🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
IN · run data-protection-2026-08-03 v13-gdpri-1.0.0
content: ai_generated 20 sources retrieved model claude-sonnet-5 ·

India

IN schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 34 claims · 20 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
34Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Regulator now exists and rules are finalized (not draft), but the material scope, territorial scope and registration provisions are enacted-but-not-yet-effective pending the 13 May 2027 commencement date.

Primary frameworkDigital Personal Data Protection Act, 2023 (DPDPA) and Digital Personal Data Protection Rules, 2025
Supervisory authorityData Protection Board of India (DPBI)
Traffic-light rationale — AmberRegulator now exists and rules are finalized (not draft), but the material scope, territorial scope and registration provisions are enacted-but-not-yet-effective pending the 13 May 2027 commencement date.

Sub-modules (5)

Regulator And AuthorityGreen

The DPBI is a four-person board constituted immediately upon the 13 Nov 2025 notification of the Rules, with its establishment and operational powers already in force.

Claims: CLM-IN-a1b2c301

Act And InstrumentsAmber

DPDPA 2023 plus the Digital Personal Data Protection Rules, 2025 form the omnibus instrument; implementation is phased with full applicability 13 May 2027.

Claims: CLM-IN-a1b2c302

Material ScopeAmber

DPDPA applies only to digital personal data (including offline data subsequently digitized); non-digitized data, domestic/personal-use processing, and lawfully public data are excluded.

Claims: CLM-IN-a1b2c303

Territorial ScopeAmber

The Act has extraterritorial reach, applying to processing outside India where connected to offering goods/services to data principals within India.

Claims: CLM-IN-a1b2c304

Regulator Registration And FilingAmber

Consent Manager registration and functioning rules apply 12 months after the 13 Nov 2025 finalization (i.e., ~13 Nov 2026); general data-fiduciary registration/filing thresholds beyond consent managers were not identified in this pass.

Claims: CLM-IN-a1b2c305

Category narrative67 words

India's Digital Personal Data Protection Act, 2023 (DPDPA) was enacted August 2023 but remained non-operational until the Ministry of Electronics and Information Technology (MeitY) notified the Digital Personal Data Protection Rules, 2025 on 13 November 2025. The Rules establish the Data Protection Board of India (DPBI) as enforcement authority (effective immediately), while the bulk of substantive obligations phase in over 18 months, becoming applicable 13 May 2027.

Sources and claims (5)
  1. ConfirmedInternational Association of Privacy ProfessionalsThe Data Protection Board of India's establishment and operational/powers provisions were brought into force immediately upon the 13 November 2025 notification of the DPDP Rules, 2025.
  2. ConfirmedInternational Association of Privacy ProfessionalsThe DPDPA becomes applicable to all entities and government departments 18 months after the 13 November 2025 Rules notification, i.e., 13 May 2027.
  3. ConfirmedOneTrust DataGuidanceDPDPA applies to the processing of digital personal data within India, excluding non-digitized offline data, personal data processed for domestic use, and data made publicly available.
  4. ConfirmedOneTrust DataGuidanceDPDPA also applies to processing outside India if the processing relates to activity connected with offering goods or services to data principals within India.
  5. ConfirmedInternational Association of Privacy ProfessionalsRules on the registration and functioning of consent managers apply 12 months after the finalization of the DPDP Rules (from 13 Nov 2025).

#

Lawful-basis and consent architecture is well documented; special-category and pseudonymisation treatment diverges structurally from GDPR and required an explicit absence finding for pseudonymisation.

Primary frameworkDigital Personal Data Protection Act, 2023, ss. on consent and legitimate uses
Supervisory authorityData Protection Board of India (DPBI)
Traffic-light rationale — AmberLawful-basis and consent architecture is well documented; special-category and pseudonymisation treatment diverges structurally from GDPR and required an explicit absence finding for pseudonymisation.

Sub-modules (4)

Lawful BasesAmber

Consent is the primary basis; the Act prescribes nine additional 'legitimate use' grounds not requiring consent.

Claims: CLM-IN-b2c3d401

Special CategoriesAmber

Unlike GDPR, DPDPA treats all personal data uniformly and does not impose heightened obligations for sensitive/special-category data.

