India's DPDP Act Is Mostly Not in Force Yet, and Leaves Out What Other Regimes Regulate Most
Correction, September 21, 2026. The commencement table originally listed sections 35 to 43 as in force from 13 November 2025. G.S.R. 843(E) brought section 1(2) and sections 35 and 38 to 43 into force on that date; sections 36 and 37 commence eighteen months after it.
Key Takeaways
- The commencement notification brought sections 3 to 17 — the core obligations — into force eighteen months from 13 November 2025, so they take effect around 13 May 2027
- The Act recognises only two grounds for processing: consent, and the "certain legitimate uses" listed in section 7. There is no legitimate interests balancing test and no special category of sensitive data
- Section 9(3) flatly prohibits tracking, behavioural monitoring and targeted advertising directed at children, and a child is anyone under 18
- Section 16 permits transfers abroad unless the Central Government notifies a restriction on a particular country — the inverse of an adequacy model
- Section 15 imposes duties on individuals, and the Schedule attaches a penalty of up to ₹10,000 for breaching them, including for filing a false or frivolous complaint
Most of the Act Is Not in Force Yet
Coverage of the DPDP Act routinely describes obligations in the present tense. The commencement schedule says otherwise, and it is the first thing worth checking.
The Act was passed on 11 August 2023 but section 1(2) provided that it would come into force on such date as the Central Government appointed by notification, expressly allowing "different dates for different provisions". The consolidated text published by India Code, stated as on 19 November 2025, records the notification that finally did it: G.S.R. 843(E) dated 13 November 2025, published in the Gazette of India, Extraordinary, Part II, section 3(i). It splits the Act into three tranches:
| In force | Provisions |
|---|---|
| 13 November 2025 | Section 1(2), section 2 (definitions), sections 18 to 26 (the Data Protection Board), sections 35 and 38 to 43, and section 44(1) and (3) |
| One year from 13 November 2025 | Section 6(9), and section 27(1)(d) |
| Eighteen months from 13 November 2025 | Sections 3 to 5, section 6(1) to (8) and (10), sections 7 to 17, section 27 except (1)(d), sections 28 to 34, 36, 37, and section 44(2) |
The third tranche is the substantive law: the grounds for processing, the notice requirement, consent, legitimate uses, children's data, significant data fiduciaries, data principal rights and duties, and cross-border transfers. On the notification's own terms, those provisions take effect eighteen months from 13 November 2025 — around 13 May 2027.
What did commence immediately is the institutional half: the definitions, and the Data Protection Board of India. The Press Information Bureau's release on the Rules describes the Board as a fully digital institution, with complaints filed and tracked online through a dedicated platform and mobile app, and appeals from its decisions lying to the Telecom Disputes Settlement and Appellate Tribunal. That an existing telecoms tribunal hears data protection appeals is itself a design choice — no specialist appellate body was created.
The Digital Personal Data Protection Rules, 2025 were notified on 14 November 2025. The PIB release records that MeitY consulted in Delhi, Mumbai, Guwahati, Kolkata, Hyderabad, Bengaluru and Chennai, and a MeitY-published summary states that 6,915 inputs were received.
Two Grounds, and Nothing Called Sensitive Data
Section 4 permits processing only for a lawful purpose and only on one of two footings: a purpose for which the Data Principal has given consent, or "certain legitimate uses".
That is the entire list. There is no legitimate interests basis requiring a balancing exercise, no vital interests limb, no public task ground of general application. Section 7 defines the legitimate uses exhaustively, opening with the case where the individual has voluntarily provided her personal data for a specified purpose and has not indicated that she does not consent to its use — and continuing into State provision of subsidies, benefits, services, certificates, licences and permits, among others.
Section 7 is also where the Act's drafting style becomes visible. The section carries worked illustrations in the statutory text itself. One describes a person making a purchase at a pharmacy who asks for a receipt by text message, and states that the pharmacy may process her data to send it. Another describes a person asking a real estate broker to find rented accommodation, and adds that once she tells the broker she no longer needs help, the broker "shall cease to process the personal data". MeitY calls this the SARAL design — Simple, Accessible, Rational and Actionable.
The larger absence is a category. The Act has no equivalent of GDPR Article 9, LGPD Article 11 or PIPL's "sensitive personal information". Health data, biometric data, religious belief, caste, sexual orientation and political opinion carry no distinct statutory treatment. The 2011 SPDI Rules had defined sensitive personal data under section 43A of the Information Technology Act 2000 — and section 44(2)(a) of the DPDP Act omits section 43A altogether.
