India's DPDP Act Explained: Rights, Rules and Deadlines

A plain-language guide to India's DPDP Act, including what is in force, individual rights, company duties, breach reporting, penalties and the 2027 compliance date.

Srajan AgarwalSrajan AgarwalFounder & Editor-in-Chief17 Aug 2026 · 1:47 PM IST16 min read
India's DPDP Act Explained: Rights, Rules and Deadlines

India's DPDP Act creates rules for collecting, using, sharing, protecting and deleting digital personal data, but most customer rights and company duties are scheduled to start on 13 May 2027, while the Consent Manager framework starts on 13 November 2026.

The law calls the person whose data is involved a Data Principal. It calls the organisation deciding the purpose and method of use a Data Fiduciary. A cloud provider, payroll firm or other vendor handling data for that organisation is a Data Processor.

The central point in 2026 is timing. Parliament passed the Digital Personal Data Protection Act, 2023 in August 2023. The government notified the final DPDP Rules, 2025 in November 2025. The Gazette then split implementation into stages. Some provisions needed to establish the Data Protection Board started in November 2025. Consent Manager registration starts in November 2026. Most rules that customers and businesses will use day to day start in May 2027.

This means the law is neither wholly inactive nor fully enforceable. Every claim about a DPDP right or duty must be read with its start date.

What is DPDP Act?

India enacted the DPDP Act on 11 August 2023 after several earlier data protection bills. The Act sets the legal framework. The Rules explain how notices, security safeguards, breach reports, children's consent, grievance systems, Consent Managers, the Data Protection Board and appeals are meant to work.

The final Rules were issued as G.S.R. 846(E), dated 13 November 2025. A corrigendum followed in December 2025. The government described the notification as the operationalisation of the Act in a Press Information Bureau release. The Gazette itself, however, gives different start dates to different provisions. That phased schedule is the controlling detail for customers, companies and public bodies.

The result is a transition period. Organisations can use it to map their data, rewrite notices, build request systems, revise vendor contracts and test breach response. Individuals should know what rights the law provides, but should also know when those rights become active.

Is India's DPDP Act in force now?

Legal status on 17 August 2026

StageDateWhat it coversStatus
Stage 113 November 2025Definitions, legal establishment and administration of the Data Protection Board, appointment process, Board meetings and staff provisionsIn force
Stage 213 November 2026Registration of Consent Managers and Board action for breach of their registration conditionsNot yet in force
Stage 313 May 2027Scope, consent, notices, lawful uses, security, breach reports, deletion, children's data, individual rights, grievances, transfers, exemptions, complaints, appeals and penaltiesNot yet in force

The India Code page for the DPDP Act lists the Act, the final Rules, the corrigendum and the 13 November 2025 commencement notifications. Rule 1 of the final Rules states that Rules 1, 2 and 17 to 21 began on publication, Rule 4 begins one year later and Rules 3, 5 to 16, 22 and 23 begin 18 months later.

Why this distinction matters

It would be inaccurate to tell a reader in August 2026 that the DPDP breach notice clock, the 90-day grievance limit or the ₹250 crore penalty is already operating under the main privacy provisions. Those provisions are scheduled for 13 May 2027.

Other laws still matter before that date. The Information Technology Act, existing security rules, CERT-In reporting directions, consumer law, contract law and sector rules from bodies such as RBI, SEBI and IRDAI can apply today. DPDP is an added framework, not a reason to ignore existing duties.

Who and what does the DPDP Act cover?

The Act covers digital personal data. Personal data means information about an individual who can be identified from that information or in relation to it. Digital personal data includes data collected online and paper data that is digitised later.

Examples can include:

  • a name linked to a mobile number;
  • an email address tied to an account;
  • a bank customer ID;
  • a delivery address;
  • a health record;
  • an employee file;
  • an IP address or device identifier when it identifies or can be linked to a person;
  • account activity, purchase history or location data linked to a person.

