At a glanceIndia has passed a dedicated data privacy law (the DPDP Act), notified the detailed rules that make it work, created a regulator — the Data Protection Board of India — to hear complaints, and set financial penalties as high as ₹250 crore for organisations that mishandle your data. Together these give you rights over your information and a body to enforce them.
Educational resource only. This explains the steps behind India’s Digital Personal Data Protection Act, 2023 (DPDP Act) and how it’s being enforced; it is not formal legal advice.
A dedicated privacy law — with rules that bite
The government didn’t just pass a law; it built the machinery to make it real.
India’s first dedicated data privacy law is the Digital Personal Data Protection Act, 2023 (DPDP Act). (For what the law actually is and who it protects, see What’s the new data privacy law in India?) What matters for protection is that the Act didn’t stay on paper: detailed rules were notified in November 2025, turning its broad principles into concrete obligations an organisation can be held to. A law without rules is aspiration — the rules are what make it enforceable, and they’re what the rest of this page is built on.
A regulator to complain to
The government created the Data Protection Board of India — an independent body whose job is to act when your data rights are ignored.
Rights on paper need somewhere to go when a company won’t listen. The DPDP Act establishes the Data Protection Board of India (Section 18) for exactly this. It’s the body that receives complaints, investigates breaches and failures, and can direct organisations to fix things or pay penalties.
The intended path is simple: you first raise your issue with the organisation through its required grievance channel; if that fails, you escalate to the Board. You are not left arguing with a company that holds all the cards.
Real penalties behind the rules
The law puts serious money on the line, so protecting your data is a financial risk for companies, not an optional courtesy.
What gives the rules teeth is the penalty framework (Section 33). Organisations that fail to protect personal data face financial penalties running into hundreds of crores of rupees — up to ₹250 crore for failing to take reasonable security safeguards that lead to a breach. Other failures — not honouring rights, not meeting children’s-data duties — carry their own penalties.
For you, the effect is indirect but powerful: the cost of being careless with your data is now high enough that organisations have a strong reason to handle it properly.
A deadline for businesses to comply
The obligations are being switched on in stages, with full compliance required by 13 May 2027 — so this isn’t a distant promise.
The Act is being phased in rather than dropped all at once. With the rules notified, businesses are in the window to build compliant systems — proper consent, the ability to show you your data, and the ability to delete it — and are required to be fully compliant by 13 May 2027. That timeline is why you may already be seeing companies update their privacy notices and consent screens: they’re preparing for a real, dated obligation.
FAQ
Is there actually a body I can complain to about my data?
Yes — the Data Protection Board of India. You typically raise the issue with the organisation first, then escalate to the Board if it isn’t resolved.
How much can a company be fined for mishandling my data?
Up to ₹250 crore for failing to take reasonable security safeguards that result in a breach, with other penalties for other failures under the Act.
Has the government actually implemented the law, or is it just passed?
Both the Act (2023) and its detailed rules (notified November 2025) exist. Obligations are being phased in, with full compliance required by 13 May 2027.
Does the government see my data because of this law?
No — the law is about controlling how organisations handle your data and giving you rights over it. The Board is a regulator that acts on complaints and failures, not a database of your information.