Claims: CLM-IN-b2c3d403

Pseudonymisation And AnonymisationRed

No statutory pseudonymisation or anonymisation definition/safe-harbour provision was located in the DPDPA, its Rules, or secondary commentary reviewed in this pass.

Absence provenance: not recorded. Searched: DPDPA pseudonymisation anonymisation safe harbour India, India Digital Personal Data Protection Rules anonymised data definition.

Category narrative49 words

DPDPA is consent-centric but supplements consent with nine statutory 'legitimate uses' grounds. Consent must be free, specific, informed, unconditional and unambiguous. Notably, the Act does not create a GDPR-style special/sensitive-category regime — all personal data is treated uniformly. No statutory pseudonymisation/anonymisation safe-harbour provisions were identified in this research pass.

Sources and claims (3)
  1. ConfirmedInternational Association of Privacy ProfessionalsDPDPA prescribes nine additional grounds for processing personal data beyond consent, defined as 'legitimate uses,' including use of voluntarily provided data for a specified purpose where the data principal has not objected.
  2. ConfirmedInternational Association of Privacy ProfessionalsThe DPDPA's consent-centric framework requires that consent obtained from data principals be free, specific, informed, unconditional, and unambiguous.
  3. ConfirmedInternational Association of Privacy ProfessionalsThe DPDPA treats all personal data uniformly without imposing heightened obligations for sensitive personal data, diverging from the GDPR's special-category regime.

#

Core rights are documented via secondary legal analysis, but portability, restriction/objection, and precise deadline mechanics require primary Rule-text confirmation.

Primary frameworkDigital Personal Data Protection Act, 2023, Chapter III (Data Principal Rights)
Supervisory authorityData Protection Board of India (DPBI)
Traffic-light rationale — AmberCore rights are documented via secondary legal analysis, but portability, restriction/objection, and precise deadline mechanics require primary Rule-text confirmation.

Sub-modules (5)

Access RightAmber

Data principals have a codified right of access to their personal data held by fiduciaries.

Claims: CLM-IN-c3d4e501

Rectification And ErasureAmber

Rights of correction and erasure ('completion') are codified alongside access.

Claims: CLM-IN-c3d4e501

Restriction And ObjectionRed

No explicit generalized right to restrict processing or object (analogous to GDPR Art 18/21) was identified; rights are limited to access, correction, completion, and nomination.

Claims: CLM-IN-c3d4e502

Data PortabilityRed

DPDPA does not include an explicit data-portability right comparable to GDPR Art 20.

Claims: CLM-IN-c3d4e502

Deadlines And Response WindowsRed

No specific statutory response-deadline window for data-principal requests or grievance redressal was located in the secondary sources reviewed.

Absence provenance: not recorded. Searched: DPDPA grievance redressal response deadline days, DPDP Rules 2025 data principal request timeline.

Category narrative53 words

Data principals are granted a narrower set of codified rights than under GDPR/CCPA: access, correction, erasure ('completion'), grievance redressal, and the right to nominate a representative. There is no explicit statutory data-portability right or generalized right to object/restrict processing, and no specific statutory response-deadline window was identified for grievance handling in this pass.

Sources and claims (2)
  1. ConfirmedInternational Association of Privacy ProfessionalsDPDPA codifies data principal rights including access, correction, erasure, grievance redressal, and the right to nominate another person to exercise rights on the data principal's behalf.
  2. ProbableInternational Association of Privacy ProfessionalsUnlike the GDPR and CCPA, the rights available to data principals under the DPDPA are limited to access, correction, completion, and nomination, with no explicit portability or general objection/restriction right.

#

Strong secondary-source coverage of DPIA/DPO/breach/retention duties, but exact SDF designation thresholds and breach-notification timelines await primary Rule-text confirmation.

Primary frameworkDigital Personal Data Protection Act, 2023 ss. 8-10; Digital Personal Data Protection Rules, 2025
Supervisory authorityData Protection Board of India (DPBI)
Traffic-light rationale — AmberStrong secondary-source coverage of DPIA/DPO/breach/retention duties, but exact SDF designation thresholds and breach-notification timelines await primary Rule-text confirmation.

Sub-modules (7)

Accountability And DpiaAmber

DPIAs are mandated only for Significant Data Fiduciaries, required once every 12 months.

