You have probably been told that 13 November 2026 is India's first hard data protection deadline and that your company needs to be ready for it. Read the commencement rule and that is not what it says. One rule commences on that date, it is titled "Registration and obligations of Consent Manager", and the phrase "Data Fiduciary" does not appear in it once.
If you are an ordinary enterprise, November gives you nothing to do. What you owe lands eighteen months from notification, in May 2027. And the part that should worry anyone running AI over customer or employee data is that the law reaching it never uses the word.
What actually commences, and when
The Digital Personal Data Protection Act, 2023 received assent on 11 August 2023 as Act 22 of 2023. It did not come into force then. Section 1(2) left commencement to notification, which is why nothing happened for two years.
The machinery arrived with the Digital Personal Data Protection Rules, 2025, notified as G.S.R. 846(E). Rule 1 splits them into three tranches:
| Tranche | Rules | In force | Who it binds |
|---|---|---|---|
| On publication | 1, 2, 17 to 21 | November 2025 | Nobody operationally. Board constitution and procedure |
| One year | 4 only | 13 November 2026 | Consent Managers applying to register |
| Eighteen months | 3, 5 to 16, 22, 23 | 13 May 2027 | Every Data Fiduciary |
One caution on the dates, and it is more interesting than it first looks. As published, Rule 1(2) counted from publication "in the Official Gazette" while Rule 1(3) and 1(4), the two limbs carrying the dates above, counted from publication "of this Gazette". A corrigendum, G.S.R. 892(E) of 10 December 2025, amended exactly those two lines to read "in the Official Gazette". Someone in the ministry noticed.
What the corrigendum does not do is name a day. The notification is headed "the 13th November, 2025", its electronic publication stamp reads CG-DL-E-14112025, and the government's own press backgrounder says 14 November. So the reference point is now consistent across the rule and the gap remains, which is why some advisers compute 14 November 2026 and 14 May 2027. If your plan turns on a single day, ask counsel rather than a blog.
Why November is not your deadline
Rule 1(3) commences Rule 4 and nothing else. Rule 4 has five sub-rules. The first lets a person who meets the First Schedule conditions apply to the Board for registration. The second lets the Board inquire and register or reject. The third points at the obligations in Part B. The remainder covers non-adherence and suspension. Every one of them addresses an applicant, a Consent Manager, or the Board.
The Act has its own commencement notification, G.S.R. 843(E), and it tells the same story. Its one-year limb brings exactly two provisions into force: section 6(9), "Every Consent Manager shall be registered with the Board", and section 27(1)(d), the Board's power to inquire into a breach of a Consent Manager's registration conditions and impose a penalty.
So the entire one-year tranche, across both instruments, is three items and a schedule, and not one of them reaches an ordinary Data Fiduciary.
The government describes it the same way. Answering Lok Sabha Unstarred Question No. 3943 on 12 August 2026, the ministry set out three phases: establishment and operationalization of the Board, then "Phase 2 (within one year): Registration and functioning of Consent Managers", then "Phase 3 (within eighteen months): Compliance obligations for Data Fiduciaries including data principal rights, security safeguards and breach notification". Compliance obligations for Data Fiduciaries are phase three. In the ministry's own schedule, you are not in phase two.
There is an oddity worth noticing in that pairing. On 13 November 2026 the Board acquires the power to fine Consent Managers over registration conditions. The general penalty machinery, sections 28 to 34, does not commence until the eighteen-month date. For six months the only penalty power in Indian data protection law points at the handful of companies trying to register.
The conditions themselves confirm who this is for. A Consent Manager must be a company incorporated in India with a net worth of not less than two crore rupees, and must hold independent certification against a standards framework the Board is required to publish. If you are not building consent-management infrastructure as a business, Rule 4 is a market-entry regime for somebody else's product.
There is a practical problem with that. The certification depends on a "data protection standards and assurance framework" which the First Schedule requires the Board to publish on its website, and the Board does not have a website. We checked four plausible domains and all four fail to resolve. It has published no regulations, no orders and no standard.
Nor is it staffed. The Board was established by G.S.R. 844(E) and sized by G.S.R. 845(E), which notifies that it "shall consist of four members". A MeitY circular dated 6 May 2026, F. No. 2(1)/2026-Pers.I, then invites applications for "(i) Chairperson : 01 Post (ii) Member : 04 Posts" in order to prepare a panel of names for a Search-cum-Selection Committee. Six months after legal establishment, the ministry was still assembling a shortlist. No appointment has been gazetted since, which is a meaningful absence given that MeitY does gazette appointments of this kind.
Treat one widely repeated claim with suspicion. Several vendor pages state that the Chairperson and Members were appointed on 6 June 2026, and search engines have begun returning it as settled fact. None of them cites a gazette number or an order. It is contradicted by the August 2026 parliamentary answer, which still describes Board operationalization as a pending phase. The likeliest explanation is a garbled reading of the May circular or of a June notification about the appointment process rather than the appointments.
