Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 23 September 2026. Methodology

Know exactly what India's DPDP Act 2023 and DPDP Rules 2025 require of you.

The official Gazette text of all 44 sections, 23 rules and 7 Schedules, their commencement status, 11 deterministic tools, downloadable templates and plain English guides, with every claim cited to the official source. No account, no tracking, no legal jargon.

What is the DPDP Act 2023?

Plain English

The Digital Personal Data Protection Act 2023 (Act No. 22 of 2023) is India's law on processing digital personal data. Enacted on 11 August 2023, it applies to processing within India and to some processing abroad, and is coming into force in phases. The DPDP Rules 2025, published on 13 November 2025, set out how it operates.

Start with the full text of all 44 sections, the glossary of defined terms or the plain English explainer What is the DPDP Act?

Is the DPDP Act in force today?

Partly. Notification G.S.R. 843(E) brings the Act into force in three groups: 17 of 44 sections are in force today, 25 commence later and 2 are partly in force.

  • 13 November 2025· officialSections 1(2) and 2, sections 18 to 26, sections 35 and 38 to 43, and section 44(1) and (3) of the Act
  • 13 November 2026· computed date, interpretation until officially confirmedSection 6(9) and section 27(1)(d) of the Act
  • 13 May 2027· computed date, interpretation until officially confirmedSections 3 to 5, section 6(1) to (8) and (10), sections 7 to 17, section 27 other than section 27(1)(d), sections 28 to 34, sections 36 and 37, and section 44(2) of the Act

Every section with its status · The full verified timeline

Everything on this site

Read the full official text

The DPDP Act 2023, chapter by chapter

All 44 sections with verified text →

11 deterministic DPDP compliance tools

How results are decided

Start where you stand

For individuals

Understand the rights the Act gives you over your personal data and the channels every Data Fiduciary must offer.

DPDP questions, answered directly

All questions with sources

What is DPDP and what is its full form?

DPDP stands for Digital Personal Data Protection. The Digital Personal Data Protection Act 2023, Act No. 22 of 2023, is India's law for processing digital personal data; it received the President's assent on 11 August 2023 and recognises both the individual's right to protect personal data and the need to process it for lawful purposes. The DPDP Rules 2025, notified on 13 November 2025, operationalise the Act. Both commence in phases: some provisions have been in force since 13 November 2025, Consent Manager registration is due on a computed date of 13 November 2026, and the main obligations are due on a computed date of 13 May 2027, both interpretation until officially confirmed. Once section 3 is in force with the main obligations, the law applies to digital personal data processed in India, and to processing abroad in connection with any activity related to offering goods or services to people in India, but not to personal or domestic processing or to data made publicly available by the individual or under a legal duty (section 3(c)).

Full answer with sources →

What is in force under the DPDP framework in 2026?

The DPDP Act 2023 was enacted on 11 August 2023 and its commencement was notified as G.S.R. 843(E) on 13 November 2025: the definitions, the sections establishing and constituting the Data Protection Board (sections 18 to 26) and certain other sections, including the rule making power, operate now, while the main obligations, the rights and the Board's inquiry and penalty powers follow 18 months after publication. The DPDP Rules 2025 were notified the same day, and Rules 1, 2 and 17 to 21 took effect at once. The main operational obligations in Rules 3, 5 to 16, 22 and 23 and the core Act sections follow 18 months after publication, which computes to 13 May 2027, and Rule 4 on Consent Manager registration and obligations, and sections 6(9) and 27(1)(d) of the Act, follow 1 year after publication, which computes to 13 November 2026. The computed dates are interpretation until officially confirmed.

Full answer with sources →

What are the penalties under the DPDP Act 2023?

Once section 33 is in force, the Data Protection Board may impose a monetary penalty specified in the Act's Schedule if, on concluding an inquiry, it determines a breach of the Act or Rules is significant, after giving the person an opportunity of being heard. Each figure is a maximum: 250 crore rupees for breach of the section 8(5) obligation to take reasonable security safeguards to prevent personal data breach; 200 crore rupees each for the section 8(6) obligation to give the Board or affected Data Principal notice of a personal data breach and for the additional obligations in relation to children under section 9; 150 crore rupees for the additional obligations of a Significant Data Fiduciary under section 10; 10,000 rupees for the duties under section 15; 50 crore rupees for any other provision of the Act or Rules; and, for breach of any term of a voluntary undertaking accepted under section 32, up to the extent applicable for the breach in respect of which the section 28 proceedings were instituted. Sections 8 to 10, 15 and 28 to 34 are in the 18 month group of G.S.R. 843(E), computed at 13 May 2027, interpretation until officially confirmed; the Schedule commencing with section 33 is our reading. As at 2 October 2026 no penalty can be imposed, because section 33 has not commenced; separately, MeitY's document library held no Board appointment that day, a MeitY circular of 6 May 2026 had invited applications, and the eGazette was not checked.

