{"slug":"india-dpdp-act","title":"Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025","short_title":"India DPDP Act","jurisdiction":"india","instrument_type":"act","status":"partially_applicable","is_binding":true,"issuing_body":"Parliament of India; Ministry of Electronics and Information Technology (Rules)","summary_plain":"The DPDP Act is India's cross-sector personal-data law. It applies to digital personal data processed in India and to processing outside India connected with offering goods or services to people in India. It requires a lawful basis (consent or specified legitimate uses), notice, purpose limitation, data accuracy, security safeguards, breach notification to the Data Protection Board and affected individuals, and grants rights of access, correction, erasure and grievance redress. Significant Data Fiduciaries face extra duties such as impact assessments and audits. The Act does not mention AI specifically, but it governs the personal data used to train and operate AI systems.\n","adopted_on":"2023-08-11","in_force_on":null,"applies_from":null,"official_source_url":"https://www.meity.gov.in/data-protection-framework","last_verified_at":null,"review_status":"pending_review","confidence_level":"medium","updated_at":"2026-09-11T14:53:02+00:00","url":"https://aipolicytracker.org/policies/india-dpdp-act","status_note":"The Act received Presidential assent on 11 August 2023 and comes into force on dates notified by the Central Government. The DPDP Rules 2025 were notified in November 2025 with phased commencement (some provisions at once, most substantive obligations after 12 to 18 months). A reviewer must confirm the exact commencement dates.\n","scope_summary":"Data Fiduciaries (controllers) and Data Processors handling digital personal data of individuals in India, including foreign entities offering goods or services to India. Excludes personal or domestic use and publicly available data made public by the individual or under law.\n","who_it_applies_to":"Any organisation processing digital personal data of individuals in India, including AI developers and deployers using such data.","key_dates_summary":"Assent 11 August 2023; DPDP Rules notified November 2025 with phased commencement; core obligations expected to apply about 18 months after notification (to be confirmed).","penalties_summary":"The Data Protection Board may impose monetary penalties up to INR 250 crore per instance for failure to take reasonable security safeguards, with lower caps for other breaches, as set out in the Schedule to the Act.\n","what_organizations_must_do":"Map personal data flows into AI systems, obtain valid consent or identify a legitimate use, publish notices, implement security safeguards and breach-notification processes, honour data-principal rights, and, if designated a Significant Data Fiduciary, appoint a Data Protection Officer, run data protection impact assessments and audits.\n","published_on":"2023-08-11","date_notes":"Commencement is phased by notification; see the deadlines table and confirm with the official source.","taxonomy":{"actor":["provider","deployer","public_authority"],"ai_system_type":["generative_ai","automated_decision_system","predictive_scoring"],"sector":["cross_sector"],"risk_category":["unclassified"],"use_case":["hiring_and_hr","health","finance_and_credit","generative_ai"]},"sections":[],"obligations":[{"slug":"india-dpdp-consent-and-notice","title":"Process personal data only with valid consent or a legitimate use, after notice","category":"privacy_data_protection","summary":"Personal data may be processed only for a lawful purpose with the individual's free, specific, informed and unambiguous consent, or for certain legitimate uses listed in the Act. A notice must describe the data, purpose, and how to exercise rights and complain.\n","practical_action":"Inventory training and inference data sources and document the consent or legitimate use for each.","is_binding":true,"applies_from":null,"section":null,"source_reference":"Sections 4 to 7","official_source_url":"https://www.meity.gov.in/data-protection-framework","review_status":"pending_review","confidence_level":"medium","last_verified_at":null,"actors":["provider","deployer"],"sectors":["cross_sector"],"use_cases":["generative_ai","finance_and_credit"],"applicability":[{"description":"All Data Fiduciaries.","actors":["provider","deployer"],"conditions":null}],"evidence_examples":[{"title":"Consent records and notices","description":null,"artifact_type":"record"}],"framework_mappings":[{"framework":"iso_42001","framework_name":"ISO/IEC 42001:2023","reference":"Annex A controls on data for AI systems","note":"Original editorial mapping.","confidence_level":"medium","is_original":true}],"url":"https://aipolicytracker.org/obligations/india-dpdp-consent-and-notice"},{"slug":"india-dpdp-security-and-breach-notification","title":"Implement reasonable security safeguards and notify breaches","category":"incident_handling","summary":"Data Fiduciaries must protect personal data with reasonable security safeguards and, on a personal data breach, inform the Data Protection Board and each affected individual in the form and manner prescribed by the Rules.