Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 23 September 2026. Methodology

Know exactly what India's DPDP Act 2023 and DPDP Rules 2025 require of you.

The official Gazette text of all 44 sections, 23 rules and 7 Schedules, their commencement status, 11 deterministic tools, downloadable templates and plain English guides, with every claim cited to the official source. No account, no tracking, no legal jargon.

What is the DPDP Act 2023?

Plain English

The Digital Personal Data Protection Act 2023 (Act No. 22 of 2023) is India's law on processing digital personal data. Enacted on 11 August 2023, it applies to processing within India and to some processing abroad, and is coming into force in phases. The DPDP Rules 2025, published on 13 November 2025, set out how it operates.

Start with the full text of all 44 sections, the glossary of defined terms or the plain English explainer What is the DPDP Act?

Is the DPDP Act in force today?

Partly. Notification G.S.R. 843(E) brings the Act into force in three groups: 17 of 44 sections are in force today, 25 commence later and 2 are partly in force.

  • 13 November 2025· officialSections 1(2) and 2, sections 18 to 26, sections 35 and 38 to 43, and section 44(1) and (3) of the Act
  • 13 November 2026· computed date, interpretation until officially confirmedSection 6(9) and section 27(1)(d) of the Act
  • 13 May 2027· computed date, interpretation until officially confirmedSections 3 to 5, section 6(1) to (8) and (10), sections 7 to 17, section 27 other than section 27(1)(d), sections 28 to 34, sections 36 and 37, and section 44(2) of the Act

Every section with its status · The full verified timeline

Everything on this site

Read the full official text

The DPDP Act 2023, chapter by chapter

All 44 sections with verified text →

11 deterministic DPDP compliance tools

How results are decided

Start where you stand

For individuals

Understand the rights the Act gives you over your personal data and the channels every Data Fiduciary must offer.

DPDP questions, answered directly

All questions with sources

What is DPDP and what is its full form?

DPDP stands for Digital Personal Data Protection. The Digital Personal Data Protection Act 2023, Act No. 22 of 2023, is India's law for processing digital personal data; it received the President's assent on 11 August 2023 and recognises both the individual's right to protect personal data and the need to process it for lawful purposes. The DPDP Rules 2025, notified on 13 November 2025, operationalise the Act. Both commence in phases: some provisions have been in force since 13 November 2025, Consent Manager registration is due on a computed date of 13 November 2026, and the main obligations are due on a computed date of 13 May 2027, both interpretation until officially confirmed. The law applies to digital personal data processed in India, and to processing abroad connected with offering goods or services to people in India.

Full answer with sources →

What is in force under the DPDP framework in 2026?

The DPDP Act 2023 was enacted on 11 August 2023 and its commencement was notified as G.S.R. 843(E) on 13 November 2025: the definitions and the Data Protection Board provisions operate now, while the main obligations and rights follow 18 months after publication. The DPDP Rules 2025 were notified the same day, and Rules 1, 2 and 17 to 21 took effect at once. The main operational obligations in Rules 3, 5 to 16, 22 and 23 and the core Act sections follow 18 months after publication, which computes to 13 May 2027, and the Consent Manager provisions follow 1 year after publication, which computes to 13 November 2026. The computed dates are interpretation until officially confirmed.

Full answer with sources →

What are the penalties under the DPDP Act 2023?

Penalties under the DPDP Act 2023 are monetary, imposed by the Data Protection Board after an inquiry, and capped by the Act's Schedule. The highest cap is 250 crore rupees for a Data Fiduciary failing its reasonable security safeguards obligation under section 8(5). Failing to notify a breach or breaching children's data obligations may each draw up to 200 crore rupees, Significant Data Fiduciary obligations up to 150 crore rupees, any other breach up to 50 crore rupees, and a Data Principal breaching statutory duties up to 10,000 rupees. These provisions sit in the commencement group due 18 months from the notification gazette, which computes to 13 May 2027; that calendar date is interpretation until officially confirmed. No penalty can be imposed on anybody today, for 2 independent reasons: section 33 has not commenced, and no Chairperson or Member of the Board has been appointed on the record.

Full answer with sources →

Does the DPDP Act apply to companies outside India?

