01What the DPDP Act is
The Digital Personal Data Protection Act, 2023 (Act 22 of 2023) is India’s first general law on the protection of personal data. It received Presidential assent on 11 August 2023. The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) were notified on 13 November 2025 and set out how the Act works in practice.
Once fully in force, the Act replaces the data protection regime under section 43A of the Information Technology Act, 2000 and the SPDI Rules, 2011.
02When it applies: the commencement timeline
- 14 November 2025The Data Protection Board provisions and Rules 1, 2 and 17 to 21 came into force.
- 13 November 2026The Consent Manager framework (Rule 4) applies.
- 13 May 2027The core obligations apply, including notice, consent, security safeguards, breach intimation, retention, children’s data, Significant Data Fiduciary duties and data principal rights.
A proposal to shorten the 18-month transition was discussed in early 2026, but no amendment has been notified, so 13 May 2027 remains the compliance date. Until then, section 43A of the IT Act and the SPDI Rules continue to apply.
03Who the Act applies to
The Act applies to digital personal data processed in India, whether collected in digital form or collected offline and digitised later. It also applies to processing outside India if it is connected with offering goods or services to people in India.
- It does not apply to personal data processed by an individual for a personal or domestic purpose.
- It does not apply to personal data that the individual has made publicly available, or that someone is legally obliged to make public.
04Key terms
- Data Principal: the individual the personal data relates to. For a child, it includes the parent or lawful guardian, and for a person with a disability, their lawful guardian.
- Data Fiduciary: the person or company that decides the purpose and means of processing.
- Data Processor: anyone who processes personal data on behalf of a Data Fiduciary.
- Consent Manager: a company registered with the Data Protection Board through which individuals give, manage and withdraw consent.
- Significant Data Fiduciary: a Data Fiduciary the Central Government notifies as significant, based on factors such as the volume and sensitivity of the data it processes.
05Consent and notice
Personal data may be processed only for a lawful purpose, either with the individual’s consent or for a legitimate use listed in the Act. Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the data needed for the stated purpose. Withdrawing consent must be as easy as giving it.
Every request for consent must come with a notice that sets out the personal data and the purpose, how to exercise rights, and how to complain to the Board. Under Rule 3 the notice must be clear, stand on its own and be understandable independently of other information. It can be given in English or any language in the Eighth Schedule to the Constitution.
Consent Managers must be companies incorporated in India with a net worth of at least ₹2 crore, registered with the Board. Their framework applies from 13 November 2026.
06Processing without consent: legitimate uses
Section 7 lists the situations in which personal data may be processed without consent:
- for a purpose for which the individual voluntarily provided the data and has not said they do not consent
- State subsidies, benefits, services, licences and permits, and other functions of the State
- complying with a legal obligation to disclose information to the State, or with a judgment, decree or order
- medical emergencies, treatment during an epidemic or public health threat, and safety during a disaster or breakdown of public order
- employment purposes, including protecting the employer from loss or liability
07Obligations of Data Fiduciaries
- Keep personal data complete, accurate and consistent where it is used to make a decision about the individual or is shared with another Data Fiduciary.
- Take reasonable security safeguards. Rule 6 sets minimum measures, including encryption, masking or tokenisation, access controls, logs and monitoring, backups, and keeping logs for at least one year.
- Engage Data Processors only under a valid contract.
- Erase personal data when consent is withdrawn or the purpose is no longer served, unless the law requires it to be kept.
- Publish the contact details of a Data Protection Officer or a person who can answer questions about processing, and run a grievance redressal mechanism.
08Personal data breaches
Under Rule 7, a Data Fiduciary must inform each affected individual without delay, and the Data Protection Board without delay. A detailed report must reach the Board within 72 hours of becoming aware of the breach, covering the facts, likely impact, mitigation, the cause and the remedial measures taken, unless the Board allows longer on request.
This runs alongside the CERT-In Directions of April 2022, which require specified cyber incidents to be reported to CERT-In within six hours of noticing them.
09Retention and erasure
Personal data must be erased once the purpose is served, unless the law requires otherwise. Rule 8 and the Third Schedule set a three-year period of inactivity, with 48 hours’ notice before erasure, only for large e-commerce entities (2 crore or more users in India), online gaming intermediaries (50 lakh or more) and social media intermediaries (2 crore or more).
