India's Digital Personal Data Protection Act was passed in 2023, but it only started to bite when MeitY notified the Digital Personal Data Protection Rules, 2025 in mid-November 2025 (the gazette notification is dated 13 November). The Rules didn't switch everything on at once. They set up an 18-month, three-stage rollout, and the second stage is now weeks away: 13 November 2026.
If your business feeds customer data into AI tools — a chatbot answering support queries, a transcription tool recording sales calls, an LLM summarising CRM notes — this timeline matters to you, even though most of the obligations that will affect you directly arrive later. This post sets out what each date actually does, based on the notified Rules and dated reporting, and what you can sensibly do before either deadline.
The three dates
13 November 2025: the Rules were notified and the institutional provisions took effect, including the legal constitution of the Data Protection Board of India, the body that hears complaints and imposes penalties.
13 November 2026: the Consent Manager framework under Rule 4 becomes operative. A Consent Manager is a registered intermediary that lets a person give, review and withdraw consent across multiple businesses from one interoperable dashboard, rather than hunting through each company's settings. To register, a Consent Manager must be a company incorporated in India with a net worth of at least ₹2 crore, and it registers with the Data Protection Board.
13 May 2027: the substantive obligations for everyone else — clear notices, valid consent, reasonable security safeguards, breach reporting, honouring data principals' rights to access, correction and erasure, and data retention and deletion rules. This is the date that turns the Act into day-to-day operational work for an ordinary business.
The awkward part: the Board still isn't staffed
The Data Protection Board exists in law, but as of early August 2026 it had no appointed Chairperson and no appointed Members. MeitY invited applications for those posts in a notification dated 6 May 2026 and issued a further notification on 6 June 2026, but reporting in LiveLaw on 1 August 2026 found the selection committees still at the stage of soliciting names. That creates an obvious problem for 13 November: Consent Managers are meant to register with a Board that, on current reporting, isn't yet able to take registrations.
It would be a mistake to read that gap as a delay to the deadline. The 13 November and 13 May dates are fixed in a notified rule, and nothing has been published that moves them. What's genuinely uncertain is how quickly the Board can start registering Consent Managers and hearing complaints — not whether the obligations exist.
Why this matters when you use an AI tool
Under the DPDP Act, the business that decides why and how personal data is processed is the "data fiduciary". When you paste a customer's details into an AI assistant or connect it to your helpdesk, you are almost always the fiduciary, and the AI vendor is acting as your "data processor". Section 8 of the Act is blunt about the consequence: the fiduciary stays responsible for compliance even when a processor does the actual processing, and may engage a processor only under a valid contract.
In practice, that means a vendor's own compliance claims don't transfer the risk to them. If an AI tool leaks or misuses your customers' data, the Act looks first at you. The penalty schedule in the Act runs up to ₹250 crore for failing to take reasonable security safeguards and up to ₹200 crore for failing to report a breach, so "we used a well-known tool" is not a defence worth relying on.
Cross-border transfer is less restrictive than many people assume. Section 16 lets the government restrict transfers to specific countries, rather than requiring data to stay in India by default. But sector rules that are stricter still apply on top — RBI's payment-data storage requirements are the familiar example — so a bank, NBFC or payments business can't treat the DPDP Act as the only test.
What to ask an AI vendor before May 2027
Is there a data processing agreement? You need a written contract that sets out what the vendor may do with your data. Consumer sign-up terms usually aren't enough for business use; many AI vendors keep a separate business or API agreement with a DPA attached.
Is my data used to train your models, and can I switch that off? This is the question that most often separates a consumer plan from a business plan of the same product. Get the answer in the contract, not a help-centre article.
Where is the data stored and processed? Even without a blanket localisation rule, you need to know the regions involved to answer your own customers, and to satisfy sector regulators where they apply.
Can you delete a specific person's data on request, and how fast? From May 2027 you'll have to act on erasure requests, which means your vendors have to be able to act on yours.
Will you tell us about a breach, and how quickly? You can only report a breach you know about. A vendor contract with a specific notification window is what makes your own reporting obligation workable.
How we track this on AIproducts.in
Every tool page in our catalogue carries a DPDP posture line (documented, partial, none or unknown) alongside the India-readiness checks. It is deliberately not one of the seven points in the India-readiness score, because DPDP compliance isn't a simple yes/no friction check the way INR billing or a GST invoice is — see our About & methodology page for how it's set. Treat it as a starting point for the questions above, not as a substitute for reading the vendor's data processing terms.
What we don't know yet
Three things are still open as of this post: when the Board's Chairperson and Members will actually be appointed; whether the Consent Manager registration process will be accepting applications on 13 November; and how the Board will approach enforcement in its first year. We'll update this post when any of those change. None of this is legal advice — for obligations specific to your business, talk to a lawyer who works on data protection.