DPDP November 2026 Updates: What actually changes (and what doesn’t) for Indian organizations
02 Sep 2026
On 13th November 2026, DPDP Act’s second phase takes effect, but it doesn’t apply to every organization and it isn’t a deadline most people think it is.
The biggest mistake organizations are making regarding the DPDP Act is that they are unclear about the expectations for 2026 and beyond. They are either overstating or missing the point.
Through this blog, we will clear the confusion and take a look at what actually changes (and what doesn’t) for Indian organizations and what they must do for compliance.
DPDP Act 2026 – What actually changes? (And What doesn’t)
Here what every provision requires along with the effective date.
|
Provision |
Phase |
Effective Date |
What It Requires |
|
Board constitution, definitions, rule-making powers |
Phase 1 |
13 Nov 2025 (in force) |
Data Protection Board established |
|
Consent Manager registration & oversight (Sec 6(9), 27(1)(d)) |
Phase 2 |
13 Nov 2026 |
Entities operating as Consent Managers must register |
|
Core consent framework, Data Fiduciary obligations, security safeguards, breach notification, penalties (Sec 3–10, 27, 28–34) |
Phase 3 |
13 May 2027 |
Full substantive compliance and enforcement |
One critical aspect to note about the November 2026 deadline is that it only applies to entities looking to register as a new Consent Manager, intermediary, not every Data Fiduciary.
So, if an organization isn’t applying to become a Consent Manager, their main compliance obligation is enforceable in May 2027, not November 2026.
What does the May 2027 phase actually require?
For most organizations not looking to register as Consent Manager, May 2027 is a real deadline, and November is the realistic checkpoint to aim for. This is because in May 2027, everything becomes fully enforceable without any grace period whatsoever.
This includes the reasonable security safeguards expected under Section 8, the breach notification duties, and the penalties.
Here is what the May 2027 deadline requires:
Section 8 – Reasonable security safeguards
No list of prescribed security tools
The Act doesn’t provide a list of approved security tools but expects organizations to have appropriate measures as per the sensitivity and volume of data.
Security must be demonstrable, not just documented
Having a policy in place alone won’t be enough, organizations will be scrutinized based on whether they can show that they have adequate and effective controls.
Visibility first
This means ensuring three things: complete awareness of where data lives, controls that prevent unauthorized access, and monitoring that can prove real oversight.
Breach notification timelines
DPDPA requires organizations to report to the Board without any delay followed by a detailed report within 72 hours. This runs in parallel with CERT-In’s existing requirement to report incidents within a 6 hour window.
Penalties
- Up to ₹200 crore for breach notification failure.
- Up to ₹250 crores for failing to implement required safeguards.
What are the consequences of non-compliance?
What makes the May 2027 deadline worth taking seriously is that the non-compliance comes with real financial consequences.
Organizations that fail to implement the required safeguards will be liable to a penalty of up to ₹250 crore and organizations failing to ensure breach notification timelines face penalties of up to ₹200 crore.
These figures aren’t reserved just for large, catastrophic events, they are the ceiling for a single violation, with the Board applying aggravating and mitigating factors under Section 33 to determine the actual number.
This means that even if an organization is small, the penalty figure still applies, making the consequences graver for them.
So, instead of being just a compliance conversation, DPDP has become a board-level risk conversation.
Six-month action plan for security teams
Here is what security teams should be doing in the next six months:
|
Expected by May 2027 |
What to do now |
How it gets fulfilled |
|
“Reasonable security safeguards” (Section 8) |
Identify gaps in access control, encryption, and threat detection coverage |
VAPT to surface exposure, Managed SIEM for continuous monitoring, MDR for detection and response |
|
Breach notification within DPDP + CERT-In timelines |
Test whether current monitoring can detect and triage an incident inside a 6-hour window |
Tabletop exercise against a dual-notification runbook, with SIEM alerting tuned to that timeline |
|
SDF-specific audit readiness (if applicable) |
Confirm SDF status; benchmark controls against audit-grade evidence requirements |
Technical gap assessment covering log retention, access governance, and third-party risk |
|
Legacy infrastructure exposure |
Map where personal data lives across systems, including shadow IT and legacy platforms |
Data discovery as the technical precursor to any consent or safeguard work |
How SharkStriker helps you through May 2027?
The DPDP Act has been around for almost a year now and most organizations are quite aware of its security expectations.
However, they struggle with limited expertise on board to timely identify and address both the security and compliance gaps.
Section 8’s expectations require organizations to have centralized visibility, timely detection of threats, and monitoring that isn’t just a tool deployed.
It means ensuring that tools across multiple vendors work in unison to create context that internal teams can work on.
In reality, several organizations struggle with tools that work independently without any shared context.
SharkStriker solves both challenges by offering dual expertise in security and compliance through a single MDR offering delivered via a vendor agnostic security platform that was purpose-built to centralize visibility and control.
Here are several ways through which SharkStriker can help Indian organizations be resilient and compliance-ready before the final enforcement in May 2027:
1. Centralized visibility and control through STRIEGO
DPDPA’s safeguard expectations start from organizations knowing where their data lives and how it is protected.
STRIEGO makes this easier by integrating tools across multiple vendors into a single vendor agnostic, open-architecture layer for centralized visibility and clear context for internal teams. This directly meets the Section 8’s requirement to prove not just that controls exist, but also there is complete oversight with clear context to act.
2. Round-the-clock monitoring
Organizations get threat detection coverage that extends beyond business hours. So, gaps in security (like missing access controls) or anomalous activity get flagged when they happen(supporting the DPDP Act’s reporting requirement), not during quarterly review.
3. Single stop access to security and compliance expertise
The Board’s scrutiny is on safeguards and controls that are operational, not just documented.
SharkStriker ‘s MDR service offers a single stop access to both security and compliance expertise, so the gaps against Section 8 get identified and addressed before they turn consequential, with a response team behind not just monitoring but also ready for action.
4. Vendor and domain expertise to fine tune stack for demonstrable defense
Section 8 requires defense that is demonstrable, not just documented. SharkStriker’s team can help organizations achieve this requirement by looking for missing controls, and fine tuning their stack, policies, and rules. They can help establish timely action by automating response through custom build playbooks and manage their security stack for continuous security improvement in an evolving threat landscape.
5. End-to-end compliance support
With dedicated compliance support and guidance at each step of the journey, from risk treatment to documentation, compliance no longer becomes an added pressure.