Report an IncidentTalk to Sales
Blog

DPDP Rules 2025: What CISOs Need to Do Before the May 2027 Compliance Deadline

August 27, 2026 | by

India’s data protection landscape has moved from policy discussions to implementation. 

The Digital Personal Data Protection Rules, 2025 (DPDP Rules) were notified by the Ministry of Electronics and Information Technology (MeitY) in November 2025, with a phased commencement timeline. Under that timeline, several substantive provisions are scheduled to take effect 18 months after publication, making May 2027 a critical compliance milestone for organisations subject to those provisions. 

For CISOs, however, the question is not simply: 

“Will we be DPDP compliant by May 2027?” 

The more important question is: 

“Will our security controls actually protect personal data, detect unauthorised activity and support an effective response when something goes wrong?” 

That distinction matters. 

DPDP compliance is not only a privacy or legal exercise. It has direct implications for identity and access management, encryption, logging, monitoring, incident response, vulnerability management, third-party risk, retention and data security. 

The DPDP Act also provides for significant financial penalties. Failure to take reasonable security safeguards to prevent a personal data breach can attract a penalty of up to ₹250 crore, while certain failures relating to breach notification can attract up to ₹200 crore. 

For CISOs, DPDP readiness therefore needs to be treated as a security and governance programme—not simply a documentation exercise. 

The Three-Phase DPDP Compliance Timeline

One of the most important things for organisations to understand is that May 2027 is not the date when DPDP preparation should begin. 

The Rules establish a phased commencement model. 

Phase 1 — Immediate Framework

November 2025 | Status: Already commenced 

The DPDP Rules were notified in November 2025. Rules 1, 2 and 17–21 came into force on the date of publication. 

For organisations, this phase should be viewed as the starting point for governance and preparation. 

The practical priorities are: 

  • Establish executive ownership 
  • Determine whether and how the DPDP Act applies 
  • Identify key stakeholders 
  • Begin personal-data discovery 
  • Map major processing activities 
  • Identify Data Processors 
  • Assess existing security controls 
  • Build a remediation roadmap 

The important message for CISOs is simple: 

The implementation programme should already be underway. 

Phase 2 — Consent Manager Provisions

November 2026 | Status: Upcoming 

Rule 4 is scheduled to commence one year after publication of the Rules. 

Organisations whose operations rely significantly on consent-based processing should use this period to review their consent architecture. 

This includes: 

  • Consent collection 
  • Purpose-specific consent 
  • Consent withdrawal 
  • Consent records 
  • User interfaces 
  • Data flows 
  • Consent-related third-party integrations 
  • Consent Manager dependencies 

Consent should not be treated as simply a checkbox on a website. 

It can affect mobile applications, customer portals, CRM systems, marketing platforms, websites and downstream data processing. 

Phase 3 — Major Compliance Milestone

May 2027 | Status: Key implementation milestone 

Rules 3, 5–16, 22 and 23 are scheduled to commence 18 months after publication. 

This brings a broad range of substantive requirements into operation, including areas relating to: 

  • Privacy notices 
  • Security safeguards 
  • Personal data breach response 
  • Retention and erasure 
  • Data Principal rights 
  • Children’s data 
  • Data Processor obligations 
  • Significant Data Fiduciary requirements, where applicable 

The objective should therefore be to reach May 2027 with controls that are already implemented, tested and operational. 

Official source: MeitY — Digital Personal Data Protection Rules, 2025 

Why 18 Months Is a Tight Window

An 18-month implementation window can appear generous. 

In practice, enterprise compliance programmes can involve multiple workstreams running at the same time: 

  • Data discovery and mapping 
  • Gap assessment 
  • Privacy notice redesign 
  • Consent workflow changes 
  • Technical security controls 
  • Vendor assessments 
  • Contract updates 
  • Data Principal rights workflows 
  • Retention and deletion 
  • Incident response 
  • Staff training 
  • Testing and validation 

The challenge is rarely one individual requirement. 

It is the number of systems, teams, vendors and business processes that have to change together. 

For example, updating a privacy notice may take weeks. 

