🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
IN v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 1 failing20 sources retrieved model claude-sonnet-5 · 2026-08-03

Based mainly on secondary sources. Only 1 of the sources retrieved for this jurisdiction is official or direct reporting of official material (tier 1 or 2), against the 3 we look for. No finding on this page is shown with confidence above “Uncertain” until stronger sources are retrieved.

India

IN schema gdpri-v2 trajectory: not yet assessedin transitionoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 34 claims · 33 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
34Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 24 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

India's data protection regime crossed a decisive threshold with the notification of the Digital Personal Data Protection Rules, 2025 on 13 November 2025, alongside establishment of the Data Protection Board of India and an accompanying Enforcement Notification. This notification operationalises the Digital Personal Data Protection Act, 2023, more than two years after its passage, and sets in motion a phased commencement architecture that runs through to 13 May 2027. For an operating environment that had lacked a functioning comprehensive privacy regulator since the Act's enactment, this is the single most consequential development in India's data-protection landscape to date, converting a statute that existed on paper into a regime with an active implementation timetable, a named regulator, and binding rules.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Regulator now exists and rules are finalized (not draft), but the material scope, territorial scope and registration provisions are enacted-but-not-yet-effective pending the 13 May 2027 commencement date.

Primary frameworkDigital Personal Data Protection Act, 2023 (DPDPA) and Digital Personal Data Protection Rules, 2025
Supervisory authorityData Protection Board of India (DPBI)
Traffic-light rationale — AmberRegulator now exists and rules are finalized (not draft), but the material scope, territorial scope and registration provisions are enacted-but-not-yet-effective pending the 13 May 2027 commencement date.

Sub-modules (5)

Regulator And AuthorityGreen

The DPBI is a four-person board constituted immediately upon the 13 Nov 2025 notification of the Rules, with its establishment and operational powers already in force.

Claims (1):

  • The Data Protection Board of India's establishment and operational/powers provisions were brought into force immediately upon the 13 November 2025 notification of the DPDP Rules, 2025.

Act And InstrumentsAmber

DPDPA 2023 plus the Digital Personal Data Protection Rules, 2025 form the omnibus instrument; implementation is phased with full applicability 13 May 2027.

Claims (1):

  • The DPDPA becomes applicable to all entities and government departments 18 months after the 13 November 2025 Rules notification, i.e., 13 May 2027.

Material ScopeAmber

DPDPA applies only to digital personal data (including offline data subsequently digitized); non-digitized data, domestic/personal-use processing, and lawfully public data are excluded.

Claims (1):

  • DPDPA applies to the processing of digital personal data within India, excluding non-digitized offline data, personal data processed for domestic use, and data made publicly available.

Territorial ScopeAmber

The Act has extraterritorial reach, applying to processing outside India where connected to offering goods/services to data principals within India.

Claims (1):

  • DPDPA also applies to processing outside India if the processing relates to activity connected with offering goods or services to data principals within India.

Regulator Registration And FilingAmber

Consent Manager registration and functioning rules apply 12 months after the 13 Nov 2025 finalization (i.e., ~13 Nov 2026); general data-fiduciary registration/filing thresholds beyond consent managers were not identified in this pass.

Claims (1):

  • Rules on the registration and functioning of consent managers apply 12 months after the finalization of the DPDP Rules (from 13 Nov 2025).
Category narrative34 words

The Digital Personal Data Protection Act, 2023 (DPDPA) is India's omnibus statute, with substantive provisions brought into force in three staggered phases via the Digital Personal Data Protection Rules, 2025, notified 13 November 2025.

Periodic update · new data 2026-09-28

Regulator & Framework

India's data protection framework moved from statute-without-machinery to an operationalised regime with the notification of the Digital Personal Data Protection Rules, 2025 on 13 November 2025. That notification simultaneously established the Data Protection Board of India and issued an accompanying Enforcement Notification, together operationalising the Digital Personal Data Protection Act, 2023 more than two years after its original passage. The commencement architecture is phased rather than immediate: Consent Manager registration with the Board becomes effective one year after the Enforcement Notification's gazette publication, placing that milestone in November 2026, while the broader substantive-obligation and penalty regime is understood to reach full enforceability by 13 May 2027.

This phased design means organisations subject to the Act face a rolling series of compliance deadlines rather than a single cutover date, and the practical significance of the framework at any given point depends on which phase is currently in force. The Board's establishment is confirmed, but as detailed under Enforcement & Redress, its operational capacity to exercise its statutory powers is itself disputed in current reporting.

Outlook

Watch November 2026 for Consent Manager registration taking effect, and 13 May 2027 for full substantive enforceability. Confirmation of the Data Protection Board's actual staffing status, addressed in the Enforcement & Redress domain, will materially affect how meaningful this framework proves to be in the interim period.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. UncertainInternational Association of Privacy Professionals — The Data Protection Board of India's establishment and operational/powers provisions were brought into force immediately upon the 13 November 2025 notification of the DPDP Rules, 2025.observed
  2. UncertainInternational Association of Privacy Professionals — The DPDPA becomes applicable to all entities and government departments 18 months after the 13 November 2025 Rules notification, i.e., 13 May 2027.observed
  3. UncertainOneTrust DataGuidance — DPDPA applies to the processing of digital personal data within India, excluding non-digitized offline data, personal data processed for domestic use, and data made publicly available.observed
  4. UncertainOneTrust DataGuidance — DPDPA also applies to processing outside India if the processing relates to activity connected with offering goods or services to data principals within India.observed
  5. UncertainInternational Association of Privacy Professionals — Rules on the registration and functioning of consent managers apply 12 months after the finalization of the DPDP Rules (from 13 Nov 2025).observed

#

Lawful-basis and consent architecture is well documented; special-category and pseudonymisation treatment diverges structurally from GDPR and required an explicit absence finding for pseudonymisation.

