||

Connecting Communities, One Page at a Time.

advertisement
advertisement

DPDP Act Explained: What is India’s Digital Personal Data Protection Law and Why is it in the News?

DPDP Act 2026 explained: Know the Digital Personal Data Protection Act’s applicability, key provisions, 2027 enforcement timeline and what the new rules mean for citizens and businesses.

Prabhav Anand 08 October 2026 12:10

DPDP Act 2026 explained: India’s Digital Personal Data Protection law, data privacy, cybersecurity and implementation timeline

DPDP Act 2026: What is India’s data protection law, who does it apply to, and when will its key provisions take effect?

Every time a person opens a bank account online, orders something through an app, signs up for a service, submits a government form or creates an account on a digital platform, personal information moves through multiple systems. Names, phone numbers, email addresses, identification details, financial information and other data can be collected, stored, analysed, shared and eventually deleted, or retained for much longer than the individual may realise.

India’s Digital Personal Data Protection Act, 2023, commonly known as the DPDP Act, is intended to establish a legal framework for how such digital personal data is processed. The law seeks to give individuals greater control over their personal data while allowing organisations and the government to process data for lawful purposes.

Advertisement

The Act received presidential assent on August 11, 2023. However, it was not designed to become fully operational immediately. The Central Government was given the power to bring different provisions into force on different dates. That phased approach is now becoming particularly important because the Digital Personal Data Protection Rules, 2025 were notified in November 2025 and the next implementation milestones fall in November 2026 and May 2027.

That is why the DPDP Act latest news is no longer simply about a law passed in 2023. It is increasingly about what the law will mean for citizens, businesses, technology companies, government agencies, children and anyone whose personal information is processed digitally.

What is the DPDP Act and what does it cover?

At its core, the Digital Personal Data Protection Act regulates the processing of digital personal data. The Act defines personal data as data about an individual who is identifiable by or in relation to that data, while digital personal data refers to personal data in digital form. The term “processing” is deliberately broad. It includes activities such as collecting, recording, organising, storing, retrieving, using, sharing, disclosing, making available, restricting, erasing and destroying digital personal data.

The law uses two important terms: Data Principal and Data Fiduciary. A Data Principal is essentially the individual to whom the personal data relates. A Data Fiduciary is the person or organisation that determines the purpose and means of processing that data. A Data Processor, meanwhile, processes personal data on behalf of a Data Fiduciary. The Act applies to the processing of digital personal data in India when the information is collected digitally, or when it is collected in non-digital form and subsequently digitised. It can also apply to processing outside India when that processing is connected with offering goods or services to individuals in India.

There are important exclusions. The Act does not apply to personal data processed by an individual for a personal or domestic purpose. It also does not apply to personal data that has been made publicly available by the individual concerned or by another person who is legally required to make it public.

This makes the question of DPDP Act applicability important. It is not a general law covering every piece of information in every format. Purely offline personal records that are never digitised fall outside its basic scope, unlike the broader scope of the European Union’s General Data Protection Regulation, or GDPR.

The basic principle is that personal data can be processed for a lawful purpose with the individual’s consent or for specified “certain legitimate uses” recognised under the Act. Consent must be free, specific, informed, unconditional and unambiguous, and must involve clear affirmative action. It should also be limited to data necessary for the specified purpose.

Importantly, consent is not necessarily permanent. Where consent is the basis for processing, a Data Principal has the right to withdraw it, and the ease of withdrawing consent should be comparable to the ease with which consent was given. Once consent is withdrawn, processing generally has to stop within a reasonable period unless another legal basis permits it.

The law also introduces the concept of Consent Managers—entities that can provide a single point through which individuals can give, manage, review and withdraw consent. The 2025 Rules provide the framework for their registration and functioning.

For individuals, the Act provides several rights. These include the right to obtain information about personal data being processed, including certain information about data shared with other Data Fiduciaries and Data Processors. Individuals can also seek correction, completion, updating and erasure of personal data, use grievance-redressal mechanisms and nominate another individual to exercise certain rights in specified circumstances.

