Skip to content
GlanceDeskJurisdiction

Home › Law library › DPDP Act / DPDP Rules

IN

DPDP Act / DPDP Rules

Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025

Sourced. Last verified 9 October 2026

India Privacy

Status
Enacted; phased in. Rules notified 13 Nov 2025 (G.S.R. 846(E)). Board rules in force 13 Nov 2025; consent manager rules from 13 Nov 2026; most business obligations from 13 May 2027.
Who it applies to
Processing of digital personal data in India, and processing outside India linked to offering goods or services to people in India. Personal/domestic use and data made public by the individual are excluded.
Size thresholds
No size threshold: every Data Fiduciary is covered. Government may designate Significant Data Fiduciaries (SDFs) based on data volume, sensitivity and risk; SDFs carry extra duties.
Regulator
Data Protection Board of India (appeals to TDSAT); rules made by the Ministry of Electronics and IT (MeitY)
Breach or incident reporting
Tell the Board without delay, then file a detailed report within 72 hours of becoming aware (extendable by the Board). Tell each affected individual without delay in plain language. No materiality threshold. CERT-In rules also apply.
Deadline to answer personal data requests
Respond to access, correction, update and erasure requests within a maximum of 90 days (Rule 14(3)).
Data protection officer
All fiduciaries must publish contact details of a person who can answer data queries (a designated officer or DPO). SDFs must appoint an India-based DPO reporting to the board.
Local representative
No separate local representative rule. Foreign fiduciaries in scope must still publish a contact person; SDF DPOs must be based in India.
Sending data abroad
Allowed by default unless the government restricts a country or conditions by order. Sector rules (e.g. RBI, SEBI) may require localisation. SDFs may face data-localisation directions and cannot send specified traffic data abroad.
Cookies and consent
Consent must be free, specific, informed and unambiguous, after a clear notice; it can be withdrawn as easily as given. Verifiable parental consent is needed for under-18s; no tracking or targeted ads aimed at children.
Maximum penalty
Up to INR 250 crore per breach for failing to keep reasonable security safeguards; up to INR 200 crore for breach-notice or children's data failures; up to INR 50 crore for other violations.

Facts marked “Being verified” are still being confirmed and are not given as answers.

What you must do

Recent changes

Rules notified 13 Nov 2025 with an 18-month phase-in to 13 May 2027. In Jan-Feb 2026 MeitY consulted on shortening this to 12 months (13 Nov 2026); no amendment had been notified as of the sources checked. Board members not yet appointed as of Aug 2026.

Sources

Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].