India Data Law

Common questions

Verified August 2026 · Checked monthly

Twenty-six questions, answered in two or three sentences each. Where a question has a page of its own, the answer links to it. Nothing here is legal advice.

Eight of these questions have a page of their own, where the provision and the source are set out in full. See the key questions.

Is the DPDP Act in force?

Partly. Definitions, the provisions establishing the Data Protection Board, the rule-making power and two of the three amendments to other Acts came into force in November 2025. Almost everything else starts on 13 May 2027.

See the status tracker

When do I have to comply?

Consent Manager registration falls due by November 2026. Everything else falls due by May 2027. The Government confirmed both dates in a written answer in the Lok Sabha on 12 August 2026 and has said no extension is under consideration.

See the deadlines

Is the Data Protection Board working?

No. It has no appointed chairperson and no appointed members. Its powers and procedure, in sections 27 and 28, do not start until May 2027 either. So it cannot receive a complaint or pass an order today.

See the full answer

Who does the Act apply to?

It applies to digital personal data processed in India, and to processing outside India that is connected with offering goods or services to people in India. The duties fall on whoever decides the purpose and means of processing.

See who it applies to

Does it apply to my company if we are based outside India?

It can. Section 3(b) reaches processing outside India where that processing is connected with offering goods or services to Data Principals in India. There is no separate limb for monitoring behaviour, which is a difference from the European Union's General Data Protection Regulation.

See who it applies to

No. Section 5(2) requires a notice, not fresh consent, for personal data collected before the Act commenced. Processing may continue until the Data Principal withdraws consent. A re-consent campaign is not required by the Act.

See the full answer

What makes a company a Data Fiduciary?

Section 2(i) says a Data Fiduciary is any person who alone or with others determines the purpose and means of processing personal data. The test is the decision, not contact with the data.

See the test

Is a vendor who only stores data for me a Data Fiduciary?

Not on that fact alone. A person who processes personal data on behalf of a Data Fiduciary is a Data Processor under section 2(k). Section 8(2) requires the Data Fiduciary to hold a valid contract with every processor it uses.

See who does what

Who counts as a child?

Section 2(f) defines a child as an individual who has not completed the age of eighteen years. That is higher than the threshold in several other data protection laws.

See every definition

Has anyone been designated a Significant Data Fiduciary?

No. Section 10(1) gives the Central Government the power to designate one and it has not been used. Until it is, the additional duties in section 10(2) and Rule 13 apply to nobody.

See the powers not used

Only if it is a company incorporated in India with a net worth of at least two crore rupees, with an independently certified platform and consent records kept for at least seven years. Registration opens on 13 November 2026 and nobody is registered yet.

See the conditions

What are the penalties?

The Schedule sets seven entries, the largest being 250 crore rupees for failing to take reasonable security safeguards. Section 33(2) requires the Board to weigh a set of factors before fixing an amount, so the figures are ceilings and not tariffs.

See all seven entries

Has any penalty been imposed under the Act?

No. The penalty and adjudication sections do not start until 13 May 2027, and the Board that would impose a penalty has no members.

See the penalties

In which languages must I give a notice?

Section 5(3) requires the Data Fiduciary to give the Data Principal the option of English or any of the twenty-two languages in the Eighth Schedule to the Constitution. The choice belongs to the Data Principal.

See the language rule

How long must I keep personal data?

Rule 6(1)(e) requires security logs and the personal data in them to be kept for one year. That is a floor for that data and not a general retention rule.

See both periods

When must I delete personal data?

Rule 8 requires certain classes of Data Fiduciary to erase personal data after three years of dormancy, with at least forty-eight hours notice to the Data Principal first. The Third Schedule sets which classes and what thresholds apply.

See both periods

Can I transfer personal data outside India?

Yes, subject to any restriction the Central Government notifies under section 16. No country has been restricted. Section 16 and Rule 15 do not start until May 2027, so transfers currently remain governed by contract and by sector regulators.

See the powers not used

Does the Act require personal data to be stored in India?

Not generally. Rule 13(4) lets the Government require a class of personal data to stay inside India, but only for a Significant Data Fiduciary and only once it notifies. No such class has been notified and no Significant Data Fiduciary has been designated.

See the powers not used

Does the Act cover paper records?

Only once they are digitised. Section 3(a) covers digital personal data, and personal data collected in non-digital form and digitised afterwards. A record that stays on paper falls outside.

See the scope

Does the Act have a category of sensitive personal data?

No. There is no defined class of sensitive personal data and no heavier duty attached to health, financial or biometric data as such. That is a deliberate departure from the Information Technology rules of 2011 and from the European Union's General Data Protection Regulation.

See what is not defined

Does the Act define harm?

No. The draft Bill of 2022 defined harm and the enacted Act does not. Guidance that cites a definition of harm from this Act is citing something that is not there.

See what is not defined

Has section 43A of the Information Technology Act been repealed?

Not yet. Section 44(2) of the DPDP Act omits it, but section 44(2) is in the group that starts on 13 May 2027. Section 43A and the rules made under it are still law. Published commentary often says otherwise.

See the Act tranches

What happened to the Right to Information Act?

Section 44(3) substituted section 8(1)(j) of the Right to Information Act, 2005 and is already in force. The Supreme Court referred the challenges to a larger bench on 16 February 2026 and refused an interim stay. It has not announced the size of that bench.

See the amendments

Is there an exemption for startups?

There is a power to create one, in section 17(3), and it has not been used. No startup has been notified, so the exemption cannot be relied on by anyone today.

See the exemptions

Do government bodies have to comply?

Generally yes, because section 2(s) includes the State in the definition of person. But section 17(2)(a) lets the Central Government exempt a notified instrumentality of the State entirely, and section 17(4) removes some erasure and correction duties for the State.

See the exemptions

What should I be doing right now?

Nothing on this site is legal advice, and what a Data Fiduciary should do depends on what it processes. What can be said factually is that most duties start on 13 May 2027, that no penalty can be imposed before then, and that the twenty-two language notice obligation is the item with the longest lead time.

See the deadlines

If your question is not here, write to editor@indiadatalaw.org. Questions asked more than once are added to this page, and questions asked often enough become pages of their own.