The Act does not create a separate legal category called sensitive personal data. That is a change from the earlier Information Technology framework. Sensitivity still matters because it can affect risk, security choices, classification as a Significant Data Fiduciary and the size of a penalty.

For financial-service readers, News4Bharat's explainers on UPI rules and customer changes and CKYC 2.0 and the proposed single customer ID provide related context. KYC data may have to be retained under financial laws even when a customer asks for erasure under DPDP.

When can an organisation use personal data?

The Act allows processing for a lawful purpose on either of two bases:

  • consent; or
  • certain legitimate uses listed in Section 7.

The phrase "legitimate use" is not a general permission to use data whenever a company thinks the use is useful. The processing must fit one of the listed situations.

What valid consent requires

Consent must be free, specific, informed, unconditional and unambiguous. It must be shown through a clear action. It must also be limited to personal data needed for the stated purpose.

An app that needs a delivery address to send an order may ask for that address. It should not bundle an unrelated request for the phone's contact list into the same consent.

The organisation must be able to prove that it gave the required notice and obtained valid consent. Withdrawal must be as easy as giving consent. Processing already completed before withdrawal does not become unlawful only because consent is later withdrawn.

What the notice must say

From 13 May 2027, Rule 3 requires a notice that can be understood on its own. It must use clear language and include:

  • an itemised description of the personal data;
  • the purpose for each use;
  • the goods, services or functions enabled by the processing;
  • a link or method to withdraw consent;
  • a method to exercise rights;
  • a method to complain to the Board.

The Act also gives the person an option to access consent requests and notices in English or a language in the Eighth Schedule to the Constitution.

Uses that may not need consent

Section 7 lists certain uses, including:

  • using data voluntarily supplied for a requested purpose, such as sending a receipt to a number supplied for that purpose;
  • specified state benefits, services, certificates, licences or permits;
  • state functions under law and stated national-security purposes;
  • disclosures required by law;
  • compliance with court or tribunal orders;
  • medical emergencies;
  • public-health action during an outbreak;
  • safety and assistance during a disaster or breakdown of public order;
  • employment purposes and stated steps to protect an employer from loss or liability.

The employment ground is not a complete workplace exemption. An employer still needs purpose limits, security, access control and a defensible reason for each use.

What rights will individuals have

Most of these rights start on 13 May 2027.

1. Right to access information

A person can ask for a summary of personal data being processed and the processing activities. The person can also ask for the identities of other Data Fiduciaries and Data Processors with whom the data was shared, with a description of the data shared. A limited exception applies to some law-enforcement and cyber-incident requests.

2. Right to correct and update data

A person can ask for inaccurate or misleading personal data to be corrected, incomplete data to be completed and old data to be updated.

3. Right to erasure

A person can ask for erasure. The organisation may keep data when retention remains necessary for the stated purpose or another law requires it.

This is not an unconditional right to delete every record. A bank, insurer, tax platform or employer may have another legal retention duty.

4. Right to grievance redressal

Every covered Data Fiduciary and Consent Manager must provide an accessible grievance route. Under Rule 14, the published response period cannot be longer than 90 days.

The person must first use the organisation's grievance route before approaching the Data Protection Board.

5. Right to nominate

A person can nominate another individual to exercise DPDP rights in the event of death or incapacity.

What the Act does not expressly provide

The Act does not set out a general right to data portability. It also does not contain a broad right to object to processing or a general right to demand a human decision in the same form found in some other privacy laws.

These gaps should not be filled by copying a list of rights from the European Union's GDPR.

You May Also Like - AI Privacy in 2026: What Happens to Your Personal Data After You Hit Send?

Do individuals have duties too

Yes. The Act requires a Data Principal to follow applicable law while exercising rights, avoid impersonating another person, avoid hiding material information when seeking state documents or identifiers, avoid false or frivolous complaints and provide authentic information when asking for correction or erasure.