Full answer with sources →

Does the DPDP Act apply to companies outside India?

Yes, once it commences. Section 3(a) covers processing of digital personal data within India and section 3(b) processing outside India in connection with any activity related to offering of goods or services to Data Principals within India; on this site's reading, offshore the test is what is offered to people in India, not merely having Indian users. Section 3 commences 18 months after publication of G.S.R. 843(E), computed as 13 May 2027, interpretation until officially confirmed. On this site's reading the Act sets no general local presence duty: representative, subsidiary and branch each appear 0 times in it. The India specific exceptions are narrow: once section 10 commences, a notified Significant Data Fiduciary must appoint a Data Protection Officer based in India, and once Rule 4 commences on the computed date of 13 November 2026, interpretation until officially confirmed, an applicant to register as a Consent Manager must be a company incorporated in India. Section 8(9) will require published contact details of a person able to answer questions, not that the person be in India. On this site's reading, the lever against a company with no Indian assets is section 37, in the same group: once in force, on a Board reference intimating monetary penalty in 2 or more instances and advising blocking in the public interest, and after a hearing, the Central Government may order blocking of public access to information in any computer resource enabling it to offer goods or services in India.

Full answer with sources →

Does the DPDP Act apply to startups?

On the text, yes, and no size test stands between a startup and the Act. Section 3 and every provision cited below commence on the computed date of 13 May 2027, interpretation until officially confirmed, so none is in force yet. Section 3 will reach processing within India and offshore processing in connection with any activity related to offering goods or services to Data Principals in India. Its exclusions, for personal or domestic purposes of an individual and for data made public by the Data Principal or under a legal duty, never turn on size. Turnover, revenue, headcount, small, micro, MSME and threshold appear 0 times in the Act and the English Rules. Size can still matter: the Third Schedule attaches the Rule 8(1) erasure timer to 3 classes of e commerce, online gaming and social media platforms defined by registered user thresholds in India, section 10(1)(a) makes volume and sensitivity of personal data 1 of an open list of Significant Data Fiduciary factors, and section 33(2)(g) makes a penalty's likely impact on the person a matter the Board weighs. Falling outside the Third Schedule is not relief: the section 8(7) erasure duty remains, and this site reads the Rule 8(3) minimum of 1 year as reaching a Data Fiduciary of any size. Section 17(3) names startups, but only as a power to notify relief from 5 provisions, and no such notification had been located as at 27 August 2026.

Full answer with sources →

Is the data breach reporting deadline in India 72 hours or 6 hours?

Both, because they are 2 separate legal regimes with different recipients. Under Rule 7 of the DPDP Rules 2025, once it is in force, a Data Fiduciary must intimate each affected Data Principal and send the Data Protection Board a description of the breach without delay, then file detailed information with the Board within 72 hours of becoming aware, or any longer period the Board allows on a written request. Separately, under the CERT In directions of 28 April 2022 issued under the IT Act, service providers, intermediaries, data centres, body corporates and government organisations must report cyber incidents listed in Annexure I, which includes data breach and data leak, to CERT In within 6 hours of noticing them. The DPDP duty is in the commencement group computed to 13 May 2027, interpretation until officially confirmed; the CERT In duty is already in effect: the directions took effect 60 days after issue, and on 25 September 2022 for MSMEs.

Full answer with sources →

Latest analysis and guides

All articles

Penalties

Jan Vishwas Act 2023: what it changed in the IT Act, and what it left alone

On the Gazette prints on file, read as at 6 September 2026. Entry 32 of the Jan Vishwas Act 2023 Schedule amended 11 provisions of the Information Technology Act, 2000 through 11 lettered limbs, multiplied all 3 section 44 penalties by 10, replaced imprisonment with a penalty in 5 provisions, and did not touch section 43A.

Current status

SPDI Rules 2011: still in force, and what the DPDP Act does to them

On the Gazette prints on file, read as at 6 September 2026, the Information Technology SPDI Rules 2011 still bind a body corporate. Rule 3 is where sensitive personal data is defined in Indian law, and section 44(2) of the DPDP Act, which directs the omission of section 43A, has not commenced.

Who runs this site and why you can trust it

Every claim is cited

Each legal statement links to the official source it comes from: the Gazette of India, India Code or MeitY, and EUR Lex for GDPR comparisons, with the page number where the source is a fixed document and the date we last verified it.

Results are decided by rules, not vibes

Tool answers come from a published rulebook. Every result shows the rule IDs and facts that produced it. Same inputs, same answer, every time.

Your data stays with you

Assessments run in your browser and are stored only on your device. No account, no analytics on your answers, one click to erase.

Edited and accountable

Edited by Abhijeet Singh. Sources last verified on 23 September 2026. All 8 official corrigendum corrections to the Rules are shown against the original text, and anything wrong here is a report away from being fixed. Status last checked 2 October 2026 against the MeitY library and India Code.