Updating the underlying application workflows, CRM processes, consent mechanisms, data flows and third-party integrations can take considerably longer. 

That is why organisations that start late may find themselves trying to implement, test and validate several major workstreams simultaneously. 

The First 90 Days: Build Visibility and Governance

The first question a CISO should ask is: 

Where does our personal data actually reside? 

Before implementing controls, organisations need visibility into what they are protecting. 

A structured assessment should identify: 

  • Personal data categories 
  • Systems processing personal data 
  • Applications and databases 
  • Cloud environments 
  • User groups 
  • Data flows 
  • Data Processors 
  • Third-party integrations 
  • Retention requirements 
  • Existing security controls 

At the governance level, organisations should also: 

  • Appoint a DPDP programme owner 
  • Establish cross-functional responsibility 
  • Involve security, legal, privacy, IT and business teams 
  • Conduct a gap assessment 
  • Identify high-risk processing activities 
  • Establish executive sponsorship 
  • Define remediation priorities 

This foundation makes the subsequent technical work significantly more effective. 

For organisations building their compliance roadmap, Eventus can also support the assessment through its DPDPA Compliance Checklist. 

DPDP Penalties: Why Security Cannot Be an Afterthought

The penalty framework makes DPDP particularly relevant to security leadership. 

The DPDP Act provides for maximum penalties that include: 

Obligation  Maximum penalty 
Failure to take reasonable security safeguards to prevent a personal data breach  ₹250 crore 
Failure to give required breach notice to the Board or affected Data Principals  ₹200 crore 
Certain breaches relating to children's data  ₹200 crore 
Certain breaches of Significant Data Fiduciary obligations  ₹150 crore 
Other specified breaches  ₹50 crore 

These are maximum statutory penalties, not automatic fines for every compliance gap. The actual consequences depend on the circumstances and applicable legal provisions. 

For CISOs, however, the risk is clear. 

A failure in security safeguards can become more than a technical issue. 

It can become a regulatory, financial, operational and reputational risk. 

That is why security controls need to be demonstrable—not merely documented. 

Security Safeguards: The CISO’s Core Responsibility

Security safeguards are one of the most important technical areas under the DPDP Rules. 

The Rules specifically address measures including encryption, masking or tokenisation, access controls, visibility through logs and monitoring, backups, retention of relevant logs and data, processor-contract safeguards, and technical and organisational measures. 

The objective should not be to create a completely separate DPDP security environment. 

Instead, organisations should assess whether their existing security capabilities adequately protect systems that process personal data. 

Encryption, Masking and Tokenisation

Organisations should evaluate appropriate protections for personal data: 

  • At rest 
  • In transit 
  • In databases 
  • In cloud storage 
  • In backups 
  • In sensitive files 
  • Across relevant communications 

Where appropriate, masking and tokenisation can reduce unnecessary exposure of personal data. 

The underlying question is: 

If an attacker gains access to this environment, how much usable personal data can they actually obtain? 

Identity and Access Management

Unauthorised access remains one of the most direct routes to personal-data exposure. 

CISOs should review: 

  • Role-based access controls 
  • Privileged accounts 
  • Administrative access 
  • Multi-factor authentication 
  • Service accounts 
  • Dormant accounts 
  • Third-party access 
  • Access reviews 
  • Privilege escalation 
  • Separation of duties 

However, access management cannot stop at determining who is authorised. 

Security teams also need to identify abnormal use of legitimate credentials. 

For example, an employee may legitimately have access to a customer database. 

But if that account suddenly accesses the database from an unusual location and downloads thousands of records, the event requires investigation. 

That is where IAM and security monitoring need to work together. 

Logging, Monitoring and the Role of a SOC

Logging is useful only when organisations can turn security events into actionable information. 

The questions CISOs should ask are: 

  • Are we collecting the right events? 
  • Are critical events being correlated? 
  • Can we identify suspicious behaviour? 
  • Can investigators reconstruct what happened? 

Relevant telemetry may come from: 

  • Identity platforms 
  • Endpoints 
  • Firewalls 
  • Network infrastructure 
  • Cloud platforms 
  • Applications 
  • Databases 
  • Email systems 
  • Security tools 
  • Critical business systems 

A SIEM can help centralise and correlate security events. 