Read that against the previous paragraph. A registration window opens in five weeks, onto an institution with no members and no published certification standard, carrying a penalty power the regulator can use before it has one for anybody else.
Two pieces of commentary to discard while you are here. There is no "legacy data revalidation" obligation on 13 November 2026, in the Act or in the Rules. The real provision is a notice duty in section 5(2), and section 5(2)(b) says in terms that the Data Fiduciary "may continue to process the personal data until and unless the Data Principal withdraws her consent." Nothing expires in November.
What you owe in May 2027
This is the list that matters: notice under Rule 3, which must carry an "itemised description" of the personal data rather than a category label; consent; security safeguards under Rule 6; breach intimation under Rule 7; retention and erasure under Rule 8; contact publication under Rule 9; children's data under Rules 10 to 12; Significant Data Fiduciary duties under Rule 13; the rights plumbing in Rule 14; and cross-border under Rule 15.
Three of those are routinely misreported, so check your plan against the text.
There is no single 72-hour breach rule. Intimation to each affected individual is "without delay", with no hour figure and no materiality threshold to hide behind. The Board gets an initial description without delay, then a detailed report within seventy-two hours of your becoming aware.
There is no universal three-year deletion rule. Rule 8(1)'s clock applies only to the classes in the Third Schedule, meaning e-commerce with at least two crore registered users, online gaming with at least fifty lakh, and social media with at least two crore. Everyone else works to the general standard: erase when the purpose is no longer served.
The ninety days is probably not a subject-access deadline. Rule 14(3) sets "a reasonable period not exceeding ninety days" and attaches it to the grievance redressal system. The government's press material describes that period as covering access, correction and erasure requests. The Rule and the backgrounder do not read the same way. Plan to the shorter interpretation and do not quote ninety days to a regulator as though it were settled.
The law never says artificial intelligence
We counted, across the full English text of both instruments.
| Term | In the Act | In the Rules |
|---|---|---|
| artificial intelligence | 0 | 0 |
| machine learning | 0 | 0 |
| automated decision | 0 | 0 |
| profiling | 0 | 0 |
| algorithm | 0 | 1 |
That silence is not an oversight the government is unaware of. MeitY's India AI Governance Guidelines, published in November 2025, state that "the use of personal data without user consent to train AI models is governed by the Digital Personal Data Protection Act", and then list what remains unsettled: "the scope and applicability of exemptions available for the training of AI models on publicly available personal data; whether the principles of collection and purpose limitation are compatible with how modern AI systems operate; the role of ‘consent managers’ in AI workflows and the value of dynamic and contextual notices in a world of multi-modal AI and ambient computing". The ministry recommends that guidance notes and model codes be issued to close those gaps. None has been.
There is no analogue of Article 22 of the GDPR. No right against solely automated decisions, no explanation right, no human review requirement, no profiling provision. If your AI governance program was built around GDPR language, the Indian hooks are somewhere else entirely.
The single mention of algorithms is Rule 13(3), and it is narrower than its reputation:
"A Significant Data Fiduciary shall observe due diligence to verify that technical measures including algorithmic software adopted by it for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data processed by it are not likely to pose a risk to the rights of Data Principals."
Four things not to over-read. It is "due diligence to verify", so nothing gets filed or certified with anyone. "Algorithmic software" appears as an example of technical measures, and the words artificial intelligence are absent. The listed activities are data-movement verbs, with no analysis, training, inference or decision-making among them. And "rights of Data Principals" has defined content in Chapter III rather than meaning open-ended fairness or bias.
It also binds only Significant Data Fiduciaries, and that is where it stops being theoretical. The status comes from a Central Government notification under section 10(1), and there is no self-assessment threshold, so nobody becomes one by crossing a record count. Section 10 sits in the eighteen-month limb of G.S.R. 843(E), which means the power to designate anyone does not exist yet.
The consequence is worth stating plainly. The only provision in Indian data protection law that mentions algorithms applies to nobody today, and cannot apply to anybody until the government starts designating after May 2027.
One live risk against that. MeitY reportedly consulted in January 2026 on moving the Significant Data Fiduciary provisions forward from the eighteen-month date, including the designation power and the Rule 13(4) localization requirement. No gazette instrument gives effect to it. A month-by-month sweep of the ministry's gazette output from November 2025 to October 2026 turns up no amendment to the commencement rule, and the August 2026 answer quoted above restates the original phases after the consultation had happened. The schedule stands, and this is still the piece most likely to move.
There is one recent sign of movement, and it points the other way. The Digital Personal Data Protection (Removal of Difficulties) Order, 2026, S.O. 5458(E) of 5 October 2026, amends the Act in two places, and one of them is section 10(2)(c)(ii), where the word "audit" becomes "data audit". The government is tidying the Significant Data Fiduciary text weeks before our publication date, while having designated nobody. The order is expressly "textual, editorial in nature" and moves no deadline.
The provision that does reach your AI, in four words
Section 8(3) is the one. Where personal data is likely to be used to make a decision that affects the Data Principal, or disclosed to another Data Fiduciary, you must ensure its "completeness, accuracy and consistency."
