Regulations
What is India’s DPDP Act, and when do its requirements apply?
India’s Digital Personal Data Protection Act, 2023, establishes a framework for processing digital personal data. It addresses organisations’ responsibilities, individuals’ rights and the conditions under which personal data may be used.
The Act received presidential assent on 11 August 2023. That date did not bring every obligation into operation.
A commencement notification dated 13 November 2025 introduced a phased timetable:
Phase | Provisions covered |
|---|---|
On Gazette publication | Specified definitions, institutional and rule-making provisions. |
One year after publication | Specified Consent Manager provisions. |
Eighteen months after publication | Most substantive processing duties, individual rights and related enforcement provisions. |
The official DPDP commencement notification identifies the sections in each phase.
As of 3 October 2026, the one-year and eighteen-month periods had not elapsed. It would therefore be inaccurate to describe all DPDP obligations as already enforceable.
The framework is relevant to a data fiduciary processing digital personal data in India and, within its stated scope, businesses abroad offering goods or services to people in India. DPDP consent management should be planned against the applicable commencement dates and implementing rules.
Türkçe
English