The listed maximum penalty for breach of these duties is ₹10,000. It is not an automatic fine for a failed complaint. The Board must follow the Act's inquiry process.

What must organisations do

From 13 May 2027, a Data Fiduciary remains responsible for processing done by it or on its behalf. Outsourcing does not transfer accountability to the vendor.

Core duties include:

  • use personal data only under the Act;
  • provide the required notice;
  • keep proof of consent when consent is the legal basis;
  • use a valid contract with each Data Processor;
  • keep data complete, accurate and consistent when it affects a decision or is shared with another Data Fiduciary;
  • take technical and organisational steps to comply;
  • apply reasonable security safeguards;
  • report a personal data breach to affected people and the Board;
  • erase data when consent is withdrawn or the purpose ends, unless another law requires retention;
  • publish a business contact for data questions;
  • operate an effective grievance system.

How does the Act protect children

The Act defines a child as a person below 18. Before processing a child's personal data, an organisation must obtain verifiable consent from a parent or lawful guardian.

It must not process data in a way likely to harm the child's well-being. It must not track or monitor a child's behaviour or direct targeted advertising at a child, subject to limited exceptions in the Rules.

The Rules provide conditional exceptions for purposes such as healthcare, education, child care, child transport, safety, legal duties and checking that a user is not a child. These are limited to the stated need. A school transport provider, for example, may track a child's location for safety during travel. That does not create a general permission to build an advertising profile.

The government may later notify a lower age for specified processing by a service that proves its processing is safe. This is not an automatic lowering of the age across all services.

What is a Significant Data Fiduciary

The Central Government can notify an organisation or class of organisations as a Significant Data Fiduciary. Factors include the volume and sensitivity of data, risk to individual rights, sovereignty, electoral democracy, state security and public order.

A notified Significant Data Fiduciary must:

  • appoint a Data Protection Officer based in India who reports to its board or governing body;
  • appoint an independent data auditor;
  • complete a data protection impact assessment and audit every 12 months;
  • send significant observations from those exercises to the Board;
  • check that algorithmic software used in personal-data processing is not likely to put individual rights at risk;
  • follow any government-notified restriction requiring specified data and related traffic data to stay in India.

The algorithm duty connects the privacy law with automated systems.

Startup compliance context: India startup ecosystem data 2026

Can personal data be sent outside India

The framework does not impose a general ban on overseas transfer.

Section 16 allows the Central Government to restrict transfers to notified countries or territories. Rule 15 allows transfer subject to any government requirements about making personal data available to a foreign state or an entity under its control.

Other Indian laws with stronger transfer or localisation requirements continue to apply. Significant Data Fiduciaries may also be directed to keep specified personal data and related traffic data inside India.

Companies should not translate this into a simple claim that all overseas transfers are allowed. They need to check sector rules, government orders, vendor locations, access rights and contract terms.

How will Consent Managers work

A Consent Manager is a registered company that provides one place for an individual to give, review, manage and withdraw consent across connected services.

Rule 4 starts on 13 November 2026. An applicant must be incorporated in India, have at least ₹2 crore net worth, operate an interoperable platform, pass independent certification requirements and avoid conflicts of interest. The Board will register qualified applicants and publish their details.

A Consent Manager is not the same as the privacy contact inside every company. It is a separate registered service acting for the individual.

How will complaints work?

The intended complaint path is:

  • send the request or grievance to the Data Fiduciary or Consent Manager;
  • give that organisation the opportunity to respond within its published period, which cannot exceed 90 days;
  • if the matter remains unresolved, complain to the Data Protection Board through its digital office;
  • appeal a Board order to TDSAT within 60 days.

The Board can examine complaints and breach notices, order urgent mitigation, conduct inquiries, accept voluntary undertakings and impose a penalty after finding a significant breach. It can refer a matter to mediation. Appeals are designed to be digital, and the Rules allow online payment of the appeal fee.

