India Passes Digital Personal Data Protection Rules Under DPDP Act
The Ministry of Electronics and IT has formally notified the rules under the Digital Personal Data Protection Act, setting compliance timelines for tech companies operating in India.
Digital privacy and data protection concept illustration
The Ministry of Electronics and Information Technology notified the final rules under the Digital Personal Data Protection Act on Monday, marking a pivotal moment for data governance in India.
Key Provisions
The rules mandate that any company processing personal data of Indian citizens must appoint a Data Protection Officer, publish a clear privacy policy in local languages, and comply with data deletion requests within 30 days.
Compliance Timeline
Large tech platforms with more than 50 million Indian users must comply within 6 months. Smaller businesses have 18 months. The Data Protection Board, the enforcement body, will begin accepting complaints from January 2027.
Impact on Tech Companies
Global technology companies including Google, Meta, Apple, and Amazon will need to make significant changes to their data practices. Companies that fail to comply face penalties of up to ₹250 crore per violation.
Industry Reaction
Industry body NASSCOM has welcomed the rules but has sought clarifications on cross-border data transfer restrictions, which could affect how Indian data is processed by global cloud providers.