At the same time, the DPDP framework is not identical to the GDPR. For example, the GDPR contains rights such as data portability and objection to processing, whereas the Indian framework follows a different structure and places primary accountability on the Data Fiduciary. International businesses therefore cannot simply assume that GDPR compliance automatically means DPDP compliance.

What does the DPDP Act mean for companies, government and children?

The DPDP Act places substantial responsibility on Data Fiduciaries. An organisation remains responsible for compliance even when it uses another entity, such as a technology provider or vendor, to process personal data on its behalf.

One of the central obligations is data security. The 2025 Rules provide greater operational detail, including safeguards such as encryption, masking or tokenisation, access controls, logging and monitoring, measures to maintain continuity and safeguards concerning contracts with Data Processors.

The Rules also establish a breach-notification framework. When a personal data breach occurs, affected individuals are to be informed without delay with information about the nature and extent of the breach, its likely consequences, measures being taken to mitigate risks and steps individuals can take to protect themselves. The Board is also to be informed, with further detailed information required within the prescribed period.

Another major feature concerns data retention. The Act requires Data Fiduciaries to erase personal data when the specified purpose is no longer being served, unless retention is required by law. The Rules subsequently prescribe specific retention periods for certain large digital businesses and purposes. For example, specified large e-commerce, online gaming and social-media entities have three-year retention periods for certain categories of data, subject to the conditions in the Rules.

Children receive additional protection. Under the Act, a child means a person below 18 years. Before processing a child’s personal data, a Data Fiduciary generally has to obtain verifiable parental or guardian consent. The Act also prohibits processing likely to cause detrimental effects on a child’s well-being and prohibits tracking, behavioural monitoring and targeted advertising directed at children, subject to prescribed exemptions.

The final Rules, however, recognise specific situations where certain restrictions can be relaxed. For example, educational institutions can process children’s data for educational activities or for safety-related tracking and behavioural monitoring under specified conditions. Healthcare providers can process children’s data where necessary for health services, while certain child-safety and government-service purposes also receive prescribed exemptions.

The framework also creates a category of Significant Data Fiduciaries. Organisations designated in this category face additional responsibilities, including requirements relating to Data Protection Officers, audits, impact assessments and other governance measures. This is particularly relevant to large organisations that process significant volumes or sensitive categories of digital personal data.

The enforcement mechanism is the Data Protection Board of India. The Board can inquire into breaches, issue directions and impose monetary penalties. The Act allows penalties of up to ₹250 crore for failure to take reasonable security safeguards to prevent personal data breaches, up to ₹200 crore for certain breach-notification failures, up to ₹150 crore for specified obligations concerning Significant Data Fiduciaries and up to ₹50 crore for other breaches covered by the Schedule.

The actual penalty is not automatically the maximum amount. The Board is required to consider factors including the nature, gravity and duration of the breach, the type of personal data affected, whether the breach was repeated, whether the organisation gained or avoided a loss, the steps taken to mitigate the consequences and the likely impact of the penalty.

For businesses, therefore, the DPDP Act is not simply a privacy-policy exercise. Compliance can require changes to data collection, consent mechanisms, vendor contracts, cybersecurity systems, retention policies, employee-data practices, customer interfaces and incident-response procedures.

DPDP Act 2025, 2026 and 2027: When will the law actually apply?

One of the most searched questions surrounding the framework is the DPDP Act applicability date. The answer requires a distinction between the Act and the Rules.

The law itself is the Digital Personal Data Protection Act, 2023. The government notified the Digital Personal Data Protection Rules, 2025 in November 2025. Therefore, references to “DPDP Act 2025” generally relate to the Rules and implementation developments rather than a separate 2025 Act. Similarly, “DPDP Act 2026” and “DPDP Act 2027” generally refer to the phased implementation of the 2023 Act during those years.

The government's November 2025 commencement notification divided implementation into three stages.

The first stage began with the notification itself. Certain foundational and institutional provisions, including the establishment-related provisions for the Data Protection Board, came into force in November 2025.

