Jurisdiction Guide
India Privacy & Data Protection Laws
Every regime below can apply to a business handling India residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
On the Horizon — Proposed, Not Yet Law · 1
Once fully in force, applies to processing of digital personal data within India, and — per Section 3(b) — to processing outside India only where connected to offering goods or services to data principals in India (notably, unlike GDPR/PIPL, this does NOT extend to profiling/behavioral-monitoring activities conducted outside India). Section 17 allows government exemption of state instrumentalities on sovereignty/security grounds and empowers the Central Government to exempt startups/small data fiduciaries by future notification — a discretionary power, not an automatic threshold-based exemption.
Status: Enacted August 11, 2023, but not yet substantively in force. Per MeitY's official gazette notifications (Nov 13-14, 2025), only Phase I (Data Protection Board establishment) is live. Phase II (Consent Manager registration) is expected around November 2026; Phase III — the core obligations that would actually make this apply to businesses (notice, consent, data-principal rights, breach reporting) — isn't scheduled to take effect until May 13, 2027.