I agree & understand the following:

This website is meant solely for providing general information about S K R and Company LLP and is not intended for advertising or soliciting work, directly or indirectly. The information on this website is made available to the user only at their own request. By accessing this website, you acknowledge and confirm that you seek information relating to S K R and Company LLP on your own accord and volition, and that no part of this website should be construed as legal, tax, or professional advice. We disclaim liability for any action taken by a user relying on content provided on this website.

IT Risk / DPDPA

DPDPA Compliance: Where India's Data Protection Law Actually Stands in 2026

Phase 2 of the DPDP Rules lands on 13 November 2026. Here's what's actually in force today, what's coming next, and what it means for your compliance roadmap.

S K R and Company LLP · 15 August 2026

The Digital Personal Data Protection Act, 2023 received Presidential assent in August 2023, but for two years it existed largely on paper. That changed on 13 November 2025, when the Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025 and began a phased rollout that is now well underway.

Three phases, three deadlines

Phase 1 is already live. It established the Data Protection Board of India and the Act’s foundational provisions, effective the day the Rules were notified. If your organisation hasn’t started building compliance infrastructure yet, this is the baseline you’re already behind on, not a future deadline.

Phase 2 arrives on 13 November 2026, roughly three months from now. This phase brings the Consent Manager framework into force: registration opens for organisations that intend to operate as a Consent Manager, with defined net-worth and certification requirements. For most businesses that aren’t Consent Managers themselves, this is the point by which consent architecture and notice mechanisms need to be genuinely operational, not just documented in a policy binder.

Phase 3, on 13 May 2027, is full enforcement. Data principal rights, 72-hour breach notification, security safeguards, retention and deletion systems, children’s data protection, and grievance redressal all become fully enforceable, backed by penalties of up to ₹250 crore for serious violations.

What this means in practice

The organisations that will handle Phase 2 comfortably are the ones that treat 2026 as the year to build, not the year to start planning. A readiness assessment at this stage does three things: maps what personal data you actually hold and where it flows, tests whether your consent and notice mechanisms would survive scrutiny, and confirms whether you could genuinely meet a 72-hour breach notification requirement if you had to today.

None of this is theoretical anymore. The Board is operational, the Rules are notified, and the clock on Phase 2 is already running. The gap between where most organisations are and where the Rules require them to be is still closeable, but it gets more expensive to close with every quarter it’s left unaddressed.

← Back to Insights