India's DPDP Act creates rules for collecting, using, sharing, protecting and deleting digital personal data, but most customer rights and company duties are scheduled to start on 13 May 2027, while the Consent Manager framework starts on 13 November 2026.
The law calls the person whose data is involved a Data Principal. It calls the organisation deciding the purpose and method of use a Data Fiduciary. A cloud provider, payroll firm or other vendor handling data for that organisation is a Data Processor.
The central point in 2026 is timing. Parliament passed the Digital Personal Data Protection Act, 2023 in August 2023. The government notified the final DPDP Rules, 2025 in November 2025. The Gazette then split implementation into stages. Some provisions needed to establish the Data Protection Board started in November 2025. Consent Manager registration starts in November 2026. Most rules that customers and businesses will use day to day start in May 2027.
This means the law is neither wholly inactive nor fully enforceable. Every claim about a DPDP right or duty must be read with its start date.
What is DPDP Act?
India enacted the DPDP Act on 11 August 2023 after several earlier data protection bills. The Act sets the legal framework. The Rules explain how notices, security safeguards, breach reports, children's consent, grievance systems, Consent Managers, the Data Protection Board and appeals are meant to work.
The final Rules were issued as G.S.R. 846(E), dated 13 November 2025. A corrigendum followed in December 2025. The government described the notification as the operationalisation of the Act in a Press Information Bureau release. The Gazette itself, however, gives different start dates to different provisions. That phased schedule is the controlling detail for customers, companies and public bodies.
The result is a transition period. Organisations can use it to map their data, rewrite notices, build request systems, revise vendor contracts and test breach response. Individuals should know what rights the law provides, but should also know when those rights become active.
Is India's DPDP Act in force now?
Legal status on 17 August 2026
| Stage | Date | What it covers | Status |
|---|---|---|---|
| Stage 1 | 13 November 2025 | Definitions, legal establishment and administration of the Data Protection Board, appointment process, Board meetings and staff provisions | In force |
| Stage 2 | 13 November 2026 | Registration of Consent Managers and Board action for breach of their registration conditions | Not yet in force |
| Stage 3 | 13 May 2027 | Scope, consent, notices, lawful uses, security, breach reports, deletion, children's data, individual rights, grievances, transfers, exemptions, complaints, appeals and penalties | Not yet in force |
The India Code page for the DPDP Act lists the Act, the final Rules, the corrigendum and the 13 November 2025 commencement notifications. Rule 1 of the final Rules states that Rules 1, 2 and 17 to 21 began on publication, Rule 4 begins one year later and Rules 3, 5 to 16, 22 and 23 begin 18 months later.
Why this distinction matters
It would be inaccurate to tell a reader in August 2026 that the DPDP breach notice clock, the 90-day grievance limit or the ₹250 crore penalty is already operating under the main privacy provisions. Those provisions are scheduled for 13 May 2027.
Other laws still matter before that date. The Information Technology Act, existing security rules, CERT-In reporting directions, consumer law, contract law and sector rules from bodies such as RBI, SEBI and IRDAI can apply today. DPDP is an added framework, not a reason to ignore existing duties.
Who and what does the DPDP Act cover?
The Act covers digital personal data. Personal data means information about an individual who can be identified from that information or in relation to it. Digital personal data includes data collected online and paper data that is digitised later.
Examples can include:
- a name linked to a mobile number;
- an email address tied to an account;
- a bank customer ID;
- a delivery address;
- a health record;
- an employee file;
- an IP address or device identifier when it identifies or can be linked to a person;
- account activity, purchase history or location data linked to a person.
The Act does not create a separate legal category called sensitive personal data. That is a change from the earlier Information Technology framework. Sensitivity still matters because it can affect risk, security choices, classification as a Significant Data Fiduciary and the size of a penalty.
For financial-service readers, News4Bharat's explainers on UPI rules and customer changes and CKYC 2.0 and the proposed single customer ID provide related context. KYC data may have to be retained under financial laws even when a customer asks for erasure under DPDP.
When can an organisation use personal data?
The Act allows processing for a lawful purpose on either of two bases:
- consent; or
- certain legitimate uses listed in Section 7.
The phrase "legitimate use" is not a general permission to use data whenever a company thinks the use is useful. The processing must fit one of the listed situations.
What valid consent requires
Consent must be free, specific, informed, unconditional and unambiguous. It must be shown through a clear action. It must also be limited to personal data needed for the stated purpose.