Primary frameworkDigital Personal Data Protection Act, 2023, ss. on consent and legitimate uses
Supervisory authorityData Protection Board of India (DPBI)
Traffic-light rationale — AmberLawful-basis and consent architecture is well documented; special-category and pseudonymisation treatment diverges structurally from GDPR and required an explicit absence finding for pseudonymisation.

Sub-modules (4)

Lawful BasesAmber

Consent is the primary basis; the Act prescribes nine additional 'legitimate use' grounds not requiring consent.

Claims (1):

  • DPDPA prescribes nine additional grounds for processing personal data beyond consent, defined as 'legitimate uses,' including use of voluntarily provided data for a specified purpose where the data principal has not objected.

Special CategoriesAmber

Unlike GDPR, DPDPA treats all personal data uniformly and does not impose heightened obligations for sensitive/special-category data.

Claims (1):

  • The DPDPA treats all personal data uniformly without imposing heightened obligations for sensitive personal data, diverging from the GDPR's special-category regime.

Pseudonymisation And AnonymisationRed

No statutory pseudonymisation or anonymisation definition/safe-harbour provision was located in the DPDPA, its Rules, or secondary commentary reviewed in this pass.

Absence provenance: unavailable. Searched: DPDPA pseudonymisation anonymisation safe harbour India, India Digital Personal Data Protection Rules anonymised data definition.

Category narrative49 words

DPDPA is consent-centric but supplements consent with nine statutory 'legitimate uses' grounds. Consent must be free, specific, informed, unconditional and unambiguous. Notably, the Act does not create a GDPR-style special/sensitive-category regime — all personal data is treated uniformly. No statutory pseudonymisation/anonymisation safe-harbour provisions were identified in this research pass.

Periodic update · new data 2026-09-28

Lawful Processing & Special Data

Under the Digital Personal Data Protection Rules, 2025, Data Fiduciaries are required to provide clear, itemised notices to data subjects specifying the purpose or purposes of processing, the categories of personal data being processed, applicable retention periods, and the mechanisms available for withdrawing consent. This notice standard is more granular than a general privacy-policy disclosure, requiring itemisation rather than an omnibus statement of purposes, and it establishes consent withdrawal as a mechanism that must be actively made available rather than merely implied.

These consent and notice requirements form part of the same Rules package that establishes the Data Protection Board and the phased commencement timetable described elsewhere in this brief; as such, the practical enforceability of the notice standard tracks the same phased schedule running through to 13 May 2027.

Outlook

The notice and consent standard is enacted but not yet fully in force under the phased commencement schedule. Organisations should expect scrutiny of notice itemisation practices to increase as the Board's operational capacity develops and as the substantive-obligation deadline of 13 May 2027 approaches.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (3)
  1. UncertainInternational Association of Privacy Professionals — DPDPA prescribes nine additional grounds for processing personal data beyond consent, defined as 'legitimate uses,' including use of voluntarily provided data for a specified purpose where the data principal has not objected.observed
  2. UncertainInternational Association of Privacy Professionals — The DPDPA's consent-centric framework requires that consent obtained from data principals be free, specific, informed, unconditional, and unambiguous.observed
  3. UncertainInternational Association of Privacy Professionals — The DPDPA treats all personal data uniformly without imposing heightened obligations for sensitive personal data, diverging from the GDPR's special-category regime.observed

#

Core rights are documented via secondary legal analysis, but portability, restriction/objection, and precise deadline mechanics require primary Rule-text confirmation.

Primary frameworkDigital Personal Data Protection Act, 2023, Chapter III (Data Principal Rights)
Supervisory authorityData Protection Board of India (DPBI)
Traffic-light rationale — AmberCore rights are documented via secondary legal analysis, but portability, restriction/objection, and precise deadline mechanics require primary Rule-text confirmation.

Sub-modules (5)

Access RightAmber

Data principals have a codified right of access to their personal data held by fiduciaries.

Claims (1):

  • DPDPA codifies data principal rights including access, correction, erasure, grievance redressal, and the right to nominate another person to exercise rights on the data principal's behalf.

Rectification And ErasureAmber

Rights of correction and erasure ('completion') are codified alongside access.

Claims (1):

  • DPDPA codifies data principal rights including access, correction, erasure, grievance redressal, and the right to nominate another person to exercise rights on the data principal's behalf.

Restriction And ObjectionRed

No explicit generalized right to restrict processing or object (analogous to GDPR Art 18/21) was identified; rights are limited to access, correction, completion, and nomination.

Claims (1):

  • Unlike the GDPR and CCPA, the rights available to data principals under the DPDPA are limited to access, correction, completion, and nomination, with no explicit portability or general objection/restriction right.

Data PortabilityRed

DPDPA does not include an explicit data-portability right comparable to GDPR Art 20.

Claims (1):

  • Unlike the GDPR and CCPA, the rights available to data principals under the DPDPA are limited to access, correction, completion, and nomination, with no explicit portability or general objection/restriction right.

Deadlines And Response WindowsRed

No specific statutory response-deadline window for data-principal requests or grievance redressal was located in the secondary sources reviewed.

