KYCKART
KYCKART Guide · September 2026Regulatory Explainer

The DPDP Compliance Timeline: When the DPDP Rules 2025 and the DPDP Act Commence for Banks and NBFCs

The DPDP Rules 2025 and the DPDP Act commence in three tranches from 13 November 2025. What each tranche brings into force for a bank or NBFC, how obligations map to existing RBI frameworks, and why the eighteen-month tranche carries the core compliance weight.

calendar_monthSeptember 11, 2026
schedule21 min read
library_books15 Cited Sources
personBhanujeet Choudhary, Head of Compliance
The DPDP Compliance Timeline: When the DPDP Rules 2025 and the DPDP Act Commence for Banks and NBFCs
01KYCKART Regulatory Analysis

When Does the DPDP Act Take Effect?

The three-stage statutory schedule and the core eighteen-month compliance tranche

The DPDP regime commences in stages under two separate instruments, both dated 13 November 2025. The Act’s own sections commence on the schedule set by G.S.R. 843(E); the Digital Personal Data Protection Rules, 2025 commence on the schedule set by Rule 1 of G.S.R. 846(E). Each instrument uses three triggers: the date of publication, one year after publication, and eighteen months after publication, which compute to 13 November 2026 and 13 May 2027 from the 13 November 2025 publication date. Neither instrument prints those two calendar dates; both express the trigger as a period running from publication. Both instruments print 13 November 2025 as their date, and a 14 November 2025 dating shifts each computed phase by one day. This page follows the date printed on the instruments.

The substantive obligations that most affect a bank or NBFC, including notice, security safeguards, breach intimation, erasure and cross-border conditions, sit in the eighteen-month tranche and are not yet in force.

“(2) Rules 1, 2 and 17 to 21 shall come into force on the date of their publication in the Official Gazette. (3) Rule 4 shall come into force one year after the date of publication of this Gazette. (4) Rules 3, 5 to 16, 22 and 23 shall come into force eighteen months after the date of publication of this Gazette.”

: Rule 1, DPDP Rules, 2025

What the Act is, its principles and its rights catalogue are covered on the DPDP Act pillar page. This page covers when the obligations commence.

02KYCKART Regulatory Analysis

Two Instruments, Two Schedules

Comparing the Act's section-level rollout with the Rules' rule-level schedule

The two commencement schedules share the same three triggers, so the dates line up. What commences in each tranche does not map one to one, which is why the two schedules are set out separately below.

Schedule A: the Act’s own sections, per G.S.R. 843(E)

TriggerProvisions of the Act appointedSubject matter
Date of publication, 13 November 2025 (one day later on a 14 November dating)s.1(2), s.2, ss.18 to 26, ss.35, 38, 39, 40, 41, 42, 43, and s.44(1) and (3)Includes the Board’s establishment and composition provisions at ss.18 to 26, and section 38’s rule that the Act is in addition to and not in derogation of other law in force
One year after publication, computed as 13 November 2026 (one day later on a 14 November dating)s.6(9) and clause (d) of sub-section (1) of section 27Pairs with Rule 4, Consent Manager registration and obligations
Eighteen months after publication, computed as 13 May 2027 (one day later on a 14 November dating)ss.3 to 5, s.6(1) to (8) and (10), ss.7 to 10, ss.11 to 17, s.27 except clause (d) of sub-section (1), ss.28 to 34, ss.36, 37 and s.44(2)The substantive obligations and rights, the section 17 exemptions, and the Board’s remaining powers

Schedule B: the Rules, per G.S.R. 846(E)

The Rules were made under sub-sections (1) and (2) of section 40 of the Act, after a draft published as G.S.R. 02(E) dated 3 January 2025 and a forty-five-day public objection period.

TriggerRules in forceSubject matter
Date of publication, 13 November 2025 (one day later on a 14 November dating)Rules 1, 2 and 17 to 21Definitions, plus the Board’s own appointment, salary and terms, meetings, digital-office functioning and staffing machinery
One year after publication, computed as 13 November 2026 (one day later on a 14 November dating)Rule 4Registration and obligations of Consent Manager
Eighteen months after publication, computed as 13 May 2027 (one day later on a 14 November dating)Rules 3, 5 to 16, 22 and 23Notice, State-processing, security safeguards, breach intimation, erasure timing, contact information, children’s and guardianship consent, Significant Data Fiduciary obligations, rights of Data Principals, cross-border transfer, the research exemption, appeals to the Appellate Tribunal and calling for information

On publication the Rules brought live only definitions and the Board’s internal machinery, while the Act brought live the Board’s establishment and composition provisions. At one year, Rule 4 pairs with Act sections 6(9) and 27(1)(d). At eighteen months, the Act’s substantive obligations, rights and exemptions arrive alongside Rules 3, 5 to 16, 22 and 23.

