Technology

India’s DPDP Act explained: what changes for users and companies

India's data protection law is now being switched on in stages, with most company duties due in May 2027. Here are the key terms, your rights, what companies must do, the penalties and the timeline.

Illustrative cover: India's DPDP Act explained: what changes for users and companies
Illustration: Pointales

India’s Digital Personal Data Protection Act, 2023 (the DPDP Act) is the country’s first general law on how organisations must handle people’s digital personal data. Parliament passed it in August 2023, and the rules that make it work were notified in November 2025. But most of it is not yet in force. The Data Protection Board’s framework started in November 2025, consent managers follow on 13 November 2026, and the core duties on companies (notice, consent, security, breach reporting and user rights) apply from 13 May 2027.

This is an informational explainer, not legal advice. Organisations should take professional advice on their own obligations.

The key terms

The Act uses its own vocabulary. The definitions below follow the Act and the government’s explainer (PIB).

  • Data principal: you, the person the data is about. For a child (anyone under 18), this includes the parent or lawful guardian.
  • Data fiduciary: the organisation that decides why and how your data is processed, such as a bank, app or hospital.
  • Data processor: a company that processes data on a fiduciary’s behalf, such as a cloud or call-centre vendor.
  • Significant data fiduciary (SDF): a fiduciary the government notifies for extra duties, based on factors such as the volume and sensitivity of data, risk to users, and risks to electoral democracy, security or public order (Section 10).
  • Consent manager: a registered company that gives you one platform to give, review and withdraw consent across services.

The Act covers digital personal data, and personal data collected on paper and later digitised. It also applies to processing outside India if it is linked to offering goods or services to people in India. It does not apply to data used for purely personal or domestic purposes, or to data a person has chosen to make public (DPDP Act, Section 3).

The default rule is consent. A company must give you a clear notice explaining what data it wants and why, and your consent must be specific to that purpose. You can withdraw it at any time, and withdrawing should be as easy as giving it (PIB).

Section 7 lists legitimate uses where consent is not needed. These include data you voluntarily give for a specific purpose without objecting (the Act’s example is a pharmacy texting you a receipt), government subsidies and services, legal obligations, medical emergencies and employment-related purposes (DPDP Act).

Your rights as a user

Once the substantive provisions start, you will be able to (PIB):

  1. Know what data a company holds about you and how it is used.
  2. Correct and update inaccurate or outdated data.
  3. Erase data that is no longer needed, subject to legal retention rules.
  4. Seek grievance redressal from the company first, then complain to the Data Protection Board.
  5. Nominate someone to exercise your rights if you die or become incapacitated.

Companies must respond to these requests within 90 days under the Rules. The Act also places duties on users, such as not filing false or frivolous complaints, with a penalty of up to ₹10,000.

What companies must do

The core duties on data fiduciaries, from the Act and Rules, are:

  • Security safeguards: take reasonable measures to prevent breaches, including logs of processing kept for at least a year (DPDP Rules).
  • Erase data when its purpose is over. Large e-commerce platforms and social media intermediaries (2 crore+ registered users in India) and online gaming intermediaries (50 lakh+ users) must erase a user’s data after three years of inactivity, with 48 hours’ warning first (DPDP Rules, Third Schedule).
  • Publish a contact for data questions, either a designated officer or a Data Protection Officer.
  • Extra duties for SDFs: appoint an India-based Data Protection Officer and an independent data auditor, and carry out a Data Protection Impact Assessment and audit every 12 months, reporting significant findings to the Board (DPDP Rules, Rule 13).

Consent managers must be Indian companies with a net worth of at least ₹2 crore and act in a fiduciary capacity towards users.

Children’s data

For anyone under 18, a company needs verifiable consent from a parent or guardian. Section 9 also bars “tracking or behavioural monitoring of children or targeted advertising directed at children” (DPDP Act). The Rules carve out exemptions for certain purposes and organisations, such as healthcare, education and real-time safety (PIB).

Breach notification

If personal data is breached, the company must (DPDP Rules, Rule 7):

  1. Tell each affected user without delay, in plain language: what happened, likely consequences, what it is doing and what you can do.
  2. Tell the Data Protection Board without delay, then send a detailed report within 72 hours (or longer if the Board allows).

Breach alerts may become a target for scammers posing as companies. The same caution applies as with payment scams; see how UPI frauds work.

The Data Protection Board and penalties

The Data Protection Board of India is the enforcer. The Rules make it a “digital-first” body: complaints are filed and tracked online, and appeals go to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) (PIB). The Board was established in law in November 2025, but as of 1 August 2026, LiveLaw reported that no chairperson or members had yet been appointed, though the selection process was under way (LiveLaw).

Maximum penalties are set in the Act’s Schedule (DPDP Act):

BreachMaximum penalty
Failing to take reasonable security safeguards₹250 crore
Failing to notify the Board or users of a breach₹200 crore
Breaking the rules on children’s data₹200 crore
SDF failing its additional obligations₹150 crore
Any other breach of the Act or Rules by a company₹50 crore
A user breaching their duties₹10,000

These are ceilings per instance, not fixed fines; the Board decides the amount.

When it all applies

The DPDP Rules, 2025 were published in the Gazette on 13 November 2025 with an 18-month phased start (DPDP Rules, Rule 1):

DateWhat starts
13 November 2025Definitions and the Data Protection Board’s set-up and functioning (Rules 1, 2, 17–21)
13 November 2026Registration and duties of consent managers (Rule 4)
13 May 2027Notice, consent, security, breach reporting, retention, children’s data, SDF duties, user rights and the rest (Rules 3, 5–16, 22, 23)

Two caveats. First, in January 2026 Business Standard reported, citing sources, that MeitY was considering shortening the window for certain provisions applying to significant data fiduciaries from 18 to 12 months, which would pull those deadlines forward to November 2026 (Business Standard). Legal analyses as of August 2026 still treated 13 May 2027 as the main date, with no amendment notified (Mondaq). Second, in February 2026 the Supreme Court referred challenges to the Act’s amendment of the RTI Act to a larger bench, but declined to stay the law (IFF).

Where critics push back

Section 17 lets the government exempt notified state agencies on grounds including security of the State and public order. The Internet Freedom Foundation argues the framework gives the state broad, discretionary powers and that the RTI amendment weakens transparency (IFF). How the law fits with Aadhaar, DigiLocker and the rest of India’s digital rails is covered in India Stack explained.

The point: The DPDP Act gives Indians rights to know, correct and erase their data, and puts companies on the hook for consent, security and breach reporting, with penalties of up to ₹250 crore. But most of it applies only from 13 May 2027, and the Data Protection Board was still awaiting appointments in mid-2026. Watch for any notified change to the timeline and for the Supreme Court’s ruling on the RTI amendment.

Sources