← AiTimeline Home

Technology · Privacy · India

Safer Internet Day: India’s Data Protection Law Journey (2000–2027)

📅 Updated 9 October 2026🔐 From the IT Act to the DPDP Act and Rules
Advertisement
In short

India's data protection law from the IT Act 2000 and 2017 privacy ruling to the DPDP Act 2023, 2025 Rules and phased dates to May 2027: what's in force.

Latest Story

Every time you install an app, pay by UPI or ask an AI assistant a question, someone collects data about you. For most of the internet era, India had no dedicated law saying what they could do with it. This page traces the India data protection law timeline from the Information Technology Act of 2000, through the 2017 judgment that made privacy a fundamental right and two failed bills, to the Digital Personal Data Protection (DPDP) Act, 2023 and the Rules notified in November 2025. It also shows what is actually in force today, what is still only scheduled, and what you can do in the meantime.

Advertisement

💡 Short Answer

India’s data protection law is the Digital Personal Data Protection Act, 2023, which received assent on 11 August 2023. Its Rules were notified on 13 November 2025 with a phased start: the Data Protection Board and definitions immediately, Consent Managers on 13 November 2026, and most duties and rights on 13 May 2027. Before it, India relied on the IT Act of 2000, its 2008 amendments and the 2011 SPDI Rules.

⚡ India Data Protection Law: Quick Facts
Main lawDPDP Act, 2023 (Act 22)
Assent11 August 2023
Rules notified13 November 2025
Consent Managers13 November 2026
Main phase13 May 2027
Top penalty₹250 crore
⚡ Quick Answers — AI Overview Ready

India’s Data Protection Law: Key Questions

Is the DPDP Act in force?
Only partly. Since 13 November 2025 the definitions, Board provisions, penalty schedule and RTI amendment are in force. Consent Manager rules start on 13 November 2026. The obligations that matter most to users, such as notice, consent, breach reporting and individuals’ rights, are scheduled for 13 May 2027.
Who enforces it?
The Data Protection Board of India, a Chairperson and four Members working digitally. It exists in law, but the government told Parliament on 12 August 2026 that recruitment was advertised only on 6 June 2026; no members had been appointed by then.
What protects my data today?
Until May 2027, mainly the IT Act: Section 43A compensation for negligent handling of sensitive data, Section 72A criminal liability for wrongful disclosure, the 2011 SPDI Rules, sector rules from regulators such as the RBI, and the constitutional right to privacy against the state.
Why did it take so long?
A 2018 committee draft became a 2019 bill that was stuck in a Joint Parliamentary Committee for two years and withdrawn in 2022. A new, shorter bill passed in 2023, but the Rules needed to operate it took until November 2025, with an 18-month runway after that.
📚 Key Takeaways

India’s Privacy Law in Ten Points

  • 2000: the IT Act was a cyber and e-commerce law, not a privacy law.
  • 2009–2011: Sections 43A and 72A and the SPDI Rules gave the first, narrow data duties.
  • 2017: Puttaswamy made privacy a fundamental right, 9–0.
  • 2018: the Srikrishna Committee drafted a full data protection bill.
  • 2019–2022: the PDP Bill went to a JPC and was withdrawn.
  • 2023: the DPDP Act passed in a week; assent on 11 August.
  • 2025: Rules notified on 13 November; an 18-month phased start began.
  • Today: the Board exists on paper; its members are not yet appointed.
  • Next: Consent Managers on 13 November 2026, the main phase on 13 May 2027.
  • The test: whether people can actually use their rights and get a complaint heard.

What Is Actually in Force on 9 October 2026

Enactment, notification and commencement are three different things. This is where each part stands.

The most common mistake in coverage of the DPDP Act is to treat the date it was passed, or the date its Rules were published, as the date it started protecting people. In fact the commencement notification of 13 November 2025 split the Act into three groups. The first group, in force now, mostly builds the machinery: definitions, the Data Protection Board, the penalty schedule and the government’s rule-making powers. It also brought one controversial change into force at once: the amendment to the Right to Information Act that widens the exemption for personal information.

The provisions that change what an app or a bank must do with your data, and what you can demand of it, are in the third group. Until 13 May 2027, the older IT Act regime continues to apply.

