India's DPDP Act: What Actually Changes for You, and When
Here is the single most useful thing to know about India’s data protection law: it exists, it is real, and almost none of it applies yet. Your new privacy rights — consent notices, the right to delete your data, penalties on companies — switch on for users on 13 May 2027, not today. Think of the DPDP Act as software that has been installed but not yet turned on, with the switch-on dates now published in the official Rules (Gazette notification).
The three dates that matter
The whole law comes down to a simple timeline:
- August 2023 — Parliament passed the DPDP Act (full text, MeitY). Then: two years of silence, because a law like this only works once its detailed Rules exist.
- 13 November 2025 — the Rules were notified. Only the plumbing went live: definitions, the legal existence of the Data Protection Board, and a small RTI change (Bar & Bench).
- 13 November 2026 — “consent managers” (apps that manage your permissions in one place) can start registering.
- 13 May 2027 — everything you will actually feel: consent notices, deletion rights, breach alerts, children’s-data rules, and fines.
Simple test for any DPDP headline you read: if it says a company was “fined under DPDP” before May 2027, it’s wrong. An independent tracker counts exactly zero DPDP enforcement actions through June 2026 (Kensara tracker).
What you get from 13 May 2027
Once the switch flips, apps that handle your personal data must:
- Ask properly. Consent requests must be standalone and in plain language — and you can ask to read the notice in any of the 22 scheduled Indian languages. (Your choice per notice; apps don’t have to publish all 22 up front — a detail many summaries get wrong.)
- Let go. You get the right to see, correct, and delete your data, with responses due within 90 days at the outside.
- Tell you when things go wrong. Companies must notify you of data breaches.
- Protect kids properly. “Child” means under 18, and consent must be verifiably parental — a real identity check, not a checkbox.
- Name someone you trust. A “nominee” can exercise your data rights if you die or lose capacity — a genuinely original Indian feature with no GDPR equivalent.
Break the rules and the fines are serious: ₹250 crore per instance for weak security, ₹200 crore for hiding a breach or misusing children’s data, ₹150 crore for big platforms failing their extra duties (Cyril Amarchand Mangaldas FAQ). One myth to drop: the ₹500-crore figure you’ll see online comes from a 2022 draft that was scrapped.
What the law does NOT do
Three things people assume, wrongly:
- It does not keep your data in India. Companies can send data abroad by default. The government can blacklist countries — but the blacklist is empty so far.
- It does not treat sensitive data specially. Your health records and your pizza orders sit in the same legal category. GDPR would treat them very differently.
- It does not fully bind the government. State agencies get broad exemptions for security and public order — the most controversial part of the law.
What to watch: the court case and the AI question
Two live threads could reshape all of this. First, the Supreme Court is hearing consolidated challenges to the government exemptions and the RTI change — notice was issued on 16 February 2026, and the bench has made “what is public data versus personal data” a central question. No ruling yet as of late July 2026 (LiveLaw).
Second, the AI gray zone. The Act excludes data you’ve “made publicly available” — which AI companies read as permission to train on public posts. But MeitY has told Parliament the opposite, and the question is also being fought on copyright grounds, as we covered in the ANI v. OpenAI ruling. Honest answer: unsettled. And one practical wrinkle: the Data Protection Board — the body you’ll complain to — was still hiring its chairperson as of 6 May 2026 (MeitY notice).
What you can do today (without waiting for 2027)
Your current toolkit comes from older laws, and it works:
- Use the grievance officer. Every significant app must have one under the IT Rules 2021 — 24 hours to acknowledge, 15 days to resolve. It’s usually buried in the app’s privacy or help pages.
- Know the breach rule. Companies must already report breaches to CERT-In within six hours — stricter than DPDP’s future rule.
- Escalate the old-fashioned ways. Consumer courts hear data-mishandling claims; High Courts have accepted petitions while the Board doesn’t function (Future of Privacy Forum).
- Fix the settings you control now. Start with your AI apps — our guide to what chatbots keep about you shows the exact toggles.
Mark 13 May 2027 in your calendar. Until then, treat every “DPDP is here” headline as marketing. For more plainly-dated guides like this one, browse our how-to and explainers hub.
Frequently asked questions
Is the DPDP Act actually in force right now?
Only partially. The Act was passed in August 2023 and the Rules were notified on 13 November 2025, but as of July 2026 only the machinery provisions are live. Consent notices, erasure rights, children's-data rules and penalties all start on 13 May 2027.
Can I force an app to delete my data today under DPDP?
Not yet as a DPDP right — erasure becomes binding on 13 May 2027. Until then, use the app's grievance officer under the IT Rules 2021, which requires acknowledgment within 24 hours and resolution within 15 days, or consumer-court remedies.
Does the DPDP Act force companies to keep Indian data in India?
No. Transfers are allowed to any country by default; the government may notify a blacklist of restricted destinations, and as of mid-2026 that list is empty. This is the opposite of GDPR's restrictive-by-default approach to transfers.
How big are DPDP fines, really?
The Schedule's ceilings run from fifty crore to two hundred and fifty crore rupees per instance depending on the violation — security-safeguard failures at the top, breach non-notification and children's-data violations next, then significant-fiduciary failures. The five-hundred-crore figure that circulates online comes from a withdrawn 2022 draft, not the enacted law.
Sources & further reading
- DPDP Act, 2023 — full text (MeitY) (primary source)
- DPDP Rules, 2025 notified — PIB / Gazette G.S.R. 846(E) (primary source)
- MeitY recruitment notice for Data Protection Board chairperson and members (6 May 2026) (primary source)
- DPDP Rules phased commencement analysis — Bar & Bench
- FAQs on the DPDP Act — Cyril Amarchand Mangaldas
- Supreme Court hearings on DPDP/RTI challenge — LiveLaw coverage
- DPDPA enforcement tracker (0 actions through June 2026)
- The DPDP Act of India, explained — Future of Privacy Forum
More of today, in 60 seconds: Today's Docket →