HomeLatest NewsGovTechDPDP compliance deadline set for May 2027 as India phases in data law

DPDP compliance deadline set for May 2027 as India phases in data law

Businesses collecting personal data from Indian citizens will have until May 2027 to comply with core DPDP obligations covering data principal rights, security safeguards and breach reporting.

Preferred Source of Google

Key Points

  • DPDP compliance for data fiduciaries to take effect within 18 months of November 2025 rules notification
  • Data Protection Board recruitment advertisement published in Employment News on 6 June 2026
  • Government clarifies CSC Village Level Entrepreneurs not classified as data fiduciaries

Businesses and organisations that collect personal from Indian citizens will have until May 2027 to comply with core obligations under India’s data protection law, the government told the on Wednesday (12 August), outlining a three-phase implementation of the Digital Personal Data Protection framework.

Jitin Prasada, minister of state for Electronics and Information Technology, said in a written reply that compliance requirements covering data principal rights, security safeguards and breach reporting will come into force within 18 months of the notification of the Digital Personal Data Protection Rules, 2025. The rules were notified on 13 November 2025, placing the compliance deadline around May 2027.

Advertisement
Infosec Reimagined
Infosec Reimagined
Infosec Reimagined 2026 is the premier information security summit where top leaders—CISOs, CROs, CIOs, CTOs and risk executives—converge to redefine cyber resilience.
Register Now →
Digital Senate
Digital Senate
Digital Senate is a premier conference uniting government leaders, technologists and innovators to share ideas, success stories and strategies on digital governance, public sector transformation, cybersecurity and emerging technologies in India.
Register Now →
CIO Prism
CIO Prism
CIO Prism unites forward-thinking technology leaders to exchange transformative insights, shape digital strategies, and foster innovation, empowering enterprises to excel in an era of rapid technological change.
Register Now →
National DefTech Summit
National DefTech Summit
Featuring keynotes, expert panels, live tech demos and strategic networking, the summit will drive actionable insights for defence sector.
Register Now →
Future-Ready Defence
Future-Ready Defence
A Leadership Dialogue on sovereign, trusted data infrastructure, AI readiness and mission resilience for Defence Forces.
Register Now →

The phased approach gives companies and government bodies time to build systems for handling personal data lawfully. Under the DPDP Act, 2023, a data fiduciary is any person or organisation that decides why and how to process someone’s personal data. A data principal is the person whose data is being collected, meaning an ordinary citizen whose name, phone number, address or other identifying information is held by a company or government department.

The first phase covers establishing the Data Protection Board of India, the body that will hear complaints from citizens and impose penalties on organisations that violate the law. The government said the Board will have a chairperson and four members, appointed through a selection committee. An advertisement for these positions was published in the Employment News on 6 June 2026. The Board is required to function digitally, meaning citizens can file complaints online without travelling to a physical office.

By the numbers

Advertisement
18 months
Transition period for data fiduciary compliance
5.8 lakh
Common Service Centres operated by VLEs
90 days
Maximum grievance redressal period

The second phase, due within one year of the rules notification, provides for registering consent managers, organisations that will help citizens give, withdraw and manage their consent for data processing. This milestone falls around November 2026.

Compliance obligations

The third phase brings the substantive obligations that will affect every company holding . Once these provisions take effect, data fiduciaries must maintain valid contracts with any data processors they use, meaning third-party vendors who handle data on their behalf. They must provide notices in 22 Indian languages explaining what data they collect and why. They must obtain meaningful consent where required and implement reasonable security safeguards to prevent breaches.

Data fiduciaries will also have to respond to citizen requests. If a person asks to see what data a company holds about them, or asks for incorrect information to be corrected or deleted, the company must act. Every data fiduciary must publish on its website or app the time period within which it will address grievances. This period cannot exceed 90 days.

Advertisement

Organisations must also personal data breaches to the Data Protection Board and comply with other obligations under the Act and Rules. Data processors, which handle data on behalf of fiduciaries, must implement their own security safeguards and stick to the terms of their processing agreements.

The clarification came in response to a question from BJP MP Karan Bhushan Singh, who asked whether Village Level Entrepreneurs operating more than 5.8 lakh Common Service Centres qualified as data fiduciaries. These VLEs help citizens in rural areas access government services involving Aadhaar, banking and health records.

The government did not classify CSC Village Level Entrepreneurs as data fiduciaries. It said CSC e-Governance Services India Limited provides assisted access to digital services through VLEs, who help citizens understand and access government services. A CSC VLE is not authorised to collect or store citizens’ data while providing such services, the government said. Under the framework, whether an entity counts as a data fiduciary depends on whether it determines the purpose and means of processing personal data.

Responding to a question on awareness of data protection rights among rural citizens, particularly in aspirational districts such as Gonda, the government said training programmes are being conducted across sectors to strengthen IT security capabilities. Initiatives including Cyber Security Awareness Month, Safer Internet Day, workshops and digital outreach campaigns are being used to educate citizens about online safety, secure digital transactions and their rights under the DPDP Act.

Your Questions, Answered

When do DPDP compliance obligations take effect for data fiduciaries?

Compliance obligations covering data principal rights, security safeguards and breach reporting take effect within 18 months of the November 2025 rules notification, placing the deadline around May 2027.

What is a data fiduciary under the DPDP Act?

A data fiduciary is any person or organisation that determines why and how to process someone's personal data. This includes companies collecting customer information and government bodies handling citizen data.

Are CSC Village Level Entrepreneurs classified as data fiduciaries?

The government said CSC VLEs are not authorised to collect or store citizens' data while providing services. Whether an entity is a data fiduciary depends on whether it determines the purpose and means of processing personal data.

What is the Data Protection Board of India?

The Data Protection Board is the body that will hear complaints from citizens and impose penalties on organisations violating the DPDP Act. It will have a chairperson and four members and is required to function digitally.

NEWSLETTERThe Daily BriefingThe day's top enterprise technology stories, curated by our editors. Monday to Friday.

Free. One-click unsubscribe anytime. We never share your email.

Tooba Aslam
Tooba Aslam
Tooba Aslam is a Correspondent at Tech Observer Magazine, covering startups, industry and advertising and marketing. With a degree in marketing, she brings a balanced perspective to reporting on innovation and market trends.
Advertisement
- Advertisement -
- Advertisement -

CSC operators cannot store Aadhaar or banking data, MeitY tells Parliament

Village Level Entrepreneurs at over 5.8 lakh Common Service Centres cannot collect or store citizen data including Aadhaar and banking records, the government has clarified in Parliament. The response also detailed the phased DPDP Act implementation timeline.

RELATED ARTICLES