Weekly updates
Last entry October 2026 · Checked weekly
Developments in Indian data protection, with major privacy enforcement from around the world. Updated every week.
This page also produces a feed, which you can follow in a feed reader. The site collects no email addresses and sends no email.
| Date | Scope | What happened | Source |
|---|---|---|---|
| 6 Oct 2026 | India | MeitY corrected the wording of sections 9(1) and 10(2)(c)(ii) of the DPDP Act by an order under section 43. The Ministry of Electronics and Information Technology issued the Digital Personal Data Protection (Removal of Difficulties) Order, 2026 under section 43(1) of the Act, dated 5 October 2026 and numbered S.O. 5458(E). The Order was published in the Gazette of India on 6 October 2026 and took effect on that date. Section 9(1) now reads “a child or of a person with disability”, and the Order states that the missing word “of” had made the two groups ambiguous. In section 10(2)(c)(ii), the word “audit” is replaced by “data audit”, so a Significant Data Fiduciary must carry out a periodic data audit. The Order changes only these words and no commencement date, and sections 9 and 10 start on 13 May 2027. |
Primary source Gazette of India copy of S.O. 5458(E), 6 October 2026, hosted by Fox Mandal |
| 30 Sep 2026 | India | MeitY's DPDP logo, tagline and mascot contests closed with 2,684 entries. The Ministry of Electronics and Information Technology ran two public contests for the DPDP Act on MyGov from 3 September to 30 September 2026. The logo and tagline contest received 1,940 entries, and the mascot design and name contest received 744 entries. MyGov shows all the entries in both contests as under review, and no result has been announced. The first prize for the logo, for the tagline and for the mascot is 1 lakh rupees each. The mascot contest page says that the winning design may be used in public awareness campaigns on the Act. |
Primary source MyGov page of the DPDP Act logo and tagline contest, September 2026 Primary source MyGov page of the DPDP mascot design and name contest, September 2026 |
| 25 Sep 2026 | India | Jharkhand trained senior state officials on the DPDP Act. The Information Technology and e-Governance Department of the Government of Jharkhand held a workshop on the DPDP Act for senior officials of state departments in Ranchi on 25 September 2026. The department organised the workshop with C-DAC Kolkata, which works under the Ministry of Electronics and Information Technology. The sessions covered the duties of a Data Fiduciary, the rights of a Data Principal, consent management, grievance redressal and the handling of personal data breaches. A government department that decides the purpose and means of processing is a Data Fiduciary under section 2(i) of the Act, and the duties of a Data Fiduciary start on 13 May 2027. The report is a single Hindi-language news item, and no government release has been published. |
Reported by ETV Bharat (Hindi) on the Jharkhand DPDP workshop, 25 September 2026 |
| 21 Sep 2026 | Global | The European Data Protection Board proposed a five-step method for setting GDPR fines. The European Data Protection Board adopted draft guidelines on administrative fines under the General Data Protection Regulation on 21 September 2026. In the method, a regulator checks that the infringement permits a fine, identifies the liable controller or processor, decides whether the infringement was intentional or negligent, weighs the aggravating and mitigating factors, and checks that the fine is effective, proportionate and dissuasive. The guidelines include 14 worked examples, and the public consultation closes on 13 November 2026. Section 33(2) of the DPDP Act lists seven matters that the Data Protection Board must consider when it sets a penalty, and the Board has published no method for applying them. Section 33 starts on 13 May 2027. |
Primary source European Data Protection Board announcement of the fining guidelines, 21 September 2026 |
| 21 Sep 2026 | Global | Ireland's data protection regulator fined Google 403 million euros over location data. The Data Protection Commission of Ireland fined Google 403 million euros on 21 September 2026. The inquiry started in February 2020 and examined how Google processed location data through its Web & App Activity, Location History and Location Accuracy settings between 25 May 2018 and 4 February 2020. The Commission found failures of lawfulness, fairness, accountability, transparency and retention under the General Data Protection Regulation, and it ordered Google to bring its processing into compliance within six months. Under the DPDP Act, the parallel duties are notice in section 5, consent in section 6 and erasure in section 8(7), and these duties start on 13 May 2027. Entry 7 of the Schedule to the Act sets the penalty for a breach of these duties at up to 50 crore rupees. |
