dpdpconsent.in
Resources

The May 2027 deadline

The DPDP Act, 2023 was passed with a staged rollout: provisions come into force as the government notifies them, with the compliance runway for most businesses expected to close by May 2027. Here's what that actually means in practice.

What’s confirmed, what isn’t

The Act itself is law. What’s still pending, as of this writing, are the detailed rules that specify exactly how obligations like notice format, consent manager registration, and breach reporting will work in practice. That gap — law passed, rules pending — is normal for Indian legislation, and it’s exactly the gap that lets a vendor claim urgency without being able to point to a specific requirement.

What is reasonably certain: the direction doesn’t reverse. Every draft and consultation has moved toward stricter notice and consent expectations, not looser ones. Waiting for perfect clarity before doing anything is a bet against the trend, not a neutral position.

Why “wait and see” costs more than it looks like

The practices that need to change — a proper front-desk ID process, a real privacy notice, a retention rule people actually follow — take weeks to bed in, not days. Front-line staff need to build new habits, not just read a new policy. Starting that process the month a rule is notified means running it under pressure, badly, in front of your own team.

Properties that start now are making the same changes on their own schedule, at their own pace, with room to get it wrong once and fix it quietly.

What to actually do before the deadline matters

Find out where you stand today. That’s the entire purpose of the free Risk Scorecard — not to scare you with a countdown, but to replace the vague sense that “we should probably do something about this” with an actual, specific list.