By Adv. K J Muhammed Aslam · Advocate, Ernakulam (Bar Council of Kerala)
Every Kerala business processing customer data faces the same May 2027 horizon: notices, consent, safeguards, breach response, rights handling, retention, vendor contracts, and possibly children-data and SDF duties — with penalties to 250 crore rupees per instance. This hub orders the fifteen-guide DPDP series into a build sequence with the phased timeline. It is general information, not legal advice.
What is the phased timeline — what bites when?
| Phase | Date | Content |
|---|---|---|
| Board constitution | 14 November 2025 | Rules 1–2 and 17–21 in force from Gazette notification; inquiry machinery stands up |
| Consent Managers | ≈13 November 2026 (displayed as 14 November 2026 on this site) | Rule 4 registration; architecture must interoperate |
| Substantive duties + penalties | ≈13 May 2027 (displayed as 14 May 2027 on this site) | Rules 3, 5–16, 22–23; obligations and Schedule penalties enforceable |
Timing note: G.S.R. 846(E) is dated 13 November 2025 and was notified on 14 November 2025 (PIB); 12- and 18-month periods computed from the 13 November 2025 date give ≈13 November 2026 and ≈13 May 2027 — displayed on this site as 14 November 2026 and 14 May 2027.
What is the build sequence — which guide when?
Foundations: the countdown and 9-month plan with consent-notice drafting and safeguards plus retention. Operations: breach playbook with the CERT-In clock comparison, principal rights workflow, processor contracts and DPIA, and employee and CCTV discipline. Special tracks: children’s data, Significant Data Fiduciaries, cross-border transfers, Consent Managers. Enforcement: penalties, Board inquiry, and TDSAT appeal with the victim-rights mirror.
How do penalties and enforcement work — and what mitigates?
Schedule ceilings to 250 crore rupees per instance with Section 33 seven-factor grading, Board digital inquiry with voluntary-undertakings tracks, and TDSAT appeal beyond — the enforcement companion maps limitation, stay, and the mitigation file to build now rather than during inquiry.
What comes after May 2027 — continuous compliance?
Compliance does not end at enforcement: periodic audits, DPIA refresh on new processing, retention-schedule execution with 48-hour notices, vendor re-assessments, rights-request metrics, and breach-drill cycles convert the May 2027 programme into steady-state governance with Board-ready evidence every quarter.
Primary sources
- Digital Personal Data Protection Act, 2023 — India Code
- DPDP Rules, 2025 (G.S.R. 846(E), 13 November 2025) — MeitY
- PIB press release on notification of the DPDP Rules, 14 November 2025 (PRID 2190014) and PIB backgrounder, 17 November 2025 (PRID 2190655)
- Gazette notifications — G.S.R. 843(E) and G.S.R. 846(E) — e-Gazette
General information — not legal advice. Office at High Court Junction, Ernakulam; practice before the High Court of Kerala.
FAQ