Children Get a Prohibition, Not a Consent Requirement
Section 2(f) defines a child as "an individual who has not completed the age of eighteen years". That is the highest threshold among the regimes covered on this site: the UK sets 13 in Article 8(1) of the UK GDPR, the EU defaults to 16 with a member state floor of 13, and COPPA reaches under-13s in the United States.
Section 9(1) requires verifiable consent of the parent or lawful guardian before processing any personal data of a child, or of a person with disability who has a lawful guardian. Section 9(2) prohibits processing likely to cause any detrimental effect on a child's well-being.
Section 9(3) is the provision with no close analogue anywhere else, and it is a flat prohibition rather than a condition:
A Data Fiduciary shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children.
Digital Personal Data Protection Act, 2023, section 9(3)
No parental consent cures it. Two escape routes exist, both controlled by government rather than by the fiduciary. Section 9(4) allows sub-sections (1) and (3) to be disapplied for prescribed classes of Data Fiduciary, prescribed purposes and prescribed conditions. Section 9(5) goes further: where the Central Government is satisfied that a Data Fiduciary processes children's data "in a manner that is verifiably safe", it may notify an age above which that particular fiduciary is exempt from all or any of the obligations in sub-sections (1) and (3). A regulator-granted, entity-specific lowering of the age of consent has no counterpart in the other regimes here.
The PIB release records that the Rules provide limited exemptions for essential purposes such as healthcare, education and real-time safety, and that for persons with disabilities who cannot make legal decisions even with support, consent must come from a lawful guardian verified under applicable laws.
Transfers Work by Negative List
Section 16 is two sub-sections long and reverses the European default:
The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified.
Digital Personal Data Protection Act, 2023, section 16(1)
There is no adequacy assessment, no standard contractual clauses, no binding corporate rules, no transfer impact assessment and no derogations list. Transfer is permitted unless and until the government names a destination it is not permitted to. Where an adequacy regime asks a controller to establish that a destination is safe, this asks only whether the destination appears on a list.
Section 16(2) preserves stricter sectoral rules: nothing in the section restricts the applicability of any Indian law providing a higher degree of protection or restriction on transfer for any personal data, Data Fiduciary or class of them. Reserve Bank of India payment-data localisation and comparable sectoral mandates therefore continue to operate above section 16 rather than being displaced by it. The PIB release adds that Significant Data Fiduciaries must comply with government-specified restrictions on certain categories of data, "including localisation where required".
Section 17(1)(d) also exempts from Chapter II, Chapter III and section 16 the processing of personal data of individuals not within India, carried out pursuant to a contract with a person outside India by a person based in India — the outsourcing carve-out that keeps Indian service providers processing foreign data outside most of the Act.
Consent Managers Are a Registered Class
Section 2(g) defines a Consent Manager as "a person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform".
Registration with the regulator is part of the definition, so the role is a licensed intermediary rather than a market service. The PIB release adds a further condition drawn from the Rules: Consent Managers "must be companies based in India". A foreign-incorporated consent platform cannot occupy the role, whatever its technical capability.
The same release describes the Rules as requiring standalone consent notices in clear and simple language explaining the specific purpose of collection and use, requiring Data Fiduciaries to display contact information for a designated officer or Data Protection Officer, and requiring responses to access, correction, update, erasure and nomination requests within a maximum of 90 days.
Significant Data Fiduciaries Are Designated on Political Criteria
Section 10 lets the Central Government notify any Data Fiduciary, or class of them, as a Significant Data Fiduciary. The factors it may consider are broader than data-protection risk: the volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential impact on "the sovereignty and integrity of India", risk to electoral democracy, security of the State, and public order.
Three of those six are national-security or political criteria rather than privacy ones, and no quantitative threshold appears in the statute — designation is an executive act, not a self-assessment against a user count or turnover figure. A company cannot read the Act and determine whether it is a Significant Data Fiduciary; it finds out when it is notified.
The consequences under section 10(2) are concrete. A Significant Data Fiduciary must appoint a Data Protection Officer who represents it under the Act, is based in India, is an individual answerable to the board of directors or similar governing body, and is the point of contact for grievance redressal. It must appoint an independent data auditor to evaluate its compliance. And it must undertake periodic Data Protection Impact Assessments — defined in the section as a process describing Data Principals' rights and the purpose of processing, and assessing and managing risk to those rights — along with periodic audits and whatever further measures are prescribed.
