Privacy & regulation · also called DPDP Act, Digital Personal Data Protection Act 2023, DPDP Rules 2025
India DPDP Act
India's Digital Personal Data Protection (DPDP) Act 2023 is the country's main data protection law, with Rules notified in November 2025 that bring its obligations into force in phases.
The DPDP Act, passed in August 2023, governs how organisations ("data fiduciaries") process digital personal data of people in India, and applies to foreign companies offering goods or services to people in India. The Ministry of Electronics and Information Technology notified the DPDP Rules on 13 November 2025, with implementation phased over about 18 months: the Data Protection Board of India was set up immediately, consent manager provisions follow after a year, and most substantive obligations apply from mid-2027.
The law is consent-centred. Consent must be free, specific, informed, unconditional and unambiguous, given by clear affirmative action, with a notice in plain language and an easy way to withdraw. Unlike GDPR, there is no general legitimate interest basis; only a limited list of "legitimate uses". Registered consent managers can help people give and manage consent across services.
For advertising, the provisions on children, meaning under-18s, are significant: processing needs verifiable parental consent, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited, subject to limited exemptions. Penalties can reach ₹250 crore per breach. With India one of the world's largest digital ad markets, DPDP reshapes consent flows for apps and publishers.
Think of it like this
The DPDP Act is like India putting a lock on every personal data drawer and handing the key to the individual, with a stricter lock for children.
An example
An Indian edtech app with many teenage users must, as obligations come into force, obtain verifiable parental consent for users under 18 and stop showing them behaviourally targeted ads.
Related terms
GDPR
The GDPR (General Data Protection Regulation) is the European Union's data protection law, applying since May 2018, which governs how organisations collect and use personal data about people in the EU.
COPPA
COPPA is the US Children's Online Privacy Protection Act, enforced by the FTC, which requires verifiable parental consent before collecting personal information from children under 13 online.
CMP (consent management platform)
A CMP (consent management platform) is software that shows users privacy choices, such as a cookie banner, records their consent or opt-outs, and passes them to the site's partners.
Data minimization
Data minimization is the privacy principle that organisations should collect and keep only the personal data that is adequate, relevant and necessary for a specific, stated purpose.
PII (personally identifiable information)
PII (personally identifiable information) is information that identifies, or can be used to identify, a specific person, such as a name, email, phone number or government ID number.
Sources: MeitY: data protection framework (DPDP Act 2023 and Rules 2025)