7 mins

Phased Commencement Under Section 1 of the DPDP Act

An enterprise guide to Section 1 of the DPDP Act, detailing how phased commencement works, compliance timelines across the Rules 2025, and the financial exposure of missing specific enforcement dates for live versus later phases.

Written byVipul Abhishek· Former Advocate, Supreme Court of India

Last updated:

Understanding Section 1 and Phased Commencement

Section 1 of the Digital Personal Data Protection Act, 2023 establishes how and when the law takes effect. Rather than imposing a single, abrupt enforcement date, the Act specifically empowers the Central Government to activate distinct obligations at different times. This means enterprise compliance teams must meticulously map their internal rollout to the phased commencement schedule detailed in the DPDP Rules, 2025. For a Head of Privacy or Chief Compliance Officer, this dictates exactly which control owners are activated first and what evidence packs must be regulator-ready immediately versus those deferred to later phases. An enterprise cannot afford to treat the Act as a single monolithic deadline; it requires managing a series of rolling compliance gates.

Statutory Text and Legal Anchors

The statutory mechanism for this phased enforcement sits explicitly in Section 1(2) of the DPDP Act. The legislation states: 'It shall come into force on such date as the Central Government may, by notification in the Official Gazette, appoint and different dates may be appointed for different provisions of this Act.' Crucially, it notes that any reference in any such provision to the commencement of the Act shall be construed as a reference to the coming into force of that specific provision. The notified Rules, 2025 operationally map these timelines, dictating exactly when compliance frameworks become legally binding across the enterprise.

Deep-Dive: Rules 2025 Commencement Schedule (Live Now vs. Later Phases)

To navigate the Rules 2025 commencement schedule effectively, enterprises must distinguish between duties that are live now (or in the initial gazetted phase) versus those reserved for later phases. In the immediate or 'live now' phases, foundational obligations take precedence. These typically include establishing the primary basis for processing, ensuring consent artefacts align with itemised notice standards (except where Section 7 legitimate uses apply), and enforcing basic data security. For example, Section 8(5) obligations to take reasonable security safeguards to prevent personal data breaches are critical initial priorities. Conversely, later phases are designed to accommodate complex structural changes. These deferred obligations often include the activation of Significant Data Fiduciary specific duties, such as appointing a resident Data Protection Officer, undertaking mandatory Data Protection Impact Assessments (DPIAs), and conducting periodic external audits. Technical integrations for verifiable parental consent architectures and Consent Managers are also traditionally mapped to these later phases to allow enterprises sufficient build time.

Applicability and Enterprise Timelines

This phased structure directly impacts Data Fiduciaries processing digital personal data within India, or processing digital personal data outside India if connected to offering goods or services to Data Principals in India. Large enterprises cannot wait for the final phase to begin building their underlying architecture, such as their Record of Processing Activities (RoPA) frameworks. When the government activates specific sections in the Official Gazette, the expectation for full, demonstrable compliance is immediate on that precise date. Furthermore, when the Significant Data Fiduciary threshold is met and notified, those specific entities will face accelerated regulatory scrutiny on their technical obligations.

Intersections with Data Principal Duties Under Section 15

The phased commencement of Section 1 also dictates when Data Principals themselves are bound by their statutory duties. Under Section 15, a Data Principal shall perform several critical duties, which become active alongside the corresponding rights. Section 15 requires Data Principals to: (a) comply with the provisions of all applicable laws for the time being in force while exercising rights under the provisions of this Act; (b) ensure not to impersonate another person while providing her personal data for a specified purpose; (c) ensure not to suppress any material information while providing her personal data for any document, unique identifier, proof of identity or proof of address issued by the State or any of its instrumentalities; (d) ensure not to register a false or frivolous grievance or complaint with a Data Fiduciary or the Board; and (e) furnish only such information as is verifiably authentic, while exercising the right to correction or erasure. Enterprises must update their terms of service to reflect these binding duties as soon as the relevant phases are live.

