DPDP Phase 2 Is Live: Your Compliance Checklist for 2027
The Digital Personal Data Protection Rules, 2025 have entered Phase 2, with the Data Protection Board moving from awareness-building to active oversight between August and November 2026. Every business that collects a customer's name, phone number, email, Aadhaar, or PAN is a Data Fiduciary and needs a consent, grievance, and retention framework in place well before the May 13, 2027 full-compliance deadline.
CA Harun Raaj
Chartered Accountant · Harun Raaj & Associates
Legal basis: Digital Personal Data Protection Rules, 2025, notified under the Digital Personal Data Protection Act, 2023 — Effective: November 13, 2025, with phased implementation through May 13, 2027. Source: MeitY notification / Data Protection Board of India. Last reviewed by CA Harun Raaj: September 2026.
The DPDP Rules, 2025 have moved into Phase 2. Between August and November 2026, the Data Protection Board shifts from setting up its own institutional framework to active regulatory supervision of businesses that handle personal data. If your firm collects, processes, or stores personal data of Indian citizens — a customer's name, mobile number, email, Aadhaar, or PAN — you are already inside the scope of this law, and Phase 2 is the window to get your compliance infrastructure ready before enforcement tightens.
Key point: Any entity that determines the purpose and means of processing personal data is a Data Fiduciary under Section 2(i) of the DPDP Act, 2023, and must have consent, grievance, and deletion mechanisms in place before the May 13, 2027 full-compliance deadline.
What Is DPDP Phase 2?
The DPDP Rules, 2025 follow a phased rollout rather than a single go-live date.
Phase 2 does not mean enforcement has begun in full force, but the Board is no longer purely in awareness mode. Businesses that wait for the May 2027 deadline to start building their compliance framework will be scrambling in the final months.
Are You a "Data Fiduciary"?
Under Section 2(i) of the DPDP Act, 2023, a Data Fiduciary is any person who determines the purpose and means of processing personal data. If your business collects a customer name, mobile number, email, Aadhaar number, or PAN, you are a Data Fiduciary. This covers CA firms, law firms, startups, e-commerce platforms, and any proprietorship or partnership that collects customer data in the ordinary course of business.
Consider a Pune-based consultancy with 18 employees that collects client names, emails, and PAN numbers as part of its engagement process. As a Data Fiduciary, that firm needs a consent notice, a designated Grievance Officer, and a documented data-deletion protocol in place before May 13, 2027 — not as a one-time filing, but as an ongoing operational practice.
Phase 2 Compliance Checklist
1. Consent Notice — Rule 3, DPDP Rules 2025. Before collecting personal data, provide a clear standalone notice stating what data is collected, the purpose of processing, the entity's name and contact details, and how the Data Principal can withdraw consent.
2. Grievance Officer — Rule 11, DPDP Rules 2025. Appoint a Grievance Officer and publish their name and contact details on your website. For smaller organisations, this can be an existing internal team member rather than a new hire.
3. Data Retention and Deletion Policy — Section 8(7), DPDP Act. Personal data must not be retained beyond the period required for the stated purpose or applicable legal requirement. A documented deletion procedure needs to back this up.
4. Children's Data Restrictions — Section 9, DPDP Act. If your platform is accessed by users under 18, verifiable parental consent must be obtained before processing their data.
5. Data Breach Notification — Section 8(6), DPDP Act. On a personal data breach, the Data Protection Board and affected Data Principals must be notified in the prescribed form within the prescribed timeline.
What Happens If You Miss the May 13, 2027 Deadline
Full compliance across consent, rights, breach notification, retention, children's data, and cross-border transfer conditions is required by May 13, 2027. Section 33 of the DPDP Act sets out steep penalties for non-compliance.
These are not theoretical numbers — they are the statutory ceiling businesses face once Phase 3 enforcement begins. The gap between Phase 2 and Phase 3 is the time to close, not to postpone.
Businesses that treat Phase 2 as the working deadline — not May 2027 — will have a functioning consent notice, a named Grievance Officer, and a documented retention policy well before the Board's oversight becomes active enforcement. That is the difference between a routine compliance review and a penalty notice.
I'm CA Harun Raaj, Visakhapatnam. If your business is still finalising its DPDP consent and grievance framework, reach out — I can help you map your obligations before Phase 3 enforcement begins.
---
See Also
Frequently Asked Questions
Does DPDP apply to sole proprietorships and small businesses?
Yes. The DPDP Act, 2023 applies to any person who determines the purpose and means of processing personal data, as defined under Section 2(i), regardless of business size or structure.
Does DPDP apply to employee data?
The Act permits processing of employee personal data for employment-related obligations under Section 4 read with Section 7. Employers must still implement consent and grievance mechanisms for employees, not just customers.
What is a Consent Manager under the DPDP Rules?
A Consent Manager is a registered entity under the DPDP Rules, 2025 that lets individuals manage and withdraw their consent across multiple businesses through a single platform. This framework is being operationalised during Phase 2, between August and November 2026.
What are the penalties for non-compliance under Section 33?
Section 33 of the DPDP Act prescribes penalties up to ₹250 crore for a data breach caused by inadequate security safeguards, up to ₹200 crore for failing to notify the Board of a breach, and ₹10,000 for Data Principal violations.
Who counts as a Data Fiduciary under the DPDP Act?
Under Section 2(i), a Data Fiduciary is any person who determines the purpose and means of processing personal data — including CA firms, law firms, startups, e-commerce platforms, and any proprietorship or partnership collecting customer data such as name, email, or PAN.
When is the DPDP Phase 3 full compliance deadline?
Phase 3, requiring full compliance with all Data Fiduciary obligations including consent, rights, breach notification, retention, and children's data provisions, falls on May 13, 2027, with no grace period expected.
Do I need to hire a dedicated Grievance Officer for a small business?
No. Under Rule 11 of the DPDP Rules, 2025, the Grievance Officer can be an existing internal team member — the requirement is to appoint and publish the officer's name and contact details, not to create a new dedicated role.
What happens if my platform is used by children under 18?
Section 9 of the DPDP Act requires verifiable parental consent before processing the personal data of users under 18, so platforms accessible to minors need this mechanism in place ahead of the Phase 3 deadline.
Go deeper with our hub guides
Statute-cited, section-by-section guides covering the same ground this article does.
Need help with this?
Our team handles the paperwork. You focus on your business.