Full compliance deadline: 13 May 2027—days left
India Data Law

Step 1 of 4 in the reading path

What the DPDP Act is, and why India has one

Verified October 2026

The Digital Personal Data Protection Act, 2023 is India's general data protection law. It is Act No. 22 of 2023. It received presidential assent on 11 August 2023. It regulates the processing of digital personal data, gives a Data Principal rights over her own data, and places obligations on a Data Fiduciary.

The Act has nine chapters, forty-four sections and one Schedule. The Schedule is the penalty table. The long title states the purpose: to provide for the processing of digital personal data in a manner that recognises both the right of individuals to protect their personal data and the need to process such personal data for lawful purposes.

Why India needed one

India had no general data protection law. The Information Technology Act, 2000 dealt with some of the ground through section 43A and rules made under it, but it was not a data protection statute and it did not give individuals rights.

That gap became a constitutional problem in 2017. On 24 August 2017 a bench of nine judges of the Supreme Court decided Justice K.S. Puttaswamy (Retd.) v. Union of India. The Court held unanimously that the right to privacy is a fundamental right, protected under Article 21 and as part of the freedoms in Part III of the Constitution. It overruled two earlier decisions that had held otherwise.

A fundamental right needs a statute to give it effect between an individual and a company. The Government constituted an expert committee under Justice B.N. Srikrishna on 31 July 2017, before the judgment was delivered, to study data protection and to draft a bill.

Six years from the judgment to a law

DateWhat happened
31 Jul 2017MeitY constituted the expert committee chaired by Justice B.N. Srikrishna.
24 Aug 2017Nine judges of the Supreme Court held in Puttaswamy that privacy is a fundamental right.
27 Jul 2018The committee reported, with a draft Personal Data Protection Bill, 2018.
11 Dec 2019The Personal Data Protection Bill, 2019 was introduced in the Lok Sabha and referred to a Joint Committee the same day.
16 Dec 2021The Joint Committee reported. It proposed eighty-one amendments and recommended extending the law to non-personal data.
3 Aug 2022The Government withdrew the 2019 Bill, saying it would bring a fresh framework instead.
18 Nov 2022MeitY released a draft Digital Personal Data Protection Bill, 2022 for public consultation.
3 Aug 2023The Digital Personal Data Protection Bill, 2023 was introduced in the Lok Sabha as Bill No. 113 of 2023.
7 Aug 2023The Lok Sabha passed the Bill.
9 Aug 2023The Rajya Sabha passed the Bill.
11 Aug 2023The President assented. The Bill became Act No. 22 of 2023.
13 Nov 2025The Government notified the DPDP Rules, 2025 and, by a separate notification, brought part of the Act into force.

Why the law matters now and did not before

The Act did not come into force when it was passed. Section 1(2) says the Act comes into force on such date as the Central Government appoints by notification, and that different dates may be appointed for different provisions. The Government appointed no date for more than two years. Between August 2023 and November 2025 the Act was law that bound nobody.

That changed on 13 November 2025. The Government issued two notifications on the same day. One brought the first group of sections into force. The other made the DPDP Rules, 2025 under section 40. Together they set the two dates that now apply to every Data Fiduciary. See the deadlines.

How the Act and the Rules fit together

The Act sets the principles and the duties. It leaves the detail to rules, using the phrase as may be prescribed throughout. Section 40 gives the Central Government the power to make those rules. Section 41 requires them to be laid before Parliament.

The DPDP Rules, 2025 are that detail. They set what a notice must look like, what reasonable security safeguards mean, how a breach is intimated, when data must be erased, what a Consent Manager must satisfy, and what a Significant Data Fiduciary must do. Neither document works without the other, and both commence in stages. The Rules page covers all 23 rules and when each starts.

Every section of the Act, in plain English

The Act has forty-four sections in nine chapters. The tables below say what each section means in plain words, and when it starts. The wording is a restatement, not the statutory text: where exact words matter, read the Act itself. For what is in force today, see the status tracker.

