India’s Digital Personal Data Protection Act received presidential assent in August 2023, making it, on paper, India’s first comprehensive data protection statute. What often surprises students encountering the Act for the first time is how long the gap has been between assent and actual, operative enforcement — a gap the Digital Personal Data Protection Rules, 2025, notified in the Official Gazette, only partially close through a phased roll-out that extends well into 2027.
What Is Actually in Force Right Now
The Data Protection Board of India and the Act’s core definitions took effect immediately upon notification of the 2025 Rules. Registration of “consent managers” — the intermediary entities meant to give individuals a single interface to grant, manage and withdraw consent across multiple data fiduciaries — follows on a roughly twelve-month timeline. The Act’s core substantive obligations on data fiduciaries — purpose limitation, data minimisation, breach notification, and the rights of the “data principal” (India’s statutory term for the data subject) to access, correction and erasure — are slated to commence formally on 14 May 2027, meaning organisations currently have a compliance runway rather than an active enforcement regime.
Why the Staggered Timeline Matters for Practice
For a law student or a young professional advising a business today, this creates an unusual situation: the DPDP Act already shapes contract drafting, privacy-policy language and internal data-governance practice as a matter of prudent anticipation, even though its penalty provisions are not yet fully operative. Sophisticated counsel are treating the 2027 commencement date the way corporate lawyers once treated GDPR’s 2018 enforcement date — as a hard deadline to build toward, not a distant abstraction.
The AI Connection
The DPDP Act’s consent requirements have become the primary binding legal constraint on how Indian AI developers can lawfully source training data, since the Act prohibits scraping or otherwise using personal data to train large language models or other neural networks without explicit, unambiguous consent from the data principal. This makes the DPDP Act, somewhat unexpectedly, the closest thing India currently has to binding AI regulation for the specific problem of training-data provenance — reinforcing the broader point that Indian AI governance is emerging through the interaction of several statutes rather than a single dedicated law.
Comparative Context
Unlike the GDPR’s extraterritorial “adequacy” architecture, the DPDP Act applies to processing of digital personal data within India and to processing outside India connected with offering goods or services to individuals in India — a jurisdictional test closer to the GDPR’s own extraterritorial reach than critics initially expected, though India has notably not adopted a GDPR-style independent supervisory authority model; the Data Protection Board’s composition and appointment process remain government-controlled in ways that privacy advocates have flagged as a structural independence concern.
What to Watch
The consent-manager ecosystem taking shape over the next year will be the first real test of whether the DPDP framework functions in practice or remains, like several of India’s earlier data-protection proposals, a well-drafted statute waiting for its implementing machinery to catch up.
Leave a Comment