The framework
The DPDP Act passed in August 2023 but sat dormant until the Ministry of Electronics and IT notified the DPDP Rules, 2025 on 13 November 2025, starting a three-phase clock. Phase one, immediate, brought in the provisions that establish the Data Protection Board of India, which the government has been setting up since. Phase two, 13 November 2026, activates the consent-manager provisions and the Board's power over consent managers. Phase three, 13 May 2027, brings everything else: notice and consent standards, data principal rights, security safeguards, breach reporting, retention limits, children's data rules, cross-border conditions, and the Board's general enforcement powers and penalties.
The design is consent-plus-narrow-exceptions. 'Legitimate uses' cover things like voluntary provision, state functions and emergencies and exclude marketing, so commercial processing of Indians' digital personal data will need clear, itemized, withdrawable consent delivered with a plain-language notice. Verifiable parental consent is required for children under 18, and tracking or behavioral monitoring of children and targeted advertising directed at them are prohibited. Significant Data Fiduciaries, designated by the government, take on DPO, audit and impact assessment duties.
Cross-border transfers have no adequacy regime. Transfers are allowed to any country the government has not blacklisted, and no blacklist has been notified. Sectoral localization (notably RBI rules for payments data) continues to apply on top.
Key instruments
Digital Personal Data Protection Act, 2023
India's first comprehensive privacy statute: consent-centric processing of digital personal data, data principal rights, Data Protection Board, penalties to INR 250 crore per breach category.
Digital Personal Data Protection Rules, 2025
Operational rules: notice format, consent managers, breach notification, security safeguards, children's data verification, Significant Data Fiduciary duties, Board procedures.
Marketing and advertising
Consent or narrow 'legitimate uses' (which do not include marketing). Notice-backed, itemized consent is the default for commercial processing. Most channel decisions here follow from that consent rule.
For growth teams, unconsented lead-list marketing to Indian consumers has a hard end date of 13 May 2027, when the duties and the penalties arrive together. Consent will need to be purpose-itemized and as easy to withdraw as to give, likely mediated by registered consent managers at scale. Children's targeting is off the table.
Cross-border transfers
Permitted to all countries except those on a government blacklist (none yet notified); sectoral rules can be stricter.
Enforcement and penalties
Up to INR 250 crore (about USD 30M) per category of breach, stackable, enforceable from 13 May 2027.