Piece of the frameworkStatus on 9 Oct 2026Date
Definitions; Board’s constitution and procedureIn force13 Nov 2025
Penalty schedule; power to make rules and remove difficultiesIn force13 Nov 2025
RTI Act amendment (s.44(3))In force13 Nov 2025
Board Chairperson and four MembersNot appointed (recruitment advertised 6 Jun 2026)Pending
Consent Manager registration (Rule 4)Scheduled13 Nov 2026
Notice, consent, legitimate uses, security safeguardsScheduled13 May 2027
Children’s data, breach reporting, individuals’ rightsScheduled13 May 2027
Complaints to the Board and penalties actually imposedScheduled13 May 2027
IT Act Section 43A and SPDI RulesStill apply until replacedOmitted 13 May 2027
The DPDP implementation clock: three phases over 18 monthsNov 25Feb 26May 26Aug 26Nov 26Feb 27May 2713 Nov 2025Phase 1: in forceBoard, definitions, penalties, RTI change13 Nov 2026Phase 2: scheduledConsent Managers (Rule 4)13 May 2027Phase 3: scheduledNotice, consent, rights, breachesToday: 9 Oct 2026Board: established in law, no members yet (LS answer, 12 Aug 2026)Time elapsed / in forceScheduledSource: MeitY commencement notification, 13 Nov 2025
Dates are counted from the Gazette date of 13 November 2025. Check the official notifications for any later change before relying on them for compliance. Scroll sideways on small screens.

What the DPDP Act Means for an Ordinary Internet User

Once the main phase is in force. Subject to the Act’s exemptions and the Rules.

ConceptWhat it means in practice
NoticeBefore or when asking for consent, the Data Fiduciary must say what data it collects, why, and how you can exercise your rights and complain.
ConsentMust be free, specific, informed, unconditional and unambiguous, by a clear affirmative action, and limited to data needed for the purpose. It can be withdrawn as easily as it was given.
Legitimate usesSection 7 allows processing without consent in listed cases, such as data you volunteered for a purpose, state benefits, legal duties, medical emergencies and employment.
Security safeguardsReasonable security measures to prevent breaches, including encryption or masking, access controls and logs, under Rule 6.
RightsAccess to a summary of your data, correction and erasure, grievance redressal, and nomination.
Children’s dataVerifiable parental consent; no tracking, behavioural monitoring or targeted ads at children.
AccountabilityData Protection Board inquiries and penalties up to ₹250 crore per breach.
📱 Interactive: Free App, Useful Service

Would you trade privacy for convenience?

A fictional free app offers personalised recommendations and asks for your contacts, location, photos, microphone and payment history. Choose how much to share to see the trade-off. This is an explainer, not legal advice; no answers are recorded.

Choose an option above

–Convenience
–Data exposed
–What the law adds

    The Penalty Schedule

    Maximum amounts per instance under the Schedule to the Act. The Board decides the actual amount, considering factors such as the nature, gravity and duration of the breach.

    BreachMaximum penalty
    Failure to take reasonable security safeguards to prevent a breach₹250 crore
    Failure to notify the Board and affected people of a breach₹200 crore
    Breach of additional obligations on children’s data₹200 crore
    Breach of Significant Data Fiduciary obligations₹150 crore
    Breach of a voluntary undertaking accepted by the BoardUp to the penalty for the original breach
    Any other breach of the Act or Rules₹50 crore
    Breach of a Data Principal’s own duties₹10,000

    Twenty-Seven Years, Three Eras

    How India went from a cyber law to a privacy law.

    The cyber-law era (2000–2011). The Information Technology Act of 2000 was written for e-commerce and cybercrime. Personal data entered the law only with the 2008 amendments, which took effect in October 2009: Section 43A made companies pay compensation if they negligently failed to protect “sensitive personal data”, and Section 72A punished disclosure of personal information in breach of a contract. The 2011 SPDI Rules defined that sensitive data and required privacy policies and consent. The regime was narrow: it covered only body corporates, only sensitive data, and offered compensation through a slow adjudication process.

    An Aadhaar enrolment camp in Malappuram district
    An Aadhaar enrolment camp in Malappuram district, Kerala, September 2013: the biometric ID programme was at the centre of India’s privacy litigation. Ministry of Information and Broadcasting, GODL-India, via Wikimedia Commons.

