Home › Law library › DPDP Act / DPDP Rules
IN
DPDP Act / DPDP Rules
Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025
Sourced. Last verified 9 October 2026
India Privacy
- Status
- Enacted; phased in. Rules notified 13 Nov 2025 (G.S.R. 846(E)). Board rules in force 13 Nov 2025; consent manager rules from 13 Nov 2026; most business obligations from 13 May 2027.
- Who it applies to
- Processing of digital personal data in India, and processing outside India linked to offering goods or services to people in India. Personal/domestic use and data made public by the individual are excluded.
- Size thresholds
- No size threshold: every Data Fiduciary is covered. Government may designate Significant Data Fiduciaries (SDFs) based on data volume, sensitivity and risk; SDFs carry extra duties.
- Regulator
- Data Protection Board of India (appeals to TDSAT); rules made by the Ministry of Electronics and IT (MeitY)
- Breach or incident reporting
- Tell the Board without delay, then file a detailed report within 72 hours of becoming aware (extendable by the Board). Tell each affected individual without delay in plain language. No materiality threshold. CERT-In rules also apply.
- Deadline to answer personal data requests
- Respond to access, correction, update and erasure requests within a maximum of 90 days (Rule 14(3)).
- Data protection officer
- All fiduciaries must publish contact details of a person who can answer data queries (a designated officer or DPO). SDFs must appoint an India-based DPO reporting to the board.
- Local representative
- No separate local representative rule. Foreign fiduciaries in scope must still publish a contact person; SDF DPOs must be based in India.
- Sending data abroad
- Allowed by default unless the government restricts a country or conditions by order. Sector rules (e.g. RBI, SEBI) may require localisation. SDFs may face data-localisation directions and cannot send specified traffic data abroad.
- Cookies and consent
- Consent must be free, specific, informed and unambiguous, after a clear notice; it can be withdrawn as easily as given. Verifiable parental consent is needed for under-18s; no tracking or targeted ads aimed at children.
- Maximum penalty
- Up to INR 250 crore per breach for failing to keep reasonable security safeguards; up to INR 200 crore for breach-notice or children's data failures; up to INR 50 crore for other violations.
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Give a clear, itemised privacy notice and get valid consent, or rely on a listed legitimate use
- Get verifiable parental consent before processing data of anyone under 18
- Put reasonable security safeguards in place and bind processors by contract
- Report breaches to the Board without delay, file a full report within 72 hours, and notify affected people
- Answer access, correction and erasure requests within 90 days and run a grievance process
- Delete data once its purpose ends; large e-commerce, social and gaming platforms delete after 3 years of inactivity
- Publish a contact person for data queries; if designated an SDF, appoint an India-based DPO and run annual DPIAs and audits
Recent changes
Rules notified 13 Nov 2025 with an 18-month phase-in to 13 May 2027. In Jan-Feb 2026 MeitY consulted on shortening this to 12 months (13 Nov 2026); no amendment had been notified as of the sources checked. Board members not yet appointed as of Aug 2026.
Sources
- Primary source: https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf
- Second source: https://ssrana.in/articles/meity-notifies-final-digital-personal-data-protection-rules-2025/
- Regulator: Data Protection Board of India (appeals to TDSAT); rules made by the Ministry of Electronics and IT (MeitY)
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].