Digital Personal Data Protection Act 2023 (DPDP)
Obligations Covered
Timeline
| Milestone | Date | Notes |
|---|---|---|
| Presidential assent | Aug 11, 2023 | Act No. 22 of 2023 |
| First Act and Rules phase | Nov 13, 2025 | Gazette G.S.R. 843(E)(a): sections 1(2), 2, 18-26, 35, 38-43 and 44(1), (3); Rules 1, 2, 17-21 under G.S.R. 846(E), Rule 1(2). This is not commencement of the core processing duties |
| Consent manager registration framework | Nov 13, 2026 | One-year phase: Act sections 6(9), 27(1)(d), and Rule 4. Framework commencement, not a universal deadline for filing registration |
| Core processing duties and remaining notified phase | May 13, 2027 | Eighteen-month phase: Act sections 3-5, 6(1)-(8), 6(10), 7-17, 27 except 27(1)(d), 28-34, 36-37, 44(2); Rules 3, 5-16, 22-23 |
Related Regulations and Standards
Related instruments are selected from shared compliance obligations and jurisdiction coverage.
Provisions (1)
Data Governance and Processing Obligations
AI processing can fall within this general data-protection law when section 3 applies. Personal/domestic processing and qualifying publicly available data are excluded by section 3(c); other exemptions are in section 17. The core consent, accuracy, security and breach-notification duties summarized here are in the eighteen-month phase, not already enforcing merely because the Board-related phase began.
Requirements
| Requirement | Details |
|---|---|
| Lawful basis | When commenced, processing must be for a lawful purpose on consent or one of the certain legitimate uses in section 7, subject to the Act's scope and exemptions (section 4) |
| Purpose limitation | For consent-based processing, consent is specific and informed and signifies agreement to the specified purpose; section 7 separately permits certain legitimate uses (section 6(1)) |
| Data accuracy | Ensure completeness, accuracy and consistency where processed data is likely to be used for a decision affecting the Data Principal or disclosed to another Data Fiduciary (section 8(3)) |
| Security safeguards | Implement reasonable security measures to prevent data breach (Section 8) |
| Breach notification | Under section 8(6) and Rule 7, notify affected Data Principals and give initial information to the Board without delay; give the Board updated details within 72 hours of awareness, or a longer period the Board allows on written request. Rule 7 is in the eighteen-month phase |
| Data minimization | Consent is limited to personal data necessary for the specified purpose (section 6(1)) |
| Erasure on withdrawal | Unless legally necessary to retain, erase on withdrawal or when it is reasonable to assume the specified purpose is no longer served, whichever is earlier, and cause the processor to erase; applicable Rules retention requirements must also be considered (section 8(7), Rule 8) |
Penalties
| Violation | Fine |
|---|---|
| Failure to implement security safeguards (section 8(5); core phase) | Up to ₹250 crore under section 33 and Schedule item 1 |
| Failure to notify breach (section 8(6); core phase) | Up to ₹200 crore under section 33 and Schedule item 2 |
| Other breaches, including applicable data-principal rights (core phase) | Up to ₹50 crore under section 33 and Schedule item 7 |
Cite this regulation
Permalink: https://everyailaw.com/regulation/in-dpdp/
JSON: https://everyailaw.com/api/v1/regulations.json
Attribution: EveryAILaw, PAICE.work PBC. “Digital Personal Data Protection Act 2023 (DPDP)”, EveryAILaw.com, May 21, 2026. https://everyailaw.com/regulation/in-dpdp/
Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.