\n","practical_action":"Extend incident response to cover AI training data and model outputs that reveal personal data.","is_binding":true,"applies_from":null,"section":null,"source_reference":"Section 8(5) and 8(6); DPDP Rules on breach intimation","official_source_url":"https://www.meity.gov.in/data-protection-framework","review_status":"pending_review","confidence_level":"medium","last_verified_at":null,"actors":["provider","deployer"],"sectors":["cross_sector"],"use_cases":["generative_ai","health"],"applicability":[{"description":"All Data Fiduciaries.","actors":["provider","deployer"],"conditions":null}],"evidence_examples":[{"title":"Breach notification procedure","description":null,"artifact_type":"document"}],"framework_mappings":[{"framework":"iso_27001","framework_name":"ISO/IEC 27001:2022","reference":"Annex A incident management controls","note":"Original editorial mapping.","confidence_level":"medium","is_original":true}],"url":"https://aipolicytracker.org/obligations/india-dpdp-security-and-breach-notification"},{"slug":"india-dpdp-significant-data-fiduciary-duties","title":"Significant Data Fiduciaries must appoint a DPO and run impact assessments and audits","category":"impact_assessment","summary":"Entities notified as Significant Data Fiduciaries, based on factors such as volume and sensitivity of data and risk to individuals, must appoint a Data Protection Officer based in India, an independent data auditor, and periodically undertake data protection impact assessments and audits.\n","practical_action":"Assess whether your AI data processing could trigger SDF designation and prepare DPIA tooling.","is_binding":true,"applies_from":null,"section":null,"source_reference":"Section 10","official_source_url":"https://www.meity.gov.in/data-protection-framework","review_status":"pending_review","confidence_level":"medium","last_verified_at":null,"actors":["provider","deployer"],"sectors":["cross_sector"],"use_cases":["generative_ai","finance_and_credit"],"applicability":[{"description":"Entities notified as Significant Data Fiduciaries.","actors":["provider","deployer"],"conditions":null}],"evidence_examples":[{"title":"Data protection impact assessment","description":null,"artifact_type":"report"}],"framework_mappings":[{"framework":"iso_42001","framework_name":"ISO/IEC 42001:2023","reference":"Clause 6.1.4 AI system impact assessment","note":"Original editorial mapping.","confidence_level":"medium","is_original":true}],"url":"https://aipolicytracker.org/obligations/india-dpdp-significant-data-fiduciary-duties"}],"applicability_rules":[],"deadlines":[{"title":"Presidential assent","due_on":"2023-08-11","date_precision":"exact","date_label":null,"display_date":"11 August 2023","description":"Act No. 22 of 2023.","source_reference":null,"official_source_url":null,"status":"passed","confidence_level":"high"},{"title":"DPDP Rules 2025 notified","due_on":"2025-11-13","date_precision":"exact","date_label":null,"display_date":"13 November 2025","description":"Notification in the Gazette; reviewer to confirm exact date.","source_reference":null,"official_source_url":null,"status":"passed","confidence_level":"medium"},{"title":"Phased commencement of substantive obligations","due_on":null,"date_precision":"tbd","date_label":"12 to 18 months after Rules notification (to be confirmed)","display_date":"12 to 18 months after Rules notification (to be confirmed)","description":"The Rules set staggered dates for consent-manager registration, notice, security and rights obligations.","source_reference":null,"official_source_url":null,"status":"tbd","confidence_level":"low"}],"versions":[],"enforcement_events":[],"procurement_rules":[],"sources":[{"title":"Digital Personal Data Protection Act, 2023 (No. 22 of 2023)","publisher":"Ministry of Electronics and Information Technology","url":"https://www.meity.gov.in/data-protection-framework","document_date":"2023-08-11","document_type":"legislation","tier":1,"tier_label":"Official primary source (government, legislature, regulator, court, standards body, intergovernmental)"},{"title":"Digital Personal Data Protection Rules, 2025","publisher":"Ministry of Electronics and Information Technology","url":"https://www.meity.gov.in/data-protection-framework","document_date":"2025-11-13","document_type":"legislation","tier":1,"tier_label":"Official primary source (government, legislature, regulator, court, standards body, intergovernmental)"}],"related_policies":["india-ai-governance-guidelines","eu-ai-act"],"related_frameworks":[],"faq":[{"question":"Does India's DPDP Act regulate AI?","answer":"Not by name, but it governs any digital personal data used to train, fine-tune or operate AI systems, requiring a lawful basis, notice, security safeguards and breach notification.\n"}],"source":{"official_source_url":"https://www.meity.gov.in/data-protection-framework","source_title":"Data Protection Framework — Digital Personal Data Protection Act, 2023","source_publisher":"Ministry of Electronics and Information Technology, Government of India","source_document_date":"2023-08-11","source_reference":"Act No. 22 of 2023","source_tier":1,"last_checked_at":null,"last_verified_at":null,"review_status":"pending_review","confidence_level":"medium","content_version":1,"change_summary":"Initial structured record; Rules commencement schedule to be confirmed.","reviewed_by":null}}