When can someone exercise DPDP rights against you?
Check any DPDP obligation against Rule 1 of the Digital Personal Data Protection Rules, 2025 — whether it is in force today, the date it starts, and the sub-clause that commences it.
What this obligation turns on
Rule 14 is the rule that turns DPDP into inbound work. It requires the means of making a request to be published, together with any identifier needed to service it and the period within which grievances are answered — so the obligation is not only to honour requests but to have advertised how, which is a thing a Data Principal can check without making a request at all. It commences with the rest of the Data Fiduciary duties on 13 May 2027.
| Question | Answer |
|---|---|
| In force today? | No |
| Binds from | 13 May 2027 |
| Imposed by | Rule 14 — Rights of Data Principals |
| Commenced by | Rule 1(4), “eighteen months after the date of publication of this Gazette” |
Rule 14 requires the Data Fiduciary and Consent Manager to publish the means by which a Data Principal makes a request, including any identifier required to service it, and to publish the period within which grievances will be answered.
Check another obligation
The same resolution for every other duty in the Rules — the rule that imposes it, the sub-clause that commences it, and whether it binds today.
Honouring a Data Principal’s access, correction or erasure request is imposed by rule 14, Rights of Data Principals. Rule 1(4) commences it “eighteen months after the date of publication of this Gazette”, which is 13 May 2027, so it does not bind today and nothing under it is yet enforceable.
Rule 14 requires the Data Fiduciary and Consent Manager to publish the means by which a Data Principal makes a request, including any identifier required to service it, and to publish the period within which grievances will be answered.
| Sub-clause | From | Rules | What it covers |
|---|---|---|---|
| Rule 1(2) | 13 November 2025 | 1, 2 and 17 to 21 | the definitions, and the machinery of the Data Protection Board — its appointment, its terms of service, and its functioning as a digital office |
| Rule 1(3) | 13 November 2026 | 4 | the registration and obligations of Consent Managers, and nothing else |
| Rule 1(4)Yours | 13 May 2027 | 3, 5 to 16, 22 and 23 | everything a Data Fiduciary has to do — notice, security safeguards, breach intimation, retention limits, Data Principal rights, Significant Data Fiduciary obligations and transfers outside India |
Indicative, and not legal advice. Rule 1 of the Digital Personal Data Protection Rules, 2025, notified as G.S.R. 846(E) on 13 November 2025. Whether a given obligation reaches your organisation is a determination for your legal team.
Take this away as a print-ready commencement schedule
Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.
The full commencement picture sets out all three tranches and why the notification date decides every one of them.
Rule 1 of the Digital Personal Data Protection Rules, 2025, read from MeitY’s own gazette PDF ofG.S.R. 846(E). Indicative, and not legal advice.
Every instrument cited here was verified against the issuing regulator's own notification on .Other worked examples
The same calculator, run for a specific entity — with the thresholds and clocks that apply to it, and the instrument each one comes from.
Questions this page answers
- Does the DPDP 72-hour breach notification rule apply now?
- No. Rule 7 of the Digital Personal Data Protection Rules, 2025 requires a full report to the Data Protection Board within seventy-two hours of becoming aware of a personal data breach, but Rule 1(4) commences rule 7 eighteen months after publication — 13 May 2027. Until then there is no DPDP breach-reporting duty of any length. The six-hour report to CERT-In is a separate obligation under section 70B of the IT Act 2000 and has been in force since June 2022.
- Is the DPDP Act in force in India?
- Partly. The Digital Personal Data Protection Act, 2023 and the Rules of 2025 are both notified, but commencement is phased. As at today the provisions in force are the definitions and the machinery of the Data Protection Board — its appointment, terms of service and functioning as a digital office. No obligation on a Data Fiduciary is in force until 13 May 2027, other than Consent Manager registration, which starts on 13 November 2026.
- When do DPDP penalties start?
- A penalty attaches to breaching an obligation, so it can only follow that obligation into force. The Data Protection Board provisions commenced on 13 November 2025, Consent Manager registration on 13 November 2026, and every Data Fiduciary duty on 13 May 2027. Claims that the penalty framework "applies from day one" describe a Board that exists but has no Data Fiduciary duty to adjudicate until the third tranche commences.
- When must we register as a Consent Manager?
- Rule 4 commences on 13 November 2026, one year after publication, and it is the only rule in that tranche. An organisation that is not offering Consent Manager services has no obligation on that date at all — the next date that reaches an ordinary Data Fiduciary is 13 May 2027.
- Were the DPDP Rules notified on 13 or 14 November 2025?
- The 13th. G.S.R. 846(E) is dated 13 November 2025; the 14th appears only in the e-gazette upload stamp CG-DL-E-14112025-267650 printed on the cover page. The distinction is load-bearing because Rule 1 sets commencement as an interval from publication rather than as fixed dates, so taking the 14th moves every downstream date by a day and makes "notified 14 November" and "in force 13 May 2027" mutually inconsistent.
- What DPDP obligations are in force today?
- Seven rules: rules 1 and 2, which are the short title and the definitions, and rules 17 to 21, which appoint the Chairperson and Members of the Data Protection Board, set their terms of service, govern the Board’s meetings and let it function as a digital office. All seven concern the regulator rather than the regulated. No safeguard, notice, retention or breach duty is among them.