Back to the index

India's data protection rules: what starts in November 2026 and what follows in May 2027

The Digital Personal Data Protection Rules, 2025 bring India's 2023 privacy law into force in stages. The rule on 'consent managers' takes effect on 13 November 2026, and most duties for apps, websites and other organisations follow from 13 May 2027. Here is what changes and how you can use your rights.

What changed

  • From 13 November 2026, the rule on registering and running consent managers takes effect.
  • From 13 May 2027, most duties for organisations take effect, including clear consent notices, breach alerts and 90-day responses to your requests.

A law that arrives in stages

Parliament passed the Digital Personal Data Protection Act in August 2023. The rules that put it into practice, the DPDP Rules, 2025, were notified in November 2025; the government's backgrounder dates the notification 14 November 2025. Public consultations held across seven cities produced 6,915 inputs that shaped the final text.

The Rules do not switch on all at once. A few provisions applied immediately. The rule on consent managers starts one year after publication, on 13 November 2026. Most other duties, including consent notices, breach alerts and responses to your requests, start after an eighteen-month phase-in, on 13 May 2027.

What a consent manager is

A consent manager is a single platform through which you can give, manage, review or withdraw your consent to how organisations use your personal data, instead of doing it app by app. Under the Rules, consent managers must be companies based in India, and Rule 4 sets out how they register and what they must do.

Which companies will offer this service, and when their services will open to the public, has not been announced.

What organisations must do from May 2027

Every organisation that decides why and how your personal data is used (a 'data fiduciary') must give you a separate, clear notice explaining the specific purpose for which your data is collected and used.

If your personal data is breached, the organisation must tell you without delay, in plain language: what happened, the likely impact, what it is doing about it, and whom to contact for help.

Organisations must show a contact for questions about personal data, such as a designated officer or a Data Protection Officer. Larger 'significant data fiduciaries' must also carry out independent audits and impact assessments.

Your rights

You can ask an organisation for a copy of your personal data, ask it to correct or update it, and in some situations ask it to erase it. You can nominate someone to exercise these rights for you. Organisations must respond to such requests within ninety days.

For a child's data, organisations need verifiable consent from a parent or guardian, except for essential services such as healthcare, education or real-time safety.

Complaints and penalties

The Data Protection Board of India will work fully digitally, with four members. You will be able to file complaints online and track them through a portal and a mobile app. Appeals against the Board's decisions go to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).

Under the Act, failing to keep reasonable security safeguards can attract a penalty of up to ₹250 crore; failing to report a breach, or breaching duties towards children, up to ₹200 crore each; and other violations up to ₹50 crore.

Why it matters

  • You will be able to see why a service wants your data, say no, or withdraw consent later.
  • You must be told if your data is breached, and you can ask for corrections or deletion.

What remains uncertain

  • Some legal summaries date the gazette notification 13 November 2025, while the government's backgrounder says 14 November 2025; the commencement dates follow the gazette publication date.
  • Which companies will become consent managers, and when their services start, is not yet known.
  • How quickly the Data Protection Board handles complaints will be clearer once its portal and app are running.

Facts and evidence

Official statement

The government notified the DPDP Rules, 2025 on 14 November 2025, according to its backgrounder; the consultation received 6,915 inputs.

Official statement

Rule 4, on registration and obligations of consent managers, comes into force one year after the Rules' publication: 13 November 2026.

Verified deadline: 13 November 2026

Official statement

Data fiduciaries must give a separate, clear notice explaining the specific purpose for collecting and using personal data.

Official statement

Consent managers, which help people manage their permissions, must be companies based in India.

Official statement

After a breach, data fiduciaries must inform affected individuals without delay, in plain language, explaining what happened, the possible impact and steps taken, with contact details for help.

Official statement

Data fiduciaries must respond to requests to access, correct, update or erase personal data within ninety days.

Official statement

Processing a child's data needs verifiable consent from a parent or guardian, except for essential services such as healthcare, education or real-time safety.

Official statement

The Data Protection Board will be fully digital with four members; appeals against its decisions go to TDSAT.

Official statement

Penalties under the Act reach ₹250 crore for failing to keep reasonable security safeguards, ₹200 crore for breach-notification or children's-data violations, and ₹50 crore for other violations.

Official statement

Significant data fiduciaries must conduct independent audits and impact assessments.

Sources

  • Press Information Bureau: Backgrounder: DPDP Rules, 2025 Notified (17 November 2025)Official record · EN

    Backgrounder: DPDP Rules, 2025 Notified (17 November 2025)

    Read the original source
  • Ministry of Electronics and Information Technology: Digital Personal Data Protection Rules, 2025 (full text)Official record · EN / HI

    Digital Personal Data Protection Rules, 2025 (full text)

    Read the original source