India didn’t have a single dedicated law on personal data privacy, until 2023. Then came a law with fines that can reach ₹250 crore. This article covers the Digital Personal Data Protection Act, and how it’s being rolled out.
Timeline
- 11 August 2023: The Digital Personal Data Protection Act, 2023 receives Presidential assent, after passing the Lok Sabha on 7 August and the Rajya Sabha on 9 August.
- 13 November 2025: The Ministry of Electronics and IT notifies the DPDP Rules, 2025, and establishes the Data Protection Board of India.
- 13 November 2026: Rules on registering and operating “Consent Managers” take effect, one year after notification.
- 13 May 2027: Full substantive compliance and enforcement powers, including penalties, become effective.
Must Know
- The Digital Personal Data Protection Act, 2023 is India’s first standalone law on personal data privacy, receiving assent on 11 August 2023.
- It governs how a “Data Fiduciary” (an organisation that decides how personal data is processed) must handle the data of a “Data Principal” (the individual the data belongs to).
- Maximum penalties can reach ₹250 crore for failing to implement reasonable security safeguards.
- The Data Protection Board of India, a fully digital statutory body, enforces the Act and can be approached with complaints.
Good to Know
- Anyone under 18 years of age counts as a “child” under the Act. Processing a child’s data needs verifiable parental consent, under Section 9.
- Non-compliance with these children’s-data provisions specifically can draw penalties up to ₹200 crore.
- A “Consent Manager” is a new registered intermediary that lets individuals give, manage, and withdraw consent for their data across different platforms, from one place.
- The Act gives Data Principals rights to access, correct, and erase their personal data, and to nominate someone to exercise these rights after their death or incapacity.
Test Yourself
Great to Know
- The Act’s long gap between assent (2023) and full enforcement (2027) shows a deliberate regulatory pattern: give organisations years to build compliance systems, before penalties actually bite.
- Unlike the EU’s GDPR, which lists several legal grounds for processing data, India’s Act leans mainly on consent and a defined set of “legitimate uses” — a narrower, simpler framework by design.
- Government agencies get certain exemptions under the Act, for reasons like national security and legal proceedings — a provision critics say could weaken the law’s protections against the state itself.
- Because a Data Protection Board complaint process now exists, individuals get a dedicated forum for data-privacy grievances, separate from ordinary civil courts.
Leave a Reply