India’s Digital Personal Data Protection Act, 2023 (DPDP Act) sets a framework for handling digital personal data, including rules for consent, individual rights, security and penalties. Its implementing Rules began taking effect in phases: some provisions took effect on publication in November 2025, while others are scheduled for November 2026 and May 2027. The distinction matters: the full operational regime did not begin all at once.
What is India’s DPDP Act?
The DPDP Act is India’s law governing the processing of digital personal data. Its preamble says it seeks to recognise both “the right of individuals to protect their personal data and the need to process such personal data for lawful purposes.” Parliament enacted the Act on 11 August 2023. The Act text provides the statutory framework; the Digital Personal Data Protection Rules, 2025 set out operational detail.
In the Act’s terminology, a Data Principal is the person the data relates to; a Data Fiduciary is the entity that decides why and how it is processed; and a Data Processor handles data on a fiduciary’s behalf. These roles help identify who makes decisions and who performs processing.
Who and what does the law cover?
The Act covers digital personal data processed in India when it was collected digitally or collected offline and later digitised. It can also apply to processing outside India when that processing is connected with offering goods or services to Data Principals in India. A company’s location alone therefore does not settle whether the law is relevant.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
The Act excludes an individual’s personal or domestic processing, as well as personal data made publicly available by the Data Principal or by someone legally required to make it public.
How can personal data be processed?
Processing must have a lawful purpose and rely on consent or a specified legitimate use under the Act. Consent must be free, specific, informed, unconditional and unambiguous, conveyed through clear affirmative action. It should cover only data necessary for the stated purpose. Where consent is the basis, the person can withdraw it, and the fiduciary must make withdrawal as easy as giving consent.
Rank #2
Consent is not the only statutory basis: the Act also lists legitimate uses. The legal basis depends on the particular processing; the existence of a consent form does not make unrelated or unnecessary data collection appropriate.
What rights do individuals have?
The Act provides Data Principals with rights that include access to information about their personal data, correction, completion, updating and erasure. It also provides grievance redressal and, where consent is the basis for processing, withdrawal of that consent.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteRank #3
The practical exercise of these rights depends on the applicable provisions and procedures. For example, a request to erase data is not the same as an unconditional promise that every record will immediately disappear; retention requirements and the purpose and legal basis of processing matter.
When do the DPDP Rules take effect?
The controlling Gazette is dated 13 November 2025. A government Press Information Bureau backgrounder posted on 17 November described the Rules as notified on 14 November; the dates differ by one day, so the Gazette date is used for the commencement schedule below.
| Rules | Commencement under the Gazette |
|---|---|
| Rules 1, 2 and 17–21 | On publication, 13 November 2025 |
| Rule 4 | One year after publication: 13 November 2026 |
| Rules 3, 5–16, 22 and 23 | Eighteen months after publication: 13 May 2027 |
The Act itself allows the Central Government to appoint commencement dates by Gazette notification, including different dates for different provisions. The schedule above reflects the 2025 Gazette and its stated anniversaries; later official notifications could affect implementation.
What do the Rules require?
The Rules supply implementation details, including clear standalone notices, reasonable security safeguards, breach reporting, retention and erasure requirements, and verifiable parental consent rules for children. Their commencement is phased, so a requirement’s presence in the Rules does not by itself mean it was already in force on publication day.
Notices and security
The Rules specify clear standalone notices and reasonable security safeguards. These are operational requirements for explaining processing and protecting personal data, rather than a replacement for the Act’s lawful-purpose and processing-basis framework.
Personal-data breaches
The Rules provide for notifying affected people without delay and sending the Data Protection Board a detailed notification within 72 hours, unless the Board allows more time. These procedures are subject to the Rules’ commencement schedule.
Retention and children’s data
The Rules set out retention and erasure requirements and require verifiable parental consent in relation to children. The precise duties depend on the relevant Rule and its commencement date; the phased schedule should be checked before treating a specific operational step as currently applicable.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What are the DPDP Act penalties?
The Act’s Schedule authorises maximum penalties for specified failures. These are ceilings, not automatic fines imposed whenever an issue occurs.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →| Specified failure | Maximum penalty authorised |
|---|---|
| Failure to take reasonable security safeguards | Up to ₹250 crore |
| Failure to notify the Board or affected Data Principals of a personal-data breach | Up to ₹200 crore |
| Breach of obligations relating to children | Up to ₹200 crore |
| Significant Data Fiduciary’s failure to fulfil its obligations | Up to ₹150 crore |
The applicable ceiling depends on the particular statutory failure; the Schedule, rather than a headline summary, is the place to verify an offence and its maximum.
Quick Recap
What should individuals and organisations take from the law?
- Individuals: Look for a clear explanation of the purpose and data involved, and use the applicable access, correction, erasure, grievance or consent-withdrawal routes.
- Organisations: Identify whether you determine purposes and means as a Data Fiduciary or process data for one, then map the relevant processing, its lawful basis and the applicable commencement date.
- Organisations handling breaches or children’s data: Pay attention to the Rules’ notification, security and verifiable-consent procedures, while checking when each provision takes effect.
- Organisations operating across borders: Assess whether processing is connected with offering goods or services to people in India; processing abroad is not automatically outside the Act.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




