Reference
How India got its data protection law
Every milestone below is verified against a primary official source before it publishes. Computed future dates are marked as such and treated as interpretation until officially confirmed.
Last verified on 17 August 2026
The Act
Act
The Digital Personal Data Protection Act 2023 is enacted
India's law for digital personal data becomes Act No. 22 of 2023. It recognises both the right of individuals to protect their personal data and the need to process personal data for lawful purposes.
Why it matters: The Act is the parent framework: it defines Data Fiduciaries, Data Principals and their rights and duties, and it empowers the Central Government to make rules operationalising it.
Status: enacted; provisions commence as notified
The Rules
Draft
Draft DPDP Rules published for public consultation
The Government publishes draft rules under section 40 of the Act as G.S.R. 02(E) and invites objections and suggestions from the public through the MyGov platform, for consideration after 18 February 2025.
Why it matters: The consultation round required before the final Rules could be made. The final Rules record that these comments were considered.
Status: superseded by the final Rules
Notification
Act commencement notified in three phases
Notification G.S.R. 843(E) appoints commencement dates for the Act in three groups: the definitions, the Data Protection Board provisions and related machinery from the date of publication; the Consent Manager registration provisions one year later; and the main obligations and rights eighteen months later.
Why it matters: This is the notification under section 1(2) that actually brings the Act into force. Until commencement was notified, the Act's provisions did not operate.
Status: in effect; the later phases are due one year and eighteen months from publication
Notification
Data Protection Board of India established
Notification G.S.R. 844(E) establishes the Data Protection Board of India under section 18, with its head office in the National Capital Region of India. A companion notification, G.S.R. 845(E), fixes the Board at four members under section 19(1).
Why it matters: The Board is the body that will receive breach intimations, hear complaints and impose penalties once the corresponding provisions operate.
Status: in effect
Implementation
First provisions of the Act come into force
Sections 1(2) and 2, sections 18 to 26, sections 35 and 38 to 43, and section 44(1) and (3) of the Act take effect on the date of publication of the commencement notification. These cover the definitions, the Data Protection Board and its machinery, rule making powers, and amendments to two other laws.
Why it matters: The Act moves from enacted to partially operating. The obligations of Data Fiduciaries and the rights of Data Principals follow in the later phases.
Status: in force
Rule
The DPDP Rules 2025 are notified
The final Digital Personal Data Protection Rules 2025 are notified as G.S.R. 846(E) in Gazette of India Extraordinary issue No. 760, after considering the public comments on the draft.
Why it matters: The Rules operationalise the Act: notices, consent managers, security safeguards, breach intimation, retention and erasure, children's data, and the Data Protection Board's functioning.
Status: published; text subject to corrigenda G.S.R. 892(E)
Implementation
Rules 1, 2 and 17 to 21 come into force
On the day of publication, the definitions and the provisions relating to the Data Protection Board start to operate. The obligations with operational lead time follow later.
Why it matters: The first slice of the Rules to take legal effect, per Rule 1(2).
Status: in force
Correction
Corrigenda to the DPDP Rules 2025 issued
Eight textual corrections to the Rules are notified as G.S.R. 892(E), published in Gazette issue No. 806 of 11 December 2025. Two of them fix the wording of the commencement rule itself.
Why it matters: The corrected wording is the operative text. Anyone quoting the Rules must apply these corrections.
Status: in effect
What comes next
ImplementationUpcoming · computed date
Rule 4 and the Consent Manager provisions of the Act due to come into force
One year after publication, the registration and obligations framework for Consent Managers is due to start operating: Rule 4 on the Rules side, and section 6(9) and section 27(1)(d) of the Act. The calendar date shown is computed from the publication dates and is presented as interpretation until officially confirmed.
Why it matters: Consent Managers can only be registered once Rule 4 operates, per Rule 1(3). The matching Act provisions commence one year from the publication of notification G.S.R. 843(E).
Status: upcoming; dates derived from Rule 1(3) and G.S.R. 843(E), interpretation until officially confirmed
ImplementationUpcoming · computed date
The main obligations of the Act and the Rules due to come into force
Eighteen months after publication, the main operational provisions are due to start on both sides: Rules 3, 5 to 16, 22 and 23, and the core of the Act, meaning sections 3 to 5, most of section 6, and sections 7 to 17 (application, grounds, notice, consent, obligations of Data Fiduciaries, children's data and the rights of Data Principals), section 27 other than 27(1)(d), sections 28 to 34, 36 and 37, and section 44(2). Section 6(9) is not in this group; it commences a year earlier. The calendar date shown is computed from the publication dates and is presented as interpretation until officially confirmed.
Why it matters: This is the date most organisations are working towards, per Rule 1(4) and paragraph (c) of notification G.S.R. 843(E).
Status: upcoming; dates derived from Rule 1(4) and G.S.R. 843(E), interpretation until officially confirmed
A note on earlier history. Milestones before 2023, including the constitutional privacy judgment, the expert committee stages and the earlier bills, are being verified against their primary sources and will appear here once confirmed. We would rather show a shorter verified timeline than an unverified longer one.