Absence provenance: unavailable. Searched: DPDPA grievance redressal response deadline days, DPDP Rules 2025 data principal request timeline.

Category narrative53 words

Data principals are granted a narrower set of codified rights than under GDPR/CCPA: access, correction, erasure ('completion'), grievance redressal, and the right to nominate a representative. There is no explicit statutory data-portability right or generalized right to object/restrict processing, and no specific statutory response-deadline window was identified for grievance handling in this pass.

no periodic updates on record for this sub-brief

Sources and claims (2)
  1. UncertainInternational Association of Privacy Professionals — DPDPA codifies data principal rights including access, correction, erasure, grievance redressal, and the right to nominate another person to exercise rights on the data principal's behalf.observed
  2. UncertainInternational Association of Privacy Professionals — Unlike the GDPR and CCPA, the rights available to data principals under the DPDPA are limited to access, correction, completion, and nomination, with no explicit portability or general objection/restriction right.observed

#

Strong secondary-source coverage of DPIA/DPO/breach/retention duties, but exact SDF designation thresholds and breach-notification timelines await primary Rule-text confirmation.

Primary frameworkDigital Personal Data Protection Act, 2023 ss. 8-10; Digital Personal Data Protection Rules, 2025
Supervisory authorityData Protection Board of India (DPBI)
Traffic-light rationale — AmberStrong secondary-source coverage of DPIA/DPO/breach/retention duties, but exact SDF designation thresholds and breach-notification timelines await primary Rule-text confirmation.

Sub-modules (7)

Accountability And DpiaAmber

DPIAs are mandated only for Significant Data Fiduciaries, required once every 12 months.

Claims (1):

  • Only entities classified as Significant Data Fiduciaries are required to conduct a DPIA, and must do so every 12 months.

Dpo RequirementsAmber

Only Significant Data Fiduciaries must appoint an India-based DPO, accountable to the board of directors/governing body rather than required to be independent.

Claims (1):

  • The DPDPA requires all Significant Data Fiduciaries to appoint a DPO based out of India, who must represent the significant data fiduciary and be accountable to its board of directors or governing body.

Ropa RequirementsRed

DPDPA does not require data fiduciaries to maintain formal records of processing activities as under GDPR Art 30, though practical record-keeping may be needed to demonstrate consent compliance.

Claims (1):

  • The DPDPA does not require data fiduciaries to maintain a formal record of processing activities, unlike GDPR Art 30.

Joint Controller ArrangementsAmber

Regulation of data processors is minimal, with only a handful of provisions; the law is focused almost entirely on data-fiduciary obligations.

Claims (1):

  • In the DPDPA, regulation of data processors is minimal, with only a handful of provisions on the topic, with the law focused almost entirely on data fiduciaries.

Security MeasuresAmber

Data fiduciaries must implement reasonable technical and organisational security safeguards to prevent a personal data breach.

Claims (1):

  • Data fiduciaries are required to protect personal data under their control or possession and implement necessary security safeguards to prevent a personal data breach.

Breach NotificationAmber

Fiduciaries must notify the DPBI and affected data principals of personal data breaches; the finalized Rules clarify notification requirements, though the precise notification-hour timeline needs primary-text confirmation.

Claims (1):

  • The finalized DPDP Rules, 2025 cover data breach notification requirements to the Data Protection Board of India and affected data principals.

Retention And DisposalAmber

The finalized Rules impose a new one-year minimum retention requirement on data fiduciaries, primarily to facilitate responses to state-agency requests (national security, investigations, SDF determination).

Claims (1):

  • The final DPDP Rules impose a new one-year minimum retention requirement on data fiduciaries, primarily to facilitate responses to state agency requests related to national security, investigations, and determination of significant data fiduciary status.
Category narrative82 words

Data fiduciaries bear the core compliance burden (processors are lightly regulated). Significant Data Fiduciaries (SDFs) — a government-designated class — face heightened duties: DPIAs every 12 months, an India-based DPO reporting to the board/governing body, and periodic independent audits. General fiduciaries must implement 'reasonable security safeguards' and notify breaches to the DPBI and affected principals. The finalized Rules add a new one-year minimum data-retention requirement for specified purposes (national security, investigations, SDF determination). No GDPR Art 30-style records-of-processing (ROPA) requirement was identified.

Periodic update · new data 2026-09-28

Controller/Processor Duties

The Digital Personal Data Protection Rules, 2025 impose significantly enhanced duties on Significant Data Fiduciaries, a heightened category of controller subject to obligations beyond those applying to ordinary Data Fiduciaries. Significant Data Fiduciaries must conduct annual Data Protection Impact Assessments and audits, a recurring accountability obligation rather than a one-time compliance exercise. All Data Fiduciaries, not only the Significant category, must notify the Data Protection Board and affected individuals of personal data breaches, with a detailed submission required within 72 hours of the breach becoming known — a materially fast notification window by comparative standards.

Significant Data Fiduciaries also face a targeted cross-border restriction under Rule 13(4), addressed in full under Cross-Border & Adequacy, which prohibits transferring traffic data pertaining to the flow of personal information outside India. Rule 13(5) separately constitutes a committee tasked with recommending further Significant-Data-Fiduciary-specific measures, suggesting the compliance burden on this category of controller is likely to continue to expand.

