Skip to main content
← Knowledge graph

Digital Personal Data Protection Act, 2023

Source of truthOfficial statute · enacted 2023 · verified 2026-06-26Read on the official source

Statutory timeline

  1. 11 August 2023Enacted

    Received Presidential assent as the Digital Personal Data Protection Act, 2023. source ↗

  2. 13 November 2025DPDP Rules, 2025 notified

    The Digital Personal Data Protection Rules, 2025 were notified (G.S.R. 846(E)), with compliance phased in over roughly 18 months. source ↗

  3. 2027 (phased)Core obligations enforceable

    Core duties — notice, consent, security safeguards, breach reporting, data-principal rights and children's-data protection — become fully enforceable under the phased schedule. source ↗

Key milestones only — not a complete amendment history. See What changed for detected regulatory updates, and always confirm current text at the official source.

Clauses that cite this Act

Data protection (DPDP)

Templates connected to this Act

Governance and Compliance Framework CharterDPDP Data-Protection Readiness AssessmentAI Use and Governance PolicyIncident Response PlanRisk RegisterData Retention ScheduleBusiness Continuity PlanAcceptable Use PolicyAccess Control PolicyData Classification and Handling PolicyChange Management PolicyStatement of Applicability (ISO 27001)Logging and Monitoring PolicyVulnerability Management PolicyAsset Management PolicyVendor DPAInformation Security PolicyHIPAA Security Rule PolicyHIPAA Notice of Privacy Practices (NPP)HIPAA Business Associate Agreement (BAA)HIPAA Breach Notification PolicyAI Management System (AIMS) Policy — ISO/IEC 42001:2023AI System Impact Assessment (AIIA)AI System Inventory & RegisterThreat Intelligence PolicyInformation Security in Project Management PolicyConfiguration & Hardening Management PolicyData Masking, Deletion & Loss Prevention StandardCapacity Management PolicyLegal, Regulatory & Contractual Requirements RegisterAccess Provisioning (Joiner-Mover-Leaver) ProcedureAuthentication & Password StandardEndpoint & Anti-Malware PolicyNetwork Security PolicySecurity Awareness & Training ProgrammeInformation Security Risk Management MethodologyInformation Security Objectives RegisterInformation Security Roles, Responsibilities & RACIISMS Monitoring, Measurement & Metrics ReportDocumented Information Control ProcedurePersonnel (HR) Security PolicyContinuous Control Monitoring & Deficiency Management PolicyPCI DSS CDE Scope & Data-FlowPCI DSS SAQ Selector & Attestation of Compliance (AOC) RecordCryptography & Key Management PolicySecure Development (Secure SDLC) PolicySupplier & Third-Party Security PolicyPhysical & Environmental Security PolicyInformation Backup PolicyISMS Scope StatementRisk Treatment PlanISMS Internal Audit ReportISMS Management Review MinutesNonconformity & Corrective Action (CAPA) RegisterCERT-In Incident Reporting SOPSOC 2 System DescriptionDPDP Privacy NoticeGST Tax InvoiceProfessional Tax — Employer Monthly WorkingForm 16 — Salary TDS Certificate WorkingBank Balance Confirmation LetterCreditors Balance Confirmation LetterDebtors Balance Confirmation LetterAudit Planning MemorandumStatutory Audit ReportCARO 2020 Checklist and ReportManagement Representation LetterCompliance Baseline Checklist / Report

Educational mapping, not legal advice. Read the Act on an official source (India Code / eCourts) and confirm specifics with a qualified advocate.