India
Tier 2 Comprehensive law Asia-PacificPrincipal framework: DPDP Act 2023 (Rules 2025, phased) (2023). Regulator: Data Protection Board. DPDP Act 2023; Rules notified Nov 2025 with phased application over about 18 months. Consent managers and SDF obligations arrive in the later phases.
At a glance
- Principal law
- Digital Personal Data Protection Act, 2023, with the DPDP Rules 2025
- Regulator
- Data Protection Board of India
- Breach notification
- Notify the Data Protection Board and each affected user (detailed report within 72 hours under the 2025 Rules)
- Maximum penalty
- Up to INR 2.5bn (about €27m) per breach category
- DPO required
- India-based DPO for Significant Data Fiduciaries
- Digital consent age
- 18 — verifiable parental consent below that
- Extraterritorial reach
- Yes — offering goods or services in India
Structure
- Structural pattern
- Not assessed
- Sub-jurisdictions
- None — no sub-national axis
- ISO code
- IN
A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.
Transfers and adequacy
- EU member
- No
- EEA member
- No
Instruments
Sources
Never independently verified — seeded from the prototype.