Which DPDP obligations bind you today, and which do not yet
Check any DPDP obligation against Rule 1 of the Digital Personal Data Protection Rules, 2025 — whether it is in force today, the date it starts, and the sub-clause that commences it.
Check an obligation
Pick the duty you are asking about. The answer names the rule that imposes it, the sub-clause of Rule 1 that commences it, and the date — because the Rules set commencement as an interval from publication rather than as three printed dates, which is most of the reason the dates get reported wrongly.
It opens on breach notification, which is the obligation most often described as current and is not.
Notifying a personal data breach is imposed by rule 7, Intimation of personal data breach. Rule 1(4) commences it “eighteen months after the date of publication of this Gazette”, which is 13 May 2027, so it does not bind today and nothing under it is yet enforceable.
Rule 7 requires a Data Fiduciary to intimate every affected Data Principal without delay, with no threshold for size or severity, and to give the Data Protection Board an initial description without delay followed by a full report within seventy-two hours of becoming aware. The seventy-two hours is a second, later clock rather than the whole obligation.
This is the one the web gets wrong. Pages published in 2026 present the seventy-two-hour report to the Data Protection Board as a current obligation. It is not: rule 7 sits in the tranche commenced by Rule 1(4), eighteen months after publication. What does bind today is the CERT-In six-hour report, which is a different duty to a different body under a different statute — and from 13 May 2027 both will run on the same incident, neither discharging the other.
| Sub-clause | From | Rules | What it covers |
|---|---|---|---|
| Rule 1(2) | 13 November 2025 | 1, 2 and 17 to 21 | the definitions, and the machinery of the Data Protection Board — its appointment, its terms of service, and its functioning as a digital office |
| Rule 1(3) | 13 November 2026 | 4 | the registration and obligations of Consent Managers, and nothing else |
| Rule 1(4)Yours | 13 May 2027 | 3, 5 to 16, 22 and 23 | everything a Data Fiduciary has to do — notice, security safeguards, breach intimation, retention limits, Data Principal rights, Significant Data Fiduciary obligations and transfers outside India |
Indicative, and not legal advice. Rule 1 of the Digital Personal Data Protection Rules, 2025, notified as G.S.R. 846(E) on 13 November 2025. Whether a given obligation reaches your organisation is a determination for your legal team.
Take this away as a print-ready commencement schedule
Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.
Three tranches, not one date
The Digital Personal Data Protection Rules, 2025 were notified as G.S.R. 846(E) on 13 November 2025. Rule 1 then commences them in three groups, and the grouping is not by subject — the whole of the middle tranche is a single rule.
| Sub-clause | Interval | From | Rules |
|---|---|---|---|
| Rule 1(2) | on the date of their publication in the Official Gazette | 13 November 2025 | 1, 2 and 17 to 21 |
| Rule 1(3) | one year after the date of publication of this Gazette | 13 November 2026 | 4 |
| Rule 1(4) | eighteen months after the date of publication of this Gazette | 13 May 2027 | 3, 5 to 16, 22 and 23 |
The seventy-two hours that are not running
Rule 7 requires a Data Fiduciary to intimate affected Data Principals without delay and to give the Data Protection Board a full report within seventy-two hours of becoming aware of a personal data breach. It is the most quoted obligation in the Rules and it is routinely presented as current, including by pages published in 2026 with 2026 in the title.
Rule 1(4) places rule 7 in the eighteen-month tranche. There is no DPDP breach-reporting duty today, of seventy-two hours or of any other length.
The error is worth understanding rather than merely correcting, because it is not random. There is a breach-reporting duty in force in India, it is six hours rather than seventy-two, and it is easy to read the two as one rule inconsistently reported. They are different in every particular that matters: CERT-In’s six-hour report runs under section 70B of the IT Act 2000 to CERT-In rather than to the Data Protection Board, it starts on noticing an incident rather than on becoming aware of a breach, it covers twenty categories of incident rather than personal data alone, and it has bound every organisation in India since June 2022.