Definitions of the roles used throughout sit on the sibling pages for Data Fiduciary, Data Processor, Consent Manager and the Data Protection Board of India.

What commences on 13 November 2026

The one-year tranche in G.S.R. 843(E) contains two items only: section 6(9) and clause (d) of sub-section (1) of section 27. Section 27 generally, and sections 28 to 34, sit in the eighteen-month tranche. The dpdprules.org commencement timeline describes the one-year mark the same way, as Rule 4 and the Consent Manager provisions.

So the Board’s power to inquire and levy penalties does not arrive at the one-year mark. G.S.R. 843(E) appoints section 27 apart from clause (d) of sub-section (1), and sections 28 to 34, eighteen months after publication.

The same point applies to the publication date. G.S.R. 843(E)brought sections 18 to 26 into force on 13 November 2025, covering establishment, composition, appointment, terms, officers and meetings. The Board’s powers under section 27, apart from clause (d) of sub-section (1), commence with the eighteen-month tranche.

03KYCKART Regulatory Analysis

Phase by Phase: What the Eighteen-Month Tranche Adds for an RBI-Regulated Entity

Mapping new statutory controls against existing banking compliance baselines

Several of the eighteen-month obligations land on control frameworks that are already in force for RBI-regulated entities. The table maps each one against those existing frameworks, scoped to the entity list the RBI IT outsourcing directions address: scheduled commercial banks excluding RRBs, local area banks, small finance banks, payments banks, primary (urban) co-operative banks, NBFCs, credit information companies and all-India financial institutions.

DPDP obligation (eighteen-month tranche, not yet in force)Already in force for an RBI-regulated entityWhat the DPDP instruments add
Rule 7: breach intimation to the Board without delay, then detailed information within seventy-two hoursCERT-In’s April 2022 directions (No. 20(3)/2022-CERT-In, 28 April 2022) require mandatory reporting of cyber incidents, including data breach and data leak, within six hours; RBI/2023-24/102 paragraph 17(h) to (i) requires reporting to RBI within six hours of detection by the third-party service provider and immediate notification on leakage of confidential customer informationA new recipient (the Board), a second-stage seventy-two-hour detailed filing, and a direct intimation to each affected Data Principal with a prescribed content list
Rule 6(1): security safeguards, including a contractual clause with the Data ProcessorParagraph 16 of RBI/2023-24/102 already mandates confidentiality controls, service-provider liability for security breach and leakage, audit rights extending to sub-contractors, and prior approval for sub-contractingA specific contractual provision for reasonable security safeguards as Rule 6(1) defines them, and the duty attaching to the Data Fiduciary for processing undertaken by or on behalf of a Data Processor
Section 8(7) erasure duty and Rule 8(3) minimum retentionPMLA section 12 five-year floors; paragraph 46 of RBI’s Master Direction : Know Your Customer (KYC) Direction, 2016 (RBI/DBR/2015-16/18, Master Direction DBR.AML.BC.No.81/14.01.001/2015-16, dated 25 February 2016, as updated to 14 August 2025) requiring transaction records for at least five years and identification records for at least five years after the relationship ends; paragraph 38, Updation / Periodic Updation of KYC, setting periodic updation at two, eight and ten years by risk categoryThe Third Schedule erasure clock does not name any financial-sector class. What applies on commencement is the section 8(7) erase-on-withdrawal duty with its compliance-with-law carve-out, and Rule 8(3)’s one-year minimum for processor-handled data and logs
Rule 13(4) and Rule 15: cross-border restrictionsParagraph 16 of RBI/2023-24/102 requires storage of data only in India as applicable per extant regulatory requirementsA no-transfer restriction on Government-specified personal data for Significant Data Fiduciaries, and Rule 15’s general-or-special-order regime, both dependent on notifications that had not been published as at mid-2026

Breach intimation: a new recipient and a second trigger, both from the eighteen-month tranche

Rule 7(2), once it commences, sets two filings to the Board. The first, without delay, describes the nature, extent, timing and location of the breach and its likely impact. The second, within seventy-two hours of becoming aware or such longer period as the Board may allow on written request, carries updated and detailed information, the broad facts and reasons, mitigation measures implemented or proposed, findings on the person who caused the breach, remedial measures to prevent recurrence, and a report on the intimations given to affected Data Principals.

