DIGITAL PRIVACY REGULATIONSThe Worldwide Register of Data Privacy Law
Tracking 197 jurisdictions
Language: English
Asia-Pacific · Adopted · Opt-in

🇮🇳 India Data Privacy Laws

India's DPDP Act began its phased start on 13 November 2025, when the DPDP Rules were notified and the provisions establishing the Data Protection Board took effect. Consent-manager provisions follow on 13 November 2026, and the substantive duties, together with the Board's enforcement powers and penalties, apply from 13 May 2027.

Updated September 28, 2026 · digitalprivacyregs.com
Status
Adopted
Consent model
Opt-in
Primary law
Digital Personal Data Protection Act, 2023 + DPDP Rules, 2025
Year
2023
Authority
Data Protection Board of India (legally established November 2025; being set up)
Marketing consent
Consent or narrow 'legitimate uses' (which do not include marketing). Notice-backed, itemized consent is the default for commercial processing.
Transfers
Permitted to all countries except those on a government blacklist (none yet notified); sectoral rules can be stricter.
Penalties
Up to INR 250 crore (about USD 30M) per category of breach, stackable, enforceable from 13 May 2027.

The framework

The DPDP Act passed in August 2023 but sat dormant until the Ministry of Electronics and IT notified the DPDP Rules, 2025 on 13 November 2025, starting a three-phase clock. Phase one, immediate, brought in the provisions that establish the Data Protection Board of India, which the government has been setting up since. Phase two, 13 November 2026, activates the consent-manager provisions and the Board's power over consent managers. Phase three, 13 May 2027, brings everything else: notice and consent standards, data principal rights, security safeguards, breach reporting, retention limits, children's data rules, cross-border conditions, and the Board's general enforcement powers and penalties.

The design is consent-plus-narrow-exceptions. 'Legitimate uses' cover things like voluntary provision, state functions and emergencies and exclude marketing, so commercial processing of Indians' digital personal data will need clear, itemized, withdrawable consent delivered with a plain-language notice. Verifiable parental consent is required for children under 18, and tracking or behavioral monitoring of children and targeted advertising directed at them are prohibited. Significant Data Fiduciaries, designated by the government, take on DPO, audit and impact assessment duties.

Cross-border transfers have no adequacy regime. Transfers are allowed to any country the government has not blacklisted, and no blacklist has been notified. Sectoral localization (notably RBI rules for payments data) continues to apply on top.

Key instruments

Digital Personal Data Protection Act, 2023

2023 · Adopted; phased commencement from 13 Nov 2025

India's first comprehensive privacy statute: consent-centric processing of digital personal data, data principal rights, Data Protection Board, penalties to INR 250 crore per breach category.

Official source →

Digital Personal Data Protection Rules, 2025

2025 · Notified 13 Nov 2025; phases to 13 May 2027

Operational rules: notice format, consent managers, breach notification, security safeguards, children's data verification, Significant Data Fiduciary duties, Board procedures.

Official source →

Marketing and advertising

Consent or narrow 'legitimate uses' (which do not include marketing). Notice-backed, itemized consent is the default for commercial processing. Most channel decisions here follow from that consent rule.

For growth teams, unconsented lead-list marketing to Indian consumers has a hard end date of 13 May 2027, when the duties and the penalties arrive together. Consent will need to be purpose-itemized and as easy to withdraw as to give, likely mediated by registered consent managers at scale. Children's targeting is off the table.

Cross-border transfers

Permitted to all countries except those on a government blacklist (none yet notified); sectoral rules can be stricter.

Enforcement and penalties

Up to INR 250 crore (about USD 30M) per category of breach, stackable, enforceable from 13 May 2027.

Primary sources

Cite this page: "India Data Privacy Laws." Digital Privacy Regulations, September 28, 2026, https://digitalprivacyregs.com/india.html. Accessed [date].