WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Asia-Pacific

India Privacy & Data Protection Laws

Every regime below can apply to a business handling India residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

On the Horizon — Proposed, Not Yet Law · 1

India
Digital Personal Data Protection Act, 2023

Once fully in force, applies to processing of digital personal data within India, and — per Section 3(b) — to processing outside India only where connected to offering goods or services to data principals in India (notably, unlike GDPR/PIPL, this does NOT extend to profiling/behavioral-monitoring activities conducted outside India). Section 17 allows government exemption of state instrumentalities on sovereignty/security grounds and empowers the Central Government to exempt startups/small data fiduciaries by future notification — a discretionary power, not an automatic threshold-based exemption.

Status: Enacted August 11, 2023, and still not substantively in force. MeitY notified the DPDP Rules, 2025 on November 13, 2025 with a three-phase commencement: Phase I (constitution of the Data Protection Board of India) took effect immediately on November 13, 2025; Phase II (Consent Manager registration, and the Board's power to inquire and impose penalties) takes effect November 13, 2026; Phase III — the core obligations that actually bind businesses (notice, consent, data-principal rights, retention limits, transfer and breach duties) — takes effect May 13, 2027.

Other Asia-Pacific jurisdictions