    The rights era (2012–2018). The push for a real law came from Aadhaar. In 2012 retired judge K.S. Puttaswamy challenged the biometric ID scheme, the same year the A.P. Shah expert group proposed national privacy principles. When the government argued that Indians had no fundamental right to privacy, the question went to a nine-judge bench. On 24 August 2017 it ruled unanimously that they do, and that informational privacy is part of that right. Weeks earlier, on 31 July 2017, the government had set up the Srikrishna Committee, whose 2018 report and draft bill shaped everything that followed.

    The legislative era (2019–2027). The 2019 bill gave the government wide exemptions, which Justice Srikrishna himself criticised, and was withdrawn in 2022 after a two-year committee process. Its 2023 successor passed within a week. It is simpler and more business-friendly, with no sensitive-data category and no default localisation, but it keeps broad state exemptions and creates a Board rather than an independent regulator.

    27 years from cyber law to enforceable privacy rights20002004200820122016202020242028IT Act (cyber law)IT Act era: 43A and SPDI Rules onlyPrivacy debateShah group to PuttaswamyFailed bills2018 draft, 2019 bill, withdrawalDPDP law on paperAssent to Rules: 2 yrs 3 mthsPhased start18-month rolloutBars show periods, not legal force. The IT Act’s Section 43A is omitted when the main DPDP phase starts. Sources: India Code, Supreme Court, MeitY.
    The longest wait was not for a court or a committee, but between passing the Act and switching it on. Scroll sideways on small screens.

    The 2019 Bill vs the 2023 Act

    PDP Bill, 2019DPDP Act, 2023
    ScopeDigital and some offline personal data; JPC wanted non-personal data tooDigital personal data only (and offline data later digitised)
    Sensitive dataSeparate category with stricter rulesNo separate category
    Data leaving IndiaSensitive data copy in India; “critical” data only in IndiaAllowed unless the government blacklists a country
    RegulatorData Protection Authority with rule-making powersData Protection Board: adjudicates and penalises
    PenaltiesUp to 4% of global turnover; some criminal offencesFixed caps up to ₹250 crore; civil only
    Government exemptionsSection 35, broadSection 17, broad

    India’s Data Protection Law: The Full Timeline, 2000–2027

    Newest first. Tags show what is in force, what is only scheduled, and what was dropped.

    Advertisement
    13 May
    2027

    The main phase is due Scheduled

    18 months after notificationSections 3–17, 27–34, 36, 37, 44(2)Rules 3, 5–16, 22, 23

    The bulk of the framework is scheduled to apply: the Act’s application, grounds for processing, notice and consent, legitimate uses, the general obligations of Data Fiduciaries, children’s data, breach reporting, individuals’ rights and duties, Significant Data Fiduciaries, cross-border transfers, and the Board’s complaints and penalty powers. Section 43A of the IT Act is omitted on the same date.

    13 Nov
    2026

    Consent Managers switch on Scheduled

    12 months after notificationSection 6(9), 27(1)(d)Rule 4

    The registration framework for Consent Managers begins: Indian companies that let people give, review and withdraw consent across many services through one interoperable platform. They must register with the Data Protection Board, which, as of the latest official answer, still had no members appointed.

    5–7 Oct
    2026

    First “removal of difficulties” order 2026

    Section 43 order dated 5 Oct, published 7 Oct

    MeitY issues the Digital Personal Data Protection (Removal of Difficulties) Order, 2026, which the government describes as textual corrections. It clarifies that verifiable consent in Section 9(1) covers personal data of a child or of a person with a disability, and that a Significant Data Fiduciary’s periodic audit in Section 10 is a data audit.

    12 Aug
    2026

    Parliament asks: where is the Board? 2026 Unresolved

    Lok Sabha unstarred question 3960Minister of State Jitin Prasada

    Asked why the Board set up in November 2025 still had no Chairperson or four Members, and whether any Consent Managers or breach complaints had been registered, the government replies that the recruitment advertisement was published in the Employment News on 6 June 2026 and that appointments go through a search-cum-selection committee. It gives no date for appointments.

    May–Jun
    2026

    Board recruitment opens 2026

    Nominations sought May 2026advertisement 6 June 2026

    Six months after the Board legally came into existence, MeitY invites applications for its Chairperson and four Members. A LiveLaw analysis on 1 August notes that courts have already begun pointing petitioners to a Board that has no one to hear them.