A SOC can provide continuous monitoring, investigation, threat detection and response. 

Importantly, the DPDP Rules do not mandate that every organisation operate a SOC. 

However, for organisations processing significant volumes of personal data, continuous monitoring can be an important capability for making security safeguards effective in practice. 

Eventus provides Managed SOC Services and SOC-as-a-Service to support continuous security monitoring and response. 

Breach Detection and Incident Response

Having security controls in place is only part of the equation. 

When an incident occurs, organisations need to determine: 

  • What happened? 
  • When did it happen? 
  • Which systems were compromised? 
  • Was personal data involved? 
  • What data was affected? 
  • Was data accessed or exfiltrated? 
  • What needs to be contained? 
  • What notification obligations apply? 

The DPDP Rules require Data Fiduciaries to notify affected Data Principals without delay and require specified information to be provided to the Board, including an initial description and subsequent detailed information within the prescribed timeline. 

A mature incident response process should therefore connect: 

Detection → Triage → Investigation → Impact Assessment → Containment → Eradication → Recovery → Notification → Lessons Learned 

This requires visibility across endpoints, identities, networks, applications and cloud environments. 

It also requires people who can interpret those signals and make decisions under pressure. 

Eventus’s Incident Response capabilities can support organisations in preparing structured detection and response processes. 

Regular Incident Response Team planning and exercises can also help identify weaknesses before a real incident occurs. 

Vulnerability Management and Security Testing

A security safeguard is only as strong as the systems it protects. 

Unpatched vulnerabilities, insecure configurations and exposed applications can create pathways into environments containing personal data. 

CISOs should therefore integrate DPDP readiness with ongoing: 

  • Vulnerability assessments 
  • Penetration testing 
  • Configuration reviews 
  • Patch management 
  • Application security testing 
  • API security testing 
  • Risk-based remediation 
  • Validation of critical fixes 

VAPT should not be treated as a once-a-year compliance exercise. 

The technology environment changes continuously, and new vulnerabilities can emerge after an assessment has been completed. 

Eventus’s Vulnerability Assessment and Penetration Testing capabilities can help organisations identify and validate weaknesses across their attack surface. 

Data Processor and Third-Party Risk

Personal data rarely stays within one organisation. 

Cloud providers, SaaS platforms, CRM systems, payroll providers, marketing platforms and other vendors may process personal data on behalf of an organisation. 

This means third-party security becomes part of the organisation’s DPDP risk profile. 

CISOs should assess critical Data Processors across areas such as: 

  • Identity and access controls 
  • Encryption 
  • Security monitoring 
  • Vulnerability management 
  • Incident response 
  • Backup and recovery 
  • Data retention 
  • Data deletion 
  • Security incident notification 
  • Business continuity 

The Rules also require appropriate security provisions in applicable contracts between Data Fiduciaries and Data Processors. 

The better question is not: 

“Does the vendor have a security certificate?” 

It is: 

“If this vendor is compromised tomorrow, can we determine quickly whether our personal data is affected?” 

That is the level of visibility modern third-party risk management requires. 

Privacy Notices and Consent Architecture

Technical controls are only one part of DPDP readiness. 

The Rules require notices to be understandable independently and to provide clear information about the personal data being processed and the specified purpose or purposes. They also require information about how Data Principals can withdraw consent and exercise their rights. 

Organisations should therefore review every major personal-data collection point, including: 

  • Websites 
  • Mobile applications 
  • Customer portals 
  • HR systems 
  • Visitor-management systems 
  • Marketing forms 
  • Service applications 
  • Physical and digital onboarding 

Consent should be purpose-specific, understandable and capable of being withdrawn through an accessible mechanism, where consent is the applicable basis. 

For data collected before implementation, organisations should also assess the applicable notice and communication requirements rather than assuming that an existing privacy policy automatically addresses them. 

Data Principal Rights Need Technical Workflows

Privacy rights cannot be implemented through policy alone. 

