Matters
The story behind Matters AI's funding journey
Professional using laptop for security consultation

DPDP Implementation Timeline: A Quarter-by-Quarter Action Calendar from February 2026 to May 2027

FEBRUARY 2026

There are two DPDP timelines that matter. The first is the statutory timeline — the three commencement dates set in the DPDP Rules 2025 that determine when each obligation becomes enforceable. That timeline is fixed and covered in our DPDP Rules 2025 guide.

The second is your operational timeline — what your organisation must actually do, in what order, by what internal dates, to be ready when the statutory deadlines arrive. That timeline is not fixed. It depends on where you are starting from, which workstreams block others, what the regulatory environment publishes between now and May 2027, and whether your organisation turns out to be a Significant Data Fiduciary.

This post is about the second timeline. It maps the regulatory events that are expected between now and May 2027, identifies the workstream interdependencies that shape your sequencing decisions, and translates all of it into a quarter-by-quarter action calendar that is specific to an organisation starting implementation in early 2026.

WorkstreamLatest Start Date to Finish by May 2027If You Start in Feb 2026
Data inventory (enterprise-wide)November 202515 months runway — use it to build a comprehensive, automated inventory
Security safeguards (Rule 6)February 202614 months runway — enough time, but no room for a slow start
Breach detection and 72-hr notificationMarch 202613 months runway — begin design immediately after security gap assessmentT
Consent architecture redesignMarch 202613 months runway — design starts now, build follows data inventory completion
Data Processor contract remediationFebruary 202614 months runway — start vendor inventory now, contracts are slow to negotiate
Data Principal rights managementMay 202611 months runway — depends on data inventory and consent record being operational first
Legacy data consent remediationJune 202610 months runway — depends on inventory completion and new consent architecture being live
Consent Manager API integrationMust be design-ready by November 20269 months to build API-ready infrastructure before Consent Manager registration opens
SDF: DPO appointmentAugust 2026 at latestIf you are a probable SDF, appoint now — the DPO needs months to get operational before the DPIA deadline
SDF: first DPIAOctober 2026 at latestRequires DPO in place, data inventory complete, and algorithmic systems mapped — all of which take months
Staff trainingDecember 2026Most organisations underestimate how long it takes to train all staff who handle personal data across multiple sites and functions
Audit preparation and evidence assemblyFebruary 20273-month buffer before May deadline for a complete internal readiness review and evidence package

You may also like

DPDP Rules 2025: What the Rules Actually Say, What They Defer, and What Is Still Missing

DPDP Rules 2025: What the Rules Actually Say, What They Defer, and What Is Still Missing

Krishna ChandraMarch 2, 2026
Arrow Right
DPDP Act 2023: India’s Digital Personal Data Protection Law Explained
DPDP

DPDP Act 2023: India’s Digital Personal Data Protection Law Explained

Krishna ChandraMarch 2, 2026
Arrow Right
Why Security Agents Are Unavoidable in Modern Enterprise Security
private

Why Security Agents Are Unavoidable in Modern Enterprise Security

Eshank TyagiFebruary 4, 2026
Arrow Right