    10 Feb
    2026

    Safer Internet Day: “Smart Tech, Safe Choices” 2026

    MeitY ISEA campaignest. 9.78 crore reached, all 36 States and UTs

    India’s campaign focuses on the safe and responsible use of AI, with a newsletter on AI-enabled frauds, cyber-hygiene sessions and outreach through public media. MeitY reports an estimated 9.78 crore people reached and 3.95 crore additional digital impressions. Awareness campaigns and data law work side by side: the law sets duties for organisations, awareness teaches people to protect themselves.

    13 Nov
    2025

    DPDP Rules notified; phase one in force In force

    Rules 1, 2, 17–21Act s.1(2), 2, 18–26, 35, 38–43, 44(1), 44(3)

    MeitY notifies the Digital Personal Data Protection Rules, 2025 together with a commencement notification that switches the framework on in three phases over 18 months. Phase one covers definitions, the constitution and procedures of the Data Protection Board (four members plus a Chairperson, functioning digitally), penalties, powers to make rules and remove difficulties, and the amendment of the RTI Act’s personal-information exemption.

    Jan–Mar
    2025

    Draft Rules out for consultation History

    Published 3 Jan 2025deadline 18 Feb, extended to 5 Mar6,915 inputs

    The draft Rules set out notice formats, Consent Manager conditions, breach reporting, children’s consent verification, data retention for large platforms and the Board’s procedures. MeitY extends the comment deadline after requests from industry. PIB later reports 6,915 inputs; MeitY’s own summary of submissions puts the figure at 6,951.

    11 Aug
    2023

    The DPDP Act becomes law History

    Introduced 3 AugLok Sabha 7 AugRajya Sabha 9 AugAct No. 22 of 2023

    The Digital Personal Data Protection Bill passes both Houses within a week of introduction and receives presidential assent. It is far shorter than the 2019 bill and sets up a Data Protection Board rather than a regulator. Assent does not make it operative: the government must notify commencement, which takes two more years.

    The old Parliament House (Samvidhan Sadan) in New Delhi
    The old Parliament House (Samvidhan Sadan) in New Delhi, where the DPDP Bill was passed in August 2023. Nikhilb239, CC BY-SA 4.0, via Wikimedia Commons.
    18 Nov
    2022

    A new draft: the DPDP Bill, 2022 History

    Public consultationgender-neutral “she/her” drafting

    MeitY publishes a much slimmer draft built only around digital personal data. It notably uses “her” and “she” for all individuals, drops mandatory localisation, and proposes penalties of up to ₹500 crore per instance. The bill introduced in 2023 lowers the cap to ₹250 crore.

    3 Aug
    2022

    The 2019 bill is withdrawn Dropped

    JPC proposed 81 amendments to a 99-section bill

    After the Joint Parliamentary Committee’s report in December 2021 recommended 81 amendments and widened the bill to cover non-personal data, the government withdraws it, promising a “comprehensive legal framework”. Supporters of a strong law call it a lost two years; industry welcomes a fresh start.

    11 Dec
    2019

    Personal Data Protection Bill, 2019 History

    Introduced in Lok Sabhareferred to a Joint Parliamentary Committee

    Based on the Srikrishna draft but with wider government exemptions, the bill proposes a Data Protection Authority, a sensitive-personal-data category and local storage of “critical” data. Justice Srikrishna himself warns it could turn India into an “Orwellian state”.

    26 Sep
    2018

    The Aadhaar judgment History

    Five-judge benchAadhaar upheld, Section 57 struck down

    Applying the privacy right, the Supreme Court upholds the Aadhaar scheme for welfare and tax but strikes down Section 57, which had let private companies demand Aadhaar for verification. Banks and telecom companies can no longer make it mandatory.

    27 Jul
    2018

    The Srikrishna Committee reports History

    “A Free and Fair Digital Economy”draft PDP Bill, 2018

    The committee, set up on 31 July 2017, proposes consent-based processing, rights for individuals, a powerful independent Data Protection Authority and storing at least one copy of personal data in India. It frames the problem as protecting individuals while letting the digital economy grow.