Outlook

The 72-hour breach-notification clock and the annual DPIA/audit cycle for Significant Data Fiduciaries are the two obligations most likely to generate near-term compliance activity as the Rules phase into force. The Rule 13(5) committee's eventual recommendations are worth monitoring as a likely source of further SDF-specific obligations.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (7)
  1. UncertainInternational Association of Privacy Professionals — Only entities classified as Significant Data Fiduciaries are required to conduct a DPIA, and must do so every 12 months.observed
  2. UncertainInternational Association of Privacy Professionals — The DPDPA requires all Significant Data Fiduciaries to appoint a DPO based out of India, who must represent the significant data fiduciary and be accountable to its board of directors or governing body.observed
  3. UncertainInternational Association of Privacy Professionals — The DPDPA does not require data fiduciaries to maintain a formal record of processing activities, unlike GDPR Art 30.observed
  4. UncertainInternational Association of Privacy Professionals — In the DPDPA, regulation of data processors is minimal, with only a handful of provisions on the topic, with the law focused almost entirely on data fiduciaries.observed
  5. UncertainInternational Association of Privacy Professionals — Data fiduciaries are required to protect personal data under their control or possession and implement necessary security safeguards to prevent a personal data breach.observed
  6. UncertainInternational Association of Privacy Professionals — The finalized DPDP Rules, 2025 cover data breach notification requirements to the Data Protection Board of India and affected data principals.observed
  7. UncertainInternational Association of Privacy Professionals — The final DPDP Rules impose a new one-year minimum retention requirement on data fiduciaries, primarily to facilitate responses to state agency requests related to national security, investigations, and determination of significant data fiduciary status.observed

#

The blacklist mechanism is well documented, but no country has yet been notified as restricted, and sector-specific localisation interacts with, rather than is superseded by, the DPDPA.

Primary frameworkDigital Personal Data Protection Act, 2023, s.16
Supervisory authorityData Protection Board of India (DPBI)
Traffic-light rationale — AmberThe blacklist mechanism is well documented, but no country has yet been notified as restricted, and sector-specific localisation interacts with, rather than is superseded by, the DPDPA.

Sub-modules (6)

Transfer MechanismsAmber

Transfers are permitted unless the central government designates a jurisdiction as restricted via notification — a 'blacklist' rather than 'whitelist' model.

Claims (1):

  • The DPDPA adopts a liberalized 'blacklisting' model under which the central government can notify specific countries to which data flow may be restricted, in contrast to the EU's 'whitelisting' adequacy approach.

Adequacy ReceivedRed

India has not received an adequacy decision from another regime under the DPDPA framework, as the Act does not employ an adequacy-decision concept at all.

Claims (1):

  • The DPDPA generally allows international data transfers except where the government restricts transfers to specific countries, departing from an adequacy-based transfer method entirely.

Adequacy GrantedRed

India does not grant adequacy decisions to other jurisdictions under DPDPA; the Act substitutes a government-notified restricted-country list for the adequacy concept.

Claims (1):

  • The DPDPA generally allows international data transfers except where the government restricts transfers to specific countries, departing from an adequacy-based transfer method entirely.

Sccs And BcrsRed

No statutory SCC or BCR mechanism is prescribed under the DPDPA; transfers rely on the default-permitted/blacklist model instead.

Absence provenance: unavailable. Searched: DPDPA standard contractual clauses binding corporate rules India.

Transfer Impact AssessmentRed

No transfer-impact-assessment requirement was identified under the DPDPA or its Rules.

Absence provenance: unavailable. Searched: DPDPA transfer impact assessment requirement.

Data LocalisationAmber

DPDPA itself does not impose blanket data localisation, but sector-specific localisation rules (e.g., RBI payment-system data, SEBI cloud framework) continue to apply alongside it.

Claims (1):

  • Sector-specific guidance from regulators such as the RBI and SEBI, mandating financial datasets to be stored in India, operates alongside the DPDPA's baseline transfer rule.
Category narrative68 words

DPDPA departs from the EU adequacy model. Under s.16(1), international transfers are permitted by default; the central government may notify a 'blacklist' of restricted countries rather than a positive 'whitelist' of adequate jurisdictions. No SCC/BCR mechanism is statutorily mandated. Sector-specific data-localisation rules (RBI payment-system data, SEBI cloud-adoption framework) continue to operate as a stricter baseline alongside the DPDPA. No transfer-impact-assessment requirement analogous to Schrems-II TIA practice was identified.

Periodic update · new data 2026-09-28

Cross-Border & Adequacy

India has not adopted an EU-style adequacy, standard-contractual-clause, or binding-corporate-rules framework for cross-border personal data transfers. Instead, the Digital Personal Data Protection Rules, 2025 impose a narrower, targeted restriction: Rule 13(4) prohibits Significant Data Fiduciaries specifically from transferring any traffic data outside India where that data pertains to the flow of personal information. This is a data-localisation measure aimed at a defined category of data and a defined category of controller, rather than a general cross-border transfer-control regime applicable to all personal data or all data fiduciaries.

Rule 13(5) establishes a committee to recommend further measures specific to Significant Data Fiduciaries, which may in time expand the scope of cross-border restrictions currently in force. As of this cycle, no broader adequacy-assessment mechanism or transfer-safeguard instrument analogous to the EU General Data Protection Regulation's Chapter V exists in the Indian framework.