Yes, once it commences. Section 3(b) applies the Act to processing of digital personal data outside India where that processing is in connection with any activity related to offering of goods or services to Data Principals within India, so a foreign company with Indian users is reached on the same test as an Indian one. 2 things almost every guide leaves out. First, section 3 is itself in the group commencing 18 months after publication of notification G.S.R. 843(E), computed as 13 May 2027 and interpretation until officially confirmed, so the provision that decides application is not in force today. Second, the Act creates no local presence duty at all: representative, subsidiary and branch office each appear 0 times in it, so there is nothing to register and, unless the Central Government notifies you as a Significant Data Fiduciary under section 10(1), nobody to appoint. The route against a company with no Indian assets is section 37, which lets the Central Government order blocking of public access to information in any computer resource that enables the company to carry on an activity relating to offering goods or services to Data Principals in India, but only on a reference from the Board after monetary penalty in 2 or more instances, and section 37 sits in the same 18 month group.

Full answer with sources →

Does the DPDP Act apply to startups?

On the text, yes, and no size test stands between a startup and the Act. Section 3 applies the Act to the processing of digital personal data within India, and to processing outside India in connection with any activity related to offering goods or services to Data Principals in India, and its only exclusions turn on the kind of processing or on who published the data, never on the size of the organisation. The words turnover, revenue, headcount, small, micro, MSME and threshold appear 0 times in the Act and 0 times in the Rules. Size still decides which duties bite, in 3 places: the Third Schedule attaches the Rule 8(1) erasure timer to 3 classes defined by registered user counts, section 10(1)(a) makes the volume and sensitivity of personal data 1 of the factors behind a Significant Data Fiduciary notification, and section 33(2)(g) makes the likely impact of a penalty on the person a matter the Board weighs. Sitting below the Third Schedule counts is not relief: you keep the section 8(7) purpose test, and this site reads the Rule 8(3) minimum of 1 year as reaching a Data Fiduciary of any size. Section 17(3) names startups, but it is a power to switch off 5 provisions and no notification under it has been located. Section 3 commences 18 months after publication, computed as 13 May 2027, which is interpretation until officially confirmed.

Full answer with sources →

Is the data breach reporting deadline in India 72 hours or 6 hours?

Both, because they are 2 separate legal regimes with different recipients. Under Rule 7 of the DPDP Rules 2025, a Data Fiduciary must intimate each affected Data Principal and send the Data Protection Board a description of the breach without delay, then file detailed information with the Board within 72 hours of becoming aware. Separately, under the CERT In directions of 28 April 2022 issued under the IT Act, service providers, intermediaries, data centres, body corporates and government organisations must report cyber incidents listed in Annexure I, which includes data breach and data leak, to CERT In within 6 hours of noticing them. The DPDP duty is in the commencement group computed to 13 May 2027, interpretation until confirmed; the CERT In duty is already in effect.

Full answer with sources →

Latest analysis and guides

All articles

Penalties

Jan Vishwas Act 2023: what it changed in the IT Act, and what it left alone

On the Gazette prints on file, read as at 6 September 2026. Entry 32 of the Jan Vishwas Act 2023 Schedule amended 11 provisions of the Information Technology Act, 2000 through 11 lettered limbs, multiplied all 3 section 44 penalties by 10, replaced imprisonment with a penalty in 5 provisions, and did not touch section 43A.

Current status

SPDI Rules 2011: still in force, and what the DPDP Act does to them

On the Gazette prints on file, read as at 6 September 2026, the Information Technology SPDI Rules 2011 still bind a body corporate. Rule 3 is where sensitive personal data is defined in Indian law, and section 44(2) of the DPDP Act, which directs the omission of section 43A, has not commenced.

Who runs this site and why you can trust it

Every claim is cited

Each legal statement links to the official source it comes from: the Gazette of India, India Code or MeitY, and EUR Lex for GDPR comparisons, with the page number where the source is a fixed document and the date we last verified it.

Results are decided by rules, not vibes

Tool answers come from a published rulebook. Every result shows the rule IDs and facts that produced it. Same inputs, same answer, every time.

Your data stays with you

Assessments run in your browser and are stored only on your device. No account, no analytics on your answers, one click to erase.

Edited and accountable

Edited by Abhijeet Singh. Sources last verified on 23 September 2026. All 8 official corrigendum corrections to the Rules are shown against the original text, and anything wrong here is a report away from being fixed. Status last checked 26 September 2026 against the MeitY library and India Code.