    Justice B.N. Srikrishna hands the committee’s data protection report to IT and Law Minister Ravi Shankar Prasad
    Justice B.N. Srikrishna hands the committee’s data protection report to IT and Law Minister Ravi Shankar Prasad, New Delhi, 27 July 2018. Government of India, GODL-India, via Wikimedia Commons.
    24 Aug
    2017

    Privacy becomes a fundamental right History

    Justice K.S. Puttaswamy (Retd.) v. Union of India9–0

    A nine-judge Constitution Bench unanimously holds that privacy is protected under Article 21 and Part III of the Constitution, overruling earlier cases (M.P. Sharma, 1954, and Kharak Singh, 1962). Informational privacy is recognised as part of it, and the court urges the government to enact a data protection law. The case began in 2012 as a challenge to Aadhaar.

    The Supreme Court of India in New Delhi
    The Supreme Court of India in New Delhi, where a nine-judge bench declared privacy a fundamental right on 24 August 2017. Subhashish Panigrahi, CC BY-SA 4.0, via Wikimedia Commons.
    24 Mar
    2015

    Section 66A struck down History

    Shreya Singhal v. Union of India

    The Supreme Court strikes down Section 66A of the IT Act, which had made “offensive” online messages a crime and led to arrests over Facebook posts. It is a speech case, not a privacy case, but it shows the 2008 amendments needed constitutional pruning.

    16 Oct
    2012

    The A.P. Shah expert group History

    Planning Commissionnine national privacy principles

    A group led by former Delhi High Court Chief Justice A.P. Shah proposes nine privacy principles, including notice, choice and consent, purpose limitation and accountability, and a privacy commissioner. Much of today’s vocabulary first appears here.

    11 Apr
    2011

    The SPDI Rules History

    Reasonable security practices and sensitive personal data rules

    Made under Section 43A, the Rules define sensitive personal data such as passwords, financial, health and biometric information, and require body corporates to publish privacy policies, take consent for collecting it and follow reasonable security practices such as ISO 27001. They do not bind the government.

    27 Oct
    2009

    The IT (Amendment) Act, 2008 takes effect History

    Passed Dec 2008assent 5 Feb 2009new s.43A, 66C, 66D, 66E, 72A

    Passed in December 2008 without debate in the Lok Sabha, the amendment adds the first explicit data protection duties: compensation under Section 43A when a company negligently fails to protect sensitive data, and criminal liability under Section 72A for disclosing personal information in breach of contract. It also creates offences for identity theft, cheating by personation and violation of privacy through images.

    17 Oct
    2000

    The Information Technology Act comes into force History

    Assent 9 June 2000e-records, digital signatures, cyber offences

    India’s first cyber law gives legal recognition to electronic records and digital signatures and creates offences such as hacking. It is a law for e-commerce and cybercrime, not for privacy, and says almost nothing about how organisations should handle personal data.

    Advertisement

    Corrections to Claims Circulating Online

    From the summary material this page was built from, checked against the Gazette notifications, PIB, Lok Sabha answers and legal reporting.

    Wrong month

    “February 2025: the consultation period continues”

    The deadline was 18 February 2025, then extended to 5 March 2025. PIB later cited 6,915 inputs; MeitY’s own summary says 6,951.

    Missing

    The Board has no members

    Describing the Board as set up in November 2025 is true only in law. The government told the Lok Sabha on 12 August 2026 that recruitment was advertised on 6 June 2026.

    Missing

    The RTI amendment is already in force

    Section 44(3), which changes the RTI Act’s personal-information exemption, came into force on 13 November 2025, not in 2027.

    Imprecise

    “2008: cyber-law amendments”

    Passed in December 2008, assent on 5 February 2009, in force on 27 October 2009. The data provisions that matter are Sections 43A and 72A.

    Missing

    Aadhaar and the Shah report

    The privacy case began as an Aadhaar challenge in 2012, and the 2012 A.P. Shah principles and the 2018 Aadhaar judgment are key steps the summary skipped.

    New

    October 2026 order

    The first Removal of Difficulties Order, dated 5 October 2026, corrected the text of Sections 9 and 10. It changes wording, not the phased dates.

    Four Tests for India’s Privacy Law

    Awareness

    Can people use their rights?

    Notices must be readable in English or any of the 22 scheduled languages. Whether people read them, and know they can complain, is another matter.