That is a data-quality duty, not an explainability duty, and it is a better fit for how enterprises actually use AI than anything in Rule 13. A model scoring a loan application, ranking a candidate, or triaging a claim is processing data to make a decision that affects a person. Section 8(3) does not ask you to explain the model. It asks whether the data going in was complete, accurate and consistent, which is a question most AI deployments cannot currently answer about their own inputs.
Where AI creates real exposure under a law that never mentions it
Three places, all of them operational rather than doctrinal.
An unapproved AI tool is a processor with no contract. Section 8(2) permits engaging a Data Processor "only under a valid contract." When an employee pastes a customer record into a consumer AI assistant, that provider is processing personal data on your behalf, and there is no contract, no notice and no consent basis covering it. You cannot produce a contract for a tool you did not know was in use. This is the clearest reason shadow AI is a DPDP problem rather than only a security one, and it is why the inventory has to exist before the policy does. The shadow AI hub collects what we know about finding those tools in the first place.
Withdrawal has to reach further than your consent records. Section 6(6) requires that on withdrawal you "cease and cause its Data Processors to cease" processing, within a reasonable time. No number is given, so anyone quoting one is inventing it. The hard part is the second half. A consent manager records the withdrawal event accurately and has no reach into prompts already sent to a vendor, retained vendor-side logs, embeddings built from the record, or an agent's context window. The consent ledger will look clean while the data is still in places you cannot enumerate.
Rule 6 asks for visibility, by name. The safeguards rule requires "visibility on the accessing of such personal data, through appropriate logs, monitoring and review, for enabling detection of unauthorised access, its investigation and remediation to prevent recurrence", and Rule 6(e) requires retaining those logs for a year. Rule 8(3) goes further and sets a one-year minimum retention floor on personal data, traffic data and processing logs, binding your processors too. The Rules' own illustration says a platform must keep order data and logs for a year even after the user deletes the account.
Read those together and the shape of the obligation is familiar. You need to be able to say what personal data moved, where it went, who touched it, and when, and keep that record for a year. We have written about the plumbing in AI audit trails and SIEM integration, and the India case is the same requirement arriving through a privacy statute rather than a security one.
Penalties, mapped properly
"Fines up to 250 crore rupees" gets quoted for every DPDP failure. The Schedule is more specific than that, and every figure is a ceiling the Board may extend to after an inquiry finds a significant breach.
| Ceiling | Attaches to |
|---|---|
| 250 crore rupees | Section 8(5), reasonable security safeguards |
| 200 crore rupees | Section 8(6), breach notification failure |
| 200 crore rupees | Section 9, obligations regarding children |
| 150 crore rupees | Section 10, Significant Data Fiduciary obligations |
| 50 crore rupees | Residual, any other provision of the Act or the rules |
Notice, consent, retention and Rule 13(3) failures all sit in that residual tier. There is also no turnover-percentage formula anywhere in the Act, which is a real difference from the EU approach and changes how the exposure models.
Scope, briefly, because it catches people out
The Act reaches processing outside India where that processing is "in connection with any activity related to offering of goods or services to Data Principals within the territory of India." There is no monitoring-of-behavior limb, so the GDPR instinct overstates the reach.
Cross-border transfer is a restriction model rather than an adequacy model. Section 16(1) lets the government restrict transfers to notified countries, so the default is permitted and there are no standard contractual clauses or transfer impact assessments to prepare. Section 16 is also in the eighteen-month limb, so that restriction power is not live yet either, and DPDP places no transfer restriction at all until it commences. Section 16(2) preserves sectoral localization under RBI, SEBI, IRDAI and telecom rules, which is usually the constraint that actually binds in the meantime.
Employee data is fully in scope with no carve-out, though section 7(i) removes the consent requirement for employment purposes. One textual oddity worth flagging rather than resolving: the rights provisions are framed around consent and section 7(a), not 7(i), which suggests an employee processed purely on the employment ground may have no access or erasure right against her employer. That reading is clear on the text and untested in practice.
What to do with the eighteen months
Stop preparing for November if you are not a Consent Manager, and reallocate that attention to May 2027.
Start with discovery, because every obligation above assumes you know where personal data goes, and AI tools are the fastest-growing category of place it goes without a record. Then get the processor contracts in place for the AI services you have sanctioned, and make an explicit decision about the ones you have not. Then turn on the logging, because Rule 6 and Rule 8 both want a year of it and that clock cannot be started retrospectively in April 2027.
The policy document comes after the visibility, not before it. If you need a starting point for the policy half, our AI acceptable use policy template covers the clauses these provisions assume, and the governance maturity assessment will tell you which of discovery, contracts or logging you are weakest on.
None of this is legal advice. Every date, rule number and figure above is taken from the Gazette text of the Act and the Rules rather than from commentary, and the items we could not verify are flagged as such in place. The Significant Data Fiduciary question and the ninety-day reading in particular are worth your counsel's time rather than ours.