The moment
The clock started in November 2025. The penalties are written down.
India notified the DPDP Rules on 14 November 2025 with an eighteen-month phased path to full compliance. Every access, correction or erasure request must be answered within ninety days. A personal-data breach must be reported to the Board and to affected individuals. Failing to maintain reasonable security safeguards carries a penalty of up to ₹250 crore; failing to notify a breach, up to ₹200 crore.
Most enterprises will meet this the expensive way: one project per obligation, one project per system, a spreadsheet to reconcile them, and a scramble before every audit. Kestryl Cockpit for DPDP is the alternative — one corpus, one journey, one evidence pack — built on infrastructure you already own.
Facts as published by the Press Information Bureau, Government of India and summarised in KPMG’s guidance to the DPDP Rules. Confirm applicability with counsel.