From 13 May 2027 both run on the same incident, and neither discharges the other. Until then, an incident plan built on DPDP is late on the clock that is actually running. The CERT-In Directions are the ones to plan against today, and the incident reporting clock resolves them into wall-clock deadlines alongside the sectoral regulators.
What binds while you wait
7 rules are in force today, and every one of them concerns the Data Protection Board rather than the organisations it will regulate:
- Rule 1 — Short title and commencement
- Rule 2 — Definitions
- Rule 17 — Appointment of Chairperson and other Members
- Rule 18 — Salary, allowances and other terms and conditions of service of Chairperson and other Members
- Rule 19 — Procedure for meetings of Board and authentication of its orders, directions and instruments
- Rule 20 — Functioning of Board as digital office
- Rule 21 — Terms and conditions of appointment and service of officers and employees of Board
The regulator existing is not the same as the duties existing, and the gap between them is the planning window rather than a reprieve. Rule 6 alone asks for encryption or tokenisation, access control, monitoring able to detect unauthorised access, backups, a year of retained logs, contractual terms binding every processor, and evidence that all of it is observed rather than adopted. That is a programme, and eighteen months is the build time for it.
Two obligations are already live and unaffected by any date here: CERT-In’s six-hour incident report, and whatever your sector regulator requires. What Rule 6 asks you to build sets out the seven safeguards in full, and which regulation applies covers the sectoral half.
Rule 1 of the Digital Personal Data Protection Rules, 2025, read from MeitY’s own gazette PDF ofG.S.R. 846(E). Indicative, and not legal advice: whether an obligation reaches your organisation is a determination for your legal team.
Every instrument cited here was verified against the issuing regulator's own notification on .Worked examples
The same calculator, run for a specific entity — with the thresholds and clocks that apply to it, and the instrument each one comes from.
Questions this page answers
- Does the DPDP 72-hour breach notification rule apply now?
- No. Rule 7 of the Digital Personal Data Protection Rules, 2025 requires a full report to the Data Protection Board within seventy-two hours of becoming aware of a personal data breach, but Rule 1(4) commences rule 7 eighteen months after publication — 13 May 2027. Until then there is no DPDP breach-reporting duty of any length. The six-hour report to CERT-In is a separate obligation under section 70B of the IT Act 2000 and has been in force since June 2022.
- Is the DPDP Act in force in India?
- Partly. The Digital Personal Data Protection Act, 2023 and the Rules of 2025 are both notified, but commencement is phased. As at today the provisions in force are the definitions and the machinery of the Data Protection Board — its appointment, terms of service and functioning as a digital office. No obligation on a Data Fiduciary is in force until 13 May 2027, other than Consent Manager registration, which starts on 13 November 2026.
- When do DPDP penalties start?
- A penalty attaches to breaching an obligation, so it can only follow that obligation into force. The Data Protection Board provisions commenced on 13 November 2025, Consent Manager registration on 13 November 2026, and every Data Fiduciary duty on 13 May 2027. Claims that the penalty framework "applies from day one" describe a Board that exists but has no Data Fiduciary duty to adjudicate until the third tranche commences.
- When must we register as a Consent Manager?
- Rule 4 commences on 13 November 2026, one year after publication, and it is the only rule in that tranche. An organisation that is not offering Consent Manager services has no obligation on that date at all — the next date that reaches an ordinary Data Fiduciary is 13 May 2027.
- Were the DPDP Rules notified on 13 or 14 November 2025?
- The 13th. G.S.R. 846(E) is dated 13 November 2025; the 14th appears only in the e-gazette upload stamp CG-DL-E-14112025-267650 printed on the cover page. The distinction is load-bearing because Rule 1 sets commencement as an interval from publication rather than as fixed dates, so taking the 14th moves every downstream date by a day and makes "notified 14 November" and "in force 13 May 2027" mutually inconsistent.
- What DPDP obligations are in force today?
- Seven rules: rules 1 and 2, which are the short title and the definitions, and rules 17 to 21, which appoint the Chairperson and Members of the Data Protection Board, set their terms of service, govern the Board’s meetings and let it function as a digital office. All seven concern the regulator rather than the regulated. No safeguard, notice, retention or breach duty is among them.