The Slow March of the DPDP Act: Where Data Protection Actually Stands

adeebtamseel123@gmail.com Avatar

India’s Digital Personal Data Protection Act received presidential assent in August 2023, making it, on paper, India’s first comprehensive data protection statute. What often surprises students encountering the Act for the first time is how long the gap has been between assent and actual, operative enforcement — a gap the Digital Personal Data Protection Rules, 2025, notified in the Official Gazette, only partially close through a phased roll-out that extends well into 2027.

What Is Actually in Force Right Now

The Data Protection Board of India and the Act’s core definitions took effect immediately upon notification of the 2025 Rules. Registration of “consent managers” — the intermediary entities meant to give individuals a single interface to grant, manage and withdraw consent across multiple data fiduciaries — follows on a roughly twelve-month timeline. The Act’s core substantive obligations on data fiduciaries — purpose limitation, data minimisation, breach notification, and the rights of the “data principal” (India’s statutory term for the data subject) to access, correction and erasure — are slated to commence formally on 14 May 2027, meaning organisations currently have a compliance runway rather than an active enforcement regime.

Why the Staggered Timeline Matters for Practice

For a law student or a young professional advising a business today, this creates an unusual situation: the DPDP Act already shapes contract drafting, privacy-policy language and internal data-governance practice as a matter of prudent anticipation, even though its penalty provisions are not yet fully operative. Sophisticated counsel are treating the 2027 commencement date the way corporate lawyers once treated GDPR’s 2018 enforcement date — as a hard deadline to build toward, not a distant abstraction.

The AI Connection

The DPDP Act’s consent requirements have become the primary binding legal constraint on how Indian AI developers can lawfully source training data, since the Act prohibits scraping or otherwise using personal data to train large language models or other neural networks without explicit, unambiguous consent from the data principal. This makes the DPDP Act, somewhat unexpectedly, the closest thing India currently has to binding AI regulation for the specific problem of training-data provenance — reinforcing the broader point that Indian AI governance is emerging through the interaction of several statutes rather than a single dedicated law.

Comparative Context

Unlike the GDPR’s extraterritorial “adequacy” architecture, the DPDP Act applies to processing of digital personal data within India and to processing outside India connected with offering goods or services to individuals in India — a jurisdictional test closer to the GDPR’s own extraterritorial reach than critics initially expected, though India has notably not adopted a GDPR-style independent supervisory authority model; the Data Protection Board’s composition and appointment process remain government-controlled in ways that privacy advocates have flagged as a structural independence concern.

What to Watch

The consent-manager ecosystem taking shape over the next year will be the first real test of whether the DPDP framework functions in practice or remains, like several of India’s earlier data-protection proposals, a well-drafted statute waiting for its implementing machinery to catch up.

Enjoying this article?

Subscribe to get new posts delivered straight to your inbox. No spam, unsubscribe anytime.

No spam. Unsubscribe anytime.

You may also like

See All Journal →

Leave a Comment

Your email address will not be published. Required fields are marked *