Digital Personal Data Protection (DPDP) Act Law in India
Last reviewed: 3 July 2026
India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules, 2025 (DPDP Rules) together form the country’s first comprehensive data protection regime. The framework rests on a single Act, a set of Rules notified via Gazette Notification G.S.R. 846(E) dated 13 November 2025, a phased three-stage commencement running to 14 May 2027, and a still-forming regulator, the Data Protection Board of India. This page is the entry point to Candour Legal’s analysis across that framework.
Where India Stands on the DPDP Act as of July 2026
The DPDP Act received Presidential assent on 11 August 2023. Its substantive provisions did not take effect immediately; the government instead notified a phased commencement. The Data Protection Board of India and the procedural machinery around it came into force from 14 November 2025. The Consent Manager framework becomes operative from 14 November 2026. The remaining substantive obligations on Data Fiduciaries, along with the Board’s power to inquire, direct, and penalise, come into force 18 months after notification, on 14 May 2027. As of mid-2026, India is in the middle phase: the law exists, parts of the machinery exist, and the compliance obligations that carry real financial exposure are still ahead of most organisations, not behind them.
The Statutory Framework
1. Consent as the Primary Legal Basis
Sections 4 to 7 of the DPDP Act make consent the default legal basis for processing personal data, subject to a defined set of “certain legitimate uses” under Section 7 (such as voluntary data sharing by the Data Principal, compliance with law, medical emergencies, and employment-related processing) that do not require consent. Consent itself must be free, specific, informed, unconditional, and unambiguous, and every consent request must be accompanied by an itemised notice in clear language, in English or any language listed in the Eighth Schedule to the Constitution.
2. General Obligations of Data Fiduciaries
Section 8 sets the baseline obligations for every Data Fiduciary, regardless of contractual arrangements with Data Processors: maintaining accuracy and completeness of personal data used for decisions affecting a Data Principal, implementing reasonable technical and organisational security safeguards, notifying the Board and affected Data Principals of a personal data breach, publishing the contact details of a Data Protection Officer or a responsible person, and maintaining an effective grievance redressal mechanism. Failure to implement reasonable security safeguards under Section 8(5) carries a penalty of up to ₹250 crore. Failure to notify a breach under Section 8(6) carries a penalty of up to ₹200 crore, per incident.
3. Children’s and Persons-with-Disability Data
Section 9 requires verifiable parental or lawful-guardian consent before processing the personal data of a child or of a person with a disability who has a lawful guardian, and prohibits any processing likely to cause a detrimental effect on a child’s well-being. This provision has the most direct impact on ed-tech, gaming, and consumer platforms with a meaningful under-18 user base.
4. Significant Data Fiduciaries
Section 10 allows the Central Government to notify certain Data Fiduciaries as Significant Data Fiduciaries (SDFs) based on factors including the volume and sensitivity of data processed, risk to Data Principal rights, potential impact on electoral democracy, security of the State, and public order. An SDF carries additional obligations: appointing a India-based Data Protection Officer accountable to the board of directors, appointing an independent data auditor, and carrying out periodic Data Protection Impact Assessments. Numerical SDF thresholds were expected through 2026 at the time of writing and had not been notified.
5. Rights of Data Principals
Chapter III of the Act, Sections 11 to 14, sets out four rights. The right to access information (Section 11) entitles a Data Principal to a summary of personal data processed, the identities of other Data Fiduciaries and Data Processors it has been shared with, and other prescribed information. The right to correction and erasure (Section 12) requires a Data Fiduciary to correct, complete, update, or erase personal data on request, subject to retention obligations under other law. The right to grievance redressal (Section 13) requires a readily available redressal mechanism, with a prescribed response window of 90 days. The right to nominate (Section 14) allows a Data Principal to nominate another individual to exercise these rights on death or incapacity.