Rule 7(1), commencing in the same tranche, runs to the customer. On becoming aware of any personal data breach, the Data Fiduciary is to intimate each affected Data Principal, to the best of its knowledge, in a concise, clear and plain manner and without delay, through her user account or any registered mode of communication. The content is prescribed: the nature, extent and timing of the breach, the consequences relevant to her, mitigation measures implemented, safety measures she may take, and business contact information of a person able to respond to her queries.

Set against that, CERT-In’s April 2022 directions took effect on 27 June 2022, with an extension to 25 September 2022 for MSMEs, and separately require ICT system logs to be maintained for a rolling 180 days within Indian jurisdiction. Lexology’s summary and the Internet Society’s impact brief both record the same notification number, six-hour reporting rule, effective date and 180-day log requirement.

Vendor governance: existing outsourcing clauses, plus a DPDP processor clause

The RBI (Outsourcing of Information Technology Services) Directions, 2023, issued by circular RBI/2023-24/102, reference DoS.CO.CSITEG/SEC.1/31.01.015/2023-24, dated 10 April 2023, came into effect from 1 October 2023. Their stated underlying principle is to ensure that outsourcing arrangements neither diminish a regulated entity’s ability to fulfil its obligations to customers nor impede effective supervision by the RBI.

Paragraph 16 already reaches most of the contract surface DPDP touches: effective access by the regulated entity to data, books, records, logs and premises; the types of material adverse event that must be reported; compliance with the IT Act, 2000; India-only data storage as applicable; confidentiality controls and service-provider liability for breach and leakage; audit rights over the provider and its sub-contractors; regulator inspection rights; prior approval for sub-contracting; termination and orderly transfer; and a non-disclosure agreement covering retained information.

What Rule 6(1) adds, when it commences, is a named contractual requirement for reasonable security safeguards as that rule defines them: encryption, obfuscation, masking or virtual tokens; access controls on computer resources; visibility on access through logs, monitoring and review; measures for continued processing such as data backups; retention of those logs and the personal data for one year unless compliance with any law in force requires otherwise; the processor contract clause itself; and appropriate technical and organisational measures.

Retention: the Third Schedule erasure clock names no financial-sector class

Rule 8(1), which commences with the eighteen-month tranche, applies to a Data Fiduciary “who is of such class and is processing personal data for such corresponding purposes as are specified in Third Schedule”. The Third Schedule names three classes: an e-commerce entity with not less than two crore registered users in India, an online gaming intermediary with not less than fifty lakh registered users in India, and a social media intermediary with not less than two crore registered users in India. For each, the period is three years from the date the Data Principal last approached the Data Fiduciary for performance of the specified purpose or exercise of her rights, or the commencement of the DPDP Rules, 2025, whichever is latest, for all purposes except enabling access to her user account or a virtual token usable to get money, goods or services. No financial-sector class appears in that Schedule.

The forty-eight-hour advance notice under Rule 8(2), telling the Data Principal her data will be erased on completion of the period, hangs off the same Third Schedule mechanism and arrives on the same date.

Two other limbs do reach a bank or NBFC when the eighteen-month tranche commences. Section 8(7) requires erasure on withdrawal of consent or as soon as it is reasonable to assume the specified purpose is no longer being served, whichever is earlier, unless retention is necessary for compliance with any law for the time being in force. Rule 8(3) requires retention of personal data, associated traffic data and other processing logs for a minimum period of one year from the date of processing for the purposes specified in the Seventh Schedule, after which erasure follows unless further retention is required for compliance with any other law in force or notified by the Government.

How DPDP sits alongside PMLA and RBI retention rules

Section 38, in force since 13 November 2025 per G.S.R. 843(E), provides that the Act is in addition to and not in derogation of other law in force, and that where a provision of the Act conflicts with a provision of another law, the Act prevails to the extent of the conflict.