Current status of the Board

The Board was legally established in November 2025 and its head office was placed in the National Capital Region. MeitY invited applications for the Chairperson and member posts, with 6 July 2026 as the closing date.

On 20 July 2026, a MeitY system listed approval for voluntary Aadhaar authentication for users of the planned Data Protection Board digital office portal, including login and complaint filing. This shows portal preparation, but it is not the same as a public launch notice.

News4Bharat did not find an official appointment announcement or a live public complaint portal in the government sources reviewed through 17 August 2026. The Board should therefore be described as legally established and under operational setup, not as a fully available complaint forum. This status should be checked again before publication and after 13 November 2026.

What are the DPDP Act penalties

The Schedule lists maximum amounts. These are ceilings, not automatic fines.

BreachMaximum listed penalty
Failure to take reasonable security safeguards₹250 crore
Failure to notify the Board or affected person of a breach₹200 crore
Breach of duties relating to children₹200 crore
Breach of Significant Data Fiduciary duties₹150 crore
Breach of a Data Principal's duties₹10,000
Breach of a voluntary undertakingUp to the amount applicable to the underlying breach
Any other breach of the Act or Rules₹50 crore

The Board must consider the nature, seriousness and duration of the breach, the type of data, repeat conduct, gain or avoided loss, mitigation, proportionality and the likely impact of the penalty.

The Act does not create a direct compensation payment for every affected person. Penalties collected by the Board go to the Consolidated Fund of India. A person may have remedies under other laws, depending on the facts.

What should people and businesses do now

Checklist for individuals

  • Read the purpose before giving consent.
  • Do not share an ID document when a service does not explain why it needs it.
  • Use account settings to remove permissions that are no longer needed.
  • Keep screenshots and emails when reporting misuse or a breach.
  • Contact the organisation's privacy or grievance address first.
  • For a cyber financial fraud, use the National Cyber Crime Reporting Portal and helpline 1930. Do not wait for the DPDP complaint system.
  • Check the Board's official status before relying on a third-party complaint link.

Checklist for organisations before 13 November 2026

  • Identify whether the business plans to apply as a Consent Manager.
  • Track the Board's appointment and registration portal.
  • Map personal data by source, purpose, system, vendor, country and retention period.
  • Find consent that is bundled, vague, pre-ticked or difficult to withdraw.
  • Record which processing relies on consent and which relies on a listed legitimate use.

Checklist for organisations before 13 May 2027

  • Rewrite each notice so it works on its own and lists data and purpose.
  • Make withdrawal as easy as consent.
  • Build access, correction, update, erasure, nomination and grievance workflows.
  • Set a grievance response period no longer than 90 days.
  • Review every processor contract and require security and deletion support.
  • Test encryption, masking, access controls, monitoring, backups and one-year log retention.
  • Create an incident playbook for immediate customer notice and the 72-hour Board update.
  • Add parent or guardian verification where children can use the service.
  • Separate child safety functions from advertising and profiling.
  • Document retention required by tax, employment, KYC or sector laws.
  • Review overseas storage and access against sector rules and future government orders.
  • Prepare evidence. A company must be able to prove notice, consent and action taken.

DPDP Act timeline and regulation tracker

DateDevelopmentLegal or editorial significance
24 August 2017Supreme Court recognised privacy as a fundamental right in the Puttaswamy judgmentConstitutional background for privacy protection
July 2018Justice B.N. Srikrishna committee submitted its report and draft billEarly data protection framework
December 2019Personal Data Protection Bill introducedEarlier bill with a different structure
August 2022Government withdrew the 2019 billCleared the way for a new draft
November 2022Draft Digital Personal Data Protection Bill releasedBasis for the 2023 law
11 August 2023President gave assent to the DPDP ActAct No. 22 of 2023 enacted
3 January 2025Draft DPDP Rules published for consultationProposed operating detail
13 November 2025Final Rules and commencement notifications issuedPhased implementation began
11 December 2025Corrigendum recorded by India CodeCorrection to final Rules
May 2026MeitY advertised Chairperson and member postsBoard staffing process began publicly
6 July 2026Application deadline for Board postsRecruitment milestone
20 July 2026Voluntary Aadhaar authentication use case approved for planned Board portalPortal setup signal, not a public launch notice
13 November 2026Consent Manager registration provisions startFirst customer-facing infrastructure phase
13 May 2027Most substantive Act and Rules provisions startMain compliance and rights date

