Rules / India

Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025

Partly in forceLawBinding

India's horizontal data protection law, governing how 'data fiduciaries' (including AI developers and deployers) collect and process digital personal data, with consent, notice, security, breach-notification and data-principal rights. The DPDP Rules 2025 (notified 13/14 Nov 2025) operationalise it in phases: Data Protection Board provisions immediately, Consent Managers after 12 months and the main obligations after 18 months.

Why it matters

Training or running AI on personal data of people in India will need DPDP-compliant consent/notice and security by 13 May 2027; note the Act exempts publicly available personal data made public by the individual.

What it requires

Data governanceConsumer rightsIncident reportingPenalties

Penalties

Up to ₹250 crore per instance (e.g. failure to maintain reasonable security safeguards).

SourceMeitY / PIB: https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdfSecondary: https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf Checked against the source on 4 Oct 2026. Substantive obligations (Rules 3, 5–16, 22, 23) apply from 13 May 2027. MeitY consulted industry in early 2026 on cutting the 18-month window to 12 months; no amending notification found as of Aug–Sep 2026. Rules notification date reported as 13 Nov (gazette) / 14 Nov 2025 (PIB).

Cite this record

Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025. Parliament of India / Ministry of Electronics and Information Technology (MeitY). Status: Partly in force. wheresthe.ai, https://wheresthe.ai/rule/in-dpdp-act-2023-and-rules-2025/ (verified 4 Oct 2026).

More from India