Primary source Data Protection Commission announcement of the Google fine, 21 September 2026 |
| 19 Sep 2026 | India | Subsidised LPG refills need biometric Aadhaar authentication from 1 October 2026. The Ministry of Petroleum and Natural Gas announced on 19 September 2026 that, from 1 October 2026, a domestic LPG consumer must complete biometric Aadhaar authentication to book a refill at the subsidised price. The ministry said that 27.43 crore consumers, 89.9 per cent of active domestic consumers, had completed the authentication. A consumer who does not complete it can buy LPG at the market price, without the subsidy, in 5 kg or 10 kg cylinders. Section 7 of the Aadhaar Act, 2016 permits the government to require Aadhaar authentication as a condition for a subsidy paid from the Consolidated Fund of India. From 13 May 2027, section 7(b) of the DPDP Act permits the State to process personal data to give a subsidy or benefit, under the standards in Rule 5 and the Second Schedule of the DPDP Rules. |
Primary source Press Information Bureau release of the Ministry of Petroleum and Natural Gas, 19 September 2026 |
| 17 Sep 2026 | India | CAMS launched a self-serve DPDP compliance platform for financial firms. Computer Age Management Services announced ConsenPro Self-Serve in a filing with BSE Limited on 17 September 2026, during the Global Fintech Fest in Mumbai. The platform covers data discovery, the generation of consent notices, the management of consent collected before the Act, and API-based connections to a company's own systems. CAMS named WhiteOak Capital and Helios Mutual Fund as the first engagements, and the platform is aimed at asset managers and mid-sized financial firms preparing for the full-compliance deadline of 13 May 2027. CAMS did not disclose pricing. |
Primary source CAMS filing with BSE Limited, 17 September 2026 Reported by Whalesbook on the ConsenPro Self-Serve launch, 17 September 2026 |
| 17 Sep 2026 | Global | The European Commission proposed a law that would bar children under 13 from social media. The European Commission published its proposal for the EU KIDS Act on 17 September 2026. Under the proposal, children under 13 could not access social media, and children aged 13 to 15 could use it only through an account managed by a parent or guardian, with a time limit of one hour a day. Platforms would have to limit features that encourage excessive use, such as infinite scroll, reward mechanisms and push notifications during sleeping hours, and AI chatbots and companions would be turned off by default for children. The European Parliament and the Council will now negotiate and decide the final text. India's parallel provision is section 9 of the DPDP Act, which requires verifiable parental consent for every user under 18 and bans tracking, behavioural monitoring and targeted advertising directed at children, and which comes into force on 13 May 2027. |
Primary source European Commission announcement of the EU KIDS Act proposal, 17 September 2026 |
| 15 Sep 2026 | India | Two central government bodies held DPDP workshops for their officers in September 2026. The Digital India website lists a one-day workshop on the DPDP Act and the DPDP Rules for officers of the Indian Council of Medical Research in Delhi on 7 September 2026. It lists a second one-day workshop for the Ministry of Coal in Delhi on 15 September 2026. The listings do not name the organiser or give the number of participants. A government body that decides the purpose and means of processing personal data is a Data Fiduciary under section 2(i) of the Act, and the duties of a Data Fiduciary start on 13 May 2027. |
Primary source Digital India listing of the DPDP workshop for ICMR officers, 7 September 2026 Primary source Digital India listing of the DPDP workshop for the Ministry of Coal, 15 September 2026 |
| 11 Sep 2026 | India | The State Bank of India said it will comply with the DPDP Act by December 2026. A senior official of the State Bank of India told Business Standard on 11 September 2026 that the bank has procured the software and hardware it needs to comply with the DPDP Act, and that it will deploy them and be compliant by the end of December 2026. The full-compliance deadline under the Rules is 13 May 2027. SBI is India's largest bank, and this is the first public commitment by a major Indian Data Fiduciary to be ready months ahead of the deadline. The bank has not published an official release, and the statement is attributed to an unnamed official. |