Both section 8(7) and Rule 8(1), when they commence, carve out retention necessary for compliance with any law for the time being in force. On the other side of that carve-out, PMLA section 12 requires a reporting entity to maintain records of all transactions in a manner enabling reconstruction of individual transactions, and records of documents evidencing client and beneficial-owner identity, account files and business correspondence, with transaction records held for five years from the date of the transaction and identity records for five years after the business relationship ends or the account is closed, whichever is later. Paragraph 46 of the KYC Master Direction, 2016, as updated to 14 August 2025, sets matching five-year floors.

The section 17 exemptions, which commence with the same eighteen-month tranche, cover processing necessary for enforcing a legal right or claim, for judicial, quasi-judicial, regulatory or supervisory functions, for prevention, detection, investigation or prosecution of offences, for processing non-resident data under a contract with a foreign entity, for court-approved schemes of merger, demerger, amalgamation or reconstruction, and for ascertaining financial information and assets or liabilities of a loan defaulter in accordance with insolvency law. Sub-section (2) covers notified State instrumentalities and research, archiving and statistical purposes, and sub-section (3) lets the Central Government notify classes of Data Fiduciary, including startups, out of specified provisions. None of those exemptions is framed by reference to a financial-sector regulator, a banking licence, or RBI regulation.

Rights handling and the identifier definition

Rule 14 takes effect with the eighteen-month tranche. Once it does, the Data Fiduciary, and where applicable the Consent Manager, publishes prominently on its website or app the means by which a Data Principal may make a rights request and the particulars required to identify her, and publishes, within a reasonable period not exceeding ninety days, the grievance redressal system, with technical and organisational measures ensuring the system responds within that period. The rule defines “identifier” to include a customer identification file number, customer acquisition form number, application reference number, enrolment ID, email address, mobile number or licence number.

Rule 3, commencing in the same tranche, sets the notice standard: independently understandable, in clear and plain language, with an itemised description of the personal data and the specified purposes including a specific description of the goods, services or uses enabled, plus the communication link and a description of other means by which she may withdraw consent with ease comparable to that with which it was given, exercise her rights, and make a complaint to the Board.

Rule 13, also an eighteen-month rule, will apply once in every twelve months from the date an entity is notified as a Significant Data Fiduciary, requiring a Data Protection Impact Assessment and an audit, a report of significant observations to the Board, due diligence that technical measures including algorithmic software do not pose a risk to Data Principals’ rights, and the no-transfer restriction on Government-specified data. The Central Government had not published a list of Significant Data Fiduciaries and the designation criteria under section 10 remained un-notified as at mid-2026, per two secondary aggregators.

04KYCKART Regulatory Analysis

The RBI Instrument That Already Exists

Supervisory guidance and ecosystem governance under RBI Advisory No. 3/2026

RBI’s Department of Supervision, through its Cyber Security and IT Risk Group, issued Advisory No. 3/2026 dated 25 March 2026 on best practices relating to customer data protection, addressed to RBI-supervised entities, according to published analyses by Consent.in and a Mondaq law-firm note. Those analyses describe it as based on a thematic study conducted across multiple categories of RBI-supervised entities in 2025, organised into twelve sections, with themes covering consent management, purpose limitation, breach notification, third-party risk and grievance redressal.

Consent.in characterises the advisory as non-binding rather than a binding direction, describes its sections as mapping onto the DPDP implementation roadmaps regulated entities are building, and reads its third-party-risk focus as a signal that regulators will hold supervised entities accountable for the data-protection practices of their whole ecosystem.

05KYCKART Regulatory Analysis

Transitional Relief and 2026 Sequencing

Absence of statutory grace periods and the reported 12-month compression proposal

Neither commencement instrument provides for a transitional or grace period. G.S.R. 843(E) and Rule 1 of the DPDP Rules, 2025 each appoint dates and stop there; the obligations in each tranche commence on the stated trigger.

There is also live movement on the trigger itself. On 23 January 2026 MeitY held stakeholder discussions with industry and proposed measures to fast-track implementation, including cutting the compliance window from eighteen months to twelve, which would move the final date from 13 May 2027 to 13 November 2026, with comments sought by 4 February 2026. The same reporting records a proposal that Rule 13(4) and Rule 15 be enforced immediately. As at 6 September 2026, no amending instrument giving effect to a shortened timeline had been located; the proposal remains reported-only and not formally notified.

