Executive summary — For two years the Digital Personal Data Protection Act sat on the statute book without the operational detail that would make it enforceable. That changed when the government notified the DPDP Rules in November 2025, starting the clock on a phased compliance runway that ends in 2027. Indian enterprises — and any organisation processing the personal data of people in India — now have a concrete deadline and a defined set of obligations. This guide explains what the framework requires and what to do about it, and connects to the broader discipline of data privacy management. The DPDP Act, 2023 established the principles; the DPDP Rules, 2025 supply the mechanics. Notified on 14 November 2025, the Rules operationalise the Act with a phased timeline that gives organisations roughly eighteen months to reach full compliance, targeted around mid-May 2027, with provisions governing consent managers taking effect about twelve months after notification. The runway is deliberate, but it is not long given how much most enterprises have to change. Who the Law Applies To The Act governs any 'data fiduciary' — the entity that determines why and how personal data is processed — handling the digital personal data of individuals in India, whether the processing happens in India or abroad. That extraterritorial reach means overseas companies offering goods or services to people in India fall within scope. Larger or higher-risk fiduciaries may be designated 'significant data fiduciaries' and carry heavier obligations, including appointing a data protection officer and conducting periodic assessments. The Core Obligations At the heart of the framework is consent. A data fiduciary must give clear notice of what data it collects and why, obtain consent that is free, specific, informed and unambiguous, and make withdrawing consent as easy as giving it. Beyond consent, the Rules require reasonable security safeguards, breach notification to the Data Protection Board and affected individuals, defined retention limits with deletion when the purpose is served, and specific protections for the data of children and persons with disabilities. Notice and consent — plain-language notice and verifiable, revocable consent for each purpose. Data principal rights — access, correction, erasure and grievance redressal, which enterprises must be able to fulfil on request. Security safeguards — reasonable technical and organisational measures to protect personal data. Breach notification — timely reporting of personal data breaches to the Board and affected individuals. Retention and deletion — holding data only as long as needed and deleting it thereafter. Preparing for the DPDP Rules runway? PrivaTrust ships with India DPDP profiles, consent workflows and reporting built in. The Consent Manager Provision One distinctive feature of the Indian framework is the consent manager: a registered intermediary through which individuals can give, manage and withdraw consent across data fiduciaries. The provisions governing consent managers take effect roughly twelve months after notification, around November 2026, ahead of the broader compliance deadline. Enterprises should design their consent architecture now so it can interoperate with this model rather than retrofitting it later. A capable consent management platform is the practical foundation for this. What to Do Now The organisations that will meet the 2027 deadline comfortably are starting in 2026. The first step is discovery: mapping what personal data you hold and where, because you cannot apply notice, consent, retention or deletion rules to data you have not found. From there, rebuild consent capture to meet the free-specific-informed standard, stand up a process to fulfil data principal rights within deadline, define retention schedules with automated deletion, and establish breach-response and governance procedures. Each of these is a project; together they are why an eighteen-month runway is not as generous as it sounds. How DPDP Fits the Global Picture Most Indian enterprises of any size already face more than one privacy regime — the GDPR for European customers, the CCPA for Californian ones — and the DPDP Rules now add a domestic obligation with its own definitions and deadlines. Rather than building a separate programme for each, the efficient path is one privacy operation that can apply the right rules per jurisdiction. Data protection also depends on controlling access to personal data, which ties compliance to identity and access management. GET DPDP-READY BEFORE THE RUNWAY RUNS OUT eMudhra will help you map your data, rebuild consent, and stand up the workflows the DPDP Rules require. Explore PrivaTrust or talk to an eMudhra expert. Tags: Data Privacy About the Author eMudhra Limited eMudhra Editorial represents the collective voice of eMudhra, providing expert insights on the latest trends in digital security, cryptographic identities, and digital transformation. Our team of industry specialists curates and delivers thought-provoking content aimed at helping businesses navigate the evolving landscape of cybersecurity and trust services with confidence.