DPDP November 2026 Updates: What actually changes (and what doesn’t) for Indian organizations

02 Sep 2026
DPDP November 2026 Updates What actually changes (and what doesn't) for Indian organizations

On 13th November 2026, DPDP Act’s second phase takes effect, but it doesn’t apply to every organization and it isn’t a deadline most people think it is.

 

The biggest mistake organizations are making regarding the DPDP Act is that they are unclear about the expectations for 2026 and beyond. They are either overstating or missing the point.

 

Through this blog, we will clear the confusion and take a look at what actually changes (and what doesn’t) for Indian organizations and what they must do for compliance.

DPDP Act 2026 – What actually changes? (And What doesn’t)

Here what every provision requires along with the effective date.

 

Provision 

Phase 

Effective Date 

What It Requires 

Board constitution, definitions, rule-making powers 

Phase 1 

13 Nov 2025 (in force) 

Data Protection Board established 

Consent Manager registration & oversight (Sec 6(9), 27(1)(d)) 

Phase 2 

13 Nov 2026 

Entities operating as Consent Managers must register 

Core consent framework, Data Fiduciary obligations, security safeguards, breach notification, penalties (Sec 3–10, 27, 28–34) 

Phase 3 

13 May 2027 

Full substantive compliance and enforcement 

 

One critical aspect to note about the November 2026 deadline is that it only applies to entities looking to register as a new Consent Manager, intermediary, not every Data Fiduciary.

 

So, if an organization isn’t applying to become a Consent Manager, their main compliance obligation is enforceable in May 2027, not November 2026.

What does the May 2027 phase actually require?

For most organizations not looking to register as Consent Manager, May 2027 is a real deadline, and November is the realistic checkpoint to aim for. This is because in May 2027, everything becomes fully enforceable without any grace period whatsoever.

 

This includes the reasonable security safeguards expected under Section 8, the breach notification duties, and the penalties.

 

Here is what the May 2027 deadline requires:

Section 8 – Reasonable security safeguards

No list of prescribed security tools

The Act doesn’t provide a list of approved security tools but expects organizations to have appropriate measures as per the sensitivity and volume of data.

 

Security must be demonstrable, not just documented

Having a policy in place alone won’t be enough, organizations will be scrutinized based on whether they can show that they have adequate and effective controls.

 

Visibility first

This means ensuring three things: complete awareness of where data lives, controls that prevent unauthorized access, and monitoring that can prove real oversight.

Breach notification timelines

DPDPA requires organizations to report to the Board without any delay followed by a detailed report within 72 hours. This runs in parallel with CERT-In’s existing requirement to report incidents within a 6 hour window.

 

Penalties

  • Up to ₹200 crore for breach notification failure.
  • Up to ₹250 crores for failing to implement required safeguards.

What are the consequences of non-compliance?

What makes the May 2027 deadline worth taking seriously is that the non-compliance comes with real financial consequences.

 

Organizations that fail to implement the required safeguards will be liable to a penalty of up to ₹250 crore and organizations failing to ensure breach notification timelines face penalties of up to ₹200 crore.

 

These figures aren’t reserved just for large, catastrophic events, they are the ceiling for a single violation, with the Board applying aggravating and mitigating factors under Section 33 to determine the actual number.

 

This means that even if an organization is small, the penalty figure still applies, making the consequences graver for them.

 

So, instead of being just a compliance conversation, DPDP has become a board-level risk conversation.

Six-month action plan for security teams

Here is what security teams should be doing in the next six months:

Expected by May 2027 

What to do now 

How it gets fulfilled 

“Reasonable security safeguards” (Section 8) 

Identify gaps in access control, encryption, and threat detection coverage 

VAPT to surface exposure, Managed SIEM for continuous monitoring, MDR for detection and response 

Breach notification within DPDP + CERT-In timelines 

Test whether current monitoring can detect and triage an incident inside a 6-hour window 

Tabletop exercise against a dual-notification runbook, with SIEM alerting tuned to that timeline 

SDF-specific audit readiness (if applicable) 

Confirm SDF status; benchmark controls against audit-grade evidence requirements 

Technical gap assessment covering log retention, access governance, and third-party risk 

Legacy infrastructure exposure 

Map where personal data lives across systems, including shadow IT and legacy platforms 

Data discovery as the technical precursor to any consent or safeguard work 

How SharkStriker helps you through May 2027?

The DPDP Act has been around for almost a year now and most organizations are quite aware of its security expectations.

 

However, they struggle with limited expertise on board to timely identify and address both the security and compliance gaps.

 

Section 8’s expectations require organizations to have centralized visibility, timely detection of threats, and monitoring that isn’t just a tool deployed.

 

It means ensuring that tools across multiple vendors work in unison to create context that internal teams can work on.

 

In reality, several organizations struggle with tools that work independently without any shared context.

 

SharkStriker solves both challenges by offering dual expertise in security and compliance through a single MDR offering delivered via a vendor agnostic security platform that was purpose-built to centralize visibility and control.

 

Here are several ways through which SharkStriker can help Indian organizations be resilient and compliance-ready before the final enforcement in May 2027:

 

1. Centralized visibility and control through STRIEGO

DPDPA’s safeguard expectations start from organizations knowing where their data lives and how it is protected.

 

STRIEGO makes this easier by integrating tools across multiple vendors into a single vendor agnostic, open-architecture layer for centralized visibility and clear context for internal teams. This directly meets the Section 8’s requirement to prove not just that controls exist, but also there is complete oversight with clear context to act.

 

2. Round-the-clock monitoring

Organizations get threat detection coverage that extends beyond business hours. So, gaps in security (like missing access controls) or anomalous activity get flagged when they happen(supporting the DPDP Act’s reporting requirement), not during quarterly review.

 

3. Single stop access to security and compliance expertise 

The Board’s scrutiny is on safeguards and controls that are operational, not just documented.

 

SharkStriker ‘s MDR service offers a single stop access to both security and compliance expertise, so the gaps against Section 8 get identified and addressed before they turn consequential, with a response team behind not just monitoring but also ready for action.

 

4. Vendor and domain expertise to fine tune stack for demonstrable defense 

Section 8 requires defense that is demonstrable, not just documented. SharkStriker’s team can help organizations achieve this requirement by looking for missing controls, and fine tuning their stack, policies, and rules. They can help establish timely action by automating response through custom build playbooks and manage their security stack for continuous security improvement in an evolving threat landscape.

 

5. End-to-end compliance support 

With dedicated compliance support and guidance at each step of the journey, from risk treatment to documentation, compliance no longer becomes an added pressure.

Get in Touch With us

We have explored what risk tolerance and risk appetite are and how important they are together in helping businesses align cybersecurity with their business goals. It can help CISOs, and C-suite make informed investment decisions for cybersecurity.

LEARN MORE