Skip to Content
CKonnect
  • Home
  • CourseKonnect
    • e-learning
    • Udemy
    • learning (Old LMS)
  • Career
    • Life @CKonnect
    • All Jobs
  • Knowledge Base
    • PrivacyReads
    • Community
    • Newsletters
    • Priv ToolKit
  • Stay Tuned
    • ComplyKonnect
    • E-PrivJournals
    • Priv-Books
  • Connects
    • 1:1
  • Contact Us
CKonnect
    • Home
    • CourseKonnect
      • e-learning
      • Udemy
      • learning (Old LMS)
    • Career
      • Life @CKonnect
      • All Jobs
    • Knowledge Base
      • PrivacyReads
      • Community
      • Newsletters
      • Priv ToolKit
    • Stay Tuned
      • ComplyKonnect
      • E-PrivJournals
      • Priv-Books
    • Connects
      • 1:1
  • Contact Us

Timeline Rules Healine

  • All Blogs
  • Digital Personal Data Act, 2023
  • Timeline Rules Healine
  • 17 July 2026 by
    Timeline Rules Healine
    CKonnect

    Phase 1 (Effective Immediately: November 2025)

    These rules are primarily administrative, focused on setting up the Data Protection Board (DPB).

    • Rule 1: Short Title and Commencement (The name of the rules)
    • Rule 2: Definitions
    • Rule 17: Appointment of Chairperson and Members of the Board
    • Rule 18: Salary, allowances, and conditions of service
    • Rule 19: Procedure for meetings of the Board
    • Rule 20: Functioning of the Board as a digital office
    • Rule 21: Terms and conditions for officers and employees of the Board

     

    Phase 2 (Effective in 12 Months: by November 2026)

    This phase is focused on creating the technical infrastructure for consent.

    • Rule 4: Registration of Consent Managers

     

    Phase 3 (Effective in 18 Months: by May 2027)

    This phase includes all the core data protection duties and user rights.

    • Rule 3: Notice and Consent
    • Rule 5: Processing data for state functions (subsidies, benefits, etc.)
    • Rule 6: Security Safeguards (To prevent breaches)
    • Rule 7: Data Breach Reporting (To the Board and to users)
    • Rule 8: Data Retention Limits (How long data can be kept)
    • Rule 9: Publishing contact information for the Data Protection Officer
    • Rule 10: Processing data of Children
    • Rule 11: Processing data of Persons with Disabilities
    • Rule 12: Exemptions related to children's data
    • Rule 13: Additional duties for Significant Data Fiduciaries (Large companies)
    • Rule 14: Data Subject Rights (Correction, Erasure, Grievance)
    • Rule 15: Transferring personal data outside of India
    • Rule 16: Exemptions for research, archiving, and statistics
    • Rule 22: Procedure for appealing to the Tribunal
    • Rule 23: Board's power to require information

    Schedule

    Rule(s) referencing it

    What it covers

    Effective date

    First Schedule

    Rule 4

    Consent Manager registration & obligations

    13 Nov 2026

    Second Schedule

    Rule 5, Rule 16

    Standards for State functions; research/statistics

    13 May 2027

    Third Schedule

    Rule 8(1)

    Retention + erasure time periods

    13 May 2027

    Fourth Schedule

    Rule 12

    Child data processing exemptions

    13 May 2027

    Fifth Schedule

    Rule 18

    Chairperson & Member service terms

    13 Nov 2025

    Sixth Schedule

    Rule 21(2)

    Officers & staff of the Board

    13 Nov 2025

    Seventh Schedule

    Rule 8(3), Rule 23(1)

    Government purposes for data requests

    13 May 2027

     

     

     

    Schedule

    Referenced in Rule(s)

    What the Schedule Contains (Exact Purpose)

    Activation Date

    Detailed Break-up (Part A / Part B)

    First Schedule

    Rule 4

    Conditions for registration + Obligations of Consent Managers

    13 Nov 2026

    ✔ Part A – Registration Conditions

     ✔ Part B – Obligations

    Second Schedule

    Rule 5(1) and Rule 16

    Standards for processing by State, and for research/statistics exemption

    13 May 2027

    No separate parts

    Third Schedule

    Rule 8(1)

    Time periods for data retention and auto-erasure for certain classes of Data Fiduciaries

    13 May 2027

    No separate parts

    Fourth Schedule

    Rule 12(1) and 12(2) (children’s data exemptions)

    Exemptions from Section 9(1) & (3) for processing children’s data

    13 May 2027

    ✔ Part A – Classes of Data Fiduciaries exempted

    ✔ Part B – Purposes for which exemption applies

    Fifth Schedule

    Rule 18

    Salary, allowances, service conditions of Board Chairperson & Members

    13 Nov 2025

    No separate parts

    Sixth Schedule

    Rule 21(2)

    Service conditions of officers & employees of the Board

    13 Nov 2025

    No separate parts

    Seventh Schedule

    Rule 8(3) and Rule 23(1)

    Government-authorised purposes & officers for requiring information from Data Fiduciaries/intermediaries

    13 May 2027

    No separate parts

     By Naukhaiz Aftab

    in Digital Personal Data Act, 2023
    Share this post
    Our blogs
    • Where Privacy Meets Tech
    • Templates That Work: Built for Real Privacy Teams
    • The Privacy Perspective: Insights from the Real World
    • CKonnect Stories
    • e-learning from CourseKonnect
    • Privacy Team Pulse
    • Our blog
    • Digital Personal Data Act, 2023
    Technical & Organizational Requirements
    Follow us

    Privacy Notice ​​Refund Policy

     Terms & Conditions

        ​    connect@ckonnect.co.in

    How can we help?

    konnect with us

    Website Logo

    Respecting your privacy is our priority.

    Allow the use of cookies from this website on this browser?

    We use cookies to provide improved experience on this website. You can learn more about our cookies and how we use them in our Cookie Policy.

    Allow all cookiesOnly allow essential cookies