What processing is taking place?
Identify the personal data, its digital form and the activity. Section 3 of the enacted Act sets out scope and exclusions; check its commencement before relying on it.
DPDP GUIDE · OFFICIAL ACT, RULES AND NOTIFICATIONS
Start with the processing and people involved, understand the framework scope and commencement, then check the official instrument. This page is a general orientation; applicability and legal duties depend on the facts and the provision in force.
Use these as starting questions. Read the statutory text and notifications for the conditions that apply to your situation.
Identify the personal data, its digital form and the activity. Section 3 of the enacted Act sets out scope and exclusions; check its commencement before relying on it.
Use the Act definitions and actual processing facts; organisational labels alone do not settle a legal role.
Act provisions and Rules can have different commencement dates. Check each relevant provision and later official updates.
Statutory framework for processing digital personal data in India and certain processing outside India connected with offering goods or services to people in India.
Read the Act ↗Appoints commencement in immediate, one-year and eighteen-month groups for specified Act provisions.
Read the notification ↗View the Official Gazette PDF ↗Final Rules, including commencement dates for different rule groups.
Read the Rules ↗The official MeitY index lists a Rules corrigendum published 16 December 2025 and related DPDP material, including the enforcement timeline. Check this listing for later official updates.
Open MeitY listing ↗The notifications specify which provisions start on publication and which start one year or eighteen months later. The date an Act or Rule is published does not, by itself, bring every provision into force.
Act: Section 1(2), Section 2, Sections 18–26, 35, 38–43, and Section 44(1) and (3).
Rules: Rules 1, 2 and 17–21.
In force on the snapshot date.
Act: Section 6(9) and Section 27(1)(d).
Rules: Rule 4.
Not yet in force on the snapshot date. Calculated date: 13 November 2026.
Act: Sections 3–5; Section 6(1)–(8) and (10); Sections 7–17; Section 27 other than clause (d) of sub-section (1); Sections 28–34, 36, 37 and Section 44(2).
Rules: Rules 3, 5–16, 22 and 23.
Not yet in force on the snapshot date. Calculated date: 13 May 2027.
Status snapshot reviewed 23 September 2026 against the official notifications listed above. The calendar dates shown are calculations from G.S.R. 843(E), dated 13 November 2025; the notification states the later tranches relative to Official Gazette publication. Confirm the Gazette publication details, any later corrigendum and the specific provision before relying on a calculated date.
The Act concerns digital personal data. Its stated scope includes data collected in digital form and data collected offline then digitised, when processed in India. It also covers processing outside India when connected with offering goods or services to Data Principals in India. The Act sets out exclusions, including personal or domestic processing and certain data made publicly available; check Section 3 for the exact conditions.
Section 4 permits processing for a lawful purpose on the basis of consent or a specified legitimate use. Consent under the Act must meet its stated quality requirements. The Act assigns responsibilities according to the defined roles and facts of the processing; an organisation’s title or possession of data alone does not settle its role.
Sections 3–5 are in the eighteen-month commencement group and are not yet in force on this snapshot date. This describes enacted text, not a claim that those provisions are currently operative.
Section 8 places responsibility on the Data Fiduciary for processing it undertakes or has done on its behalf. Duties include reasonable security safeguards, breach response, erasure in specified circumstances and grievance handling. Under Section 8(3), where personal data is likely to be used to make a decision affecting a Data Principal or disclosed to another Data Fiduciary, reasonable efforts must be made to ensure the data is complete, accurate and consistent.
Rule 7, when in force, separates breach notices: affected Data Principals and the Board are notified without delay; updated and detailed information to the Board is due within 72 hours, unless the Board allows a longer period.
Section 8(3) addresses data completeness, accuracy and consistency in its stated circumstances. It does not create a general DPDP right to human review of every automated decision; other law, sector rules or organisational policy may call for additional safeguards.
Sections 11–14 provide rights that include access to information, correction and erasure, grievance redressal and nomination, subject to the Act’s conditions and exceptions.
The Act defines a child as an individual who has not completed 18 years. Section 9 addresses verifiable parental or guardian consent, processing likely to harm a child’s well-being, and restrictions on tracking, behavioural monitoring and targeted advertising. Section 9(5) also allows the Central Government, after a verifiably safe-processing assessment, to notify a higher age for specified Section 9(1) or 9(3) obligations. Rule 12 exemptions apply to specified Section 9(1) and 9(3) obligations, subject to conditions; they are not a general exemption from Section 9(2).
The Central Government may notify a Data Fiduciary or class as Significant Data Fiduciary. Additional duties apply to a notified entity; do not infer this status solely from industry, scale or use of AI.
Sections 8–14 are in the eighteen-month commencement group. Rule 7 and Rule 12 are also in that group. This is a summary of the enacted framework, not a claim that every described duty is operative on the snapshot date.
Section 16 gives the Central Government power to restrict transfers to a specified country or territory by notification and preserves stricter requirements under other Indian laws. Rule 15 addresses requirements for making personal data available to a foreign State or an entity under its control. Rule 13(4) provides an additional restriction for personal data and related traffic data specified for a Significant Data Fiduciary.
Section 16 and Rules 13 and 15 are in the eighteen-month commencement group and are not yet in force on this snapshot date. Check current notifications, the organisation’s status and any stricter sector-specific law; the Act does not name a fixed set of prohibited countries in its text.
DPDP is not the only source to check. Separate sector or identity-related instruments can apply depending on the service and the entity’s actual role.
The RBI direction addresses payment-system providers authorised or approved to operate payment systems in India and data relating to those systems. A financial-services or payment-technology label alone does not settle whether an entity or activity is in scope.
Read the RBI direction ↗Read RBI applicability FAQ ↗Where an activity involves Aadhaar enrolment, authentication or related services, check the current Aadhaar law and UIDAI instruments for the specific operation and role. Not every identity or customer record falls within this framework.
Review UIDAI regulations ↗These are examples, not an exhaustive list or a determination of applicability. Verify the instrument, current version, exact provision, entity role and processing facts.
ENACTED SCHEDULE · STATUS CHECKED 23 SEPTEMBER 2026
The Schedule sets the maximum monetary penalty for each listed category. These are statutory ceilings, not automatic or standard fines.
Failure to take reasonable safeguards to prevent a personal data breach.
May extend to ₹250 crore.
Failure to notify the Board or affected Data Principals of a personal data breach.
May extend to ₹200 crore.
Breach of the Act’s additional obligations in relation to children.
May extend to ₹200 crore.
Breach of the additional obligations that apply to a notified Significant Data Fiduciary.
May extend to ₹150 crore.
Breach of a Data Principal’s duties under the Act.
May extend to ₹10,000.
Breach of a term of an undertaking accepted by the Board.
Up to the penalty applicable for the breach in respect of which proceedings under Section 28 were instituted.
Breach of another provision of the Act or Rules.
May extend to ₹50 crore.
Section 33 says the Board may impose a Schedule penalty after inquiry if it determines that a breach is significant and gives the person an opportunity to be heard. It must consider factors including the breach’s nature, gravity and duration; the type and nature of data affected; repetition; gain or loss avoided; mitigation steps and their timing and effectiveness; proportionality and effectiveness in securing observance and deterring breaches; and likely impact. Sections 28–34, including Section 33, are in the eighteen-month commencement group and are not yet in force on this snapshot date. Check later official notifications before relying on this status.
A public summary cannot decide a particular organisation’s applicability or compliance. Obtain qualified legal advice where a legal determination is needed.