Reported by Business Standard on the SBI compliance target, 11 September 2026 |
| 10 Sep 2026 | India | The RBI Governor told fintech companies to treat customer data as a fiduciary responsibility. Reserve Bank of India Governor Sanjay Malhotra spoke at the Global Fintech Fest in Mumbai on 10 September 2026 and said that fintech companies should treat customer data as a fiduciary responsibility and not as a business asset. Data Fiduciary is the term the DPDP Act itself uses in section 2(i) for the entity that decides the purpose and means of processing personal data. At the same event, the Indian Digital Payments Intelligence Corporation said its Smart Registry for fraud intelligence has operated since 1 September 2026 with eight banks, and that participating banks share account data in salted and hashed form rather than as raw customer records. UIDAI also launched a face-authentication software development kit at the event on 9 September 2026. |
Reported by Business Standard on the Governor's remarks, 10 September 2026 Reported by MediaNama on the DPIP Smart Registry, September 2026 |
| 8 Sep 2026 | India | Canara Bank is reported to have committed about 60 crore rupees to DPDP compliance. Naavi.org reported on 8 September 2026, from procurement posts published on LinkedIn, that Canara Bank has awarded a contract of 52.19 crore rupees for an IT compliance solution, a contract of 82 lakh rupees for audit resources, and a six-month engagement for a privacy AI platform, together about 60 crore rupees, for compliance with the DPDP Act. Canara Bank has not confirmed the figures, and the bank has published no statement. These are the first public rupee figures on what DPDP compliance costs a large Indian bank. Elets BFSI, citing the same posts, estimates a spend of about 860 crore rupees across the banking sector if other banks spend at a similar rate. |
Reported by Naavi.org on the Canara Bank contracts, 8 September 2026 Reported by Elets BFSI on the reported investment, 9 September 2026 |
| 3 Sep 2026 | India | MeitY opened a public contest for a DPDP Act logo and tagline. The Ministry of Electronics and Information Technology opened a logo and tagline contest for the DPDP Act on the MyGov platform, running from 3 to 30 September 2026. The first prize in each category is one lakh rupees. The logo must convey privacy, trust, citizen empowerment and responsible data use and must work in colour and in monochrome, and the tagline may run to eight words at most, in English and in Hindi. Entries created entirely with AI tools are excluded. A public identity campaign for the Act signals that the Government has begun preparing citizens for the rights that arrive on 13 May 2027. |
Primary source MyGov contest page, DPDP Act Logo and Tagline Contest, 3 to 30 September 2026 |
| 3 Sep 2026 | India | Delhi and NCERT trained their officers on the DPDP Act. The Information Technology Department of the Government of Delhi held a workshop on the DPDP Act on 3 September 2026 with the National e-Governance Division of MeitY, for nodal officers drawn from departments across the Delhi government. The National Council of Educational Research and Training held a workshop for its officers on the same day. Press reports link both to a letter of 20 August 2026 from the Cabinet Secretary, which directs every central ministry, state government and union territory to prepare a time-bound DPDP compliance plan. Government departments that decide the purpose and means of processing are Data Fiduciaries under section 2(i), and the duties of a Data Fiduciary start on 13 May 2027. Each report is a single Hindi-language news item, and no government release has been published. |
Reported by Asianet News Hindi on the Delhi workshop, 3 September 2026 Reported by Dainik Jagran on the NCERT workshop, 3 September 2026 |
| 3 Sep 2026 | India | The GST intelligence arm proposed that payment systems record which website sent each payment. The Directorate General of GST Intelligence proposed that payment systems record the website from which a payment originates, together with the bank accounts linked to the receiving merchant. The proposal aims at shell merchants that route money for illegal betting platforms, and MediaNama reports about 70,000 crore rupees routed through roughly 750 such merchants. No draft rule or notification has been published. MediaNama notes that a record kept to establish which website a person visited serves a different purpose from completing the payment, and consent under section 6(1) of the DPDP Act, which comes into force on 13 May 2027, is consent for a specified purpose. |
Reported by MediaNama on the DGGI proposal, 3 September 2026 |
