India · verified through August 25, 2026

DPDP readiness, with commencement kept precise.

The Act is enacted, but commencement is staged. Rules 6–8 belong to a future eighteen-month tranche, and the exact Gazette publication date was not verified in the authoritative research session.

Educational mapping · not legal advice

The commencement ledger

The Digital Personal Data Protection Act, 2023 (No. 22 of 2023) received Presidential assent on 11 August 2023. Section 1(2) provides for commencement on dates appointed by Central Government notification, with different dates permitted for different provisions.

Under the Digital Personal Data Protection Rules, 2025, Rules 1, 2 and 17–21 commence on Gazette publication; Rule 4 is scheduled one year after publication; and Rules 3, 5–16, 22 and 23 are scheduled eighteen months after publication. Rules 6, 7 and 8 therefore sit in that future eighteen-month tranche. The exact Gazette publication date was not verified, so this page does not convert that interval into a calendar date.

Completed monetary DPDP enforcement0 cases / ₹0 within the supplied library only
Phased statusMapped substantive obligations, inquiry/penalty powers and Rules 6–8 future at 13/14 May 2027; board paper recommends planning to 12 May 2027 due to date ambiguity.

Official MeitY Rules PDF (opens in a new tab)

Seven readiness points

Future Tranche 3 — 13/14 May 2027; plan to 12 May 2027 due to Gazette-date ambiguity.

1 · Rule 6(1)(a) / working-paper item (i)

Requirement: Encryption, obfuscation, masking or virtual tokens as reasonable security safeguards.

PDI control outcome: Mask / Vault / Strip for supported structured data, subject to policy and legal hold.

Boundary: Structured-data remediation only; it does not establish that the full safeguard duty is legally sufficient.

Future Tranche 3 — 13/14 May 2027; plan to 12 May 2027.

2 · Rule 6(1)(c) / working-paper item (iii)

Requirement: Logs, monitoring and review enabling detection, investigation and remediation.

PDI control outcome: Kestryl audit row product capability supports review evidence.

Boundary: Audit rows support the control; they do not by themselves satisfy all monitoring, detection, investigation or remediation duties.

Future Tranche 3 — 13/14 May 2027; plan to 12 May 2027. The three-year dormancy and 48-hour notice mechanics are future.

3 · Section 8(7) and Rule 8

Requirement: Erase on withdrawal or when the specified purpose is no longer served, whichever is earlier, unless legal retention is necessary. Rule 8/Third Schedule adds a three-year inactivity trigger only for specified classes and thresholds: e-commerce entities with at least 2 crore registered users, online gaming intermediaries with at least 50 lakh users, and social-media intermediaries with at least 2 crore users, subject to stated exclusions; give at least 48 hours’ pre-erasure notice.

PDI control outcome: Strip for supported structured data plus erasure evidence.

Boundary: Subject to policy, legal hold, applicable retention law, class/threshold scoping and downstream processor duties. Documents and attachments are inventoried, not altered.

Future Tranche 3 — 13/14 May 2027; plan to 12 May 2027.

4 · Rule 7 (implementing Section 8(6))

Requirement: Inventory the nature, extent, timing and location of the breach; notify affected Data Principals without delay; notify the Board without delay and provide the detailed report within 72 hours of awareness, unless the Board allows longer on written request.

PDI control outcome: Discovery and inventory can support breach scoping and evidence preparation.

Boundary: Documents and attachments are scanned and inventoried, not altered. PDI does not send notices or determine legal reportability.

Future Tranche 3 — 13/14 May 2027; plan to 12 May 2027.

5 · Section 6(10)

Requirement: The burden is on the Data Fiduciary to prove notice and consent only where consent is relied upon.

PDI control outcome: Evidence packs support review of notice/consent artefacts and related data locations.

Boundary: Evidence packs do not prove legal sufficiency, validity of consent, or that consent is the correct lawful basis.

Future Tranche 3 — 13/14 May 2027; plan to 12 May 2027.

6 · Section 33(2)(e)

Requirement: The Board must consider whether mitigation occurred and the timeliness and effectiveness of that action when determining a monetary penalty.

PDI control outcome: The discovery-to-review-to-remediation chain supports evidence of mitigation activity and timing.

Boundary: Technical evidence supports review; it does not determine the Board’s penalty or prove effectiveness.

Live now in the board paper; amended 25 January 2024 and 21 August 2025.

7 · Aadhaar (Sharing of Information) Regulations, 2016

Requirement: Core biometric information may not be shared; core biometrics captured for authentication by a requesting entity may not be stored or shared; identity information is purpose- and consent-constrained.

PDI control outcome: OCR identifies Aadhaar text in scans, images and shared drives for inventory and review.

Boundary: PDI does not mask, redact or otherwise alter source documents or attachments.

How Kestryl fits

Kestryl supports discovery and inventory across structured data and unstructured attachments or images, creates audit rows and evidence packs, and offers Mask, Vault, and Strip modes for supported structured data under approved policy. It does not alter source attachments or documents, perform legal notice, establish valid consent, satisfy erasure by itself, or prove legal compliance.