India

India Passes Digital Personal Data Protection Rules Under DPDP Act

The Ministry of Electronics and IT has formally notified the rules under the Digital Personal Data Protection Act, setting compliance timelines for tech companies operating in India.

Synthesized Multi-Source Coverage

Cross-verified and synthesized across 2 independent reporting sources:

Digital privacy and data protection concept illustration

Digital privacy and data protection concept illustration

The Ministry of Electronics and Information Technology notified the final rules under the Digital Personal Data Protection Act on Monday, marking a pivotal moment for data governance in India.

Key Provisions

The rules mandate that any company processing personal data of Indian citizens must appoint a Data Protection Officer, publish a clear privacy policy in local languages, and comply with data deletion requests within 30 days.

Compliance Timeline

Large tech platforms with more than 50 million Indian users must comply within 6 months. Smaller businesses have 18 months. The Data Protection Board, the enforcement body, will begin accepting complaints from January 2027.

Impact on Tech Companies

Global technology companies including Google, Meta, Apple, and Amazon will need to make significant changes to their data practices. Companies that fail to comply face penalties of up to ₹250 crore per violation.

Industry Reaction

Industry body NASSCOM has welcomed the rules but has sought clarifications on cross-border data transfer restrictions, which could affect how Indian data is processed by global cloud providers.

Sources

DPDPData PrivacyIndiaRegulationTech Policy