DATA PRIVACY

Data Privacy in India

17 April 2026 |

7 min read

India's digital personal data protection regime is now fully operative. The Digital Personal Data Protection Act, 2023 ("DPDP Act") received Presidential assent on 11 August 2023.¹ The Digital Personal Data Protection Rules, 2025 ("DPDP Rules") were notified on 13 November 2025 under Gazette Notification G.S.R. 846(E), bringing the implementation framework into effect.² Together, the Act and the Rules constitute the most significant overhaul of India's data governance architecture since the Information Technology Act, 2000 – and the first comprehensive rights based data protection legislation in the country's history.

This article sets out the architecture of the DPDP framework, identifies the core obligations imposed on data fiduciaries, and situates India's approach within the global data protection landscape.

The architecture of the DPDP framework

Scope and territorial application

The DPDP Act applies to the processing of "digital personal data" – personal data collected in digital form, or personal data collected in non-digital form that is subsequently digitised – within the territory of India, or to the processing of digital personal data outside India where that processing is in connection with "any activity related to offering of goods or services to Data Principals within the territory of India."³

This extra-territorial reach – which mirrors the approach of the General Data Protection Regulation ("GDPR") in the EU – confirms that the DPDP Act applies to any international organisation that offers goods or services to Indian consumers, regardless of where the organisation's data processing infrastructure is located. Global businesses that have previously focused their data protection compliance efforts on GDPR must now conduct a parallel assessment of their DPDP Act obligations in respect of their Indian operations and their Indian customer bases.

The Act applies to "digital personal data" – a defined term that broadly captures any data about an identifiable individual in digital form. Anonymised data – from which it is not possible to identify the individual – falls outside the DPDP framework, consistent with the approach of most comparable international regimes.

The core obligations: Data fiduciaries and data processors

The DPDP Act organises its obligations around two principal categories of actor: the "Data Fiduciary" (the entity that determines the purpose and means of processing – equivalent to the GDPR "controller") and the "Data Processor" (the entity that processes personal data on behalf of a Data Fiduciary – equivalent to the GDPR "processor").⁴

Data Fiduciaries bear the primary compliance burden under the DPDP framework. Their core obligations include:

  1. Lawful basis: Processing must be based on a valid lawful basis. The DPDP Act recognises "consent" and "legitimate uses" – a defined category that encompasses processing for compliance with Indian law, employment-related purposes, public interest functions, and certain other enumerated uses – as the two primary bases. The "legitimate uses" category is narrower than the GDPR's equivalent "legitimate interests" basis, which does not require the basis to be enumerated in the legislation.
  2. Notice: Before or at the time of seeking consent, the Data Fiduciary must provide a notice to the Data Principal in plain language, specifying the personal data to be processed, the purpose of processing, and the manner in which the Data Principal may exercise their rights.⁵
  3. Consent management: Consent under the DPDP Act must be free, specific, informed, unconditional, and unambiguous – requirements consistent with GDPR-standard consent. The DPDP Rules introduce a "Consent Manager" – a registered entity that provides a unified platform through which Data Principals may grant, manage, review, and withdraw consent across multiple Data Fiduciaries.⁶ This is an architecturally distinctive feature of the Indian framework, without a close equivalent in GDPR or any other major data protection regime.
  4. Data Principal rights: The DPDP Act confers a suite of rights on Data Principals: the right to access information about the personal data processed, the right to correction and erasure, the right to grievance redressal, and the right to nominate a representative to exercise data rights in the event of the Data Principal's death or incapacity.
  5. Data retention: Personal data must be erased once the purpose for which it was collected is fulfilled and the Data Principal has not made or is not likely to make any complaint or grievance in relation to the processing. The Data Fiduciary must also ensure that Data Processors erase personal data held on its behalf on the fulfilment of the processing purpose.
  6. Security standards: Data Fiduciaries are required to implement reasonable security safeguards to prevent personal data breaches. The DPDP Rules specify that the standards of security required are those prescribed by the Data Protection Board of India ("DPBI").

Significant data fiduciaries

The DPDP Act introduces the concept of the "Significant Data Fiduciary" ("SDF") – a Data Fiduciary designated as such by the Central Government on the basis of specified criteria, including the volume and sensitivity of personal data processed, the potential impact on national security and public order, and the risk to electoral democracy.⁷ SDFs are subject to additional obligations beyond those applicable to ordinary Data Fiduciaries, including:

  • The appointment of a Data Protection Officer ("DPO"), a senior individual who is a resident of India.
  • The engagement of an independent data auditor to conduct an annual data protection audit.
  • The periodic performance of a Data Protection Impact Assessment ("DPIA") in the prescribed form.
  • Additional restrictions on the transfer of personal data outside India, which may be imposed by the Central Government by notification.

The Central Government has not yet published the final list of entities designated as SDFs. However, the criteria in the DPDP Act and Rules indicate that large technology platforms, financial market infrastructure operators, and major e-commerce entities are likely candidates. Businesses that believe they may qualify for SDF designation should begin preparing for SDF compliance as a precautionary measure.

