Rule 1, Short Title and Commencement: The Three-Phase Commencement of the DPDP Framework
Rule 1 appears, at first sight, to be a purely procedural provision. It gives the Rules their short title and specifies when different provisions will come into force. In the context of the Digital Personal Data Protection Act, 2023 (“DPDP Act”), however, Rule 1 performs a much more consequential function. It establishes the temporal architecture of India’s data-protection regime.
The DPDP framework does not become enforceable on a single date. The Central Government has deliberately divided implementation into three phases, with the principal operational obligations being deferred to allow Data Fiduciaries, Data Processors, Consent Managers and other participants in the ecosystem time to build the necessary legal, technical and organisational infrastructure.
The Rules were notified on 13 November 2025. The commencement notification for the Act was issued on the same date. The Gazette notification expressly divides the Act into three commencement dates:13 November 2025,13 November 2026, and13 May 2027. ([eGazette][1])
The most important point, therefore, is this:
“The DPDP Act, 2023” is not, by itself, a sufficient answer to the question whether a particular obligation is presently enforceable. One must identify the provision, identify the corresponding Rule, and then identify its applicable commencement phase.
This becomes particularly important because the commencement of the Rules does not mirror the commencement of the Act provision-by-provision in a simple one-to-one fashion. Some Rules become operative before the substantive statutory obligations which they help implement. Others commence simultaneously with the relevant statutory regime.
The entire framework can therefore be understood through the following three dates.