The Data Principal Has Duties — and a Penalty
Section 15 lists duties owed by the individual the Act protects. She is to comply with applicable laws while exercising her rights; not to impersonate another person when providing personal data; not to suppress material information when providing data for a State-issued document, unique identifier, proof of identity or proof of address; "to ensure not to register a false or frivolous grievance or complaint with a Data Fiduciary or the Board"; and to furnish only verifiably authentic information when exercising the right to correction or erasure.
The Schedule then gives that section teeth. "Breach in observance of the duties under section 15" carries a penalty that may extend to ten thousand rupees. A data protection statute that fines the data subject is unusual; one that fines her specifically for complaining without merit is, among the regimes surveyed here, unique.
The Penalty Schedule
Section 33(1) and the Schedule set the amounts the Board may impose. Every figure is a ceiling — the Schedule says "may extend to" throughout, not a fixed or minimum sum.
| Breach | Penalty may extend to |
|---|---|
| Failure to take reasonable security safeguards to prevent a personal data breach, under section 8(5) | ₹250 crore |
| Failure to give the Board or affected Data Principals notice of a personal data breach, under section 8(6) | ₹200 crore |
| Breach of the additional obligations in relation to children under section 9 | ₹200 crore |
| Breach of the additional obligations of a Significant Data Fiduciary under section 10 | ₹150 crore |
| Breach of the duties under section 15 | ₹10,000 |
| Breach of a voluntary undertaking accepted by the Board under section 32 | The extent applicable to the breach for which section 28 proceedings were instituted |
| Breach of any other provision of the Act or Rules | ₹50 crore |
The ordering is worth noting. The largest exposure attaches to security failure rather than to unlawful processing, and breach-notification failure is penalised at the same ceiling as children's-data breaches. Unlike the GDPR, the LGPD or Quebec's Law 25, none of these figures is expressed as a percentage of turnover — they are absolute rupee caps, which bear differently on a large multinational than on a domestic firm.
It Rewrote India's Freedom of Information Law on the Way Through
Section 44 makes consequential amendments, and one of them reaches well outside data protection.
Section 44(3) provides that in section 8(1) of the Right to Information Act, 2005, clause (j) is substituted by: "information which relates to personal information;". The clause it replaced had exempted personal information whose disclosure has no relationship to any public activity or interest, or which would cause unwarranted invasion of privacy — subject to a proviso allowing disclosure where the public authority was satisfied the larger public interest justified it. The substituted clause carries no such qualification on its face.
Section 44(2) makes the Information Technology Act changes: section 43A is omitted, section 87(2)(ob) is omitted, and the DPDP Act is added to the proviso to section 81. Section 43A was the provision under which the 2011 SPDI Rules operated and which supported compensation claims for negligent handling of sensitive personal data. Its omission sits in the third commencement tranche, so it takes effect with the substantive provisions rather than immediately.
Two things follow from that timing, and both are simply what the notification says. Until the third tranche commences, section 43A of the IT Act and the 2011 Rules made under it remain the operative Indian data protection law for the matters they cover. After it, they do not — and sections 3 to 17 of the DPDP Act do.
Background
For the underlying law rather than this development: Technology & SaaS privacy law.
Frequently Asked Questions
When do the DPDP Act's obligations actually apply?
Does the DPDP Act have a sensitive personal data category?
Can a company send Indian personal data abroad?
What does the Act say about advertising to children?
Can an individual be penalised under the DPDP Act?
Where do appeals from the Data Protection Board go?
Sources
Everything above is reported from these documents. Follow them to verify.
- The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), consolidated text as on 19 November 2025 (India Code) (November 19, 2025) statute
- G.S.R. 843(E), Ministry of Electronics and Information Technology notification appointing commencement dates, Gazette of India, Extraordinary, 13 November 2025 (November 13, 2025) regulation
- The Digital Personal Data Protection Act, 2023, as published in the Gazette of India (MeitY) (August 11, 2023) statute
- Press Information Bureau, Government notifies DPDP Rules to empower citizens and protect privacy (November 14, 2025) agency release
- Press Information Bureau, DPDP Rules, 2025 Notified — background note (November 17, 2025) agency release
- MeitY, Digital Personal Data Protection Rules, 2025 (November 14, 2025) regulation
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.