DPDP May 2027 Deadline. Live countdown to hard enforcement.
DPDP Rules 2025 gave every Indian Data Fiduciary 18 months to become compliant. That window closes on 13 May 2027 — with penalties up to ₹250 crore active from Day 1 and zero grace period. Below is the exact 12-month sequence that gets you there, and the phase-by-phase deadlines you should not miss along the way.
No grace period. Full Schedule 1 penalty framework applies from 00:00 IST.
Every DPDP deadline you should not miss
DPDP Act 2023 enacted
The Digital Personal Data Protection Act receives presidential assent. Institutional structure defined.
DPDP Rules 2025 notified
MeitY publishes the operational Rules. 18-month implementation window begins.
Implementation window (18 months)
DPB constituted. Consent Manager registrations open. Soft enforcement — DPB guidance and warnings, but no formal penalty adjudication of substantive violations. This is your window.
Consent Manager registration deadline
Any entity intending to operate as a Consent Manager must be registered with the DPB by this date. ₹2 crore net worth requirement, interoperable API, 22-language support. Registration guide.
DPDP Act full enforcement
Every Data Fiduciary must have: valid consent for all processing, published privacy notice in 22 languages, live DSR portal, breach response playbook (72h DPB + 6h CERT-In), signed vendor DPAs, DPIA library, retention schedule, cross-border transfer register. Full Schedule 1 penalty framework — up to ₹250 crore per violation type. No grace period.
What to ship in what month to hit 13 May 2027
Sequenced for a mid-market Indian business starting today. dcomply\'s Onboarding Wizard drives this exact schedule automatically.
What you are exposed to on 13 May 2027
Penalties are cumulative per violation, per inquiry. A single incident touching multiple obligations can compound. Companies with demonstrated compliance programmes get materially lower penalties — that is the only mitigation.
May 2027 deadline FAQ
Is 13 May 2027 really the DPDP hard-enforcement deadline?
Yes. DPDP Rules 2025 were notified by MeitY on 14 November 2025 with an 18-month implementation window. That places the hard-enforcement date at 13 May 2027. From that day, the Data Protection Board can adjudicate any DPDP violation with the full Schedule 1 penalty framework (up to ₹250 crore per violation).
What is enforced before May 2027?
DPB institutional provisions are already active (2026). Consent Manager registration window closes 13 November 2026. Breach reporting to the DPB is possible today under the Act itself. What May 2027 activates is the FULL penalty framework and formal DPB adjudication of consent, DSR, DPIA and retention obligations.
We are only 10 months out. Is it too late to start?
No, but it is tight. Realistic implementation for a mid-market Indian business is 6-9 months (discovery, implementation, testing, evidence). A 12-month runway is comfortable; a 6-month sprint is possible with a dedicated project manager. Starting after Q1 2027 is a real risk. dcomply's 12-month plan below sequences everything correctly.
What if we simply do nothing?
From 13 May 2027 you are exposed to Schedule 1 penalties for every non-compliant processing activity. Typical exposure: failure to notify breach = ₹200 Cr, failure to protect PII = ₹250 Cr, consent violations = ₹150 Cr per instance. The DPB has said it will not apply maximums against companies with a demonstrated programme — but doing nothing removes that mitigation.
Is there a grace period after May 2027?
No. The 18-month notification window IS the grace period. From 13 May 2027, penalty framework applies from Day 1.
How does the 12-month plan below actually work?
It sequences the 6 things that must ship before enforcement: (1) gap assessment, (2) processing register, (3) consent + privacy notice, (4) DSR portal, (5) vendor DPA chain, (6) breach + DPIA playbooks. Each month unlocks the next. dcomply's Onboarding Wizard drives this sequence automatically.
We have GDPR. Are we ready for DPDP?
You are ~70% ready. GDPR and DPDP overlap on: consent principles, DSR, breach notification, purpose limitation, security safeguards, DPO for large processors. They differ on: legal basis (GDPR 6 vs DPDP consent + 4 legitimate uses), children's consent (GDPR 16, DPDP 18), cross-border (GDPR adequacy vs DPDP whitelist), consent manager (DPDP-unique), languages (DPDP mandates 22 Indian languages). Fixing the 30% gap takes 6-8 weeks with dcomply.
What happens on 13 May 2027 for consumers?
From that day, Indian data principals can file DPDP complaints with the DPB. The DPB's digital portal (already live for institutional matters) opens to consumer complaints. Every Data Fiduciary must have DSR intake, grievance mechanism (Section 13), and a published DPO / responsible person by then.
Every day you wait is a day of exposure.
Start the 12-month plan today. Free tenant. Owner-led. Compliant by May 2027 without emergency spending.