Outlook

Watch for the Rule 13(5) committee's recommendations, which represent the most likely near-term source of any expansion to India's currently narrow, traffic-data-specific localisation restriction. Organisations processing traffic data through Significant Data Fiduciary structures should treat the current Rule 13(4) restriction as a hard constraint on data flow architecture.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (3)
  1. UncertainInternational Association of Privacy Professionals — The DPDPA adopts a liberalized 'blacklisting' model under which the central government can notify specific countries to which data flow may be restricted, in contrast to the EU's 'whitelisting' adequacy approach.observed
  2. UncertainInternational Association of Privacy Professionals — The DPDPA generally allows international data transfers except where the government restricts transfers to specific countries, departing from an adequacy-based transfer method entirely.observed
  3. UncertainOneTrust DataGuidance — Sector-specific guidance from regulators such as the RBI and SEBI, mandating financial datasets to be stored in India, operates alongside the DPDPA's baseline transfer rule.observed

#

Financial-sector overlay is well evidenced; other sectoral sub-modules require targeted follow-up research against sector regulator (RBI, IRDAI, TRAI, UGC/health-ministry) primary sources.

Primary frameworkRBI/SEBI sectoral directions operating alongside DPDPA s.16
Supervisory authorityReserve Bank of India (RBI)
Traffic-light rationale — AmberFinancial-sector overlay is well evidenced; other sectoral sub-modules require targeted follow-up research against sector regulator (RBI, IRDAI, TRAI, UGC/health-ministry) primary sources.

Sub-modules (7)

Financial Sector OverlayAmber

RBI Master Directions on Cyber Resilience and Digital Payment Security Controls, and SEBI's cloud-adoption framework, mandate India-based storage of specified financial datasets, operating alongside DPDPA.

Claims (1):

  • Sector-specific guidance released by regulators such as the RBI and SEBI, mandating financial datasets to be stored in India, operates alongside the DPDPA.

Health Sector OverlayRed

No health-sector-specific DP overlay (e.g., Ayushman Bharat Digital Mission rules) was surfaced in this pass.

Absence provenance: unavailable. Searched: India health data protection ABDM DPDPA overlay.

Telecoms And EprivacyRed

No telecoms/ePrivacy-equivalent overlay (e.g., TRAI subscriber-data rules interacting with DPDPA) was surfaced in this pass.

Absence provenance: unavailable. Searched: India TRAI subscriber data DPDPA telecom overlay.

Employment DataRed

No employment-sector-specific DP overlay was surfaced in this pass.

Absence provenance: unavailable. Searched: India employment data DPDPA employer overlay.

Credit And ScoringRed

No credit-scoring-specific DP overlay (beyond general DPIA relevance to credit checks) was surfaced in this pass.

Absence provenance: unavailable. Searched: India credit scoring DPDPA overlay CIBIL.

EducationRed

No education-sector-specific DP overlay was surfaced in this pass.

Absence provenance: unavailable. Searched: India education sector DPDPA overlay.

InsuranceRed

No insurance-sector-specific DP overlay (e.g., IRDAI rules) was surfaced in this pass.

Absence provenance: unavailable. Searched: India IRDAI insurance data DPDPA overlay.

Category narrative55 words

The clearest sectoral overlay identified is financial services: RBI Master Directions on cyber resilience/payment-data localisation and SEBI cloud-adoption rules mandate in-India storage of specified datasets and operate as a stricter baseline alongside the DPDPA's general transfer rule. No specific health, telecoms/ePrivacy, employment, credit-scoring, education, or insurance sectoral DP overlays were surfaced in this research pass.

Sources and claims (1)
  1. UncertainOneTrust DataGuidance — Sector-specific guidance released by regulators such as the RBI and SEBI, mandating financial datasets to be stored in India, operates alongside the DPDPA.observed

#

Only the children-targeted-advertising ban was substantiated; broader adtech sub-modules are largely unaddressed by the DPDPA and require dedicated follow-up.

Primary frameworkDigital Personal Data Protection Act, 2023, s.9 (children)
Supervisory authorityData Protection Board of India (DPBI)
Traffic-light rationale — AmberOnly the children-targeted-advertising ban was substantiated; broader adtech sub-modules are largely unaddressed by the DPDPA and require dedicated follow-up.

Sub-modules (6)

Cookies And TrackersRed

No dedicated cookie/tracker consent regime analogous to EU ePrivacy was identified under DPDPA.

Absence provenance: unavailable. Searched: DPDPA cookie consent tracker regime India.

Dark PatternsRed

No dark-pattern-specific statutory prohibition under DPDPA was identified (India has separate CCPA/ASCI consumer-protection guidelines on dark patterns, outside DP scope).

Absence provenance: unavailable. Searched: DPDPA dark patterns prohibition.

Opt Out SignalsRed

No recognition of universal opt-out signals (e.g., Global Privacy Control) was identified under DPDPA.

Absence provenance: unavailable. Searched: DPDPA global privacy control opt-out signal.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room-specific rule was identified under DPDPA.

Absence provenance: unavailable. Searched: DPDPA data clean room rules.

Cross Context AdvertisingAmber

DPDPA prohibits behavioral monitoring, tracking, or targeted advertising directed at children, functioning as a narrow cross-context-advertising restriction limited to minors.

Claims (1):

  • Data fiduciaries are prohibited from undertaking processing that involves tracking, behavioral monitoring of children, or targeted advertising directed at children, subject to narrow prescribed exemptions.

Direct MarketingAmber

No general direct-marketing consent/suppression regime distinct from the consent-and-legitimate-use framework was identified, aside from the children's targeted-advertising ban.