    Compliance

    Can organisations map their data?

    Most firms must know what they hold, why, and for how long, and build consent and deletion into products by May 2027.

    Enforcement

    Will the Board be ready?

    A Board without members cannot register Consent Managers or hear complaints. Appointments before 13 November 2026 are the first test.

    Trust

    Will the state hold itself to the law?

    Broad Section 17 exemptions mean the biggest data holder, the government, can exempt its own agencies. Critics see this as the law’s main gap.

    What Remains Contested

    • Government exemptions: privacy groups say Section 17 lets agencies escape the law on vague grounds; the government says national security requires it.
    • The RTI change: transparency campaigners say it shields officials’ conduct from disclosure; the government says it protects personal privacy.
    • Board independence: members are chosen through a government-led process and the Board sits under MeitY’s framework, unlike regulators with statutory independence.
    • Children’s consent: treating everyone under 18 as a child needing parental consent is criticised as impractical for teenagers and a push towards age verification.
    • Timeline: industry has sought more time; privacy advocates say 18 months on top of two years was already long.

    How to Stay Safer Online Now

    General habits, not legal advice. They work whether or not a particular provision is in force.

    Participants work on smartphones at a training workshop in Maharashtra
    Participants work on smartphones at a training workshop in Maharashtra. आर्या जोशी, CC BY-SA 4.0, via Wikimedia Commons.
    • Check app permissions: does a torch or game really need contacts, microphone or location?
    • Use unique passwords and two-factor authentication: a password manager makes this practical.
    • Verify before you pay: confirm payment requests and links through a channel you trust; never share OTPs.
    • Share less: avoid posting Aadhaar, PAN, bank details or documents; use masked Aadhaar where accepted.
    • Review privacy settings: check who sees your posts, profile and location.
    • Be careful with AI tools: do not paste passwords, confidential work files or financial details into chatbots.
    • Know where to report: cybercrime.gov.in or 1930 for fraud; the company’s grievance officer for data complaints.

    What to Watch

    • Board appointments: whether the Chairperson and Members are named before Consent Managers start.
    • 13 November 2026: the first Consent Manager registrations.
    • Significant Data Fiduciaries: which companies the government designates.
    • Further orders or amendments: any change to the 13 May 2027 date.
    • 13 May 2027: the main phase, and the first complaints the Board hears.

    Quick Quiz

    1. When did the DPDP Act receive presidential assent?
    A. 24 Aug 2017 · B. 11 Aug 2023 · C. 13 Nov 2025 · D. 13 May 2027
    B. 11 August 2023. The Rules followed on 13 November 2025.
    2. Which case declared privacy a fundamental right?
    A. Shreya Singhal · B. Kharak Singh · C. K.S. Puttaswamy · D. M.P. Sharma
    C. Justice K.S. Puttaswamy (Retd.) v. Union of India, 24 August 2017, 9–0.
    3. What starts on 13 November 2026?
    A. All of the Act · B. Consent Managers · C. The RTI amendment · D. Safer Internet Day
    B. The Consent Manager framework under Rule 4.
    4. What is the largest penalty under the DPDP Act?
    A. ₹50 crore · B. ₹150 crore · C. ₹250 crore · D. 4% of global turnover
    C. ₹250 crore, for failing to take reasonable security safeguards.
    5. What was India’s Safer Internet Day 2026 theme about?
    A. Passwords · B. Safe and responsible use of AI · C. Online gaming · D. UPI fraud
    B. “Smart Tech, Safe Choices – Exploring the Safe and Responsible Use of AI”.

    Explore More Timelines

    People Also Ask

    What is Safer Internet Day?
    An international awareness day promoting safer, more responsible use of the internet, especially by children and young people. It is held on the second day of the second week of February; in 2026 it fell on 10 February.
    Is DPDP the same as GDPR?
    No. Both are built on consent, purpose limitation and individual rights, but India’s Act is shorter, has no separate sensitive-data category, allows transfers abroad by default, gives the government wider exemptions and uses a Board with civil penalties rather than independent supervisory authorities.
    What is a Consent Manager?
    A company registered with the Data Protection Board that gives people a single, interoperable platform to give, manage, review and withdraw consent across different Data Fiduciaries. The framework starts on 13 November 2026.
    What is a Significant Data Fiduciary?
    A Data Fiduciary the government designates because of the volume or sensitivity of the data it processes or the risk to individuals. It must appoint a Data Protection Officer based in India, an independent data auditor, and carry out periodic impact assessments and data audits.
    Is personal data in WhatsApp chats covered?
    The Act covers digital personal data processed by Data Fiduciaries. It does not apply to data processed by an individual for a personal or domestic purpose, or to data that the person has made publicly available themselves.

