Data Protection Atlas

India

Tier 2 Comprehensive law Asia-Pacific

Principal framework: DPDP Act 2023 (Rules 2025, phased) (2023). Regulator: Data Protection Board. DPDP Act 2023; Rules notified Nov 2025 with phased application over about 18 months. Consent managers and SDF obligations arrive in the later phases.

At a glance

Principal law
Digital Personal Data Protection Act, 2023, with the DPDP Rules 2025
Regulator
Data Protection Board of India
Breach notification
Notify the Data Protection Board and each affected user (detailed report within 72 hours under the 2025 Rules)
Maximum penalty
Up to INR 2.5bn (about €27m) per breach category
DPO required
India-based DPO for Significant Data Fiduciaries
Digital consent age
18 — verifiable parental consent below that
Extraterritorial reach
Yes — offering goods or services in India

Structure

Structural pattern
Not assessed
Sub-jurisdictions
None — no sub-national axis
ISO code
IN

A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.

Transfers and adequacy

EU member
No
EEA member
No

Instruments

Sources

Never independently verified — seeded from the prototype.