News4Bharat POV

The largest risk in DPDP coverage is not missing the ₹250 crore figure. It is reporting the law without its dates.

For readers, a right has value only when the route to use it exists. For businesses, a deadline matters only when the required workflow is understood. The current transition should therefore be measured by operational evidence: a list of data and purposes, notices that can be read on their own, consent records, tested deletion, vendor clauses, a child-user plan and a breach drill that can produce a customer notice and Board report.

The Rules also create two tensions that deserve continued reporting. First, the law supports erasure but preserves data when another law or listed government purpose requires retention. Second, the framework allows overseas transfers but keeps room for later restrictions and specified localisation. Both points will be settled in practice through notifications, Board orders and sector rules.

The Board's operational status is the next reporting test. Legal establishment, recruitment, identity verification approval and a working complaint portal are separate milestones. News coverage should label each one correctly.

Primary sources

  • Digital Personal Data Protection Act, 2023, official MeitY PDF
  • Digital Personal Data Protection Rules, 2025, official Gazette PDF
  • India Code DPDP Act page with Rules, corrigendum and commencement notifications
  • MeitY DPDP Act page
  • PIB release on the final DPDP Rules
  • MeitY vacancy notice for Data Protection Board Chairperson and members
  • Government list showing the planned Board portal Aadhaar use case
  • PIB cybersecurity incident data
  • CERT-In security incident reporting page

Updated on 17 August 2026: Added the current phased commencement position, the July 2026 Board recruitment and portal-preparation developments, the final breach and retention rules, and a source check on the Board's operational status.

Frequently Asked Questions

Is the DPDP Act in force in India now?

Partly. Board setup and procedural provisions started on 13 November 2025. Consent Manager registration provisions start on 13 November 2026.

What does DPDP stand for?

DPDP stands for Digital Personal Data Protection.

Does the Act cover paper records?

It covers personal data collected on paper if that data is digitised later. A paper file that remains entirely non-digital is outside the stated scope of Section 3.

Does every use of personal data require consent?

No. Consent is one legal basis. Section 7 lists certain legitimate uses, including requested services, legal disclosures, emergencies, public-health action and specified employment purposes.

Can I ask a company to delete my data?

Yes, from the main commencement date. The company may retain data needed for the stated purpose or required by another law.

Can a person complain directly to the Data Protection Board?

The Act requires the person to first use the grievance route offered by the Data Fiduciary or Consent Manager. The Board's public complaint portal and staffing should also be confirmed before a complaint route is published.

Srajan Agarwal

About the Author

Srajan Agarwal

Founder & Editor-in-Chief

Srajan Agarwal, an advertising, digital marketing, and content strategy professional driven by the idea that powerful storytelling can shape brands, influence decisions, and build lasting impact. As the Founder of News4Bharat and someone deeply involved in content-led initiatives, I work at the intersection of content marketing, digital growth, media strategy, and brand storytelling. My experience spans across building editorial ecosystems, executing high-performance digital campaigns, and crafting narratives that connect with the right audience at the right time. Over the years, I’ve worked on content strategy, SEO content writing, social media marketing, performance marketing, branding, and digital campaign execution, helping brands establish a strong and differentiated voice in competitive markets. I believe in blending creative storytelling with data-driven marketing, ensuring that every piece of content is not just engaging—but also delivers measurable results.

© Copyright 2026 News4Bharat - All Rights Reserved.