Claims: CLM-IN-d4e5f601

Dpo RequirementsAmber

Only Significant Data Fiduciaries must appoint an India-based DPO, accountable to the board of directors/governing body rather than required to be independent.

Claims: CLM-IN-d4e5f602

Ropa RequirementsRed

DPDPA does not require data fiduciaries to maintain formal records of processing activities as under GDPR Art 30, though practical record-keeping may be needed to demonstrate consent compliance.

Claims: CLM-IN-d4e5f603

Joint Controller ArrangementsAmber

Regulation of data processors is minimal, with only a handful of provisions; the law is focused almost entirely on data-fiduciary obligations.

Claims: CLM-IN-d4e5f604

Security MeasuresAmber

Data fiduciaries must implement reasonable technical and organisational security safeguards to prevent a personal data breach.

Claims: CLM-IN-d4e5f605

Breach NotificationAmber

Fiduciaries must notify the DPBI and affected data principals of personal data breaches; the finalized Rules clarify notification requirements, though the precise notification-hour timeline needs primary-text confirmation.

Claims: CLM-IN-d4e5f606

Retention And DisposalAmber

The finalized Rules impose a new one-year minimum retention requirement on data fiduciaries, primarily to facilitate responses to state-agency requests (national security, investigations, SDF determination).

Claims: CLM-IN-d4e5f607

Category narrative82 words

Data fiduciaries bear the core compliance burden (processors are lightly regulated). Significant Data Fiduciaries (SDFs) — a government-designated class — face heightened duties: DPIAs every 12 months, an India-based DPO reporting to the board/governing body, and periodic independent audits. General fiduciaries must implement 'reasonable security safeguards' and notify breaches to the DPBI and affected principals. The finalized Rules add a new one-year minimum data-retention requirement for specified purposes (national security, investigations, SDF determination). No GDPR Art 30-style records-of-processing (ROPA) requirement was identified.

Sources and claims (7)
  1. ConfirmedInternational Association of Privacy ProfessionalsOnly entities classified as Significant Data Fiduciaries are required to conduct a DPIA, and must do so every 12 months.
  2. ConfirmedInternational Association of Privacy ProfessionalsThe DPDPA requires all Significant Data Fiduciaries to appoint a DPO based out of India, who must represent the significant data fiduciary and be accountable to its board of directors or governing body.
  3. ConfirmedInternational Association of Privacy ProfessionalsThe DPDPA does not require data fiduciaries to maintain a formal record of processing activities, unlike GDPR Art 30.
  4. ConfirmedInternational Association of Privacy ProfessionalsIn the DPDPA, regulation of data processors is minimal, with only a handful of provisions on the topic, with the law focused almost entirely on data fiduciaries.
  5. ConfirmedInternational Association of Privacy ProfessionalsData fiduciaries are required to protect personal data under their control or possession and implement necessary security safeguards to prevent a personal data breach.
  6. ConfirmedInternational Association of Privacy ProfessionalsThe finalized DPDP Rules, 2025 cover data breach notification requirements to the Data Protection Board of India and affected data principals.
  7. ConfirmedInternational Association of Privacy ProfessionalsThe final DPDP Rules impose a new one-year minimum retention requirement on data fiduciaries, primarily to facilitate responses to state agency requests related to national security, investigations, and determination of significant data fiduciary status.

#

The blacklist mechanism is well documented, but no country has yet been notified as restricted, and sector-specific localisation interacts with, rather than is superseded by, the DPDPA.

Primary frameworkDigital Personal Data Protection Act, 2023, s.16
Supervisory authorityData Protection Board of India (DPBI)
Traffic-light rationale — AmberThe blacklist mechanism is well documented, but no country has yet been notified as restricted, and sector-specific localisation interacts with, rather than is superseded by, the DPDPA.

Sub-modules (6)

Transfer MechanismsAmber

Transfers are permitted unless the central government designates a jurisdiction as restricted via notification — a 'blacklist' rather than 'whitelist' model.

Claims: CLM-IN-e5f6a701

Adequacy ReceivedRed

India has not received an adequacy decision from another regime under the DPDPA framework, as the Act does not employ an adequacy-decision concept at all.

Claims: CLM-IN-e5f6a702

Adequacy GrantedRed

India does not grant adequacy decisions to other jurisdictions under DPDPA; the Act substitutes a government-notified restricted-country list for the adequacy concept.

