Legal Register
Visual Infographic
I-02 Commencement & Timelines ๐Ÿ‘ค Executive Sponsors & Legal Counsel

The Three Tranches Timeline

Staged Statutory Activation: Tranche 1 (Nov 2025), Tranche 2 (Nov 2026), and the Substantive Cliff (May 2027)

The commencement of DPDP operates across three distinct chronological milestones. Tranche 1 (13 November 2025) establishes institutional machinery, definitions, and Board formation powers. Tranche 2 (13 November 2026) activates the transitional notice and consent framework under Rule 4. Tranche 3 (13 May 2027) represents the hard substantive compliance cliff: all fiduciary obligations (ss.3โ€“17), data principal rights (ss.11โ€“14), cross-border rules (s.16), and Board penalties (ss.27โ€“34) become fully enforceable with zero bedding-in grace period.

Statutory Source: Ch. 2 ยง3, Appendix A.10
Archetype: timeline
I-02 DiagramArchetype: TIMELINE

The Three Tranches Timeline

Chronological Commencement Milestones & Statutory Activation
13 Nov 2025Tranche 1

Institutional & Board Infrastructure

Establishment of the Data Protection Board of India, appointment mechanisms, definitions, and rule-making provisions.

Activated Provisions:
s.1(2)s.2ss.18-26s.35ss.38-43s.44(1),(3)rr.1,2,17-21
13 Nov 2026Tranche 2

Transitional Notice & Consent Machinery

One-year transitional gate for preparing multilingual notices and legacy consent migration.

Activated Provisions:
r.4 (Notice transitional window)Initial CM framework setup
13 May 2027Tranche 3

The Substantive Compliance Cliff

Complete substantive enforcement. Full statutory penalties (up to โ‚น250 Cr) live with zero transitional buffer.

Activated Provisions:
ss.3-17 (Fiduciary Duties)ss.11-14 (Principal Rights)s.16 (Transfers)ss.27-34 (Penalties & Board Inquiry)rr.3,5-16,22,23

๐Ÿ’ก Core Architectural Insights & Takeaways

Key technical and regulatory takeaways established by this architecture diagram.

โœฆ The 13 May 2027 cliff has NO post-commencement grace period; all technical controls must be live before day zero.
โœฆ Tranche 1 activates governance and regulatory bodies, not enterprise duties.
โœฆ Legacy data must be re-notified or verified prior to 13 May 2027 to avoid illegal processing.

๐Ÿ“œ Statutory Grounding & Legal Perimeter

Primary Act and subordinate Rule provisions establishing the enforceable legal mandate for this diagram.

Enforceable Provisions:
Section 1(2)Rule 1Rule 2Rule 4Rules 17 to 21Rules 3,5-16,22,23

๐Ÿ—๏ธ Target Architecture & Impacted Systems

Enterprise nodes and store topologies impacted by this architectural pattern.

View Complete Topology (SYS-001..014) โ†’
SYS-001 Details โ†’
Customer App & Web Portal

Public client boundary & untrusted intake surface for notices and consent capture

SYS-002 Details โ†’
Core Lending Monolith & Transaction Store

Domestic production database and primary system of record for loan servicing

SYS-003 Details โ†’
Marketing Automation Engine

Processor-operated messaging engine (ENT-004) gated by optional consent

SYS-004 Details โ†’
Enterprise Cloud Data Warehouse

Purpose-partitioned analytical warehouse staging operational reporting

SYS-005 Details โ†’
Analytics & AI/ML Training Environment

Model training and algorithm development node gated against unconsented data

SYS-006 Details โ†’
HRMS & Applicant Tracking System

Internal employer database holding employee payroll and candidate records

SYS-007 Details โ†’
Digitized Legacy Document Archive

Cold physical and scanned document store subject to statutory retention schedules

SYS-008 Details โ†’
Foreign-Region Secondary Backup Replica

Offshore disaster recovery replica; isolated pending cross-border transfer checks

SYS-009 Details โ†’
Overseas Analytics Cluster

Third-party international BI environment (ENT-005); prohibited unconsented reuse

SYS-010 Details โ†’
Consent Ledger & Policy Decision Point

Immutable consent event store and Policy Decision Point issuing authority tokens

SYS-011 Details โ†’
Principal Rights & Grievance Service

Self-service orchestration service for managing DSARs and grievance redressal

SYS-012 Details โ†’
SIEM & Security Telemetry Store

Security log repository preserving tamper-evident dual-clock audit trails

SYS-013 Details โ†’
Processor Orchestration Gateway & Queue

Integration pipeline tracking downstream processor instructions and acknowledgements

SYS-014 Details โ†’
Restore Quarantine & Sandbox Store

Isolated test environment ensuring recovered backups pass tombstone replay

โš™๏ธ Associated Operational Controls

Control Master Matrix obligations enforcing the standards illustrated in this infographic.

Open Control Matrix โ†’

๐Ÿ› ๏ธ Implementation Guidance & Traps

Recommended technical sequencing and operational failure modes to avoid.

Recommended Implementation Sequence

  1. Calculate workback schedules backward from 13 May 2027.
  2. Complete data discovery and purpose inventory by Q3 2026.
  3. Deploy multilingual notice templates and consent ledger by 13 Nov 2026 (Tranche 2).
  4. Execute simulated breach and DSAR drills in Q1 2027.

Enterprise Traps & Failure Modes

  • โš ๏ธ Assuming a 2-year grace period begins after May 2027.
  • โš ๏ธ Failing to account for the time needed to renegotiate vendor contracts across hundreds of processors.
  • โš ๏ธ Postponing data erasure automation until after the law becomes live.

๐Ÿ“ Verifiable Evidence Artifacts Vault

Required evidentiary workpapers for regulatory inspections and SDF audits.

๐Ÿ“„ Programme Transformation Gantt Chart (manifest.json)
๐Ÿ“„ Board Readiness Briefing Pack
๐Ÿ“„ Tranche Cutover Verification Checklist (C-03)