There are two DPDP timelines that matter. The first is the statutory timeline — the three commencement dates set in the DPDP Rules 2025 that determine when each obligation becomes enforceable. That timeline is fixed and covered in our DPDP Rules 2025 guide.
The second is your operational timeline — what your organisation must actually do, in what order, by what internal dates, to be ready when the statutory deadlines arrive. That timeline is not fixed. It depends on where you are starting from, which workstreams block others, what the regulatory environment publishes between now and May 2027, and whether your organisation turns out to be a Significant Data Fiduciary.
This post is about the second timeline. It maps the regulatory events that are expected between now and May 2027, identifies the workstream interdependencies that shape your sequencing decisions, and translates all of it into a quarter-by-quarter action calendar that is specific to an organisation starting implementation in early 2026.
| Workstream | Latest Start Date to Finish by May 2027 | If You Start in Feb 2026 |
|---|---|---|
| Data inventory (enterprise-wide) | November 2025 | 15 months runway — use it to build a comprehensive, automated inventory |
| Security safeguards (Rule 6) | February 2026 | 14 months runway — enough time, but no room for a slow start |
| Breach detection and 72-hr notification | March 2026 | 13 months runway — begin design immediately after security gap assessmentT |
| Consent architecture redesign | March 2026 | 13 months runway — design starts now, build follows data inventory completion |
| Data Processor contract remediation | February 2026 | 14 months runway — start vendor inventory now, contracts are slow to negotiate |
| Data Principal rights management | May 2026 | 11 months runway — depends on data inventory and consent record being operational first |
| Legacy data consent remediation | June 2026 | 10 months runway — depends on inventory completion and new consent architecture being live |
| Consent Manager API integration | Must be design-ready by November 2026 | 9 months to build API-ready infrastructure before Consent Manager registration opens |
| SDF: DPO appointment | August 2026 at latest | If you are a probable SDF, appoint now — the DPO needs months to get operational before the DPIA deadline |
| SDF: first DPIA | October 2026 at latest | Requires DPO in place, data inventory complete, and algorithmic systems mapped — all of which take months |
| Staff training | December 2026 | Most organisations underestimate how long it takes to train all staff who handle personal data across multiple sites and functions |
| Audit preparation and evidence assembly | February 2027 | 3-month buffer before May deadline for a complete internal readiness review and evidence package |