Claims: CLM-IN-e5f6a702

Sccs And BcrsRed

No statutory SCC or BCR mechanism is prescribed under the DPDPA; transfers rely on the default-permitted/blacklist model instead.

Absence provenance: not recorded. Searched: DPDPA standard contractual clauses binding corporate rules India.

Transfer Impact AssessmentRed

No transfer-impact-assessment requirement was identified under the DPDPA or its Rules.

Absence provenance: not recorded. Searched: DPDPA transfer impact assessment requirement.

Data LocalisationAmber

DPDPA itself does not impose blanket data localisation, but sector-specific localisation rules (e.g., RBI payment-system data, SEBI cloud framework) continue to apply alongside it.

Claims: CLM-IN-e5f6a703

Category narrative68 words

DPDPA departs from the EU adequacy model. Under s.16(1), international transfers are permitted by default; the central government may notify a 'blacklist' of restricted countries rather than a positive 'whitelist' of adequate jurisdictions. No SCC/BCR mechanism is statutorily mandated. Sector-specific data-localisation rules (RBI payment-system data, SEBI cloud-adoption framework) continue to operate as a stricter baseline alongside the DPDPA. No transfer-impact-assessment requirement analogous to Schrems-II TIA practice was identified.

Sources and claims (3)
  1. ConfirmedInternational Association of Privacy ProfessionalsThe DPDPA adopts a liberalized 'blacklisting' model under which the central government can notify specific countries to which data flow may be restricted, in contrast to the EU's 'whitelisting' adequacy approach.
  2. ConfirmedInternational Association of Privacy ProfessionalsThe DPDPA generally allows international data transfers except where the government restricts transfers to specific countries, departing from an adequacy-based transfer method entirely.
  3. ConfirmedOneTrust DataGuidanceSector-specific guidance from regulators such as the RBI and SEBI, mandating financial datasets to be stored in India, operates alongside the DPDPA's baseline transfer rule.

#

Financial-sector overlay is well evidenced; other sectoral sub-modules require targeted follow-up research against sector regulator (RBI, IRDAI, TRAI, UGC/health-ministry) primary sources.

Primary frameworkRBI/SEBI sectoral directions operating alongside DPDPA s.16
Supervisory authorityReserve Bank of India (RBI)
Traffic-light rationale — AmberFinancial-sector overlay is well evidenced; other sectoral sub-modules require targeted follow-up research against sector regulator (RBI, IRDAI, TRAI, UGC/health-ministry) primary sources.

Sub-modules (7)

Financial Sector OverlayAmber

RBI Master Directions on Cyber Resilience and Digital Payment Security Controls, and SEBI's cloud-adoption framework, mandate India-based storage of specified financial datasets, operating alongside DPDPA.

Claims: CLM-IN-f6a7b801

Health Sector OverlayRed

No health-sector-specific DP overlay (e.g., Ayushman Bharat Digital Mission rules) was surfaced in this pass.

Absence provenance: not recorded. Searched: India health data protection ABDM DPDPA overlay.

Telecoms And EprivacyRed

No telecoms/ePrivacy-equivalent overlay (e.g., TRAI subscriber-data rules interacting with DPDPA) was surfaced in this pass.

Absence provenance: not recorded. Searched: India TRAI subscriber data DPDPA telecom overlay.

Employment DataRed

No employment-sector-specific DP overlay was surfaced in this pass.

Absence provenance: not recorded. Searched: India employment data DPDPA employer overlay.

Credit And ScoringRed

No credit-scoring-specific DP overlay (beyond general DPIA relevance to credit checks) was surfaced in this pass.

Absence provenance: not recorded. Searched: India credit scoring DPDPA overlay CIBIL.

EducationRed

No education-sector-specific DP overlay was surfaced in this pass.

Absence provenance: not recorded. Searched: India education sector DPDPA overlay.

InsuranceRed

No insurance-sector-specific DP overlay (e.g., IRDAI rules) was surfaced in this pass.

Absence provenance: not recorded. Searched: India IRDAI insurance data DPDPA overlay.

Category narrative55 words

The clearest sectoral overlay identified is financial services: RBI Master Directions on cyber resilience/payment-data localisation and SEBI cloud-adoption rules mandate in-India storage of specified datasets and operate as a stricter baseline alongside the DPDPA's general transfer rule. No specific health, telecoms/ePrivacy, employment, credit-scoring, education, or insurance sectoral DP overlays were surfaced in this research pass.