An app that needs a delivery address to send an order may ask for that address. It should not bundle an unrelated request for the phone's contact list into the same consent.
The organisation must be able to prove that it gave the required notice and obtained valid consent. Withdrawal must be as easy as giving consent. Processing already completed before withdrawal does not become unlawful only because consent is later withdrawn.
What the notice must say
From 13 May 2027, Rule 3 requires a notice that can be understood on its own. It must use clear language and include:
- an itemised description of the personal data;
- the purpose for each use;
- the goods, services or functions enabled by the processing;
- a link or method to withdraw consent;
- a method to exercise rights;
- a method to complain to the Board.
The Act also gives the person an option to access consent requests and notices in English or a language in the Eighth Schedule to the Constitution.
Uses that may not need consent
Section 7 lists certain uses, including:
- using data voluntarily supplied for a requested purpose, such as sending a receipt to a number supplied for that purpose;
- specified state benefits, services, certificates, licences or permits;
- state functions under law and stated national-security purposes;
- disclosures required by law;
- compliance with court or tribunal orders;
- medical emergencies;
- public-health action during an outbreak;
- safety and assistance during a disaster or breakdown of public order;
- employment purposes and stated steps to protect an employer from loss or liability.
The employment ground is not a complete workplace exemption. An employer still needs purpose limits, security, access control and a defensible reason for each use.
What rights will individuals have
Most of these rights start on 13 May 2027.
1. Right to access information
A person can ask for a summary of personal data being processed and the processing activities. The person can also ask for the identities of other Data Fiduciaries and Data Processors with whom the data was shared, with a description of the data shared. A limited exception applies to some law-enforcement and cyber-incident requests.
2. Right to correct and update data
A person can ask for inaccurate or misleading personal data to be corrected, incomplete data to be completed and old data to be updated.
3. Right to erasure
A person can ask for erasure. The organisation may keep data when retention remains necessary for the stated purpose or another law requires it.
This is not an unconditional right to delete every record. A bank, insurer, tax platform or employer may have another legal retention duty.
4. Right to grievance redressal
Every covered Data Fiduciary and Consent Manager must provide an accessible grievance route. Under Rule 14, the published response period cannot be longer than 90 days.
The person must first use the organisation's grievance route before approaching the Data Protection Board.
5. Right to nominate
A person can nominate another individual to exercise DPDP rights in the event of death or incapacity.
What the Act does not expressly provide
The Act does not set out a general right to data portability. It also does not contain a broad right to object to processing or a general right to demand a human decision in the same form found in some other privacy laws.
These gaps should not be filled by copying a list of rights from the European Union's GDPR.
You May Also Like - AI Privacy in 2026: What Happens to Your Personal Data After You Hit Send?
Do individuals have duties too
Yes. The Act requires a Data Principal to follow applicable law while exercising rights, avoid impersonating another person, avoid hiding material information when seeking state documents or identifiers, avoid false or frivolous complaints and provide authentic information when asking for correction or erasure.
The listed maximum penalty for breach of these duties is ₹10,000. It is not an automatic fine for a failed complaint. The Board must follow the Act's inquiry process.
What must organisations do
From 13 May 2027, a Data Fiduciary remains responsible for processing done by it or on its behalf. Outsourcing does not transfer accountability to the vendor.
Core duties include:
- use personal data only under the Act;
- provide the required notice;
- keep proof of consent when consent is the legal basis;
- use a valid contract with each Data Processor;
- keep data complete, accurate and consistent when it affects a decision or is shared with another Data Fiduciary;
- take technical and organisational steps to comply;
- apply reasonable security safeguards;
- report a personal data breach to affected people and the Board;
- erase data when consent is withdrawn or the purpose ends, unless another law requires retention;
- publish a business contact for data questions;
- operate an effective grievance system.
How does the Act protect children
The Act defines a child as a person below 18. Before processing a child's personal data, an organisation must obtain verifiable consent from a parent or lawful guardian.
It must not process data in a way likely to harm the child's well-being. It must not track or monitor a child's behaviour or direct targeted advertising at a child, subject to limited exceptions in the Rules.
The Rules provide conditional exceptions for purposes such as healthcare, education, child care, child transport, safety, legal duties and checking that a user is not a child. These are limited to the stated need. A school transport provider, for example, may track a child's location for safety during travel. That does not create a general permission to build an advertising profile.