    Frequently Asked Questions

    What is India’s data protection law?
    The Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023). It governs how organisations, called Data Fiduciaries, process digital personal data of individuals, called Data Principals. Its operating detail is in the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025.
    When did the DPDP Act become law?
    Parliament passed it in August 2023 (Lok Sabha on 7 August, Rajya Sabha on 9 August) and the President gave assent on 11 August 2023. Becoming law is not the same as coming into force: its provisions were switched on in phases from 13 November 2025.
    Is the whole DPDP Act in force now?
    No. As of 9 October 2026 only the first phase is in force: definitions, the provisions setting up the Data Protection Board, penalties and rule-making powers, and the amendment to the RTI Act. Consent Manager rules start on 13 November 2026, and most duties on companies and the rights of individuals on 13 May 2027.
    When will companies have to comply with the DPDP Act?
    The main obligations, including notice, consent, security safeguards, breach reporting, children’s data rules and individuals’ rights, are scheduled to apply 18 months after the 13 November 2025 notification, which is 13 May 2027. Check the Gazette notifications for any change before relying on a date.
    What happens on 13 November 2026?
    The one-year phase begins. It switches on Rule 4 and the related provision of the Act on Consent Managers: registered companies that let individuals give, manage, review and withdraw consent through one platform. Applicants must be incorporated in India and meet net-worth and technical conditions set in the Rules.
    Has the Data Protection Board of India been set up?
    In law, yes: the Rules creating it took effect on 13 November 2025. In practice it had no Chairperson or Members as of August 2026. The government told the Lok Sabha on 12 August 2026 that the recruitment advertisement was published in the Employment News on 6 June 2026, and appointments go through a search-cum-selection committee.
    Who is a Data Fiduciary?
    Any person, company, government body or other entity that decides why and how digital personal data is processed. An app, a bank, a hospital, an online shop or a government department can all be Data Fiduciaries. Processors acting on their behalf are Data Processors.
    Who is a Data Principal?
    The individual the personal data is about. For a child (anyone under 18) or a person with a disability who has a lawful guardian, the parent or guardian acts for them.
    Does the DPDP Act require consent for everything?
    No. Consent is one ground. Section 7 lists “certain legitimate uses” that do not need consent, such as data a person voluntarily gives for a specified purpose, state subsidies and services, legal obligations, medical emergencies, disasters and employment purposes.
    What rights will I have under the DPDP Act?
    Once the main phase starts, the right to a summary of the data processed and who it was shared with; correction, completion, updating and erasure; grievance redressal by the Data Fiduciary; and the right to nominate someone to act on your behalf after death or incapacity.
    Do individuals have duties under the DPDP Act?
    Yes. Data Principals must not impersonate others, suppress material information when providing data for official documents, or file false or frivolous complaints. Breaching these duties can attract a penalty of up to ₹10,000.
    What are the penalties under the DPDP Act?
    Up to ₹250 crore for failing to take reasonable security safeguards; up to ₹200 crore each for failing to report a breach or breaching the rules on children’s data; up to ₹150 crore for Significant Data Fiduciary failures; and up to ₹50 crore for other breaches. Penalties are civil, imposed by the Board.
    How does the DPDP Act protect children?
    Data Fiduciaries must obtain verifiable consent from a parent or lawful guardian before processing a child’s data, and must not carry out tracking, behavioural monitoring or targeted advertising directed at children. The Rules set out how consent is verified and some exemptions, for example for schools and health services.
    What must a company do after a data breach?
    Under the Act it must inform the Data Protection Board and each affected person. The Rules require the notice to individuals without delay and a detailed report to the Board within 72 hours, describing the breach, its likely impact and the steps taken. These duties start with the main phase.
    Does the DPDP Act stop data leaving India?
    Not by default. Unlike the 2019 bill, which required some data to stay in India, the Act lets data flow abroad unless the government restricts transfers to specific countries by notification. Sector rules, such as RBI’s payment-data localisation, still apply.
