India's Digital Personal Data Protection Act spent 27 months as a statute without force - assented on 11 August 2023, dormant until the government notified the DPDP Rules, 2025 in mid-November 2025 (G.S.R. 846(E), dated 13 November 2025). What commenced then was not the law but a timetable: a three-phase rollout ending in May 2027, a Data Protection Board that exists on paper but has no members, and a penalty schedule that cannot yet be invoked. This tracker keeps the moving parts in one place, each cited to the gazette or a primary source, and is refreshed quarterly. It pairs with our DPDP compliance guide, which covers what to do; this page tracks where enforcement actually stands. Status as of 21 July 2026. This is legal information, not legal advice - confirm anything you rely on with counsel in your jurisdiction.

Where DPDP enforcement stands right now

The one-paragraph status: the machinery provisions are in force; the obligations are not; nobody has been fined; the Board has no members. The commencement notification (G.S.R. 843(E), 13 November 2025) split the Act into three phases - immediate, 12 months, 18 months. As of July 2026, only phase one binds: definitions, the Data Protection Board's establishment provisions, rule-making powers, and - most controversially - the Section 44(3) amendment to the RTI Act. Consent, notice, security safeguards, breach notification, data-principal rights, and the penalty regime all arrive with phase three in May 2027.

The phased timeline: what binds when

The operative dates, from the commencement notification and Rule 1(2)-(4) of the DPDP Rules, 2025 (deadlines are expressed in the gazette as one year / eighteen months from publication; most trackers render them as 13 November 2026 and 13 May 2027):

PhaseEffectiveWhat commences
1 - Machinery13 Nov 2025Definitions (s.2); Data Protection Board establishment and machinery (ss.18-26); s.35 good-faith protection; rule-making and miscellaneous (ss.38-43, 44(1)); the s.44(3) RTI amendment; Rules 1-2 and 17-21 (Board appointments, salaries, digital-office functioning)
2 - Consent managersNov 2026 (12 months)Section 6(9), s.27(1)(d); Rule 4 - registration and obligations of consent managers (First Schedule conditions: Indian company, net worth at least Rs 2 crore)
3 - Substantive obligationsMay 2027 (18 months)Everything else: consent and notice (ss.4-7, Rule 3), security safeguards (s.8(5), Rule 6), breach notification (s.8(6), Rule 7 - detailed report to the Board within 72 hours), retention/erasure (Rule 8), children's data (s.9, Rules 10-12), Significant Data Fiduciary duties (s.10, Rule 13), data-principal rights (ss.11-14, Rule 14), cross-border conditions (s.16, Rule 15), inquiries and the penalty regime (ss.27-28, 33 with the Schedule)

One live variable: MeitY consulted in early 2026 on compressing the window for Significant Data Fiduciaries - large platforms, banks, and similar - to 12 months (November 2026). No gazette amendment had issued as of July 2026, and SDF designation criteria remain un-notified; treat the acceleration as a proposal, not law, and watch for a notification.

The Data Protection Board: established, unstaffed

The Data Protection Board of India legally exists - and has zero members. G.S.R. 844(E) established the Board with effect from 13 November 2025 (head office in the National Capital Region), and G.S.R. 845(E) fixed its strength at a chairperson plus four members. The recruitment reality has lagged: the Economic Times reported in April 2026 that the selection committees themselves had not been notified five months after establishment, and MeitY's circular of 6 May 2026 finally invited applications for the chairperson and all four member posts. As of this page's July 2026 verification, no appointments had been announced.

The design, when staffed, is a "digital by design" adjudicator: complaints filed and tracked online, inquiries conducted digitally, appeals to the Telecom Disputes Settlement and Appellate Tribunal. Until then the practical consequence is simple - there is no functioning forum: no complaints adjudicated, no penalty orders, no published enforcement posture. (One curiosity for the record: the Madhya Pradesh High Court directed a petitioner toward the Board in April 2026 - a forum that could not yet hear anyone.)

The penalty schedule: what exposure looks like

The Schedule to the Act (read with s.33) sets per-violation maxima - discretionary, with no minimums and no criminal sanctions, and imposable only once phase three commences:

ViolationProvisionMaximum penalty
Failure to take reasonable security safeguardss.8(5)Rs 250 crore
Failure to notify a breach to the Board / data principalss.8(6)Rs 200 crore
Breach of children's-data obligationss.9Rs 200 crore
Breach of Significant Data Fiduciary obligationss.10Rs 150 crore
Any other breach-Rs 50 crore
Breach of data-principal dutiess.15Rs 10,000

Section 33's factors (gravity, repetitiveness, proportionality) govern quantum, and s.42 lets the government amend the Schedule - capped at doubling the enacted figures. The scale of the affected population frames the stakes: TRAI counted 1,028.61 million internet subscribers in India as of 31 December 2025 - the data-principal base these duties will run to.