The government may later notify a lower age for specified processing by a service that proves its processing is safe. This is not an automatic lowering of the age across all services.
What is a Significant Data Fiduciary
The Central Government can notify an organisation or class of organisations as a Significant Data Fiduciary. Factors include the volume and sensitivity of data, risk to individual rights, sovereignty, electoral democracy, state security and public order.
A notified Significant Data Fiduciary must:
- appoint a Data Protection Officer based in India who reports to its board or governing body;
- appoint an independent data auditor;
- complete a data protection impact assessment and audit every 12 months;
- send significant observations from those exercises to the Board;
- check that algorithmic software used in personal-data processing is not likely to put individual rights at risk;
- follow any government-notified restriction requiring specified data and related traffic data to stay in India.
The algorithm duty connects the privacy law with automated systems.
Startup compliance context: India startup ecosystem data 2026
Can personal data be sent outside India
The framework does not impose a general ban on overseas transfer.
Section 16 allows the Central Government to restrict transfers to notified countries or territories. Rule 15 allows transfer subject to any government requirements about making personal data available to a foreign state or an entity under its control.
Other Indian laws with stronger transfer or localisation requirements continue to apply. Significant Data Fiduciaries may also be directed to keep specified personal data and related traffic data inside India.
Companies should not translate this into a simple claim that all overseas transfers are allowed. They need to check sector rules, government orders, vendor locations, access rights and contract terms.
How will Consent Managers work
A Consent Manager is a registered company that provides one place for an individual to give, review, manage and withdraw consent across connected services.
Rule 4 starts on 13 November 2026. An applicant must be incorporated in India, have at least ₹2 crore net worth, operate an interoperable platform, pass independent certification requirements and avoid conflicts of interest. The Board will register qualified applicants and publish their details.
A Consent Manager is not the same as the privacy contact inside every company. It is a separate registered service acting for the individual.
How will complaints work?
The intended complaint path is:
- send the request or grievance to the Data Fiduciary or Consent Manager;
- give that organisation the opportunity to respond within its published period, which cannot exceed 90 days;
- if the matter remains unresolved, complain to the Data Protection Board through its digital office;
- appeal a Board order to TDSAT within 60 days.
The Board can examine complaints and breach notices, order urgent mitigation, conduct inquiries, accept voluntary undertakings and impose a penalty after finding a significant breach. It can refer a matter to mediation. Appeals are designed to be digital, and the Rules allow online payment of the appeal fee.
Current status of the Board
The Board was legally established in November 2025 and its head office was placed in the National Capital Region. MeitY invited applications for the Chairperson and member posts, with 6 July 2026 as the closing date.
On 20 July 2026, a MeitY system listed approval for voluntary Aadhaar authentication for users of the planned Data Protection Board digital office portal, including login and complaint filing. This shows portal preparation, but it is not the same as a public launch notice.
News4Bharat did not find an official appointment announcement or a live public complaint portal in the government sources reviewed through 17 August 2026. The Board should therefore be described as legally established and under operational setup, not as a fully available complaint forum. This status should be checked again before publication and after 13 November 2026.
What are the DPDP Act penalties
The Schedule lists maximum amounts. These are ceilings, not automatic fines.
| Breach | Maximum listed penalty |
|---|---|
| Failure to take reasonable security safeguards | ₹250 crore |
| Failure to notify the Board or affected person of a breach | ₹200 crore |
| Breach of duties relating to children | ₹200 crore |
| Breach of Significant Data Fiduciary duties | ₹150 crore |
| Breach of a Data Principal's duties | ₹10,000 |
| Breach of a voluntary undertaking | Up to the amount applicable to the underlying breach |
| Any other breach of the Act or Rules | ₹50 crore |
The Board must consider the nature, seriousness and duration of the breach, the type of data, repeat conduct, gain or avoided loss, mitigation, proportionality and the likely impact of the penalty.
The Act does not create a direct compensation payment for every affected person. Penalties collected by the Board go to the Consolidated Fund of India. A person may have remedies under other laws, depending on the facts.
What should people and businesses do now
Checklist for individuals
- Read the purpose before giving consent.
- Do not share an ID document when a service does not explain why it needs it.
- Use account settings to remove permissions that are no longer needed.
- Keep screenshots and emails when reporting misuse or a breach.
