Insights/Regulatory Newsroom
DPDP Enforcement Countdown: Your Action Plan for the 13 May 2027 Deadline
Published
Reading time2 minutes
FromTriad ICS Research

Nine months to full DPDP obligations. A quarter-by-quarter plan to get there without a last-minute scramble.
The DPDP Rules 2025 were notified on 13 November 2025 with a phased timeline. The provisions establishing the Data Protection Board took effect immediately. Consent Manager registration follows after one year, in November 2026. The core obligations for Data Fiduciaries, including notices, consent, security safeguards, breach notification and Data Principal rights, apply from 13 May 2027. That is about nine months away.
What is at stake
Under the Act, failing to take reasonable security safeguards to prevent a personal data breach can attract a penalty of up to ₹250 crore. Failing to notify the Board and affected Data Principals of a breach can attract up to ₹200 crore, as can failing to meet obligations around children’s data. Other breaches of the Act can attract up to ₹50 crore.
August to October 2026: know your data
- Build a personal data inventory: what you collect, why, where it is stored, who can access it, and which vendors process it.
- Identify processing that involves children’s data, which requires verifiable parental consent.
- Assess whether you could be notified as a Significant Data Fiduciary, which brings additional duties such as periodic data protection impact assessments and audits.
November 2026 to January 2027: notices and consent
- Draft standalone, itemised privacy notices for each collection point.
- Redesign consent flows so each purpose can be accepted or refused separately, and withdrawal is as easy as consent.
- Decide whether you will integrate with registered Consent Managers as they come online.
February to March 2027: safeguards and vendors
- Align security safeguards with the Rules: encryption or masking where appropriate, access control, logging and monitoring, and backups.
- Retain relevant logs and personal data processing records for at least one year, as the Rules require.
- Update contracts with Data Processors to require equivalent safeguards and prompt breach notification to you.
April to May 2027: rights and breach readiness
- Publish how Data Principals can access, correct and erase their data, and set up a process to respond within the timelines in the Rules.
- Write and rehearse a breach notification runbook: notify affected individuals without delay, and send the Board an initial intimation followed by a detailed report within 72 hours.
- Run a dry run: pick one customer and one vendor, and walk through every obligation end to end.
Start with the inventory
Every later step depends on knowing where personal data lives. If you do one thing this month, make it the data map.
This article is general information, not legal advice. Compliance services do not guarantee certification; certification bodies issue certificates.