06KYCKART Regulatory Analysis

Penalty Exposure

Enforcement machinery and statutory dispute routes under the eighteen-month tranche

The Board’s inquiry and penalty machinery sits in the eighteen-month tranche: section 27 except clause (d) of sub-section (1), and sections 28 to 34. The penalty Schedule, the complaint procedure and appeals to the Appellate Tribunal are covered on the Data Protection Board of India page. Rule 22, the appeal rule, commences in the same tranche.

07KYCKART Regulatory Analysis

What This Sequencing Means for a Bank or NBFC's 2026 Calendar

Practical interpretations for sequencing retention, reporting, and vendor controls

The observations below are this piece’s reading of the sourced material above. The instruments and sources cited earlier carry the facts; the conclusions drawn from them here are editorial.

Read together, the Third Schedule’s three named classes and the Rule 8(3) one-year minimum suggest the retention workstream for an RBI-regulated entity is mainly a documentation exercise. The automatic erasure clock applies to e-commerce, online gaming and social media classes at defined user thresholds, and a bank or NBFC appears in none of them. What would remain, once the eighteen-month tranche commences, is the section 8(7) duty with its compliance-with-law carve-out, and the PMLA and RBI KYC five-year floors already sit inside that carve-out. The practical implication is that the work is mapping each data category to the law that requires holding it, and being able to show that mapping.

Existing CERT-In and RBI reporting obligations already run to six hours, so a compliance team could reasonably read Rule 7’s seventy-two-hour window as slack. Rule 7(1) makes that reading look incomplete. The seventy-two-hour filing is a second-stage detailed submission to a new recipient, and it sits alongside a separate intimation running to each affected customer with a prescribed content list.

On the vendor side, paragraph 16 of RBI/2023-24/102, in effect since 1 October 2023, already requires confidentiality, breach-liability, audit, sub-contractor and India-storage clauses in the outsourcing agreement. That overlap suggests contract remediation under Rule 6(1) starts from an existing clause set, with the specific addition being a safeguards clause matching Rule 6(1)’s own list.

One forward-looking note, clearly a hypothesis rather than a forecast of regulator behaviour. If the MeitY proposal reported on 23 January 2026 were notified in the form described, the eighteen-month tranche would land on 13 November 2026 instead, and no amending instrument had been located as at 6 September 2026. Neither commencement instrument contains a transitional provision, and the only change reported so far would move the date earlier. On this piece’s reading, a 2026 plan aimed at the last months of the window therefore carries a timing risk that a plan aimed at an earlier internal target avoids.

KYCKART Regulatory Analysis

Frequently Asked Questions

Core determinations on commencement dates, banking deadlines, and transitional relief

This piece is informational and does not constitute legal, tax or compliance advice. Any institution planning against the dates set out above should have its own legal counsel review the position, and the application of these instruments to its own processing, before acting on it. Sourcing notes for the material above: the texts of G.S.R. 843(E) and G.S.R. 846(E) are cited from third-party mirrors carrying the Gazette of India Extraordinary masthead, Part II Section 3(i), the file number F. No. AA-11038/1/2025-CL&ES and the signature of Ajit Kumar, Jt. Secy., because indiacode.nic.in was not reachable; DPDP Act section texts are cited to a secondary aggregator rather than the official statute site; the RBI IT outsourcing circular is cited from a complete mirror PDF reproducing the RBI letterhead and circular number; the CERT-In directions and PMLA section 12 are cited from secondary summaries rather than primary texts; and the primary text of RBI Advisory No. 3/2026 is not publicly available, so its existence, section count and contents are reported here on the basis of two secondary analyses and should be confirmed against the RBI circular before being relied on.

BC
Bhanujeet Choudhary
Head of Compliance, KYCKART · Published September 11, 2026

DPDP Compliance Roadmap

Aligning Your Banking Architecture with the DPDP Implementation Schedule?

Speak with KYCKART’s compliance and technical specialists to understand how to sequence customer consent logging, vendor data protection agreements, and breach response systems well ahead of statutory commencement.

Speak with Our Compliance Teamarrow_forward