DPDP GUIDE · OFFICIAL ACT, RULES AND NOTIFICATIONS

A practical guide to the DPDP framework in India.

Start with the processing and people involved, understand the framework scope and commencement, then check the official instrument. This page is a general orientation; applicability and legal duties depend on the facts and the provision in force.

Three checks before drawing a conclusion

Use these as starting questions. Read the statutory text and notifications for the conditions that apply to your situation.

SCOPE

What processing is taking place?

Identify the personal data, its digital form and the activity. Section 3 of the enacted Act sets out scope and exclusions; check its commencement before relying on it.

ROLES

Who determines the purpose and means?

Use the Act definitions and actual processing facts; organisational labels alone do not settle a legal role.

COMMENCEMENT

Which provisions have started?

Act provisions and Rules can have different commencement dates. Check each relevant provision and later official updates.

Primary official materials

Commencement is phased

The notifications specify which provisions start on publication and which start one year or eighteen months later. The date an Act or Rule is published does not, by itself, bring every provision into force.

Status snapshot reviewed 23 September 2026 against the official notifications listed above. The calendar dates shown are calculations from G.S.R. 843(E), dated 13 November 2025; the notification states the later tranches relative to Official Gazette publication. Confirm the Gazette publication details, any later corrigendum and the specific provision before relying on a calculated date.

What the Act covers

The Act concerns digital personal data. Its stated scope includes data collected in digital form and data collected offline then digitised, when processed in India. It also covers processing outside India when connected with offering goods or services to Data Principals in India. The Act sets out exclusions, including personal or domestic processing and certain data made publicly available; check Section 3 for the exact conditions.

Section 4 permits processing for a lawful purpose on the basis of consent or a specified legitimate use. Consent under the Act must meet its stated quality requirements. The Act assigns responsibilities according to the defined roles and facts of the processing; an organisation’s title or possession of data alone does not settle its role.

Sections 3–5 are in the eighteen-month commencement group and are not yet in force on this snapshot date. This describes enacted text, not a claim that those provisions are currently operative.

Core responsibilities and rights in the framework

Data Fiduciary responsibilities

Section 8 places responsibility on the Data Fiduciary for processing it undertakes or has done on its behalf. Duties include reasonable security safeguards, breach response, erasure in specified circumstances and grievance handling. Under Section 8(3), where personal data is likely to be used to make a decision affecting a Data Principal or disclosed to another Data Fiduciary, reasonable efforts must be made to ensure the data is complete, accurate and consistent.

Rule 7, when in force, separates breach notices: affected Data Principals and the Board are notified without delay; updated and detailed information to the Board is due within 72 hours, unless the Board allows a longer period.

Section 8(3) addresses data completeness, accuracy and consistency in its stated circumstances. It does not create a general DPDP right to human review of every automated decision; other law, sector rules or organisational policy may call for additional safeguards.

Data Principal rights

Sections 11–14 provide rights that include access to information, correction and erasure, grievance redressal and nomination, subject to the Act’s conditions and exceptions.

Children’s personal data

The Act defines a child as an individual who has not completed 18 years. Section 9 addresses verifiable parental or guardian consent, processing likely to harm a child’s well-being, and restrictions on tracking, behavioural monitoring and targeted advertising. Section 9(5) also allows the Central Government, after a verifiably safe-processing assessment, to notify a higher age for specified Section 9(1) or 9(3) obligations. Rule 12 exemptions apply to specified Section 9(1) and 9(3) obligations, subject to conditions; they are not a general exemption from Section 9(2).

Significant Data Fiduciaries

The Central Government may notify a Data Fiduciary or class as Significant Data Fiduciary. Additional duties apply to a notified entity; do not infer this status solely from industry, scale or use of AI.

Sections 8–14 are in the eighteen-month commencement group. Rule 7 and Rule 12 are also in that group. This is a summary of the enacted framework, not a claim that every described duty is operative on the snapshot date.

Cross-border rules have separate conditions

Section 16 gives the Central Government power to restrict transfers to a specified country or territory by notification and preserves stricter requirements under other Indian laws. Rule 15 addresses requirements for making personal data available to a foreign State or an entity under its control. Rule 13(4) provides an additional restriction for personal data and related traffic data specified for a Significant Data Fiduciary.

Section 16 and Rules 13 and 15 are in the eighteen-month commencement group and are not yet in force on this snapshot date. Check current notifications, the organisation’s status and any stricter sector-specific law; the Act does not name a fixed set of prohibited countries in its text.

Other official frameworks may apply

DPDP is not the only source to check. Separate sector or identity-related instruments can apply depending on the service and the entity’s actual role.

These are examples, not an exhaustive list or a determination of applicability. Verify the instrument, current version, exact provision, entity role and processing facts.

ENACTED SCHEDULE · STATUS CHECKED 23 SEPTEMBER 2026

Penalty ceilings in the Act

The Schedule sets the maximum monetary penalty for each listed category. These are statutory ceilings, not automatic or standard fines.

Section 33 says the Board may impose a Schedule penalty after inquiry if it determines that a breach is significant and gives the person an opportunity to be heard. It must consider factors including the breach’s nature, gravity and duration; the type and nature of data affected; repetition; gain or loss avoided; mitigation steps and their timing and effectiveness; proportionality and effectiveness in securing observance and deterring breaches; and likely impact. Sections 28–34, including Section 33, are in the eighteen-month commencement group and are not yet in force on this snapshot date. Check later official notifications before relying on this status.

Read Section 33 and the Schedule in the official Act ↗

How to use this page

  • Check the relevant Act section and Rule, then verify its commencement date.
  • Read the conditions, exemptions, definitions and schedules that apply to that provision.
  • Check later official notifications, corrigenda and any other law relevant to the processing.
  • Assess the organisation’s actual roles, purposes, data and processing facts before reaching a conclusion.

A public summary cannot decide a particular organisation’s applicability or compliance. Obtain qualified legal advice where a legal determination is needed.