Digital Personal Data Protection Act 2023 (DPDP)

Jurisdiction:
India
phased enforcement
Effective:
Nov 13, 2025
Authority:
Data Protection Board of India
Official text

Obligations Covered

Data Governance

Timeline

MilestoneDateNotes
Presidential assentAug 11, 2023Act No. 22 of 2023
First Act and Rules phaseNov 13, 2025Gazette G.S.R. 843(E)(a): sections 1(2), 2, 18-26, 35, 38-43 and 44(1), (3); Rules 1, 2, 17-21 under G.S.R. 846(E), Rule 1(2). This is not commencement of the core processing duties
Consent manager registration frameworkNov 13, 2026One-year phase: Act sections 6(9), 27(1)(d), and Rule 4. Framework commencement, not a universal deadline for filing registration
Core processing duties and remaining notified phaseMay 13, 2027Eighteen-month phase: Act sections 3-5, 6(1)-(8), 6(10), 7-17, 27 except 27(1)(d), 28-34, 36-37, 44(2); Rules 3, 5-16, 22-23

Related Regulations and Standards

Related instruments are selected from shared compliance obligations and jurisdiction coverage.

Provisions (1)

Data Governance and Processing Obligations

Copy link to this provision

Obligation:
Data Governance
pending
Effective:
May 13, 2027
Risk tier:
all
Scope:
Data Fiduciaries processing digital personal data within India, or outside India in connection with offering goods or services to Data Principals within India, subject to section 3 exclusions and section 17 exemptions
sleepercross-domain
AI processing can fall within this general data-protection law when section 3 applies. Personal/domestic processing and qualifying publicly available data are excluded by section 3(c); other exemptions are in section 17. The core consent, accuracy, security and breach-notification duties summarized here are in the eighteen-month phase, not already enforcing merely because the Board-related phase began.

Requirements

RequirementDetails
Lawful basisWhen commenced, processing must be for a lawful purpose on consent or one of the certain legitimate uses in section 7, subject to the Act's scope and exemptions (section 4)
Purpose limitationFor consent-based processing, consent is specific and informed and signifies agreement to the specified purpose; section 7 separately permits certain legitimate uses (section 6(1))
Data accuracyEnsure completeness, accuracy and consistency where processed data is likely to be used for a decision affecting the Data Principal or disclosed to another Data Fiduciary (section 8(3))
Security safeguardsImplement reasonable security measures to prevent data breach (Section 8)
Breach notificationUnder section 8(6) and Rule 7, notify affected Data Principals and give initial information to the Board without delay; give the Board updated details within 72 hours of awareness, or a longer period the Board allows on written request. Rule 7 is in the eighteen-month phase
Data minimizationConsent is limited to personal data necessary for the specified purpose (section 6(1))
Erasure on withdrawalUnless legally necessary to retain, erase on withdrawal or when it is reasonable to assume the specified purpose is no longer served, whichever is earlier, and cause the processor to erase; applicable Rules retention requirements must also be considered (section 8(7), Rule 8)

Penalties

ViolationFine
Failure to implement security safeguards (section 8(5); core phase)Up to ₹250 crore under section 33 and Schedule item 1
Failure to notify breach (section 8(6); core phase)Up to ₹200 crore under section 33 and Schedule item 2
Other breaches, including applicable data-principal rights (core phase)Up to ₹50 crore under section 33 and Schedule item 7
Cite this regulation

Permalink: https://everyailaw.com/regulation/in-dpdp/

JSON: https://everyailaw.com/api/v1/regulations.json

Attribution: EveryAILaw, PAICE.work PBC. “Digital Personal Data Protection Act 2023 (DPDP)”, EveryAILaw.com, May 21, 2026. https://everyailaw.com/regulation/in-dpdp/

Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.