Claims (1):

  • Data fiduciaries are prohibited from undertaking processing that involves tracking, behavioral monitoring of children, or targeted advertising directed at children, subject to narrow prescribed exemptions.
Category narrative47 words

DPDPA does not contain a GDPR-ePrivacy-style dedicated cookie/tracker consent regime. The clearest adtech-relevant provision is the children's-data ban on tracking, behavioral monitoring and targeted advertising directed at children. No dark-pattern-specific prohibition, opt-out-signal (e.g., GPC) recognition, clean-room/DCR rule, or general cross-context 'sale/share' concept analogous to CPRA was identified.

Sources and claims (1)
  1. UncertainInternational Association of Privacy Professionals — Data fiduciaries are prohibited from undertaking processing that involves tracking, behavioral monitoring of children, or targeted advertising directed at children, subject to narrow prescribed exemptions.observed

#

Profiling restriction and state-exemption findings are sourced; ADM transparency, AI risk assessment, biometric and genetic sub-modules remain unaddressed by DPDPA and require dedicated follow-up (and cross-reference to the AI-governance surface).

Primary frameworkDigital Personal Data Protection Act, 2023, s.9 (children) and exemption provisions
Supervisory authorityData Protection Board of India (DPBI)
Traffic-light rationale — AmberProfiling restriction and state-exemption findings are sourced; ADM transparency, AI risk assessment, biometric and genetic sub-modules remain unaddressed by DPDPA and require dedicated follow-up (and cross-reference to the AI-governance surface).

Sub-modules (6)

Profiling RestrictionsAmber

Behavioral monitoring, tracking, or profiling of children is prohibited except for certain essential services (health care, education, real-time safety).

Claims (1):

  • Data fiduciaries are prohibited from undertaking processing that involves tracking or behavioral monitoring of children, except when providing certain essential services such as health care, education, or real-time safety.

Automated Decision Making TransparencyRed

No general Art 22-style automated-decision-making transparency/explanation right was identified under DPDPA.

Absence provenance: unavailable. Searched: DPDPA automated decision making transparency right.

Ai Risk AssessmentsAmber

MeitY released the India AI Governance Guidelines in November 2025 as a separate, non-DPDPA instrument; no DPDPA-specific AI-risk-assessment mandate was identified.

Claims (1):

  • MeitY released the India Artificial Intelligence Governance Guidelines on 5 November 2025, a separate non-DPDPA instrument relevant to algorithmic governance context.

Biometric RegimeRed

No DPDPA-specific biometric-data regime (facial recognition, fingerprint, gait) was identified in this pass.

Absence provenance: unavailable. Searched: DPDPA biometric data facial recognition regime India.

Genetic DataRed

No DPDPA-specific genetic-data regime was identified in this pass.

Absence provenance: unavailable. Searched: DPDPA genetic data regime India.

State Surveillance CarveoutsAmber

DPDPA contains broad exemptions permitting government and government-instrumentality processing, including for national security purposes, which Justice B.N. Srikrishna (former Expert Committee chair) has criticized as a source of concern.

Claims (1):

  • Provisions granting exemptions to the government and government bodies under the DPDPA have been described by Justice B.N. Srikrishna, former chair of the Expert Committee on Data Protection, as causing 'great concern.'
Category narrative68 words

DPDPA's algorithmic-governance content is limited: a children-specific profiling/behavioral-monitoring ban, and broad government/state exemptions (including for national security) that have drawn criticism from Justice B.N. Srikrishna for granting excessive latitude to the state. Separately, MeitY released non-DPDPA India AI Governance Guidelines in November 2025, relevant context but not a DPDPA-binding obligation. No Art 22-style ADM-transparency right, dedicated AI-risk-assessment mandate, biometric-specific regime, or genetic-data regime was identified within DPDPA itself.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. UncertainInternational Association of Privacy Professionals — Data fiduciaries are prohibited from undertaking processing that involves tracking or behavioral monitoring of children, except when providing certain essential services such as health care, education, or real-time safety.observed
  2. UncertainInternational Association of Privacy Professionals — Provisions granting exemptions to the government and government bodies under the DPDPA have been described by Justice B.N. Srikrishna, former chair of the Expert Committee on Data Protection, as causing 'great concern.'observed
  3. UncertainInternational Association of Privacy Professionals — MeitY released the India Artificial Intelligence Governance Guidelines on 5 November 2025, a separate non-DPDPA instrument relevant to algorithmic governance context.observed

#

Core child/dependent-adult consent architecture is well sourced from the finalized Rules; education-settings sub-module remains unaddressed.

Primary frameworkDigital Personal Data Protection Act, 2023, s.9; Digital Personal Data Protection Rules, 2025
Supervisory authorityData Protection Board of India (DPBI)
Traffic-light rationale — AmberCore child/dependent-adult consent architecture is well sourced from the finalized Rules; education-settings sub-module remains unaddressed.

Sub-modules (5)

Age VerificationAmber

DPDPA defines a child as an individual under age 18; businesses must confirm the guardian/parent is an adult.

Claims (1):

  • The DPDPA defines a child as an individual under age 18 for purposes of the parental/guardian consent requirement.

Minor Profiling BansAmber

Tracking, behavioral monitoring, and targeted advertising directed at children are prohibited, subject to prescribed exemptions for certain classes of fiduciaries or purposes.

Claims (1):

  • Data fiduciaries are prohibited from processing that involves tracking, behavioral monitoring, or targeted advertising directed at children, though the government may notify exempt classes of fiduciaries.

Education SettingsRed

No education-setting-specific children's-data rule distinct from the general minor-consent regime was identified in this pass.

Absence provenance: unavailable. Searched: DPDPA education sector children data rules India.

