Law / India

India

privacy

India's Digital Personal Data Protection Act, 2023 (DPDPA, No. 22 of 2023) received Presidential assent on 11 August 2023, but its substantive chapters have not yet commenced.

Notification G.S.R. 843(E) (Gazette of India Extraordinary, Part II Sec. 3(i), 13 November 2025), issued under DPDPA s.1(2), appointed its own publication date, 13 November 2025, as the date on which s.1(2), s.2 (definitions), sections 18 to 26 (the Data Protection Board), section 35, sections 38 to 43, and section 44(1) and (3) came into force, and appointed eighteen months from that same publication date, 13 May 2027, as the date on which sections 3 to 5, section 6(1) to (8) and (10), sections 7 to 10, sections 11 to 17, section 27 (except (1)(d)), sections 28 to 34, 36, 37, and section 44(2), the entire lawful-basis, consent, data-subject-rights, and cross-border-transfer chapters, come into force.

The Act has no special or sensitive-category tier at all, so once its duties commence, a voiceprint or faceprint is governed as ordinary personal data under the same general consent and security rules as any other identifier, not as a distinct heightened category.

Section 3(c)(ii) carves out personal data the data principal has made or caused to be made publicly available, one of the broadest such carve-outs in the region, though it does not on its own terms rescue an identifier a service derives from that public material.

Because section 44(2), which would repeal IT Act section 43A and the Sensitive Personal Data or Information Rules, 2011, is itself among the provisions not yet commenced, the SPDI Rules 2011 remain India's operative sensitive-data regime today; this document does not author them as an instrument, for lack of a verified working primary URL this pass.

15 instruments named 6 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

Digital Personal Data Protection Act, 2023, breach notification duties

cite Digital Personal Data Protection Act, 2023 (DPDPA), No. 22 of 2023, breach notification, s.8(6) stage IMMINENT in force in 256 days effective 2027-05-13 binds public and private bodies source official statute and Rules text, Ministry of Electronics and Information Technology (MeitY)
What it requires

Section 8(6) requires a Data Fiduciary to give the Board and each affected Data Principal intimation of a personal data breach, in the form and manner prescribed. Rule 7 fills in that detail: notify each affected Data Principal without delay, notify the Board without delay with an initial description, then supply a detailed follow-up report within 72 hours of becoming aware of the breach, or such longer period as the Board allows.

Neither provision is currently in force: s.8 sits in the sections-3-to-17 bucket, appointed by Notification G.S.R. 843(E) (13 November 2025) to commence eighteen months after its own publication date, 13 May 2027; Rule 7 sits in the parallel rules-3-to-16 bucket, appointed to the same 13 May 2027 date by the Rules' own Rule 1(4).

Comprehensive regime

Digital Personal Data Protection Act, 2023, comprehensive regime and lawful basis

cite Digital Personal Data Protection Act, 2023 (DPDPA), No. 22 of 2023, ss.2(t), 4, 6, 7, 8 stage IMMINENT in force in 256 days effective 2027-05-13 binds public and private bodies source official statute text, Ministry of Electronics and Information Technology (MeitY)
What it requires

The DPDPA is India's first comprehensive personal-data statute, defining "personal data" broadly and technology-neutrally as any data about an identifiable individual (s.2(t)), with no separate sensitive or special-category tier for any kind of data, biometric included.

A Data Fiduciary must have a lawful basis under s.4 before processing, ordinarily the data principal's free, specific, informed, unconditional and unambiguous consent under s.6, or one of s.7's enumerated legitimate uses (voluntarily-provided data for a specified purpose, state functions, employment, medical emergency). A Data Fiduciary bears general erasure (s.8(7)) and security-safeguard (s.8(5)) duties.

None of ss.4, 6, 7, or 8 have commenced: Notification G.S.R. 843(E) (13 November 2025) appoints eighteen months from its own publication date, 13 May 2027, as their commencement date under clause (c); that calendar date is arithmetic on the notification's own offset, not a separately printed date. Section 2's definitions, by contrast, came into force on the notification's publication date itself, 13 November 2025, under clause (a).