- Contact the organisation's privacy or grievance address first.
- For a cyber financial fraud, use the National Cyber Crime Reporting Portal and helpline 1930. Do not wait for the DPDP complaint system.
- Check the Board's official status before relying on a third-party complaint link.
Checklist for organisations before 13 November 2026
- Identify whether the business plans to apply as a Consent Manager.
- Track the Board's appointment and registration portal.
- Map personal data by source, purpose, system, vendor, country and retention period.
- Find consent that is bundled, vague, pre-ticked or difficult to withdraw.
- Record which processing relies on consent and which relies on a listed legitimate use.
Checklist for organisations before 13 May 2027
- Rewrite each notice so it works on its own and lists data and purpose.
- Make withdrawal as easy as consent.
- Build access, correction, update, erasure, nomination and grievance workflows.
- Set a grievance response period no longer than 90 days.
- Review every processor contract and require security and deletion support.
- Test encryption, masking, access controls, monitoring, backups and one-year log retention.
- Create an incident playbook for immediate customer notice and the 72-hour Board update.
- Add parent or guardian verification where children can use the service.
- Separate child safety functions from advertising and profiling.
- Document retention required by tax, employment, KYC or sector laws.
- Review overseas storage and access against sector rules and future government orders.
- Prepare evidence. A company must be able to prove notice, consent and action taken.
DPDP Act timeline and regulation tracker
| Date | Development | Legal or editorial significance |
|---|---|---|
| 24 August 2017 | Supreme Court recognised privacy as a fundamental right in the Puttaswamy judgment | Constitutional background for privacy protection |
| July 2018 | Justice B.N. Srikrishna committee submitted its report and draft bill | Early data protection framework |
| December 2019 | Personal Data Protection Bill introduced | Earlier bill with a different structure |
| August 2022 | Government withdrew the 2019 bill | Cleared the way for a new draft |
| November 2022 | Draft Digital Personal Data Protection Bill released | Basis for the 2023 law |
| 11 August 2023 | President gave assent to the DPDP Act | Act No. 22 of 2023 enacted |
| 3 January 2025 | Draft DPDP Rules published for consultation | Proposed operating detail |
| 13 November 2025 | Final Rules and commencement notifications issued | Phased implementation began |
| 11 December 2025 | Corrigendum recorded by India Code | Correction to final Rules |
| May 2026 | MeitY advertised Chairperson and member posts | Board staffing process began publicly |
| 6 July 2026 | Application deadline for Board posts | Recruitment milestone |
| 20 July 2026 | Voluntary Aadhaar authentication use case approved for planned Board portal | Portal setup signal, not a public launch notice |
| 13 November 2026 | Consent Manager registration provisions start | First customer-facing infrastructure phase |
| 13 May 2027 | Most substantive Act and Rules provisions start | Main compliance and rights date |
News4Bharat POV
The largest risk in DPDP coverage is not missing the ₹250 crore figure. It is reporting the law without its dates.
For readers, a right has value only when the route to use it exists. For businesses, a deadline matters only when the required workflow is understood. The current transition should therefore be measured by operational evidence: a list of data and purposes, notices that can be read on their own, consent records, tested deletion, vendor clauses, a child-user plan and a breach drill that can produce a customer notice and Board report.
The Rules also create two tensions that deserve continued reporting. First, the law supports erasure but preserves data when another law or listed government purpose requires retention. Second, the framework allows overseas transfers but keeps room for later restrictions and specified localisation. Both points will be settled in practice through notifications, Board orders and sector rules.
The Board's operational status is the next reporting test. Legal establishment, recruitment, identity verification approval and a working complaint portal are separate milestones. News coverage should label each one correctly.
Primary sources
- Digital Personal Data Protection Act, 2023, official MeitY PDF
- Digital Personal Data Protection Rules, 2025, official Gazette PDF
- India Code DPDP Act page with Rules, corrigendum and commencement notifications
- MeitY DPDP Act page
- PIB release on the final DPDP Rules
- MeitY vacancy notice for Data Protection Board Chairperson and members
- Government list showing the planned Board portal Aadhaar use case
- PIB cybersecurity incident data
- CERT-In security incident reporting page
Updated on 17 August 2026: Added the current phased commencement position, the July 2026 Board recruitment and portal-preparation developments, the final breach and retention rules, and a source check on the Board's operational status.