| 27 Aug 2026 | India | The Cabinet Secretary directed ministries and states to comply with the DPDP Act. The Cabinet Secretary directed all central ministries, state governments and union territories to comply with the Digital Personal Data Protection Act, 2023. Press reports state that the direction went out in a letter of 20 August 2026, and that each ministry and state must prepare a time-bound compliance plan and appoint a nodal officer. Government departments that decide the purpose and means of processing are Data Fiduciaries under section 2(i), and the duties of a Data Fiduciary in sections 4 to 10 start on 13 May 2027. The Data Protection Board, which will enforce those duties, has no chairperson and no members. |
Reported by Financial Express, “Centre puts ministries, states on DPDP compliance clock”, August 2026 Reported by KNN India on the 20 August letter, 29 August 2026 |
| 26 Aug 2026 | Global | Meta agreed to pay up to 18 billion dollars to settle United States claims over harm to children. Meta agreed on 26 August 2026 to settle claims by United States state attorneys general that Facebook and Instagram were designed to keep children on the platforms and that Meta collected children's data unlawfully. The settlement is worth up to 18 billion dollars over ten years and requires design changes for users under 18, including daily usage limits, hidden like counts and stronger age verification. On 21 August 2026 TikTok and ByteDance agreed to pay 400 million dollars to settle a United States government case under the Children's Online Privacy Protection Act. India's parallel provisions are section 9 of the DPDP Act, which requires verifiable parental consent and bans tracking, behavioural monitoring and targeted advertising directed at children, and Rule 10, which sets how a parent is verified. Both come into force on 13 May 2027, and the Schedule sets the penalty for a breach of section 9 at up to 200 crore rupees. |
Primary source United States Department of Justice press release on the TikTok settlement, 21 August 2026 Reported by Al Jazeera on the Meta settlement, 27 August 2026 |
| 12 Aug 2026 | India | The Government confirmed both compliance dates in Parliament. The Minister of State for Electronics and Information Technology answered a written question in the Lok Sabha on 12 August 2026. The answer states that Consent Manager registration falls due by November 2026. It states that full compliance falls due by May 2027. Both dates are now on the parliamentary record. A reader can cite the answer instead of press commentary. |
Reported by Tech Observer, 18 August 2026 (the answer itself is not yet published online) |
| 12 Aug 2026 | India | Common Service Centre operators may not collect or store citizen data. The same parliamentary answer states that Village Level Entrepreneurs at Common Service Centres are not authorised to collect or store citizen data. The answer does not say whether they are Data Fiduciaries. India has more than 5.8 lakh Common Service Centres. The operators are not authorised to collect or store Aadhaar records, banking records or health records. On the section 2(i) test, an operator who decides nothing about the purpose or the means is not a Data Fiduciary. The obligations then sit with the government department whose service the centre delivers. That is a reading of the Act and not a statement by the Government. This is the first official statement about who handles data at a Common Service Centre. |
Reported by Tech Observer, 18 August 2026 |
| 7 Aug 2026 | India | The Supreme Court gave the Union Government two weeks to reply on section 44(3). The Supreme Court heard the challenges to the Act and the Rules on 7 August 2026. It gave the Union Government two weeks to file its reply. The Court referred the matter to a larger bench on 16 February 2026, on which date it also refused an interim stay. It has not announced the size of the larger bench. Section 44(3) substitutes section 8(1)(j) of the Right to Information Act, 2005 and came into force in November 2025. The Court did not stay the provision, so the amendment stays in force while the reference is heard. |
Reported by LiveLaw, 16 February 2026, on the reference to a larger bench |
| 1 Aug 2026 | India | The Data Protection Board still has no chairperson and no members. The recruitment advertisement was published in Employment News on 6 June 2026 for a chairperson and four members. No appointment has been announced since. The Madhya Pradesh High Court at Indore directed a petitioner to file a representation before the Board in Parth Sharma v. Union of India. The Board cannot receive a complaint or pass an order until the Government appoints members. |
Reported by LiveLaw, 1 August 2026 |