Chapter I — Preliminary (sections 1 to 3)

SectionWhat it meansStatus
s.1Names the Act and lets the Government bring different provisions into force on different dates. That is why parts of the Act apply today and parts do not.In force
s.2Defines the twenty-eight terms the Act uses, from personal data to Data Fiduciary to child. See every definition explained.In force
s.3Says who the Act covers: digital personal data processed in India, including paper records once they are digitised, and processing abroad connected with offering goods or services to people in India. Purely personal use, and data the person made public herself, are excluded. See the full test.13 May 2027

Chapter II — What a Data Fiduciary must do (sections 4 to 10)

SectionWhat it meansStatus
s.4Personal data may only be processed for a lawful purpose, and only with the person's consent or for one of the legitimate uses in section 7.13 May 2027
s.5Before asking for consent, the company must tell the person what data it wants, why, how to exercise her rights and how to complain to the Board. For data collected before the Act, a notice is enough: fresh consent is not required. The notice must be available in English or any of the twenty-two Eighth Schedule languages.13 May 2027
s.6Consent must be free, specific, informed, unconditional and unambiguous, given by a clear positive act, and limited to the data actually needed. Withdrawing it must be as easy as giving it. Consent Managers, who give people one place to manage consent, must register with the Board. That duty, in s.6(9), starts 13 November 2026.13 May 2027
s.7Lists the cases where consent is not needed, called legitimate uses: data the person gave voluntarily and has not objected to, State subsidies and services, medical emergencies, employment matters, and similar.13 May 2027
s.8The general duties. The company stays responsible even when a vendor processes the data, must have a valid contract with every processor, keep data accurate when it is used for decisions about the person, take reasonable security safeguards, tell the Board and the affected people about a breach, erase data once consent is withdrawn or the purpose is served, and run a grievance system. The two largest penalties in the Act, ₹250 crore and ₹200 crore, attach to the security and breach duties here.13 May 2027
s.9Children's data. A company must get verifiable consent from a parent or guardian before processing the data of anyone under eighteen, must not process data in a way likely to harm a child, and must not track children, monitor their behaviour or target advertising at them. The Government can exempt classes of company or lower the age threshold by notification.13 May 2027
s.10Lets the Government designate large or high-risk companies as Significant Data Fiduciaries. A designated company must appoint a Data Protection Officer based in India, an independent data auditor, and carry out periodic data audits and impact assessments. Nobody has been designated.13 May 2027

Chapter III — Your rights and duties (sections 11 to 15)

SectionWhat it meansStatus
s.11You can ask a company what personal data it holds about you, what it is doing with it, and who it has shared it with.13 May 2027
s.12You can ask for your data to be corrected, completed, updated or erased.13 May 2027
s.13You have a right to grievance redressal. The company must give you an easy way to complain and must respond within the prescribed time, and you must use it before going to the Board.13 May 2027
s.14You can nominate another person to exercise your rights if you die or become incapable.13 May 2027
s.15You have duties too: do not impersonate anyone, do not suppress material information, do not file false or frivolous complaints. Breaching them can cost you up to ₹10,000.13 May 2027

Chapter IV — Transfers abroad and exemptions (sections 16 and 17)

SectionWhat it meansStatus
s.16Personal data may be sent to any country except one the Government restricts by notification. No country has been restricted.13 May 2027
s.17The exemptions. Parts of the Act do not apply to legal claims, courts and regulators, crime investigation, foreign-only outsourcing contracts, approved mergers and loan-default checks. The Government can exempt its own notified agencies entirely, exempt research and statistics, and exempt startups, a power it has never used. See the exemptions in full.13 May 2027

Chapter V — The Data Protection Board (sections 18 to 26)

All of Chapter V is in force since 14 November 2025. It creates the regulator on paper: section 18 establishes the Board, section 19 sets its composition and how the chairperson and members are appointed, section 20 their pay and term, section 21 disqualification, section 22 resignation and vacancies, section 23 its officers and employees, section 24 makes them public servants, section 25 sets the chairperson's powers, and section 26 says a vacancy does not invalidate the Board's proceedings. What the chapter does not do is appoint anyone. No chairperson or member has been appointed.