Every Data Fiduciary must also keep personal data, related traffic data and processing logs for at least one year for the purposes in the Seventh Schedule.
10Children and persons with disabilities
A child is anyone under 18. Processing a child’s personal data needs the verifiable consent of a parent or lawful guardian. Data Fiduciaries must not process children’s data in a way likely to harm their well-being, and must not track, behaviourally monitor or target advertising at children.
Rule 10 allows parental consent to be verified through reliable identity details the Data Fiduciary already holds, details the parent provides, or a virtual token such as one issued through DigiLocker. The Fourth Schedule exempts classes such as healthcare professionals, educational institutions and crèches for specified purposes. For persons with disabilities, the guardian must be verified under Rule 11.
11Significant Data Fiduciaries and Data Protection Officers
A Significant Data Fiduciary must appoint a Data Protection Officer based in India who is responsible to its board, appoint an independent data auditor, and carry out a Data Protection Impact Assessment and an audit every 12 months (Rule 13). It must also check that algorithmic software does not put individuals’ rights at risk, and keep specified personal data in India if the government requires it. No Significant Data Fiduciary had been notified as of September 2026.
Other Data Fiduciaries do not have to appoint a DPO, but must publish the contact details of a person who can answer questions about their processing.
12Rights and duties of Data Principals
Data Fiduciaries must publish a response period for these requests of no more than 90 days (Rule 14). Individuals also have duties, such as not impersonating anyone and not filing false or frivolous complaints; a breach can attract a penalty of up to ₹10,000.
- Access: a summary of the personal data being processed and the processing, and the identities of others it has been shared with.
- Correction, completion, updating and erasure.
- Grievance redressal, which must be used before going to the Board.
- Nomination of another person to exercise these rights on death or incapacity.
13Cross-border data transfers
Personal data may be transferred outside India except to countries the Central Government restricts by notification. No country has been restricted so far. Sector laws that impose stricter localisation, such as RBI’s payment data rules, continue to apply, and Rule 15 lets the government set requirements for making data available to foreign states.
14Exemptions
Most obligations do not apply where processing is needed to enforce a legal right or claim, by courts and regulators performing their functions, for preventing, investigating or prosecuting offences, for processing in India of non-residents’ data under a foreign contract, for approved mergers and schemes of arrangement, or to ascertain the financial position of loan defaulters. The government may also exempt notified State bodies, processing for research, archiving or statistics, and classes of Data Fiduciaries such as startups.
15The Data Protection Board, appeals and penalties
The Data Protection Board of India inquires into breaches, directs remedial measures and imposes penalties. It can refer disputes to mediation and accept voluntary undertakings. The Board was established on 13 November 2025; as of September 2026, no Chairperson or Members had been reported as appointed. Appeals against its orders go to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) within 60 days.
The Schedule to the Act sets maximum penalties by type of breach. There are no criminal offences under the Act.
| Up to ₹250 crore | failing to take reasonable security safeguards |
| Up to ₹200 crore | failing to notify a personal data breach |
| Up to ₹200 crore | breaching the obligations on children’s data |
| Up to ₹150 crore | breaching the additional obligations of a Significant Data Fiduciary |
| Up to ₹50 crore | any other breach of the Act or Rules |
| Up to ₹10,000 | breach of a Data Principal’s duties |
16How the DPDP Act fits with other laws
The Act applies in addition to other laws, and prevails where they conflict. Sector regulators such as RBI, SEBI and IRDAI continue to set their own data rules. Section 44(3) amended section 8(1)(j) of the RTI Act to exempt personal information; a challenge to that amendment was referred to a larger bench of the Supreme Court in February 2026, which declined an interim stay.
17Guidance by sector
18How to prepare before 13 May 2027
- Map the personal data you collect, where it is stored, who it is shared with and why.
- Rewrite privacy notices and consent flows to meet Rule 3 and section 6, with an easy way to withdraw consent.
- Review contracts with vendors and processors, and your cross-border data flows.
- Put Rule 6 security safeguards in place and keep logs for at least one year.
- Prepare a breach response plan that meets the 72-hour report to the Board and CERT-In’s six-hour rule.
- Set retention periods and erasure processes, and a way to handle rights requests within your published response period.
- Check whether you process children’s data or could be notified as a Significant Data Fiduciary.