Digital Personal Data Protection Rules, 2025

cite G.S.R. 846(E), Digital Personal Data Protection Rules, 2025, notified 13 November 2025 stage RECENT in force 10 months effective 2025-11-13 binds public and private bodies source official Rules text, Gazette of India Extraordinary, Ministry of Electronics and Information Technology
What it requires

The Rules implement the DPDPA's app-facing detail: consent-notice form, security safeguards, breach notification (Rule 7), children's-data verification, and Significant Data Fiduciary duties including an annual Data Protection Impact Assessment and algorithmic-fairness assessment (Rule 13).

As notified, only Rules 1, 2, and 17 to 21, the Data Protection Board's own administrative machinery (member recruitment, meeting procedure, digital-office functioning, staff appointment), are currently in force. Rule 4 (Consent Manager registration) commences 13 November 2026; the app-facing bulk (Rules 3, 5 to 16, 22, and 23) commences 13 May 2027.

Cross border transfer

Digital Personal Data Protection Act, 2023, cross-border transfer restrictions

cite Digital Personal Data Protection Act, 2023 (DPDPA), No. 22 of 2023, cross-border transfer, s.16 stage IMMINENT in force in 256 days effective 2027-05-13 binds public and private bodies source official statute text, Ministry of Electronics and Information Technology (MeitY)
What it requires

Section 16(1) sets a blacklist model: transfer of personal data outside India is permitted by default to any country or territory, except where the Central Government affirmatively notifies a restriction. This flips the 2019/2021 draft Bills' government-approved whitelist model. No data-localization mandate appears anywhere in the Act.

Section 16 sits inside the sections-3-to-17 bucket; Notification G.S.R. 843(E) (13 November 2025) appoints eighteen months from its own publication date, 13 May 2027, as this bucket's commencement date. No restricted-country list has been notified because the enabling section is not yet in force.

Data subject rights

Digital Personal Data Protection Act, 2023, data subject rights

cite Digital Personal Data Protection Act, 2023 (DPDPA), No. 22 of 2023, data subject rights, ss.11-14 stage IMMINENT in force in 256 days effective 2027-05-13 binds public and private bodies source official statute text, Ministry of Electronics and Information Technology (MeitY)
What it requires

Once in force, a data principal may demand a summary of their processed personal data and the identities of the Fiduciaries and Processors it was shared with (s.11), correction, completion, updating and erasure (s.12), grievance redressal against the Fiduciary in the first instance with a complaint to the Board only after that process is exhausted (s.13), and a right to nominate another individual to exercise these rights on death or incapacity (s.14).

No express portability or objection right appears in the Act text as read. None of this currently binds; Notification G.S.R. 843(E) (13 November 2025) appoints eighteen months from its own publication date, 13 May 2027, as Chapter III's commencement date.

Enforcement supervision

Digital Personal Data Protection Act, 2023, Data Protection Board and penalties

cite Digital Personal Data Protection Act, 2023 (DPDPA), Data Protection Board and penalties, ss.18-26, 33, 39 stage RECENT in force 10 months effective 2025-11-13 binds public and private bodies source official statute text, Ministry of Electronics and Information Technology (MeitY)
What it requires

The Data Protection Board of India (Chapter VI, ss.18-26) is established and administratively operational, and section 39's ouster of civil-court jurisdiction over any matter the Board is empowered to decide is also in force, both since 13 November 2025 under Notification G.S.R. 843(E), clause (a).

Its penalty powers, set out in the Schedule under s.33(1), are exclusively civil monetary: up to Rs 250 crore for a failure to take reasonable security safeguards, up to Rs 200 crore for failing to notify a breach, up to Rs 200 crore for a children's-data violation, up to Rs 150 crore for a Significant Data Fiduciary violation, and up to Rs 10,000 for a data principal's own breach of their s.15 duties (impersonation, suppressing material information, frivolous complaints).

No provision found authorizes the Board to award compensation to an affected data principal directly; its penalties are payable to government. Section 33 (the penalty Schedule) and the rest of the complaint and appeal machinery (ss.27-34, except s.27(1)(d)) have not commenced; Notification G.S.R. 843(E), clause (c), appoints eighteen months from its own publication date, 13 May 2027, as their commencement date.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.