Dependent AdultsAmber

For individuals with disabilities, consent must be obtained from their lawful guardian, verified in accordance with India's guardianship laws.

Claims (1):

  • For individuals with disabilities, consent must be obtained from their lawful guardian, who must be verified in accordance with India's guardianship laws.
Category narrative55 words

DPDPA defines a child as under 18 and mandates verifiable parental/guardian consent before processing a child's data, with the finalized Rules elaborating mechanisms including digital-locker-based parental verification. Narrow exemptions apply for health/safety purposes. Persons with disabilities also require lawful-guardian consent, verified per India's guardianship laws. No education-setting-specific carve-out beyond the general children's regime was identified.

Periodic update · new data 2026-09-28

Children & Vulnerable Groups

Section 9 of the Digital Personal Data Protection Act, 2023 mandates that organisations obtain verifiable consent from a child's parent or guardian before processing that child's personal data. This is a statutory requirement under the primary Act itself, distinct from the phased Rules-level obligations discussed elsewhere in this brief, though its practical enforceability moves in step with the same phased commencement timetable running through to 13 May 2027.

No further detail on verification mechanisms, age thresholds, or exceptions for parental-consent requirements was available in the claims for this cycle.

Outlook

As the Data Protection Board's operational capacity develops and the substantive-obligation deadline approaches, expect increased organisational focus on verifiable-parental-consent mechanisms for services likely to be accessed by children.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (4)
  1. UncertainInternational Association of Privacy Professionals — The DPDPA defines a child as an individual under age 18 for purposes of the parental/guardian consent requirement.observed
  2. UncertainInternational Association of Privacy Professionals — Verifiable consent must be obtained from the parent or lawful guardian before processing a child's personal data; the finalized Rules elaborate mechanisms such as digital-locker-based parental verification, with narrowly defined health- and safety-specific exemptions.observed
  3. UncertainInternational Association of Privacy Professionals — Data fiduciaries are prohibited from processing that involves tracking, behavioral monitoring, or targeted advertising directed at children, though the government may notify exempt classes of fiduciaries.observed
  4. UncertainInternational Association of Privacy Professionals — For individuals with disabilities, consent must be obtained from their lawful guardian, who must be verified in accordance with India's guardianship laws.observed

#

Penalty framework and Board constitution are well documented; enforcement-activity track record under DPDPA itself is not yet available since substantive obligations are not yet effective, and collective-redress mechanisms remain unconfirmed.

Primary frameworkDigital Personal Data Protection Act, 2023, Chapter on Data Protection Board and Penalties
Supervisory authorityData Protection Board of India (DPBI)
Traffic-light rationale — AmberPenalty framework and Board constitution are well documented; enforcement-activity track record under DPDPA itself is not yet available since substantive obligations are not yet effective, and collective-redress mechanisms remain unconfirmed.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

Monetary penalties for significant non-compliance may extend to INR 250 crore; no criminal penalties are imposed; turnover is not a factor in determining the penalty.

Claims (1):

  • Sanctions under DPDPA are monetary penalties which, unlike GDPR's turnover-based penalties, may extend to INR 250 crores (approximately USD27 million); the DPDPA imposes no criminal penalties and does not consider business turnover in determining the penalty.

Enforcement Activity IndexAmber

No DPDPA-specific enforcement decisions exist yet given the phased commencement; the CCI's Rs 213-crore fine against Meta/WhatsApp (Nov 2024, upheld on appeal) is a competition-law action, not a DPDPA enforcement action, but is noted as adjacent context.

Claims (1):

  • India's Competition Commission (CCI) fined Meta and WhatsApp approximately Rs 213 crore (~USD24 million) in a November 2024 order over a 2021 WhatsApp privacy-policy data-sharing update, a penalty upheld on appeal though a related data-sharing ban was reversed.

Regulator Funding And CapacityAmber

The DPBI is constituted as a four-person board, established immediately upon the 13 Nov 2025 Rules notification.

Claims (1):

  • Rules for the establishment of the four-person Data Protection Board of India took force with their publication in the Official Gazette on 13 November 2025.

Collective Redress And Class ActionsRed

No DPDPA-specific collective-redress or class-action mechanism was identified in this pass.

Absence provenance: unavailable. Searched: DPDPA class action collective redress data principals.

Private Right Of ActionAmber

The DPDPA provides no statutory right for data principals to claim damages directly; the finalized Rules indicate a DPBI mediation mechanism that may serve as an indirect dispute-settlement route.

Claims (1):

  • The DPDPA provides no statutory right to claim damages, though the new rules indicate a mediation mechanism carried out by the DPBI that may serve as an indirect way for data fiduciaries to settle disputes with data principals.

Recent Developments 180DAmber

A February 2026 secondary-source update reconfirmed the DPIA obligation for Significant Data Fiduciaries under ss.8 and 10 DPDPA and Rule 13 of the DPDP Rules, within the broader 18-month phased-commencement window running to 13 May 2027.

Claims (1):

  • DPIAs are mandated only for Significant Data Fiduciaries under the DPDPA and DPDP Rules, required when processing is likely to result in high risk to individuals' rights, and must be conducted once every 12 months, per Sections 8 and 10 of the DPDPA and Rule 13 of the DPDP Rules.
Category narrative96 words

The DPBI's penalty framework is monetary-only (no criminal penalties), with fines able to reach INR 250 crore (~USD27M) for 'significant' non-compliance, assessed on nature/gravity/duration/repetition factors rather than turnover. There is no statutory right to claim damages, though DPBI may offer a mediation mechanism. The Board itself (four members) is already constituted and operational. A February 2026 update confirms DPIA obligations under ss.8/10 DPDPA and Rule 13. Separately, India's Competition Commission (CCI) fined Meta/WhatsApp ~Rs 213 crore in Nov 2024 under competition law (not DPDPA) — noted as adjacent enforcement-environment context. No DPDPA-specific collective-redress/class-action mechanism was identified.

