How-To 7 min read 25 July 2026

Your DPDP Implementation Timeline: A 90-Day Plan Before May 2027

A month-by-month DPDP implementation plan for Indian businesses — what to do in days 1–30, 31–60 and 61–90 to be compliant well before the May 13, 2027 enforcement date.

The DPDP deadline is a date: May 13, 2027, when the core obligations of the DPDP Rules 2025 become enforceable. This is the operational plan — 90 days of part-time, sequenced work that takes a typical SMB from nothing to a working compliance system, with room to spare. (For what changes on that date and why, see DPDP Rules 2025 explained; if you'd rather software ran most of these steps for you, see what DPDP compliance software covers.)

Days 1–30: Know Your Ground

  • Week 1 — Applicability. Take the free 2-minute checker; document the conclusion. Flag immediately if you might touch children's data (Section 9) — it changes your whole plan.
  • Weeks 2–3 — Data map. Inventory what personal data you collect, where it's stored, who accesses it, who you share it with. A spreadsheet is fine; completeness matters more than format.
  • Week 4 — Processor list. Every tool and partner that handles customer data (Section 8(2)), with their privacy terms noted. Start requesting Data Processing Agreements now — the slowest vendors take weeks.

Days 31–60: Build the Paper and the Pipes

  • Week 5 — Privacy notice. Draft it from the data map: itemised data, specified purposes, withdrawal and complaint links (Section 5(1), Rule 3). Use the notice guide and template, in the languages your customers read (Section 5(3)).
  • Weeks 6–7 — Consent collection. Wire consent into every channel: checkout checkbox, WhatsApp flow, counter QR (Section 6). Start keeping proper consent records from the first day.
  • Week 8 — Rights channel. A request address or portal, an owner, and published response timelines (Sections 11–13, Rule 14).

Days 61–90: Harden and Rehearse

  • Week 9 — Security basics. 2FA everywhere customer data lives, access limits, backups, password-protected files (Section 8(5), Rule 6).
  • Week 10 — Breach plan. Write the Rule 7 sequence down — who notifies customers and the Board without delay, who files the 72-hour particulars — and run one tabletop drill. See the 72-hour rule.
  • Week 11 — Team training. One hour, documented, using the staff training guide.
  • Week 12 — Retention and review. Write the retention policy (Section 8(7)), delete something per it, and walk the whole system once as a customer would.

After Day 90: The Long Tail

Two workstreams continue past the sprint. Re-noticing existing customers (Section 5(2)) — batch it monthly until your pre-Act database is covered. And keeping the system honest — requests answered on time, records accumulating, notice versions archived. Track both against the interactive DPDP compliance checklist, and if you'd rather the pipes ran themselves, that's what DPDP compliance software is for.

References & Sources

  1. Ministry of Electronics & IT — The Digital Personal Data Protection Act, 2023 (Sections 5, 6, 8, 9, 11–13).
  2. The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) — Rule 1 (commencement: core obligations from May 13, 2027), Rule 3, Rule 4 (Consent Managers from November 2026), Rules 6–8, Rule 14.

General information, not legal advice. Verify obligations and dates against the notified text for your specific business.

DPDPImplementationTimelinePlanningSMB

Check Your DPDP Compliance

Free 2-minute checker — get your specific obligations and penalty exposure.