Organisations need operational workflows to handle applicable Data Principal requests, including processes for: 

  • Access 
  • Correction 
  • Erasure 
  • Consent withdrawal 
  • Grievances 
  • Identity verification 
  • Request tracking 
  • Response management 
  • Coordination with Data Processors 

The Rules also require Data Fiduciaries to prominently publish relevant contact information for questions relating to personal-data processing and rights. 

Consider a customer whose information exists across a CRM, billing system, support platform, marketing platform and cloud database. 

A rights request cannot be handled reliably if those systems operate in isolation. 

Organisations therefore need to connect rights-management processes with: 

Data inventory + application architecture + identity + third-party processing 

This is where privacy requirements become an operational technology challenge. 

Retention, Erasure and Data Minimisation

The longer unnecessary personal data remains in an environment, the longer it remains exposed to potential compromise. 

Organisations should establish clear retention and erasure processes based on applicable requirements. 

This includes: 

  • Defining retention periods 
  • Identifying business and regulatory requirements 
  • Automating deletion where appropriate 
  • Addressing archived data 
  • Considering backups 
  • Extending applicable requirements to processors 
  • Maintaining appropriate evidence of processes 

The Rules contain specific retention requirements in defined circumstances, including a minimum one-year retention period for certain personal data, traffic data and processing logs. They also prescribe specific erasure and pre-erasure notification requirements for certain Data Fiduciaries and purposes. 

The goal is not simply to delete data after an arbitrary number of days. 

It is to ensure that personal data is not retained indefinitely without a legitimate and applicable reason. 

Children’s Data Requires Additional Controls

Organisations that process children’s personal data need to assess the additional obligations applicable to such processing. 

The Rules provide for verifiable parental consent before processing a child’s personal data, subject to the applicable framework and exemptions. 

Relevant considerations include: 

  • Age-related controls 
  • Parental consent 
  • Appropriate verification mechanisms 
  • Restrictions on behavioural monitoring 
  • Restrictions on targeted advertising 
  • Additional safeguards around children’s data 

This should be considered even where children are not the organisation’s primary audience. 

For example, children’s data could potentially appear in: 

  • Visitor-management systems 
  • Healthcare platforms 
  • Educational services 
  • Consumer applications 
  • Family accounts 

Data discovery therefore needs to consider how children’s data could enter the organisation’s systems, not simply whether children are a target audience. 

Significant Data Fiduciary Preparation

Organisations that may be designated as Significant Data Fiduciaries (SDFs) should plan for additional governance and accountability requirements. 

Depending on applicability, this can include: 

  • Appointment of a Data Protection Officer 
  • Independent data auditing 
  • Data Protection Impact Assessments 
  • Periodic assessments 
  • Governance over processing activities 
  • Additional accountability mechanisms 

SDF readiness should not operate as a separate legal project. 

It should be integrated into the organisation’s wider: 

Security + Privacy + Risk + Governance framework 

DPDP and CERT-In: Where CISOs Need to Connect the Frameworks

DPDP is not India’s only cybersecurity requirement. 

Organisations may also have obligations under other applicable laws, sectoral regulations and cybersecurity directions. 

One important example is the CERT-In Cyber Security Directions issued under Section 70B of the Information Technology Act, 2000. 

The CERT-In Directions require specified cyber incidents to be reported within six hours of noticing the incident or being brought to notice of it. 

This is important for CISOs because a single security incident can potentially trigger multiple regulatory and contractual obligations. 

The answer should not be separate security processes for every regulation. 

Instead, organisations can build shared capabilities around: 

  • 24×7 monitoring 
  • Incident detection 
  • Log management 
  • Evidence preservation 
  • Incident response 
  • Vulnerability management 
  • Access governance 
  • Regulatory reporting workflows 

Official source: CERT-In Cyber Security Directions 

Eventus can also help organisations assess their broader CERT-In compliance and security readiness. 

Industry-Specific DPDP Priorities

The practical implementation of DPDP will vary significantly by industry. 