    Is the government exempt from the DPDP Act?
    Partly. Section 17 lets the government exempt its agencies in the interests of sovereignty, security, public order and related grounds, and exempts processing for research and some other purposes. Critics, including privacy groups, say these exemptions are too broad; the government says they are needed for national security.
    How did the DPDP Act change the RTI Act?
    Section 44(3) amended Section 8(1)(j) of the Right to Information Act to exempt personal information from disclosure without the earlier public-interest override. This amendment came into force on 13 November 2025. Transparency activists and journalists’ groups have criticised it.
    What happens to Section 43A of the IT Act?
    Section 43A, which since 2009 let people claim compensation when a company negligently failed to protect sensitive personal data, is omitted by Section 44(2) of the DPDP Act. That omission is in the 18-month phase, so 43A remains until about May 2027.
    What was the Puttaswamy judgment?
    Justice K.S. Puttaswamy (Retd.) v. Union of India, decided on 24 August 2017 by a nine-judge bench of the Supreme Court. It unanimously held that privacy is a fundamental right under Article 21 and Part III of the Constitution, and urged the government to put a data protection law in place.
    What did the Srikrishna Committee recommend?
    The committee, set up in July 2017 and chaired by retired Supreme Court judge B.N. Srikrishna, submitted its report and a draft Personal Data Protection Bill on 27 July 2018. It proposed a powerful Data Protection Authority, consent-based processing, special protection for sensitive data, and storing a copy of personal data in India.
    Why was the Personal Data Protection Bill, 2019 withdrawn?
    A Joint Parliamentary Committee reported in December 2021 with 81 amendments and wider recommendations, including bringing non-personal data in. The government withdrew the bill on 3 August 2022, saying it would bring a comprehensive new legal framework instead.
    What changed between the 2019 bill and the 2023 Act?
    The 2023 Act is shorter and narrower. It dropped the separate category of sensitive personal data, mandatory localisation, criminal penalties and non-personal data; replaced the proposed Data Protection Authority with an adjudicating Board; and kept broad powers for the government to exempt its agencies.
    What is the DPDP Removal of Difficulties Order 2026?
    An order dated 5 October 2026 under Section 43 of the Act, published on 7 October, described by the government as textual corrections. It clarifies that the verifiable-consent rule in Section 9(1) applies to the data of a child or of a person with a disability, and that Significant Data Fiduciaries must carry out a periodic data audit.
    What was the Safer Internet Day 2026 theme in India?
    “Smart Tech, Safe Choices – Exploring the Safe and Responsible Use of AI”. MeitY ran the campaign on 10 February 2026 under its Information Security Education and Awareness (ISEA) programme and said it reached an estimated 9.78 crore people across all 36 States and Union Territories, with 3.95 crore more digital impressions.
    Where can I report a cybercrime in India?
    On the National Cyber Crime Reporting Portal, cybercrime.gov.in, or by calling the helpline 1930 for financial fraud. Complaints about how a company handles your data go first to that company’s grievance officer; once the main DPDP phase is in force, unresolved complaints can go to the Data Protection Board.

    A Law on Paper, Privacy in Practice

    India’s data protection story runs from a cyber law written before smartphones, through a constitutional judgment and two abandoned bills, to a law that is still switching on. Safer Internet Day is a reminder that legal duties and personal habits are different tools: the law tells organisations what they owe you, and awareness helps you notice when they fall short.

    The real measure of the DPDP Act will not be the number of pages in it, but whether, after May 2027, an ordinary user can find out what an app knows about them, get it deleted, and have a complaint heard by a Board that actually sits.

    Related AiTimeline Stories

    ⚠️ Editorial Note

    Last updated 9 October 2026. This page is general information, not legal advice. Commencement dates are calculated from the Gazette date of 13 November 2025 and reflect the official notifications and the government’s Lok Sabha answer of 12 August 2026; check the latest Gazette notifications and any amendments before relying on a date for compliance. Criticism of the Act is attributed to those who make it. Sources are listed below.

    Advertisement
    French Teenagers: Education Protests Timeline (1968-2026) Tariff Walls and Trade Bridges: The Hidden Forces Reshaping Global Trade
    →
    Next Article