6. Cross-Border Data Transfer
Section 16 adopts a negative-list model: transfer of personal data outside India is permitted to every country or territory except those the Central Government specifically restricts by notification. This is the inverse of the EU’s GDPR, which prohibits transfer unless an adequacy decision or an approved safeguard applies. As of mid-2026, no country had been notified as restricted, making cross-border transfer broadly permissible, though Data Fiduciaries remain responsible for the personal data after transfer and must continue to observe sectoral requirements (such as RBI data-localisation directions for payments data) that operate independently of the DPDP Act.
7. Exemptions
Section 17 carves out two categories of exemption relevant to most businesses. Section 17(2)(a) allows the Central Government to exempt any instrumentality of the State from the Act’s provisions on grounds of sovereignty, security, public order, or friendly relations with foreign states, though this exemption is function-based rather than a blanket immunity for all government activity. Section 17(2)(b) exempts processing necessary for research, archiving, or statistical purposes, provided the data is not used to make a decision specific to an individual and the processing follows government-prescribed standards. Neither exemption removes a Data Principal’s core rights under Chapter III.
8. The Consent Manager Framework
Section 2(g) read with Section 6(7) defines a Consent Manager as an entity registered with the Data Protection Board that gives a Data Principal a single, interoperable platform to give, manage, review, and withdraw consent across multiple Data Fiduciaries. The First Schedule to the DPDP Rules sets registration conditions: incorporation in India, a minimum net worth of ₹2 crore, fit-and-proper governance standards, and an obligation to route personal data without ever being able to read it. Registration opens 14 November 2026. Candour Legal’s detailed analysis of the Consent Manager framework, including its overlap with the RBI’s existing Account Aggregator regime, is linked below.
The Phased Implementation Timeline
- 11 August 2023 — DPDP Act receives Presidential assent.
- 13 November 2025 — DPDP Rules, 2025 notified (G.S.R. 846(E)); Data Protection Board of India established on paper from 14 November 2025.
- 14 November 2026 — Consent Manager registration framework becomes operative.
- 14 May 2027 — Remaining substantive provisions, including the Board’s inquiry, direction, and penalty powers, come into force.
Enforcement in 2026: What the Landscape Looks Like
The Data Protection Board of India, the body that will register Consent Managers, receive breach notifications, and eventually adjudicate penalties, had not had its Chairperson or Members appointed as of mid-2026, with a Cabinet Secretary-led search-cum-selection committee still evaluating candidates. Appeals from Board orders lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT). Separately, the Consent Manager framework is set to operate alongside the RBI’s existing, population-scale Account Aggregator ecosystem, and the two regimes’ overlapping jurisdiction on grievance redressal and technical standard-setting remains formally unresolved. Organisations building compliance programmes in 2026 are, in effect, building toward a moving regulatory target rather than a settled one.
Who Regulates What
- MeitY: policy ownership of the DPDP Act and Rules, notifications, and the Consent Manager technical framework.
- Data Protection Board of India: registration of Consent Managers, breach inquiries, directions, and penalties once fully constituted.
- RBI: Account Aggregator framework, payments data localisation, and sectoral financial-data rules that operate alongside the DPDP Act.
- Sectoral regulators (SEBI, IRDAI, National Health Authority): sector-specific consent and data-sharing frameworks (for example, the Health Locker for medical data) that will need to be reconciled with the Board’s eventual technical standards.
- TDSAT: appellate forum for orders of the Data Protection Board.
Common Compliance Mistakes We See
- Treating consent as a one-time banner rather than an itemised, purpose-specific record. Section 4-7 requires specific, unambiguous consent per purpose, not omnibus acceptance of a privacy policy.
- No verifiable parental consent mechanism for platforms with under-18 users. Section 9 applies regardless of whether the platform is designed for children specifically.
- Assuming SDF status does not apply because no threshold has been notified. The absence of numerical thresholds is a timing gap, not a substantive exemption; businesses in scope on a qualitative reading of Section 10 should not wait for the notification to begin DPIA and audit preparation.
- No breach-response runbook aligned to the Rule 7 timeline. Affected Data Principals and the Board must be notified without delay, with a detailed report due within 72 hours — a timeline with no “where feasible” qualifier.
- Assuming cross-border transfer is unrestricted and therefore unregulated. Section 16’s negative list currently permits transfer to most jurisdictions, but sectoral localisation rules and post-transfer security obligations continue to apply independently.