Corporate Offices 

Priorities include: 

  • Employee data 
  • Visitor management 
  • Access systems 
  • Biometric data, where applicable 
  • HR platforms 
  • Workforce vendors 

Manufacturing 

Focus on: 

  • Gate-pass information 
  • Contractor data 
  • Employee systems 
  • Visitor records 
  • Third-party contractors 
  • Retention and deletion 

Healthcare 

Focus on: 

  • Patient information 
  • Consent architecture 
  • Access controls 
  • Health-related personal data 
  • Third-party healthcare platforms 
  • Children’s data, where applicable 

Technology and SaaS 

Focus on: 

  • Data Fiduciary vs Data Processor roles 
  • Multi-tenant environments 
  • Cloud security 
  • Customer data 
  • Data Processing Agreements 
  • Access segregation 
  • Potential SDF considerations 

Retail and E-commerce 

Focus on: 

  • Customer accounts 
  • Marketing consent 
  • Loyalty programmes 
  • Consumer rights 
  • Retention 
  • Third-party processors 

A Practical DPDP Roadmap for CISOs

Organisations can work backwards from the May 2027 milestone. 

Timeline  Priority  Key activities 
First 90 days  Discover  Data inventory, mapping, applicability assessment, governance and gap analysis 
Months 3–6  Design  Privacy notices, consent architecture, security architecture, vendor requirements 
Months 6–9  Implement  Encryption, IAM, MFA, logging, monitoring, backup and vulnerability remediation 
Months 9–12  Operationalise  Rights workflows, retention/deletion, processor governance and incident response 
Months 12–15  Test  VAPT, control testing, incident simulations, access reviews and monitoring validation 
Months 15–18  Validate  External assessment, remediation, training, evidence readiness and executive sign-off 
May 2027 onward  Operate  Continuous monitoring, testing, governance and regulatory updates 

This roadmap is not a substitute for a legal applicability assessment, but it gives security teams a practical way to structure implementation. 

DPDP Compliance Checklist for CISOs

Before the May 2027 milestone, CISOs should be able to answer yes to the following: 

Governance 

  • Is there an accountable DPDP programme owner? 
  • Are security, privacy, legal, IT and business teams aligned? 
  • Has executive sponsorship and budget been established? 
  • Have applicable obligations been assessed? 

Data 

  • Do we know what personal data we process? 
  • Do we know where it is stored? 
  • Have major data flows been mapped? 
  • Have relevant Data Processors been identified? 
  • Are retention requirements documented? 

Security 

  • Is sensitive personal data appropriately protected? 
  • Are access controls reviewed regularly? 
  • Is MFA implemented where appropriate? 
  • Is privileged access controlled? 
  • Are relevant security events logged? 
  • Are critical events monitored? 
  • Are backups protected and tested? 

Detection and Response 

  • Can we detect suspicious activity involving personal-data systems? 
  • Can we determine whether a breach involves personal data? 
  • Is our incident response playbook tested? 
  • Can we preserve relevant evidence? 
  • Can we coordinate regulatory notifications where required? 

Vulnerability Management 

  • Are critical vulnerabilities identified? 
  • Are remediation priorities risk-based? 
  • Is VAPT performed where appropriate? 
  • Are critical fixes validated? 

Third Parties 

  • Have critical Data Processors been assessed? 
  • Are contractual security requirements documented? 
  • Can processors support incident response? 
  • Can data be deleted or returned when required? 

Rights and Retention 

  • Can Data Principal requests be tracked? 
  • Can applicable access, correction and erasure requests be fulfilled? 
  • Are consent withdrawal processes operational? 
  • Are retention and deletion processes automated where appropriate? 

Validation 

  • Have controls been tested? 
  • Have incident response exercises been conducted? 
  • Has staff training been completed? 
  • Is evidence available to demonstrate that controls operate effectively? 
  • Has leadership reviewed the organisation’s readiness? 

Compliance should be demonstrable—not theoretical. 

What Happens After May 2027?

May 2027 should not be treated as the end of the DPDP programme. 

Compliance needs to become part of normal enterprise operations. 