Compliance Roadmap for Enterprise Teams

First, map existing processes to the phased schedule by matching every single data collection point to the earliest applicable enforcement date. Second, establish immediate breach intimation workflows. The obligation to report personal data breaches to affected Data Principals without delay, and to the Data Protection Board within 72 hours under the Rules, 2025, requires cross-team coordination that takes months to design and test. Third, update all consent architectures to ensure they align with the Rules, 2025 itemised notice standards, keeping in mind that consent is the primary basis for processing, except where Section 7 legitimate uses apply. Fourth, centralise vendor oversight by amending processor contracts to guarantee they can support your phased evidence generation requirements well before their specific compliance window closes.

Financial Exposure for Missing Phase Deadlines

Failing to align your internal readiness with the gazetted commencement dates exposes the enterprise to immediate and severe regulatory action. The Act Schedule explicitly outlines maximum penalties once a provision is live. According to the penalty schedule, a breach in observing the obligation of a Data Fiduciary to take reasonable security safeguards to prevent a personal data breach under sub-section (5) of section 8 carries a penalty that may extend to two hundred and fifty crore rupees (Rs. 250 Crore). Similarly, missing the specific commencement window for breach notification obligations - specifically, a breach in observing the obligation to give the Board or affected Data Principal notice of a personal data breach under sub-section (6) of section 8 - carries a penalty that may extend to two hundred crore rupees (Rs. 200 Crore). The Data Protection Board will heavily weigh the enterprise's documented readiness and audit trails when determining the final quantum.

Managing the Final Deadline Pressure

Enterprises are on a strict countdown to final enforcement across all phases. Exactly 261 days remain until the DPDP hard compliance deadline of 13 May 2027. By this date, all transitional grace periods and phased rollouts will be completely exhausted. Heads of Compliance must ensure their privacy governance structures, consent management platforms, and incident response playbooks are fully operational, stress-tested, and ready for an external regulatory audit well before this final window closes.

Next Steps for Compliance Leaders

Tracking phased commencement manually across internal spreadsheets creates a significant risk of missing a gazetted enforcement date. You need a centralized platform that connects evolving regulatory timelines directly to your internal control owners and evidence workflows. Run a section-level gap check at freescan.complydp.com to see if your current setup satisfies the immediate, live requirements of the DPDP Act and Rules, 2025, and prepare your transition for the later phases.

Sources

Frequently asked questions

How does the phased commencement under Section 1 affect my compliance roadmap?

Section 1(2) allows the government to enforce different sections of the DPDP Act on different dates. Heads of Compliance must align their internal project plans with the specific timelines published in the Rules, 2025, separating live now requirements from later phases, to avoid severe penalties.

Can we wait for all phases to go live before implementing data protection controls?

No. Waiting exposes the enterprise to massive regulatory risk. Provisions like breach notification under Section 8(6) and basic security safeguards under Section 8(5) demand earlier enforcement, and missing them can lead to fines extending to 200 crore rupees and 250 crore rupees, respectively.

What must a large enterprise prioritise as the first phases come into force?

Teams should prioritise data mapping, setting up a Record of Processing Activities, establishing reasonable security safeguards, and building incident response plans. Reporting breaches to affected Data Principals without delay and to the Board within 72 hours requires immediate and significant operational readiness.

How does the primary basis of consent interact with the enforcement timeline?

Consent is the primary basis for processing, except where Section 7 legitimate uses apply. Enterprises must ensure their consent artefacts and itemised notices meet the specific standards of the Rules, 2025 precisely by the date those corresponding consent provisions are officially commenced in the Official Gazette.

What is the final deadline for full compliance across all phases?

The transition periods culminate in a final deadline. Exactly 261 days remain until the DPDP hard compliance deadline of 13 May 2027, by which point all enterprise evidence packs, control environments, and delegated data duties must be fully operational and regulator-ready.