- No named, publicly available contact for data protection queries. Section 8 requires publication of DPO or responsible-person contact details; its absence is one of the easiest compliance gaps for a regulator to identify.
How Candour Legal Advises
Candour Legal advises data fiduciaries, significant data fiduciaries, consent-tech platforms, and businesses across banking, healthcare, e-commerce, and technology sectors on DPDP Act compliance architecture. Our data protection practice sits at the intersection of the firm’s cyber law, banking and financial regulation, and corporate compliance work.
- Compliance architecture: consent-flow audits, itemised notice drafting, DPO appointment and grievance-mechanism design, and SDF-readiness assessments.
- Breach response: runbook design aligned to the Rule 7 timeline, and representation before the Data Protection Board once fully constituted.
- Sector-specific advisory: BFSI and fintech (Account Aggregator/Consent Manager interface), healthcare (sensitive personal data and the Health Locker interface), e-commerce (consent and IT Rules interplay), and employers (HR data and background-check compliance).
- Consent Manager structuring: registration-readiness advisory for entities considering Consent Manager status ahead of the 14 November 2026 window.
Frequently Asked Questions
Is the DPDP Act in force in India?
Partially. The Act received Presidential assent in August 2023. The Data Protection Board’s procedural provisions are in force from November 2025, the Consent Manager framework becomes operative in November 2026, and the remaining substantive compliance obligations and penalty powers take effect from 14 May 2027.
What are the penalties under the DPDP Act?
The Schedule to the Act sets penalties of up to ₹250 crore for failure to implement reasonable security safeguards under Section 8(5), and up to ₹200 crore for failure to notify a data breach under Section 8(6), among other specified contraventions.
Does the DPDP Act apply to businesses outside India?
Yes. The Act applies extraterritorially to processing of digital personal data outside India where that processing is connected to offering goods or services to Data Principals located in India.
What is a Significant Data Fiduciary?
A Data Fiduciary the Central Government notifies under Section 10 based on factors such as data volume and sensitivity, and risk to Data Principal rights, security of the State, or electoral democracy. SDFs carry additional obligations including an India-based DPO, an independent auditor, and periodic Data Protection Impact Assessments.
How much time does a business have to report a data breach?
Under Rule 7 of the DPDP Rules, 2025, affected Data Principals and the Data Protection Board must be notified without delay upon the Data Fiduciary becoming aware of a breach, with a detailed report due to the Board within 72 hours.
Can personal data be transferred outside India under the DPDP Act?
Yes, subject to a negative-list model under Section 16: transfer is permitted to all countries except those the Central Government specifically restricts by notification. No country had been restricted as of mid-2026.
DPDP Sector Guides
Sector-specific compliance issues differ enough that a general reading of the Act often misses what matters most for a given industry. These guides apply the framework above to five sectors where Candour Legal advises regularly.
- DPDP Compliance for BFSI and Fintech
- DPDP Compliance for Healthcare Providers
- DPDP Compliance for E-Commerce and Platforms
- DPDP Compliance for Employers
- DPDP Compliance for GCCs
Read our DPDP analysis
- DPDP Consent Managers: A November 2026 Deadline, But No Regulator Yet
- DPDP Act and GCCs in India: The Outsourcing Exemption Explained
- MeitY’s IT Rules Second Amendment 2026: The Compliance Stack Collides with DPDP
- Online Gaming Rules 2026: A Comprehensive Guide to MeitY’s Light-Touch Framework for India
- Delhi Court’s Judgment Reiterates Right to be Forgotten in the Digital Era
- Understanding the DPDP Act in India
- India Digital Personal Data Protection Act 2023: A Compliance Guide for Businesses
- All DPDP Act articles
This page is analytical commentary on Indian law, not legal advice. Please see our Disclaimer and Terms of Use. For engagement enquiries, write to contact@candourlegal.com.
BEFORE YOU GO
Get a free 15-minute case assessment
Tell us what’s going on and a Candour Legal advocate will call you back — no charge, no obligation.