Organisations should continue to: 

  • Review processing activities 
  • Monitor security controls 
  • Assess third-party risk 
  • Test incident response 
  • Review access privileges 
  • Validate retention and deletion 
  • Train employees 
  • Assess major technology or processing changes 
  • Monitor regulatory guidance 
  • Maintain evidence of control effectiveness 

The strongest compliance programmes will not be the ones that simply pass an assessment once. 

They will be the ones that continue operating effectively as the organisation changes. 

What CISOs Should Do Now

The first step is not drafting another privacy policy. 

Start with visibility. 

  • Map the data. 
  • Identify the systems. 
  • Understand the processors. 
  • Assess the controls. 
  • Identify the gaps. 
  • Prioritise the risks. 

Then build the implementation programme around those findings. 

Organisations that wait until 2027 may discover that the difficult part is not understanding the regulation. 

It is changing the technology, contracts, processes and behaviour needed to comply with it. 

Conclusion

The Digital Personal Data Protection Rules, 2025 have moved India’s data protection framework into a more operational phase, with a phased commencement model that makes May 2027 a major implementation milestone. 

For organisations subject to the framework, May 2027 is a critical milestone—but it should not be treated as the starting point for compliance. 

For CISOs, DPDP readiness is fundamentally about whether the organisation can: 

  • Identify personal data. 
  • Control access to it. 
  • Protect it. 
  • Monitor activity around it. 
  • Detect threats. 
  • Respond to breaches. 
  • Recover when systems are disrupted. 
  • And demonstrate that those controls actually work. 

At Eventus Security, we believe DPDP readiness should connect privacy and regulatory requirements with the security operations that protect data every day. 

Because when personal data is at risk, a policy cannot detect the threat. 

Security operations can. 

And organisations that start building those capabilities now will be in a much stronger position when the May 2027 milestone arrives. 

Frequently Asked Questions

What are the DPDP Rules 2025?

The Digital Personal Data Protection Rules, 2025 establish detailed rules for implementing India’s Digital Personal Data Protection Act, 2023. The Rules were notified in November 2025 and use a phased commencement model. 

What is the DPDP compliance deadline?

The Rules follow a phased implementation timeline. May 2027 is the key 18-month commencement milestone for Rules 3, 5–16, 22 and 23. Organisations should assess the official enforcement timeline to determine which provisions apply and when. 

What is the maximum DPDP penalty?

The DPDP Act provides for a maximum penalty of ₹250 crore for failure to take reasonable security safeguards to prevent a personal data breach. Other specified breaches can attract penalties of up to ₹200 crore, ₹150 crore or ₹50 crore, depending on the applicable provision. 

Does DPDP require a SOC?

No. The DPDP Rules do not require every organisation to operate a Security Operations Centre. However, continuous monitoring, detection and response can be important capabilities for organisations seeking to maintain effective security safeguards. 

How can a SOC support DPDP compliance?

A SOC can monitor security events across endpoints, identities, networks, cloud environments, applications and other systems. It can help organisations detect suspicious activity, investigate potential breaches and support incident response. 

Does DPDP replace CERT-In requirements?

No. DPDP and CERT-In operate under different regulatory frameworks. Organisations need to assess the requirements applicable to their specific business, sector and incidents. 

What should a CISO do first for DPDP compliance?

Start with data visibility. Identify personal data, map where it resides and flows, identify Data Processors, assess applicable requirements and perform a security gap assessment. 

How does VAPT support DPDP readiness?

VAPT can help identify exploitable vulnerabilities in applications, infrastructure and systems that may expose personal data. It should form part of an ongoing risk-based security validation programme rather than being treated as a one-time compliance exercise. 

Mohd Kaif Idrisi
Mohd Kaif Idrisi is a cybersecurity and GRC professional with experience in information security governance, risk management, compliance, and internal and external audits. He is a Certified ISO 27001:2022 Lead Auditor with experience across ISO 27001, ISO 9001, ISO 27035, SOC 2 Type II, Saudi NCA ECC, Qatar NIA, GDPR, DPDP, and PDPA.
Report an Incident
Report an Incident - Blog
Ask Experts
Our team of expert is available 24x7 to help any organization experiencing an active breach.

More Topic

crossmenuchevron-down
linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram