digital office
  • Rule 21Terms and conditions of appointment and service of officers and employees of Board

The regulator existing is not the same as the duties existing, and the gap between them is the planning window rather than a reprieve. Rule 6 alone asks for encryption or tokenisation, access control, monitoring able to detect unauthorised access, backups, a year of retained logs, contractual terms binding every processor, and evidence that all of it is observed rather than adopted. That is a programme, and eighteen months is the build time for it.

Two obligations are already live and unaffected by any date here: CERT-In’s six-hour incident report, and whatever your sector regulator requires. What Rule 6 asks you to build sets out the seven safeguards in full, and which regulation applies covers the sectoral half.

Rule 1 of the Digital Personal Data Protection Rules, 2025, read from MeitY’s own gazette PDF ofG.S.R. 846(E). Indicative, and not legal advice: whether an obligation reaches your organisation is a determination for your legal team.

Every instrument cited here was verified against the issuing regulator's own notification on .

Worked examples

The same calculator, run for a specific entity — with the thresholds and clocks that apply to it, and the instrument each one comes from.

Questions this page answers

Does the DPDP 72-hour breach notification rule apply now?
No. Rule 7 of the Digital Personal Data Protection Rules, 2025 requires a full report to the Data Protection Board within seventy-two hours of becoming aware of a personal data breach, but Rule 1(4) commences rule 7 eighteen months after publication — 13 May 2027. Until then there is no DPDP breach-reporting duty of any length. The six-hour report to CERT-In is a separate obligation under section 70B of the IT Act 2000 and has been in force since June 2022.
Is the DPDP Act in force in India?
Partly. The Digital Personal Data Protection Act, 2023 and the Rules of 2025 are both notified, but commencement is phased. As at today the provisions in force are the definitions and the machinery of the Data Protection Board — its appointment, terms of service and functioning as a digital office. No obligation on a Data Fiduciary is in force until 13 May 2027, other than Consent Manager registration, which starts on 13 November 2026.
When do DPDP penalties start?
A penalty attaches to breaching an obligation, so it can only follow that obligation into force. The Data Protection Board provisions commenced on 13 November 2025, Consent Manager registration on 13 November 2026, and every Data Fiduciary duty on 13 May 2027. Claims that the penalty framework "applies from day one" describe a Board that exists but has no Data Fiduciary duty to adjudicate until the third tranche commences.
When must we register as a Consent Manager?
Rule 4 commences on 13 November 2026, one year after publication, and it is the only rule in that tranche. An organisation that is not offering Consent Manager services has no obligation on that date at all — the next date that reaches an ordinary Data Fiduciary is 13 May 2027.
Were the DPDP Rules notified on 13 or 14 November 2025?
The 13th. G.S.R. 846(E) is dated 13 November 2025; the 14th appears only in the e-gazette upload stamp CG-DL-E-14112025-267650 printed on the cover page. The distinction is load-bearing because Rule 1 sets commencement as an interval from publication rather than as fixed dates, so taking the 14th moves every downstream date by a day and makes "notified 14 November" and "in force 13 May 2027" mutually inconsistent.
What DPDP obligations are in force today?
Seven rules: rules 1 and 2, which are the short title and the definitions, and rules 17 to 21, which appoint the Chairperson and Members of the Data Protection Board, set their terms of service, govern the Board’s meetings and let it function as a digital office. All seven concern the regulator rather than the regulated. No safeguard, notice, retention or breach duty is among them.

This tool is one skill out of sixteen.

What runs on this page is the browser-sized version of incident-notify, a skill in BitScoreCoWork — our MIT-licensed Claude plugin. The full version runs against your own Bitsight tenancy and works from your measured attack surface rather than a form. The source is public, so you can read exactly what it does before you run it.

Read the source The Applied AI practice

Knowing the rule is the easy half.

This page tells you what you owe. It cannot tell you what an attacker already sees. Your organisation has a security rating calculated from signals visible from outside — request the complimentary Cyber Risk Rating Report and find out what it says. No agent, no system access, no questionnaire.

Request my rating All free tools