Sources and claims (1)
  1. ConfirmedOneTrust DataGuidanceSector-specific guidance released by regulators such as the RBI and SEBI, mandating financial datasets to be stored in India, operates alongside the DPDPA.

#

Only the children-targeted-advertising ban was substantiated; broader adtech sub-modules are largely unaddressed by the DPDPA and require dedicated follow-up.

Primary frameworkDigital Personal Data Protection Act, 2023, s.9 (children)
Supervisory authorityData Protection Board of India (DPBI)
Traffic-light rationale — AmberOnly the children-targeted-advertising ban was substantiated; broader adtech sub-modules are largely unaddressed by the DPDPA and require dedicated follow-up.

Sub-modules (6)

Cookies And TrackersRed

No dedicated cookie/tracker consent regime analogous to EU ePrivacy was identified under DPDPA.

Absence provenance: not recorded. Searched: DPDPA cookie consent tracker regime India.

Dark PatternsRed

No dark-pattern-specific statutory prohibition under DPDPA was identified (India has separate CCPA/ASCI consumer-protection guidelines on dark patterns, outside DP scope).

Absence provenance: not recorded. Searched: DPDPA dark patterns prohibition.

Opt Out SignalsRed

No recognition of universal opt-out signals (e.g., Global Privacy Control) was identified under DPDPA.

Absence provenance: not recorded. Searched: DPDPA global privacy control opt-out signal.

Clean Rooms And DcrRed

No clean-room/data-collaboration-room-specific rule was identified under DPDPA.

Absence provenance: not recorded. Searched: DPDPA data clean room rules.

Cross Context AdvertisingAmber

DPDPA prohibits behavioral monitoring, tracking, or targeted advertising directed at children, functioning as a narrow cross-context-advertising restriction limited to minors.

Claims: CLM-IN-a7b8c901

Direct MarketingAmber

No general direct-marketing consent/suppression regime distinct from the consent-and-legitimate-use framework was identified, aside from the children's targeted-advertising ban.

Claims: CLM-IN-a7b8c901

Category narrative47 words

DPDPA does not contain a GDPR-ePrivacy-style dedicated cookie/tracker consent regime. The clearest adtech-relevant provision is the children's-data ban on tracking, behavioral monitoring and targeted advertising directed at children. No dark-pattern-specific prohibition, opt-out-signal (e.g., GPC) recognition, clean-room/DCR rule, or general cross-context 'sale/share' concept analogous to CPRA was identified.

Sources and claims (1)
  1. ConfirmedInternational Association of Privacy ProfessionalsData fiduciaries are prohibited from undertaking processing that involves tracking, behavioral monitoring of children, or targeted advertising directed at children, subject to narrow prescribed exemptions.

#

Profiling restriction and state-exemption findings are sourced; ADM transparency, AI risk assessment, biometric and genetic sub-modules remain unaddressed by DPDPA and require dedicated follow-up (and cross-reference to the AI-governance surface).

Primary frameworkDigital Personal Data Protection Act, 2023, s.9 (children) and exemption provisions
Supervisory authorityData Protection Board of India (DPBI)
Traffic-light rationale — AmberProfiling restriction and state-exemption findings are sourced; ADM transparency, AI risk assessment, biometric and genetic sub-modules remain unaddressed by DPDPA and require dedicated follow-up (and cross-reference to the AI-governance surface).

Sub-modules (6)

Profiling RestrictionsAmber

Behavioral monitoring, tracking, or profiling of children is prohibited except for certain essential services (health care, education, real-time safety).

Claims: CLM-IN-b8c9d001

Automated Decision Making TransparencyRed

No general Art 22-style automated-decision-making transparency/explanation right was identified under DPDPA.

Absence provenance: not recorded. Searched: DPDPA automated decision making transparency right.

Ai Risk AssessmentsAmber

MeitY released the India AI Governance Guidelines in November 2025 as a separate, non-DPDPA instrument; no DPDPA-specific AI-risk-assessment mandate was identified.

Claims: CLM-IN-b8c9d003

Biometric RegimeRed

No DPDPA-specific biometric-data regime (facial recognition, fingerprint, gait) was identified in this pass.

