13 May 2027: a working plan for Data Fiduciaries
The DPDP Rules were notified on 13 November 2025 and apply in full on 13 May 2027. What to have in place each quarter between now and then.
By Promiz · Published · 5 min read · Based on the DPDP Act, 2023 and DPDP Rules, 2025 · Not legal advice
What are the dates?
The DPDP Rules, 2025 were notified on 13 November 2025, and the Data Protection Board was set up. Consent Manager provisions start on 13 November 2026, with an earlier date proposed for Significant Data Fiduciaries. On 13 May 2027 the notice, consent, rights, security, breach and erasure duties apply in full to every Data Fiduciary.
Confirm the dates that apply to you with your legal team, and check whether the proposed Significant Data Fiduciary date has been notified.
What should be done first?
Start with the inventory: every purpose you process personal data for, the legal basis for each, the retention period, and where the data flows. This list drives everything else - the notices, the consent choices, the retention clocks and the systems a withdrawal has to reach.
Then fix the record. Decide where consent will be stored, in what form, and how you will prove later what was shown. If the answer is a database table someone can edit, that is the first thing to change.
What comes next?
Publish the notices and collect consent per purpose across web, forms and any offline channel. Wire withdrawals to every downstream system and make each one confirm. Turn retention periods into clocks with legal holds where RBI, IRDAI or a dispute require data to be kept. Open the rights portal and the request queue with deadlines.
Set up the breach log before you need it. The 72-hour clock does not wait for a process to be written.
What should be ready by May 2027?
Evidence for each duty, ready to hand over: the notice versions and snapshots, the consent records and their integrity check, the closed withdrawal tasks with confirmations, the retention log with deletions confirmed, the rights requests with reply dates, and the breach log even if it is empty.
The readiness check on this site walks the twelve questions the Board would ask. Take it now and again a quarter before the deadline.