This website is meant solely for providing general information about S K R and Company LLP and is not intended for advertising or soliciting work, directly or indirectly. The information on this website is made available to the user only at their own request. By accessing this website, you acknowledge and confirm that you seek information relating to S K R and Company LLP on your own accord and volition, and that no part of this website should be construed as legal, tax, or professional advice. We disclaim liability for any action taken by a user relying on content provided on this website.
The Digital Personal Data Protection Rules, 2025 came into force in phases starting 13 November 2025. Phase 2 — the Consent Manager framework — takes effect 13 November 2026. Full enforcement, including most financial penalties, lands 13 May 2027.
The Data Protection Board of India and the Act's foundational provisions are already active. If your organisation hasn't started building compliance infrastructure, this phase is the baseline you're already behind on.
Consent Manager registration opens, with defined net-worth and certification requirements for organisations that intend to operate as one. For most businesses, this phase marks when consent architecture and notice mechanisms need to be operational, not just documented.
Substantive obligations — data principal rights, breach notification within 72 hours, security safeguards, retention and deletion systems, children's data protection, and grievance redressal — become fully enforceable, with penalties of up to ₹250 crore for serious violations.
Identifying what personal data you hold, where it lives, and how it flows through your organisation and vendors.
Assessing existing consent mechanisms against DPDPA's notice and consent requirements, and designing what's missing.
Building the process and documentation a Data Fiduciary needs to handle data principal requests and complaints.
Testing whether your organisation can actually meet the 72-hour breach notification requirement — not just whether a policy document says you can.