I agree & understand the following:

This website is meant solely for providing general information about S K R and Company LLP and is not intended for advertising or soliciting work, directly or indirectly. The information on this website is made available to the user only at their own request. By accessing this website, you acknowledge and confirm that you seek information relating to S K R and Company LLP on your own accord and volition, and that no part of this website should be construed as legal, tax, or professional advice. We disclaim liability for any action taken by a user relying on content provided on this website.

DPDPA Advisory

DPDPA compliance, on a real timeline.

The Digital Personal Data Protection Rules, 2025 came into force in phases starting 13 November 2025. Phase 2 — the Consent Manager framework — takes effect 13 November 2026. Full enforcement, including most financial penalties, lands 13 May 2027.

Timeline

Where the Act actually stands today.

Phase 1 — In force since 13 Nov 2025

Institutional Foundation

The Data Protection Board of India and the Act's foundational provisions are already active. If your organisation hasn't started building compliance infrastructure, this phase is the baseline you're already behind on.

Phase 2 — 13 Nov 2026

Consent Manager Framework

Consent Manager registration opens, with defined net-worth and certification requirements for organisations that intend to operate as one. For most businesses, this phase marks when consent architecture and notice mechanisms need to be operational, not just documented.

Phase 3 — 13 May 2027

Full Enforcement

Substantive obligations — data principal rights, breach notification within 72 hours, security safeguards, retention and deletion systems, children's data protection, and grievance redressal — become fully enforceable, with penalties of up to ₹250 crore for serious violations.

What we do

DPDPA Readiness Assessment.

Data Mapping

Identifying what personal data you hold, where it lives, and how it flows through your organisation and vendors.

Consent Architecture Review

Assessing existing consent mechanisms against DPDPA's notice and consent requirements, and designing what's missing.

Grievance Redressal Design

Building the process and documentation a Data Fiduciary needs to handle data principal requests and complaints.

Breach Response Readiness

Testing whether your organisation can actually meet the 72-hour breach notification requirement — not just whether a policy document says you can.