Cross-border data transfers: The negative list model

Rule 15 of the DPDP Rules operationalises Section 16 of the DPDP Act, which addresses the transfer of personal data outside India. The mechanism adopted is a "negative list" model: transfers are permitted to any jurisdiction unless the Central Government expressly restricts or prohibits transfers to specific countries or territories by notification.⁸

This approach represents a significant departure from the GDPR model, which requires a positive justification for every cross-border transfer (adequacy decision, standard contractual clauses, binding corporate rules, or one of the specified derogations). Under the Indian model, the default position is transfer-permissive, with restrictions imposed only if and when the Central Government identifies specific jurisdiction-level concerns. The practical consequence is that, in the absence of any Central Government notification restricting transfers to specific jurisdictions, organisations may transfer personal data outside India freely – subject to compliance with all other DPDP obligations, including the requirement that any Data Processor outside India complies with the Data Fiduciary's obligations.

The negative list model has been welcomed by industry – particularly by global businesses that operate highly integrated data processing environments across multiple jurisdictions – as avoiding the fragmentation and compliance overhead associated with GDPR's adequacy mechanism. It has attracted criticism from privacy advocacy groups on the grounds that it provides weaker protection for data transferred to jurisdictions without comparable privacy protections.

The Data Protection Board of India

The DPDP Act establishes the Data Protection Board of India as the regulatory authority responsible for adjudicating complaints and determining penalties.⁹ The DPBI is an independent statutory body with a Chairperson and such other members as the Central Government may appoint.

The DPBI has jurisdiction to:

  1. Adjudicate complaints from Data Principals alleging breach of the DPDP Act or Rules.
  2. Take cognisance of personal data breach notifications filed by Data Fiduciaries and investigate the circumstances of the breach.
  3. Impose financial penalties on Data Fiduciaries found to have breached the Act.

The DPDP Act prescribes a tiered penalty structure. The maximum penalty for a Data Fiduciary's failure to implement adequate security safeguards resulting in a personal data breach is INR 250 crore (approximately USD 30 million). Failure to notify the DPBI of a personal data breach attracts a penalty of up to INR 200 crore. The maximum aggregate penalty for multiple violations in a given year is INR 500 crore.¹⁰

These penalty levels are materially lower than GDPR's maximum (4% of global annual turnover or EUR 20 million, whichever is higher). For large global corporations, DPDP penalties may represent a less significant deterrent than GDPR penalties. However, for domestic Indian businesses and smaller international operators, the INR 250 crore ceiling is commercially significant.

Comparative context: The DPDP Act and global frameworks

The DPDP Act has been widely compared with the GDPR, and the comparison is instructive. Both frameworks are rights-based – they confer defined rights on individuals – and both impose obligations on entities that process personal data for commercial purposes. The DPDP Act is, however, architecturally simpler: with 44 sections and 23 rules, it is considerably less granular than GDPR's 99 articles and accompanying recitals.

The DPDP framework is also distinctive in its avoidance of a "legitimate interests" lawful basis beyond the enumerated "legitimate uses" category, its Consent Manager architecture, and its negative-list cross-border transfer model. These design choices reflect India's specific policy priorities: enabling digital economic growth while establishing a rights framework that can evolve through subordinate legislation and government notification, rather than requiring Parliamentary amendment.

The Personal Data Protection Bill 2019 – the predecessor legislation that was withdrawn in 2022 after more than three years of Committee scrutiny – took a materially stricter approach to data localisation on the GDPR adequacy model. The DPDP Act's adoption of the negative list model represents a deliberate policy choice in favour of international data integration.

Practical implications for businesses

Businesses operating in India or offering goods and services to Indian consumers should, as an immediate priority:

  1. Map their data flows to identify the personal data collected from Indian Data Principals, the purposes of processing, and the lawful bases relied upon.
  2. Update their privacy notices to comply with the DPDP Act's notice requirements, in plain language accessible to a non-technically sophisticated audience.
  3. Review consent management mechanisms to ensure that consent obtained by automated means meets the DPDP standard – free, specific, informed, unconditional, and unambiguous.
  4. Implement personal data breach notification procedures consistent with the DPBI notification requirements.
  5. Assess whether they are likely to be designated as SDFs and, if so, begin building the compliance infrastructure – DPO appointment, audit programme, DPIA framework – required.

Conclusion

The DPDP Act and Rules represent a mature and commercially workable data protection framework. India has made deliberate policy choices that distinguish its approach from the GDPR – most notably on cross-border transfers and the "legitimate uses" basis – that reflect the country's ambition to remain a globally integrated digital economy. The framework is now operative, and the window for pre-compliance preparation has closed. Businesses that do not have a DPDP compliance programme in place should treat this as an urgent priority.




Endnotes

¹ Digital Personal Data Protection Act 2023 (India) (Act 22 of 2023; Presidential assent 11 August 2023).

² Digital Personal Data Protection Rules 2025 (Gazette of India, G.S.R. 846(E), 13 November 2025).

³ DPDP Act 2023, s 3.

⁴ DPDP Act 2023, s 2(i) (Data Fiduciary), s 2(k) (Data Processor).

⁵ DPDP Act 2023, s 5.

⁶ DPDP Rules 2025, r 4 (Consent Manager).

⁷ DPDP Act 2023, s 10.

⁸ DPDP Rules 2025, r 15; Digital Personal Data Protection Act 2023, s 16.

⁹ DPDP Act 2023, ss 18-27 (Data Protection Board of India).

¹⁰ DPDP Act 2023, Sch 1 (Penalties).

Authors

Silverlake Advisory
SL

Silverlake Advisory

Silverlake Advisory