The Act's most novel institution - the registered consent manager, an interoperable platform through which individuals give, manage, and withdraw consent - is still entirely prospective. Registration conditions sit in the Rules' First Schedule (an Indian-incorporated company, net worth of at least Rs 2 crore, conflict-of-interest safeguards), but Rule 4 does not commence until November 2026, the Board that would register applicants has no members, and zero consent managers were registered as of mid-2026. Businesses building consent flows should design for the framework's arrival without waiting on it: the substantive consent standard (free, specific, informed, unconditional, unambiguous - no bundling) binds directly from May 2027 whether or not a consent-manager ecosystem exists by then.

The Section 44(3) RTI flashpoint and the court challenge

The one substantive change already in force is the most contested: Section 44(3), effective 13 November 2025, rewrote s.8(1)(j) of the Right to Information Act so that "information which relates to personal information" is exempt from disclosure - deleting the old public-activity and public-interest tests. Over a hundred opposition MPs demanded its repeal in 2025; the government maintains the DPDP Act and RTI regime are in harmony.

The dispute is now constitutional: writ petitions challenging s.44(3) (and other provisions, including the Board's composition rules) were filed in early 2026, and on 16 February 2026 a bench headed by the Chief Justice issued notice, declined any interim stay, and referred the challenge to a five-judge Constitution Bench (Supreme Court Observer case page). The matter was pending as of July 2026. For compliance teams the takeaway is procedural: the Act's architecture could yet be adjusted by the Court mid-rollout - one more reason this page carries a verification date.

How India's runway compares with the GDPR's

India's staggered rollout is long by global standards - useful context when calibrating urgency:

MilestoneGDPR (EU)DPDP (India)
Text finalisedApril 2016 (adopted)August 2023 (assent)
Rules / application detailsIn the Regulation itselfNovember 2025 (Rules notified)
Obligations apply25 May 2018 - all at once (~25 months)Phased: Nov 2026 and May 2027 (~45 months from assent)
Regulator ready on day oneYes - existing national DPAsNo - Board established Nov 2025, unstaffed as of Jul 2026
First major fine~8 months after application (CNIL v Google, EUR 50m, Jan 2019)None possible before May 2027

The GDPR precedent suggests enforcement follows readiness quickly once obligations bite: the CNIL's EUR 50 million Google fine landed within a year of application, on complaints filed the day GDPR became applicable. Indian organisations reading the long runway as low urgency are making a timing bet on a Board that will, by May 2027, have had a year to staff up and a complaint portal designed for volume. Our comparison of the two regimes' substance is in the DPDP compliance guide; the short version is that GDPR programmes need real adaptation - consent standards, Eighth Schedule language notices, no legitimate-interests basis, 72-hour Board reporting - not relabelling.

What legal teams should do with the time

Three uses of the runway earn their keep. Data mapping first: phase-three duties (notice per processing purpose, erasure timelines, rights fulfilment) are impossible without knowing what personal data sits where - and in most Indian organisations that inventory does not exist yet. Contract and vendor paper: data-processing terms, breach-notification flow-downs, and the cross-border conditions of Rule 15 take procurement cycles to land, and the documents live in exactly the repositories AI review handles well - a review matrix across the vendor-contract estate ("does this contract contain breach-notification obligations? erasure terms? cross-border transfer language?") is the fast way to scope the remediation. Board-watching: appointments, SDF designation, and any gazette acceleration are the three triggers that convert this tracker's "not yet" rows into deadlines. For teams running that monitoring and gap analysis, Judicio's research and review tools are free to trial for 7 days - 500 credits, no card required. See also our India jurisdiction hub for the wider regulatory picture.

Sources and methodology

Primary sources, linked in place: the DPDP Act gazette text (11 August 2023) and its Schedule; commencement notification G.S.R. 843(E), Rules G.S.R. 846(E), Board establishment G.S.R. 844(E) and strength G.S.R. 845(E) (all dated 13 November 2025 - PIB's release of 14 November describes the same instruments); the PIB explainer; MeitY's recruitment circular of 6 May 2026; the Supreme Court Observer's case page on the constitutional challenge; TRAI's performance-indicator report for October-December 2025; and CNIL deliberation SAN-2019-001 for the GDPR comparison. Where reporting conventions differ (13 vs 14 November publication; 12 vs 13 month-boundary dates), we state the gazette formulation and note the variance.

Methodology: every row above is keyed to a gazette notification or named primary document; proposals (the SDF acceleration) are labelled as proposals; absences (no Board members, no consent managers, no enforcement actions) are verified as absences against multiple mid-2026 sources rather than assumed. This tracker is refreshed quarterly - faster if a commencement-changing notification issues. Legal information, not legal advice.