AI Governance9 min readAugust 14, 2026

India's DPDP Rules Are Live: The 18-Month Compliance Countdown, Read as an Engineering Spec

M
Mohammed UsmanFounder & CEO

Mohammed Usman is the founder and CEO of Masarrati with 15+ years in product engineering. He has led the development of 10+ production AI, blockchain, and cybersecurity platforms for enterprise clients across UAE, MENA, and Europe.

AI/ML ArchitectureBlockchain SystemsEnterprise Security

TL;DR

The DPDP Rules were notified on 14 November 2025 with a phased clock: Data Protection Board immediately, consent managers by November 2026, full compliance by May 2027. Read as an engineering spec, that means consent as a queryable system of record, notices generated from a purpose registry, rights requests that execute across the data estate, tracked grievance workflows, and processor governance with technical evidence — built now, not retrofitted in 2027.

Updated August 14, 2026

India's data protection regime stopped being theoretical on 14 November 2025, when the Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025 — the operating manual for the DPDP Act that had been waiting since 2023. The Rules run on a phased clock: the Data Protection Board of India framework took effect immediately, consent manager registration provisions switch on at twelve months in November 2026, and the substantive obligations — consent, notice, data principal rights, grievance redressal — reach full compliance at eighteen months, in May 2027.

Eighteen months sounds generous. It is not, because most of what the Act requires is not paperwork — it is systems. Consent that is recorded, provable and revocable; notices generated per purpose; rights requests that actually execute against your data estate; and security safeguards that stand up to a regulator holding a penalty schedule that reaches 250 crore rupees. Companies that read the Rules as a legal memo will spend 2027 retrofitting. Companies that read them as an engineering specification get to build once.

The clock, precisely

Already in force. The Data Protection Board — the adjudicating authority that will receive breach notifications and impose penalties — is established and operating under the Rules' first phase.

November 2026. Consent manager provisions activate: registered independent platforms that maintain consent records, give data principals dashboards, and interoperate with data fiduciaries. If your consent architecture cannot integrate with a consent manager, this is the deadline that exposes it.

May 2027. The rest arrives at once — consent and notice requirements, data principal rights, grievance redressal timelines, and the obligations attached to Significant Data Fiduciary designation, which reporting on the Rules describes as including data protection impact assessments, annual audits and algorithmic oversight.

What the obligations mean in build terms

Consent as a system of record. The DPDPA is a consent-first statute — analyses consistently note it recognises no legitimate-interests basis of the GDPR kind. That makes the consent record the load-bearing artefact of your entire compliance posture: captured per purpose, timestamped, versioned against the notice shown, queryable at processing time, and revocable with effect. A checkbox in a signup form is not a consent architecture.

Notice generation, not notice copywriting. Notices must describe the personal data and purpose specifically enough to make consent meaningful. For a product with dozens of processing purposes, maintaining accurate notices manually is how drift happens; generating them from the same purpose registry the code enforces is how they stay true.

Rights that execute. Access, correction and erasure requests have to traverse the real data estate — production databases, analytics stores, backups policy, processor relationships. Erasure especially is a data engineering problem: knowing where a principal's data lives is the prerequisite, and most organisations discover at their first request that they do not.

Grievance redressal with timelines. A tracked queue with response deadlines and an escalation path to the Board — a workflow system, not a shared inbox.

Processor governance. Data fiduciaries answer for their processors. Contracts matter, but so does technical accountability: scoped access, logged flows, and the ability to demonstrate what a processor could and could not touch.

Who should move first

Reporting on the Rules describes enhanced duties for Significant Data Fiduciaries — DPIAs, annual audits, algorithmic oversight. If your scale, data volume or sector makes SDF designation plausible, the audit-facing artefacts are the long-lead items: an audit trail cannot be backfilled, so the systems that generate it need to exist well before the first audit cycle. And every consumer-facing platform should treat November 2026, not May 2027, as its real deadline — consent manager interoperability forces the consent architecture question early.

Where Masarrati fits

Masarrati builds this class of system for Indian and Gulf enterprises: consent and purpose infrastructure inside custom software platforms, GRC and compliance automation that maintains the control evidence, DPIA artefacts and audit trails regulators ask for — with the DPDPA joining ISO 27001, SOC 2, GDPR and the UAE's PDPL in one mapped control library — and AI systems whose data pipelines respect consent boundaries by construction. As an ISO 27001 certified engineering company headquartered in Hyderabad, we build under this regime ourselves. Legal interpretation belongs to your counsel; what we deliver is a platform whose records make compliance demonstrable.

Frequently Asked Questions

When do India's DPDP Rules take effect?

MeitY notified the DPDP Rules on 14 November 2025 with a phased timeline: the Data Protection Board framework took effect immediately, consent manager registration provisions activate at twelve months in November 2026, and full compliance with consent, notice, data principal rights and grievance obligations arrives at eighteen months, in May 2027.

What is a consent manager under the DPDPA?

A registered independent platform that maintains consent records, gives data principals a dashboard over their consents, and interoperates with data fiduciaries. The consent manager provisions switch on in November 2026, which makes consent-architecture interoperability the earliest hard engineering deadline in the regime.

What are Significant Data Fiduciary obligations?

Reporting on the Rules describes enhanced duties for organisations designated as Significant Data Fiduciaries, including data protection impact assessments, annual audits and algorithmic oversight. Because audit trails cannot be backfilled, the systems that generate this evidence are the long-lead compliance items.

Does the DPDPA have a legitimate-interests basis like GDPR?

Analyses of the Act consistently note that it does not recognise a GDPR-style legitimate-interests basis — consent is the default posture, alongside a narrow set of legitimate uses. That places the consent record at the centre of the compliance architecture: per-purpose, versioned, queryable at processing time and revocable with effect.