Absence provenance: not recorded. Searched: DPDPA biometric data facial recognition regime India.

Genetic DataRed

No DPDPA-specific genetic-data regime was identified in this pass.

Absence provenance: not recorded. Searched: DPDPA genetic data regime India.

State Surveillance CarveoutsAmber

DPDPA contains broad exemptions permitting government and government-instrumentality processing, including for national security purposes, which Justice B.N. Srikrishna (former Expert Committee chair) has criticized as a source of concern.

Claims: CLM-IN-b8c9d002

Category narrative68 words

DPDPA's algorithmic-governance content is limited: a children-specific profiling/behavioral-monitoring ban, and broad government/state exemptions (including for national security) that have drawn criticism from Justice B.N. Srikrishna for granting excessive latitude to the state. Separately, MeitY released non-DPDPA India AI Governance Guidelines in November 2025, relevant context but not a DPDPA-binding obligation. No Art 22-style ADM-transparency right, dedicated AI-risk-assessment mandate, biometric-specific regime, or genetic-data regime was identified within DPDPA itself.

Sources and claims (3)
  1. ConfirmedInternational Association of Privacy ProfessionalsData fiduciaries are prohibited from undertaking processing that involves tracking or behavioral monitoring of children, except when providing certain essential services such as health care, education, or real-time safety.
  2. ConfirmedInternational Association of Privacy ProfessionalsProvisions granting exemptions to the government and government bodies under the DPDPA have been described by Justice B.N. Srikrishna, former chair of the Expert Committee on Data Protection, as causing 'great concern.'
  3. ProbableInternational Association of Privacy ProfessionalsMeitY released the India Artificial Intelligence Governance Guidelines on 5 November 2025, a separate non-DPDPA instrument relevant to algorithmic governance context.

#

Core child/dependent-adult consent architecture is well sourced from the finalized Rules; education-settings sub-module remains unaddressed.

Primary frameworkDigital Personal Data Protection Act, 2023, s.9; Digital Personal Data Protection Rules, 2025
Supervisory authorityData Protection Board of India (DPBI)
Traffic-light rationale — AmberCore child/dependent-adult consent architecture is well sourced from the finalized Rules; education-settings sub-module remains unaddressed.

Sub-modules (5)

Age VerificationAmber

DPDPA defines a child as an individual under age 18; businesses must confirm the guardian/parent is an adult.

Claims: CLM-IN-c9d0e101

Minor Profiling BansAmber

Tracking, behavioral monitoring, and targeted advertising directed at children are prohibited, subject to prescribed exemptions for certain classes of fiduciaries or purposes.

Claims: CLM-IN-c9d0e103

Education SettingsRed

No education-setting-specific children's-data rule distinct from the general minor-consent regime was identified in this pass.

Absence provenance: not recorded. Searched: DPDPA education sector children data rules India.

Dependent AdultsAmber

For individuals with disabilities, consent must be obtained from their lawful guardian, verified in accordance with India's guardianship laws.

Claims: CLM-IN-c9d0e104

Category narrative55 words

DPDPA defines a child as under 18 and mandates verifiable parental/guardian consent before processing a child's data, with the finalized Rules elaborating mechanisms including digital-locker-based parental verification. Narrow exemptions apply for health/safety purposes. Persons with disabilities also require lawful-guardian consent, verified per India's guardianship laws. No education-setting-specific carve-out beyond the general children's regime was identified.

Sources and claims (4)
  1. ConfirmedInternational Association of Privacy ProfessionalsThe DPDPA defines a child as an individual under age 18 for purposes of the parental/guardian consent requirement.
  2. ConfirmedInternational Association of Privacy ProfessionalsVerifiable consent must be obtained from the parent or lawful guardian before processing a child's personal data; the finalized Rules elaborate mechanisms such as digital-locker-based parental verification, with narrowly defined health- and safety-specific exemptions.
  3. ConfirmedInternational Association of Privacy ProfessionalsData fiduciaries are prohibited from processing that involves tracking, behavioral monitoring, or targeted advertising directed at children, though the government may notify exempt classes of fiduciaries.
  4. ConfirmedInternational Association of Privacy ProfessionalsFor individuals with disabilities, consent must be obtained from their lawful guardian, who must be verified in accordance with India's guardianship laws.

