India's DPDP Act governs one of the largest data markets in the world and departs from the GDPR model in consequential ways, including its consent manager framework. This hub tracks implementation.

India (DPDP Act)

The Data Protection Board of India Exists in Law, Has a Pay Scale and a Selection Committee, and Has No Members Yet

September 21, 2026

The Data Protection Board of India was established by Gazette notification on 13 November 2025, with its head office in the National Capital Region. MeitY invited applications for a Chairperson and four Members in May 2026, and no appointment had been notified by 21 September 2026. This explainer covers its staffing, its digital procedure and which of its powers are not yet in force.

Read more →
India (DPDP Act)

India's DPDP Breach Rule Has No Harm Threshold and a 72-Hour Report, and It Does Not Start Until 2027

September 21, 2026

Section 8(6) of India's Digital Personal Data Protection Act requires a Data Fiduciary to tell the Data Protection Board and each affected individual about a personal data breach, and rule 7 of the 2025 Rules fills in the content and a 72-hour clock. Both sit in the commencement tranche that starts eighteen months after 13 November 2025, while CERT-In's six-hour incident reporting already applies.

Read more →
India (DPDP Act)

India's DPDP Act Is Mostly Not in Force Yet, and Leaves Out What Other Regimes Regulate Most

August 24, 2026

The Digital Personal Data Protection Act was passed in August 2023 and its Rules were notified in November 2025, but the commencement notification staggers the obligations over eighteen months. Meanwhile the statute leaves out a sensitive data category entirely, permits transfers unless the government forbids them, imposes duties on individuals, and rewrote India's freedom of information law.

Read more →