India DPDP Act: requirements, deadlines and compliance actions
Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025
What is the India DPDP Act?
The DPDP Act is India's cross-sector personal-data law. It applies to digital personal data processed in India and to processing outside India connected with offering goods or services to people in India. It requires a lawful basis (consent or specified legitimate uses), notice, purpose limitation, data accuracy, security safeguards, breach notification to the Data Protection Board and affected individuals, and grants rights of access, correction, erasure and grievance redress. Significant Data Fiduciaries face extra duties such as impact assessments and audits. The Act does not mention AI specifically, but it governs the personal data used to train and operate AI systems.
Status note: The Act received Presidential assent on 11 August 2023 and comes into force on dates notified by the Central Government. The DPDP Rules 2025 were notified in November 2025 with phased commencement (some provisions at once, most substantive obligations after 12 to 18 months). A reviewer must confirm the exact commencement dates.
Who does it apply to?
Data Fiduciaries (controllers) and Data Processors handling digital personal data of individuals in India, including foreign entities offering goods or services to India. Excludes personal or domestic use and publicly available data made public by the individual or under law.
Any organisation processing digital personal data of individuals in India, including AI developers and deployers using such data.
When do the requirements apply?
Assent 11 August 2023; DPDP Rules notified November 2025 with phased commencement; core obligations expected to apply about 18 months after notification (to be confirmed).
| Date | Milestone | Source reference | Status |
|---|---|---|---|
| Presidential assent Act No. 22 of 2023. |
— | Passed | |
| DPDP Rules 2025 notified Notification in the Gazette; reviewer to confirm exact date. |
— | Passed confidence: medium |
|
| 12 to 18 months after Rules notification (to be confirmed) | Phased commencement of substantive obligations The Rules set staggered dates for consent-manager registration, notice, security and rights obligations. |
— | Tbd confidence: low |
Commencement is phased by notification; see the deadlines table and confirm with the official source.
What must organisations do?
Map personal data flows into AI systems, obtain valid consent or identify a legitimate use, publish notices, implement security safeguards and breach-notification processes, honour data-principal rights, and, if designated a Significant Data Fiduciary, appoint a Data Protection Officer, run data protection impact assessments and audits.
Legal requirement Process personal data only with valid consent or a legitimate use, after notice Sections 4 to 7
Personal data may be processed only for a lawful purpose with the individual's free, specific, informed and unambiguous consent, or for certain legitimate uses listed in the Act. A notice must describe the data, purpose, and how to exercise rights and complain.
Practical action: Inventory training and inference data sources and document the consent or legitimate use for each.
Evidence examples: Consent records and notices
Framework mapping (original, editorial): ISO/IEC 42001:2023 Annex A controls on data for AI systems
Obligation page Source-linked
Legal requirement Implement reasonable security safeguards and notify breaches Section 8(5) and 8(6); DPDP Rules on breach intimation
Data Fiduciaries must protect personal data with reasonable security safeguards and, on a personal data breach, inform the Data Protection Board and each affected individual in the form and manner prescribed by the Rules.
Practical action: Extend incident response to cover AI training data and model outputs that reveal personal data.
Evidence examples: Breach notification procedure
Framework mapping (original, editorial): ISO/IEC 27001:2022 Annex A incident management controls
Obligation page Source-linked
Legal requirement Significant Data Fiduciaries must appoint a DPO and run impact assessments and audits Section 10
Entities notified as Significant Data Fiduciaries, based on factors such as volume and sensitivity of data and risk to individuals, must appoint a Data Protection Officer based in India, an independent data auditor, and periodically undertake data protection impact assessments and audits.
Practical action: Assess whether your AI data processing could trigger SDF designation and prepare DPIA tooling.
Evidence examples: Data protection impact assessment
Framework mapping (original, editorial): ISO/IEC 42001:2023 Clause 6.1.4 AI system impact assessment
Obligation page Source-linked
Penalties
The Data Protection Board may impose monetary penalties up to INR 250 crore per instance for failure to take reasonable security safeguards, with lower caps for other breaches, as set out in the Schedule to the Act.
Official sources
-
Digital Personal Data Protection Act, 2023 (No. 22 of 2023)
Ministry of Electronics and Information Technology · 11 Aug 2023 · Tier 1 source
-
Digital Personal Data Protection Rules, 2025
Ministry of Electronics and Information Technology · 13 Nov 2025 · Tier 1 source
Change history
Record version 1: Initial structured record; Rules commencement schedule to be confirmed.. Full edit history is in the GitHub repository.
Frequently asked questions
- Does India's DPDP Act regulate AI?
- Not by name, but it governs any digital personal data used to train, fine-tune or operate AI systems, requiring a lawful basis, notice, security safeguards and breach notification.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.