The second stage arrives one year after notification—November 14, 2026. This includes provisions relating to Consent Managers and certain related obligations. For organisations and digital platforms, this is the next major milestone as India moves towards operationalising the consent-management ecosystem.

The third and most significant stage arrives 18 months after notification—May 14, 2027. This covers the core operational provisions of the Act, including the principal obligations of Data Fiduciaries, individual rights, children's data protections, Significant Data Fiduciary obligations and major compliance and enforcement provisions. The Rules follow a corresponding phased timeline.

That is why DPDP Act 2027 is becoming particularly important for companies. The May 2027 date is effectively the key deadline for full operational readiness. Organisations are expected to use the transition period to map their data flows, identify why and where personal information is processed, update privacy notices, establish mechanisms for consent withdrawal and individual rights, review retention practices and strengthen breach-response procedures.

The framework also allows international transfers of personal data, although the Central Government can restrict transfers to specified countries or territories. The Rules add that organisations transferring data outside India must meet requirements that the government may specify concerning access by foreign states or entities under their control.

For anyone looking for a DPDP Act summary PDF, the most authoritative starting point is the official text of the Digital Personal Data Protection Act, 2023 published by the Ministry of Electronics and Information Technology, rather than secondary summaries. The official Act contains the definitions, applicability provisions, rights, obligations, exemptions, enforcement mechanism and penalty schedule.

For DPDP Act UPSC preparation, the framework is particularly relevant to questions around privacy, fundamental rights, digital governance, technology regulation and the relationship between individual rights and state power. The legislative background is also important: the DPDP framework followed years of debate, beginning with the Justice B.N. Srikrishna Committee’s work on data protection, the Personal Data Protection Bill, 2019 and its subsequent withdrawal before the 2023 legislation was introduced and passed.

But the DPDP debate is not limited to technology companies or privacy.

Why is the DPDP Act in the news now?

The immediate reason is implementation. With November 14, 2026 approaching and the bulk of operational obligations scheduled for May 14, 2027, organisations are moving from drafting privacy policies to preparing actual compliance systems. India Briefing has identified data mapping, consent systems, contracts, breach response, rights-management workflows and retention controls among the areas businesses need to address before the main 2027 deadline.

There is also a larger constitutional question around the law's impact on transparency.

Section 44(3) of the DPDP Act amended Section 8(1)(j) of the Right to Information Act, 2005. The amendment replaced the earlier wording of the RTI exemption with a provision covering information that relates to “personal information.”

This has triggered a significant debate over where the boundary should lie between an individual's right to privacy and a citizen's right to know how the state functions.

A September 2026 analysis published by LiveLaw highlighted the constitutional challenge to the amended RTI provision. According to the report, petitions challenging the amendment have been referred to a five-judge Constitution Bench of the Supreme Court. The central concern is whether the new formulation has narrowed the public-interest balancing mechanism that previously existed within the RTI framework.

The issue is significant because government agencies possess enormous amounts of information about citizens. At the same time, journalists, researchers and citizens often rely on the RTI Act to obtain information about public expenditure, government decisions, public servants and the functioning of institutions.

This creates a difficult legal balance: how can the state protect personal privacy without making “personal information” so broad that legitimate public scrutiny becomes harder?

The DPDP Act was framed primarily as a data-protection law, but its consequences therefore extend into questions of governance, transparency and accountability. The debate is not simply about whether companies can use a person's phone number or email address. It is also about who controls information, how long it can be retained, when it can be shared, what citizens can demand from organisations and government bodies, and where privacy ends and public interest begins.

For citizens, the DPDP framework ultimately promises a clearer set of rights over digital personal information. For businesses, it creates a new compliance architecture. For the government, it establishes new responsibilities while also providing specific exemptions and powers. And for courts and lawmakers, it raises a larger constitutional question: how should privacy, transparency, innovation and state power coexist in an increasingly data-driven India?

That question is likely to become more important as the country moves from the legislation's passage to its actual enforcement. The DPDP Act may have been enacted in 2023, but 2026 and 2027 are the years in which its practical impact will increasingly be felt.

Also Read


    advertisement