Others

Implementation Capacity and the DPDP Act Timeline

Raghav Pandey

The Digital Personal Data Protection Rules came into force on November 13 2025, with full compliance due by May 13, 2027, giving Indian businesses eighteen months to overhaul their data architecture, train personnel, redesign consent flows and build breach-notification infrastructure from scratch.

Eighteen months sounds reasonable until you compare it with what the rest of the world got when facing similar transitions. The European Union gave businesses two full years to prepare for the General Data Protection Regulation, from April 2016 to May 2018, and those additional six months proved essential for reasons that went beyond mere administrative convenience. The EU’s regulatory apparatus used that runway to issue detailed guidance, businesses piloted their compliance systems and discovered unanticipated problems and smaller players observed how larger competitors navigated the transition before committing their own limited resources to a particular compliance strategy.

The government’s impatience is understandable, given that Indian citizens have waited years for meaningful data protection while the DPDPA itself was enacted in August 2023 and the rules took another two years to finalise. During extended transition periods, large platforms continue accumulating data and building targeting capabilities without constraint, entrenching advantages that persist even after regulation arrives. Faster implementation levels the playing field sooner by stopping this accumulation. The counterargument that businesses have been aware of the law since 2023 carries some force, but awareness of a statute’s existence differs substantially from having implementable rules against which compliance systems can actually be designed and tested.

India’s recent regulatory history offers instructive cautionary tales about what happens when implementation outpaces institutional capacity. When the goods and services tax launched in July 2017, the GSTN portal crashed repeatedly under the volume of filings, businesses struggled with compliance procedures they did not understand, and the GST Council found itself issuing over 1,500 notifications, circulars and clarifications in the years that followed as it attempted to patch a system that had never been given adequate time to stabilise before going live. The World Bank’s 2018 India Development Update described the Indian GST as among the most complex indirect tax structures in the world, with one of the highest numbers of rate slabs among comparable jurisdictions. The delayed constitution of the GST Appellate Tribunal left over 40,000 cases pending resolution, many involving input tax credit disputes that could have been avoided with clearer initial guidance.

The Companies Act 2013 presents a different but related lesson, since the legislative process itself took four years from the 2009 Bill to the 2013 Act and the actual problem lay in staged implementation without complete rules, which forced businesses to consult both the old and new statutes simultaneously and reduced compliance to a formalistic exercise in navigating regulatory ambiguity. The Real Estate Regulation and Development Act has faced similar implementation challenges, with state-level enforcement remaining so uneven that the Supreme Court described RERA’s overall performance as ‘disappointing’ in its observations as recently as March 2025.

The government deserves credit for building some transition logic into the DPDPA framework through its phased structure, with Board establishment in 2025, consent manager registration opening in 2026 and full compliance required only in 2027. The question is whether that eighteen-month substantive compliance window provides adequate time for the kind of deep structural changes that genuine data protection requires, particularly given that the digital ecosystem functions as an interconnected structure in which startups and mid-sized enterprises depend on APIs and infrastructure provided by larger platforms. If those larger data fiduciaries are still mid-transition when the deadline arrives, the downstream effects will cascade through the system regardless of how diligently smaller players have attempted to prepare.

Aligning with the GDPR’s two-year transition period would push full enforcement to November 2027 or later, giving the Data Protection Board time to issue guidance based on early implementation experience, allowing the consent manager ecosystem to mature and enabling smaller businesses to learn from the compliance efforts of larger players before committing their own scarce resources. The additional period would also send a signal to the investment community that India’s regulatory environment prioritises durable compliance over speed, since investors routinely price in regulatory risk when timelines appear designed to generate widespread non-compliance rather than genuine behavioural change.

A data protection regime that delivers meaningful results rather than generating a decade of litigation and retrofitted guidance would serve India far better than one that meets an arbitrary deadline while struggling to address problems that could have been anticipated with a slightly longer runway. The citizens who have waited years for protection would benefit most from a framework that actually works when it finally arrives.

Related Articles

Back to top button