Author: Kshama Shukla, City Academy Law College, Lucknow
To the Point
If your organisation collects, stores, or processes personal data of anyone in India whether it’s a customer’s phone number, an employee’s Aadhaar copy, or a user’s browsing history you are now operating under one of the strictest legal regimes India has ever created for privacy. The Digital Personal Data Protection Act, 2023 DPDP Act, read with the Digital Personal Data Protection Rules, 2025 DPDP Rules notified on 13 November 2025, has moved from paper to practice. Enforcement is rolling out in phases through 13 May 2027, penalties can reach up to 250 crore, and the old approach of treating a “privacy policy” as a tick-box exercise is no longer good enough. This article breaks down what the law actually requires, why it matters, and how organisations can realistically get ahead of it without drowning in jargon.
Use of Legal Jargon
1. Data Fiduciary: The entity that decides why and how personal data is processed essentially, the business or organisation in charge. Think of it as the “data owner” in a functional sense, though the individual still legally owns their own data.
2. Data Principal: The individual to whom the personal data belongs to the customer, employee, patient, or user.
3. Data Processor: A third party engaged by the Fiduciary to process data on its behalf (a cloud vendor, a payroll company, an analytics firm).
4. Significant Data Fiduciary (SDF): A category of Fiduciary designated by the government because of the volume or sensitivity of data it handles, subjecting it to heightened obligations like data protection officers and audits.
5. Consent Manager: A registered intermediary that lets individuals give, manage, and withdraw consent across multiple platforms through one interface.
6. Data Protection Board of India (DPBI): The adjudicatory body set up under the Act to handle complaints, investigate breaches, and impose penalties.
7. Personal Data Breach: Any unauthorised processing, loss, disclosure, or alteration of personal data that compromises its confidentiality, integrity, or availability.
The Proof
Legislative history: The DPDP Act received presidential assent in August 2023, following years of debate that trace back to the Supreme Court’s landmark privacy ruling. It remained largely dormant legislation on the books but without operational rules until 2025.
The turning point: On 13 November 2025, the Ministry of Electronics and Information Technology (MeitY) published the DPDP Rules, 2025 in the Official Gazette, alongside a formal Enforcement Notification and the constitution of the Data Protection Board of India. This was the moment the law stopped being theoretical.
Phased rollout: Rather than switching on the entire Act at once, the government adopted a staggered implementation across three broad milestones:
Phase I (13 November 2025 immediate effect): Provisions relating to the establishment and functioning of the Data Protection Board of India came into force right away, giving the regulator a formal existence even before most business obligations kick in.
Phase II (13 November 2026 one year from notification):This is the milestone most businesses need to prepare for now. It brings into force front-end obligations redesigned privacy notices, consent collection mechanisms, grievance redressalsystems, and the operationalisation of the Consent Manager framework, which requires registered consent managers to have a minimum net worth of roughly 20 million (about USD 225,000) and to be India-incorporated companies meeting specified technical certification standards.
Phase III (13 May 2027 full compliance deadline): By this date, the entire framework including data breach notification duties, individual rights handling, and Significant Data Fiduciary obligations such as data localisation restrictions and mandatory audits must be fully operative.
Why the delay matters practically: Legal commentators have flagged that several critical pieces including the exact criteria for designating Significant Data Fiduciaries and the scope of cross-border data transfer restrictions remain pending further government notification even as of early 2026. This means businesses are compliance-planning against a moving target, which itself is a legal risk worth taking seriously rather than dismissing as bureaucratic delay.
The financial stakes: Penalties for non-compliance are steep by Indian regulatory standards, with the ceiling set at 250 crore(roughly USD 30 million) for the most serious violations, such as failure to take reasonable security safeguards leading to a data breach. Unlike some older Indian regulatory frameworks, this isn’t a nominal fine designed to be absorbed as a cost of doing business it is structured to be a genuine deterrent.
