Skip to main content

Sources last verified on 17 August 2026. Methodology

Reference

How India got its data protection law

Every milestone below is verified against a primary official source before it publishes. Computed future dates are marked as such and treated as interpretation until officially confirmed.

Last verified on 17 August 2026

The Act

  1. Act

    The Digital Personal Data Protection Act 2023 is enacted

    India's law for digital personal data becomes Act No. 22 of 2023. It recognises both the right of individuals to protect their personal data and the need to process personal data for lawful purposes.

    Why it matters: The Act is the parent framework: it defines Data Fiduciaries, Data Principals and their rights and duties, and it empowers the Central Government to make rules operationalising it.

    Status: enacted; provisions commence as notified

The Rules

  1. Draft

    Draft DPDP Rules published for public consultation

    The Government publishes draft rules under section 40 of the Act as G.S.R. 02(E) and invites objections and suggestions from the public through the MyGov platform, for consideration after 18 February 2025.

    Why it matters: The consultation round required before the final Rules could be made. The final Rules record that these comments were considered.

    Status: superseded by the final Rules

  2. Notification

    Act commencement notified in three phases

    Notification G.S.R. 843(E) appoints commencement dates for the Act in three groups: the definitions, the Data Protection Board provisions and related machinery from the date of publication; the Consent Manager registration provisions one year later; and the main obligations and rights eighteen months later.

    Why it matters: This is the notification under section 1(2) that actually brings the Act into force. Until commencement was notified, the Act's provisions did not operate.

    Status: in effect; the later phases are due one year and eighteen months from publication

  3. Notification

    Data Protection Board of India established

    Notification G.S.R. 844(E) establishes the Data Protection Board of India under section 18, with its head office in the National Capital Region of India. A companion notification, G.S.R. 845(E), fixes the Board at four members under section 19(1).

    Why it matters: The Board is the body that will receive breach intimations, hear complaints and impose penalties once the corresponding provisions operate.

    Status: in effect

  4. Implementation

    First provisions of the Act come into force

    Sections 1(2) and 2, sections 18 to 26, sections 35 and 38 to 43, and section 44(1) and (3) of the Act take effect on the date of publication of the commencement notification. These cover the definitions, the Data Protection Board and its machinery, rule making powers, and amendments to two other laws.

    Why it matters: The Act moves from enacted to partially operating. The obligations of Data Fiduciaries and the rights of Data Principals follow in the later phases.

    Status: in force

  5. Rule

    The DPDP Rules 2025 are notified

    The final Digital Personal Data Protection Rules 2025 are notified as G.S.R. 846(E) in Gazette of India Extraordinary issue No. 760, after considering the public comments on the draft.

    Why it matters: The Rules operationalise the Act: notices, consent managers, security safeguards, breach intimation, retention and erasure, children's data, and the Data Protection Board's functioning.

    Status: published; text subject to corrigenda G.S.R. 892(E)

  6. Implementation

    Rules 1, 2 and 17 to 21 come into force

    On the day of publication, the definitions and the provisions relating to the Data Protection Board start to operate. The obligations with operational lead time follow later.

    Why it matters: The first slice of the Rules to take legal effect, per Rule 1(2).

    Status: in force

  7. Correction

    Corrigenda to the DPDP Rules 2025 issued

    Eight textual corrections to the Rules are notified as G.S.R. 892(E), published in Gazette issue No. 806 of 11 December 2025. Two of them fix the wording of the commencement rule itself.

    Why it matters: The corrected wording is the operative text. Anyone quoting the Rules must apply these corrections.

    Status: in effect

What comes next

  1. ImplementationUpcoming · computed date

    Rule 4 and the Consent Manager provisions of the Act due to come into force

    One year after publication, the registration and obligations framework for Consent Managers is due to start operating: Rule 4 on the Rules side, and section 6(9) and section 27(1)(d) of the Act. The calendar date shown is computed from the publication dates and is presented as interpretation until officially confirmed.

    Why it matters: Consent Managers can only be registered once Rule 4 operates, per Rule 1(3). The matching Act provisions commence one year from the publication of notification G.S.R. 843(E).

    Status: upcoming; dates derived from Rule 1(3) and G.S.R. 843(E), interpretation until officially confirmed

  2. ImplementationUpcoming · computed date

    The main obligations of the Act and the Rules due to come into force

    Eighteen months after publication, the main operational provisions are due to start on both sides: Rules 3, 5 to 16, 22 and 23, and the core of the Act, meaning sections 3 to 5, most of section 6, and sections 7 to 17 (application, grounds, notice, consent, obligations of Data Fiduciaries, children's data and the rights of Data Principals), section 27 other than 27(1)(d), sections 28 to 34, 36 and 37, and section 44(2). Section 6(9) is not in this group; it commences a year earlier. The calendar date shown is computed from the publication dates and is presented as interpretation until officially confirmed.

    Why it matters: This is the date most organisations are working towards, per Rule 1(4) and paragraph (c) of notification G.S.R. 843(E).

    Status: upcoming; dates derived from Rule 1(4) and G.S.R. 843(E), interpretation until officially confirmed

A note on earlier history. Milestones before 2023, including the constitutional privacy judgment, the expert committee stages and the earlier bills, are being verified against their primary sources and will appear here once confirmed. We would rather show a shorter verified timeline than an unverified longer one.