#

Penalty framework and Board constitution are well documented; enforcement-activity track record under DPDPA itself is not yet available since substantive obligations are not yet effective, and collective-redress mechanisms remain unconfirmed.

Primary frameworkDigital Personal Data Protection Act, 2023, Chapter on Data Protection Board and Penalties
Supervisory authorityData Protection Board of India (DPBI)
Traffic-light rationale — AmberPenalty framework and Board constitution are well documented; enforcement-activity track record under DPDPA itself is not yet available since substantive obligations are not yet effective, and collective-redress mechanisms remain unconfirmed.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

Monetary penalties for significant non-compliance may extend to INR 250 crore; no criminal penalties are imposed; turnover is not a factor in determining the penalty.

Claims: CLM-IN-d0e1f201

Enforcement Activity IndexAmber

No DPDPA-specific enforcement decisions exist yet given the phased commencement; the CCI's Rs 213-crore fine against Meta/WhatsApp (Nov 2024, upheld on appeal) is a competition-law action, not a DPDPA enforcement action, but is noted as adjacent context.

Claims: CLM-IN-d0e1f205

Regulator Funding And CapacityAmber

The DPBI is constituted as a four-person board, established immediately upon the 13 Nov 2025 Rules notification.

Claims: CLM-IN-d0e1f203

Collective Redress And Class ActionsRed

No DPDPA-specific collective-redress or class-action mechanism was identified in this pass.

Absence provenance: not recorded. Searched: DPDPA class action collective redress data principals.

Private Right Of ActionAmber

The DPDPA provides no statutory right for data principals to claim damages directly; the finalized Rules indicate a DPBI mediation mechanism that may serve as an indirect dispute-settlement route.

Claims: CLM-IN-d0e1f202

Recent Developments 180DAmber

A February 2026 secondary-source update reconfirmed the DPIA obligation for Significant Data Fiduciaries under ss.8 and 10 DPDPA and Rule 13 of the DPDP Rules, within the broader 18-month phased-commencement window running to 13 May 2027.

Claims: CLM-IN-d0e1f204

Category narrative96 words

The DPBI's penalty framework is monetary-only (no criminal penalties), with fines able to reach INR 250 crore (~USD27M) for 'significant' non-compliance, assessed on nature/gravity/duration/repetition factors rather than turnover. There is no statutory right to claim damages, though DPBI may offer a mediation mechanism. The Board itself (four members) is already constituted and operational. A February 2026 update confirms DPIA obligations under ss.8/10 DPDPA and Rule 13. Separately, India's Competition Commission (CCI) fined Meta/WhatsApp ~Rs 213 crore in Nov 2024 under competition law (not DPDPA) — noted as adjacent enforcement-environment context. No DPDPA-specific collective-redress/class-action mechanism was identified.

Sources and claims (5)
  1. ConfirmedInternational Association of Privacy ProfessionalsSanctions under DPDPA are monetary penalties which, unlike GDPR's turnover-based penalties, may extend to INR 250 crores (approximately USD27 million); the DPDPA imposes no criminal penalties and does not consider business turnover in determining the penalty.
  2. ConfirmedInternational Association of Privacy ProfessionalsThe DPDPA provides no statutory right to claim damages, though the new rules indicate a mediation mechanism carried out by the DPBI that may serve as an indirect way for data fiduciaries to settle disputes with data principals.
  3. ConfirmedInternational Association of Privacy ProfessionalsRules for the establishment of the four-person Data Protection Board of India took force with their publication in the Official Gazette on 13 November 2025.
  4. ConfirmedOneTrust DataGuidanceDPIAs are mandated only for Significant Data Fiduciaries under the DPDPA and DPDP Rules, required when processing is likely to result in high risk to individuals' rights, and must be conducted once every 12 months, per Sections 8 and 10 of the DPDPA and Rule 13 of the DPDP Rules.
  5. ConfirmedInternational Association of Privacy ProfessionalsIndia's Competition Commission (CCI) fined Meta and WhatsApp approximately Rs 213 crore (~USD24 million) in a November 2024 order over a 2021 WhatsApp privacy-policy data-sharing update, a penalty upheld on appeal though a related data-sharing ban was reversed.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for India
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 34 claim(s), 20 source(s) in the cumulative register.