Abstract
Data privacy in India has moved from a constitutional principle to an enforceable statutory obligation. The DPDP Act, 2023, combined with the DPDP Rules, 2025, establishes a consent-centric framework requiring organisations (Data Fiduciaries) to obtain clear, specific consent before processing personal data, to notify individuals in plain and accessible language about what data is collected and why, to report data breaches to both the regulator and affected individuals, and to allow individuals meaningful rights over their own data including access, correction, and erasure. The law applies to any entity processing digital personal data connected to India, regardless of where that entity is physically located, giving it an extraterritorial reach similar to the EU’s GDPR. Implementation is happening in three phases ending 13 May 2027, and while some provisions are already active, most operational obligations for ordinary businesses become enforceable through November 2026 and May 2027. Non-compliance can trigger penalties as high as 250 crore. For businesses, the shift in mindset required is significant: personal data can no longer be treated purely as a business asset to be exploited, but must be handled as a responsibility owed to the individual it belongs to.
Case Laws
Indian data privacy jurisprudence, while young in statutory terms, rests on a firm constitutional foundation built through judicial precedent:
Justice K.S. Puttaswamy (Retd.) v. Union of India (2017): This nine-judge Constitutional Bench decision is the bedrock of the entire DPDP framework. The Supreme Court held that the right to privacy is a fundamental right protected under Article 21 of the Constitution, intrinsic to the right to life and personal liberty. This ruling is what compelled the legislature to eventually draft comprehensive data protection legislation — the DPDP Act is, in many ways, Parliament’s statutory answer to a right the judiciary had already recognised.
Aadhaar Judgment Justice K.S. Puttaswamy (Retd.) v. Union of India (2018): In a related but distinct proceeding, the Supreme Court examined the constitutionality of the Aadhaarbiometric identification scheme. While it upheld Aadhaar’s core validity for certain government welfare purposes, it struck down provisions allowing private entities to mandatorily seek Aadhaar-based authentication, reinforcing that data minimisation and purpose limitation are constitutional expectations, not just good practice.
Shreya Singhal v. Union of India (2015): Though primarily concerned with free speech and Section 66A of the Information Technology Act, this judgment is frequently cited in Indian privacy discourse for its broader articulation of how digital rights must be balanced against state and private overreach, influencing how courts have since approached digital-era rights.
It is worth noting plainly: because the DPDP Rules only became operative in November 2025, there is not yet a substantial body of case law interpreting the Act and Rules themselves. Litigation and Data Protection Board rulings interpreting specific provisions such as what constitutes “reasonable security safeguards” or how breach notification timelines will be enforced are expected to develop through 2026 and 2027 as the phased rollout matures. Businesses and practitioners should treat the current period as one of building compliance infrastructure ahead of enforcement, rather than waiting for judicial clarity that does not yet exist.
Conclusion
The DPDP Act and its accompanying Rules mark the end of India’s long-running absence of a dedicated data protection statute a gap the Supreme Court itself had flagged as a constitutional concern back in 2017. What makes 2026 particularly important is that this is no longer a law waiting to be born; it is a law being switched on, provision by provision, with hard deadlines in November 2026 and May 2027 that carry real financial consequences. For businesses, the practical task ahead is not simply legal box-ticking it requires rebuilding consent flows, training staff on breach response, renegotiating vendor contracts to include data processing safeguards, and, for larger entities, preparing for designation as a Significant Data Fiduciary with its accompanying audit and localisation obligations. For individuals, the law finally offers a structured, enforceable mechanism to know what happens to their data and to do something about it when things go wrong. Compliance built now, while enforcement is still ramping up, will be far less painful than compliance attempted after a Data Protection Board notice arrives.
Q1: Does the DPDP Act apply to foreign companies that have no physical office in India?
Yes. The Act applies to the processing of digital personal data of individuals located in India, regardless of where the processing entity is based, provided the processing is connected with offering goods or services to individuals in India.
Q2: Is the DPDP Act fully enforceable right now?
Not entirely. As of mid-2026, only the provisions relating to the Data Protection Board’s establishment are fully in force. Most operational obligations for ordinary businesses become enforceable in phases through November 2026, with full compliance required by 13 May 2027.
Q3: What counts as a reportable data breach under the law?
Any unauthorised access, disclosure, alteration, or loss of personal data that compromises its confidentiality, integrity, or availability can trigger notification obligations to both the Data Protection Board and affected individuals, once the relevant provisions come into force.
Q4: What is a Consent Manager, and do businesses need to become one?
A Consent Manager is a registered intermediary that helps individuals manage consent across platforms. Most ordinary businesses will not need to register as one; this role is meant for specialised entities meeting specific financial and technical eligibility criteria, with registration opening around November 2026.



