Ask most compliance teams what happens to the Digital Personal Data Protection Act this November, and the answer tends to be some version of “enforcement begins.” That isn't quite right, and the gap between the popular timeline and the actual one matters more than it looks.
The Digital Personal Data Protection Rules were notified on 14 November 2025, after the Ministry of Electronics and Information Technology worked through roughly 6,900 stakeholder comments gathered across seven cities. Rule 1(2) of the notification staggers when different obligations take effect. A small set of provisions, mainly those establishing the Data Protection Board and the Search-cum-Selection Committee tasked with staffing it, took effect the day the Rules were published. Consent Manager registration, the interoperable platform through which individuals are meant to grant, review and withdraw consent, comes into force twelve months later, around mid-November 2026. Everything else that actually changes how a business collects, notifies, stores and reports on personal data, including the content of consent notices, breach-reporting timelines, verifiable parental consent for children's data, and the additional duties on Significant Data Fiduciaries commences eighteen months out, around 13 May 2027.
November 2026 only opens a registration window for a category of intermediary that barely exists yet in India. Section 33's penalty schedule, running from Rs. 50 crore for violations of a data principal's rights up to Rs. 250 crore for security-safeguards failures. with Rs. 200 crore tiers for breach-notification and children's-data violations and Rs.150 crore for Significant Data Fiduciary duties, does not engage until May 2027. A business that treats "November 2026" as its deadline is either over-preparing for a milestone that doesn't touch its obligations or, worse, quietly deciding it has another eighteen months to think about the parts that do.
The date that should worry it is the one nobody can currently attach to a functioning institution. LiveLaw reported on 1 August 2026 that the Data Protection Board of India, the body Section 27 creates to receive complaints, conduct inquiries and impose those Section 33 penalties, had no appointed Chairperson or Members more than eight months after the Rules that were supposed to bring it into being. The Search-cum-Selection Committee, chaired by the Cabinet Secretary and including the Secretaries of Legal Affairs and MeitY, had solicited nominations through May and June 2026 without finalising an appointment. That reporting drew, appropriately, on Puttaswamy and on a Madhya Pradesh High Court order in Parth Sharma v. Union of India, in which a petitioner was directed to file a representation before a Board that had no operational capacity to receive it.
What you are left with is a compliance architecture assembled in the wrong order. The infrastructure obligations are on a fixed statutory clock, irrespective of institutional readiness: Consent Manager registration in November, the full substantive regime in May 2027, both dates set by rule, neither contingent on anyone sitting at the Board to interpret them. There is no equivalent date for the adjudicatory body that gives effect to those obligations, which determines what “verifiable consent” requires in practice, where the line is drawn on “reasonable security safeguards,” and which entities cross the threshold into Significant Data Fiduciary status. The Act and the Rules do not require the Board to be established by the time the eighteen-month period expires. If the search committee's process takes time, India could be in May 2027 with a fully operational statute, live penalty provisions and a Board that has not issued a single order interpreting any of them.
That is another problem than the one already reported. The LiveLaw article tackled this head on. The non-existence of the Board affects those seeking redress today. It also affects businesses seeking to establish compliance programs against a law with no accumulated interpretation to rely on. Normally, an eighteen-month runway would see a general counsel trying to triangulate what a loyalty-programme dataset means for a Significant Data Fiduciary or how an age-gate satisfies the children's data provisions by month sixteen or seventeen against some body of Board orders or circulars. There may not be any. The first Board orders on any of these questions could come after, not before the deadline they were meant to clarify, assuming a newly constituted regulator goes from appointment to a published order within its first year at all.
The breach-notification rule is a good example of how much is up to interpretation no one has tried out yet. The DPDP Rules have no minimum size for a reportable breach, unlike the GDPR's risk-based threshold, meaning ten compromised records would trigger the same obligation as ten million. Data Fiduciaries must notify the Board of a breach within seventy-two hours of learning of the breach, not the conclusion of their investigation, including root cause, measures taken to contain the breach and notices sent to Data Principals, and Data Principals are to receive a separate plain-language notice “as soon as practicable.” That instinct on the part of the compliance officer to dismiss a small, contained incident as immaterial and skip the filing is the kind of judgment call that would normally be tested against Board precedent within a year or two of the rules taking effect.
Significant Data Fiduciaries are the most acute version of this. The SDF status entails a mandatory Data Protection Officer, an annual Data Protection Impact Assessment, and an independent compliance audit once every twelve months, in addition to the baseline duties every fiduciary carries. The Rules tie SDF designation to volume and sensitivity of data processed, not to a fixed bright line. This is exactly the sort of threshold issue that a functioning Board would normally be expected to clarify by early orders. Companies just above that threshold are being asked to self-assess against a standard that may not get its first authoritative reading for years.
None of this is an argument for delay. This time, there is no guaranty that the clarification will come before the deadline to which it would apply, so waiting for the Board to clarify an ambiguous term before building a system around it is not a viable strategy. A more secure path is to record the interpretation a business actually takes, and why, treating each judgment call, on verifiable parental consent, on SDF status, on what constitutes a reportable breach, as something a future Board might review years later, rather than something it will bless in advance. Whether or not the Board that would prosecute is seated on day one, section 33 penalty exposure attaches to conduct within the compliance window. An enforcer arriving eighteen months late does not erase eighteen months of processing that happened without one. The pieces worth finishing first are consent-notice architecture, breach-notification workflows and DPIA readiness for likely SDFs, precisely because they are hardest to retrofit once a complaint, however delayed, eventually reaches an adjudicator.
People do worse in the meantime. Technically, a data principal whose erasure request under Section 12 is ignored will have a route to the Board once the substantive Rules commence. But a formal route without a functioning office at the other end of it is, as the Madhya Pradesh High Court's own order demonstrated, a route that leads to a filing with nowhere to go. Until the Search-cum-Selection Committee has done its job, the more realistic avenues for a user with a live grievance are through the Data Fiduciary's own grievance officer, mandated under the Rules irrespective of the Board's status, or through existing consumer protection and information technology remedies that don't require a body still being staffed.
Oddly enough, the only part of this timeline that is on schedule is the Consent Manager framework. Registration is scheduled to open in November. India will have a functioning privacy-tech infrastructure long before the law it is supposed to serve is fully in force. Whether this is reassuring or irrelevant depends on whether the plumbing matters more than the plumber's license to inspect it. By May 2027, businesses may learn which one the Board, whenever it arrives, was actually constructed to check.
Author is a final year Law student at O.P. Jindal Global University. Views are personal.