Chapter VI — What the Board can do (sections 27 and 28)

SectionWhat it meansStatus
s.27The Board's powers: direct urgent remedial measures after a breach, inquire into complaints and government references, and impose penalties. One clause, s.27(1)(d) on inquiring into a Consent Manager's breach of its registration conditions, starts 13 November 2026. The rest starts in May 2027, so today the Board could not act even if it had members.13 May 2027
s.28How the Board works: as a digital office, where a complaint can be filed and decided online, with the powers of a civil court to summon people and take evidence.13 May 2027

Chapter VII — Appeals and settlement (sections 29 to 32)

SectionWhat it meansStatus
s.29A person unhappy with a Board order can appeal to the Telecom Disputes Settlement and Appellate Tribunal within sixty days.13 May 2027
s.30The Tribunal's orders are enforceable like a court decree.13 May 2027
s.31The Board can send the parties to mediation instead of deciding the dispute itself.13 May 2027
s.32A company under inquiry can offer a voluntary undertaking, which is a promise to act or stop acting in a certain way. If the Board accepts it, the inquiry on those facts ends. Breaking the promise is itself penalised.13 May 2027

Chapter VIII — Penalties (sections 33 and 34)

SectionWhat it meansStatus
s.33After an inquiry, the Board can impose the monetary penalties in the Schedule, up to ₹250 crore per breach. Section 33(2) lists the seven matters the Board must weigh in fixing the amount. See all seven penalty entries.13 May 2027
s.34Penalties go to the Consolidated Fund of India. The Act gives the affected individual no compensation.13 May 2027

Chapter IX — Miscellaneous (sections 35 to 44)

SectionWhat it meansStatus
s.35Nobody can be sued for something done under the Act in good faith.In force
s.36The Government can call for information from the Board, a Data Fiduciary or an intermediary.13 May 2027
s.37On the Board's advice, and after repeated penalties, the Government can order access to a Data Fiduciary's service blocked in India.13 May 2027
s.38The Act operates alongside other laws. Where another law conflicts, this Act prevails to the extent of the conflict.In force
s.39Civil courts cannot hear any matter the Board is empowered to decide. Since s.27, which gives the Board its powers, is not yet in force, what this bar covers today is untested.In force
s.40The Government's power to make rules under the Act. The DPDP Rules, 2025 were made under it.In force
s.41Every rule and notification must be laid before Parliament.In force
s.42The Government can amend the penalty Schedule, but can never raise a penalty to more than twice the original figure.In force
s.43Lets the Government issue orders to remove difficulties in giving effect to the Act, for a limited period after commencement. The Government used this power by S.O. 5458(E) of 5 October 2026 to correct the wording of sections 9(1) and 10(2)(c)(ii).In force
s.44Amends three other laws: the TRAI Act, so DPDP appeals go to the Appellate Tribunal (in force); the IT Act, omitting section 43A (not in force, see below); and the RTI Act, substituting section 8(1)(j) (in force, and under challenge in the Supreme Court).Split, see below

The Schedule at the end of the Act is the penalty table, with seven entries. See the penalties explained.

Three other laws the Act changes

Section 44 amends three statutes. Section 44(1) amends the Telecom Regulatory Authority of India Act, 1997. The Telecom Disputes Settlement and Appellate Tribunal now hears appeals under this Act. The right of appeal itself starts on 13 May 2027. See the courts. Section 44(2) amends the Information Technology Act, 2000, and omits section 43A of that Act. Section 44(3) substitutes section 8(1)(j) of the Right to Information Act, 2005.

Two of these are already in force and one is not. Section 44(1) and section 44(3) came into force in November 2025. Section 44(2) sits in the group that starts in May 2027, which means section 43A of the Information Technology Act has not been omitted and is still law. Published commentary often states this incorrectly.

The change to the Right to Information Act is under challenge in the Supreme Court. The Supreme Court referred the challenges to the Act and the Rules to a larger bench on 16 February 2026. It refused an interim stay on the same date. It has not announced the size of the larger bench. Section 44(3) is the most prominent ground in that case.

What would change this page

A judgment of the larger bench on section 44(3). An amendment to the Act. A notification bringing the remaining provisions into force earlier or later than the dates now set.

Sources. The Act as published by India Code and by MeitY. Committee and bill dates from PRS Legislative Research and the Press Information Bureau. See the sources page.

Next in the reading path: What are the DPDP Rules →