Periodic update · new data 2026-09-28

Enforcement & Redress

The Data Protection Board of India, established via the 13 November 2025 notification, holds the power to impose penalties of up to INR 250 crore per violation for security-safeguard failures under the Digital Personal Data Protection Act's penalty schedule — the ceiling for the most severe violation class under the Act. That penalty power is, however, currently the subject of a genuine and unresolved conflict in available reporting. One tracker states that the Board had zero members as of July 2026 and could not yet hear complaints or impose fines, while other commentary describes the Board as already operational. Both positions are drawn from sourced reporting and neither is resolved by the material available this cycle; the state of the Board's actual operational capacity should be treated as disputed rather than settled in either direction.

This uncertainty matters because it determines whether the substantial penalty powers created by the Act are currently exercisable in practice, as distinct from existing on paper pending the Board's full staffing. The full substantive-obligation and penalty regime is understood to become enforceable by 13 May 2027, which may resolve, or may simply coincide with, the current staffing ambiguity.

Outlook

Resolution of the Data Protection Board's actual staffing and operational status is the single most consequential open question in India's data-protection enforcement landscape. Until that is clarified, the practical bite of the INR 250 crore maximum penalty and the Board's broader adjudicatory powers should be treated as uncertain rather than confirmed.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (5)
  1. UncertainInternational Association of Privacy Professionals — Sanctions under DPDPA are monetary penalties which, unlike GDPR's turnover-based penalties, may extend to INR 250 crores (approximately USD27 million); the DPDPA imposes no criminal penalties and does not consider business turnover in determining the penalty.observed
  2. UncertainInternational Association of Privacy Professionals — The DPDPA provides no statutory right to claim damages, though the new rules indicate a mediation mechanism carried out by the DPBI that may serve as an indirect way for data fiduciaries to settle disputes with data principals.observed
  3. UncertainInternational Association of Privacy Professionals — Rules for the establishment of the four-person Data Protection Board of India took force with their publication in the Official Gazette on 13 November 2025.observed
  4. UncertainOneTrust DataGuidance — DPIAs are mandated only for Significant Data Fiduciaries under the DPDPA and DPDP Rules, required when processing is likely to result in high risk to individuals' rights, and must be conducted once every 12 months, per Sections 8 and 10 of the DPDPA and Rule 13 of the DPDP Rules.observed
  5. UncertainInternational Association of Privacy Professionals — India's Competition Commission (CCI) fined Meta and WhatsApp approximately Rs 213 crore (~USD24 million) in a November 2024 order over a 2021 WhatsApp privacy-policy data-sharing update, a penalty upheld on appeal though a related data-sharing ban was reversed.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

Blocking. 1 failing check(s).

schema_validpass
min_t1_per_instrument_metwaived
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metFAIL
tier_a_b_national_primary_pct0.0
aggregator_only_jurisdiction_count1
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for India
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 34 claim(s) (34 category placement(s)), 33 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsdeadlines and response windows
Art. 14Data Subject Rightsdeadlines and response windows
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redresscollective redress and class actions
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redressregulator powers and penalties
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, controller_processor_duties, cross_border_and_adequacy, children_and_vulnerable_groups, and enforcement_and_redress achieved solid T2 secondary-source coverage anchored to the 13 Nov 2025 DPDP Rules notification and IAPP's DPDPA operational-impact series. lawful_processing_and_special_data and data_subject_rights are moderately covered but rely on comparative-analysis commentary (T2) rather than direct primary Rule-text citation. sectoral_watch is populated only for financial_sector_overlay (RBI/SEBI, T3 secondary guidance); health, telecoms, employment, credit, education, and insurance sub-modules carry absent_field_provenance. adtech_and_commercial_privacy and algorithmic_biometric_and_surveillance_governance are thinly populated, drawing mainly on the children's-data tracking/targeted-advertising ban and the state-exemption criticism; cookies/trackers, dark patterns, opt-out signals, clean rooms, ADM transparency, biometric, and genetic sub-modules are unaddressed. No direct access to the official Gazette-published DPDPA Act text, the full DPDP Rules 2025 text, or the DPBI's own website was achieved in this pass — all findings rest on T2/T3 secondary legal-industry analysis (principally IAPP and OneTrust DataGuidance), and the seed file gdpri-baseline-seeds-T1T2.json for JID=IN was not directly retrievable via the tools available to this research station.

Unresolved questions (6):

  • What is the exact statutory/Rule-specified breach-notification timeline (hours) owed to the DPBI and to affected data principals?
  • What precise volume/sensitivity/risk thresholds will the government use to designate 'Significant Data Fiduciaries'?
  • Will the Minister's stated intent (Nov 2025) to shorten the 18-month compliance deadline to 12 months be formally notified, and if so, on what date?
  • What is the definitive list (if any) of countries the central government has notified as transfer-restricted under s.16?
  • Are there sector-specific DP overlays for health, telecoms, employment, credit-scoring, education, or insurance in India that interact with the DPDPA?
  • What specific mechanisms exist (if any) for collective redress or class actions by data principals under DPDPA?

Escalate to primary-source review: yes