India is the world's most populous country, and it now has its first comprehensive data-protection law. The Digital Personal Data Protection (DPDP) Act is consent-first — consent is the primary basis for processing personal data, with fewer of the alternative bases the GDPR allows — and it reaches well beyond India's borders. If you serve users in India, this is coming, and the phased timeline means the smart move is to prepare now rather than wait for the 2027 deadline.
Key takeaways
- The DPDP Rules were notified in November 2025; the framework is rolling out in phases.
- Core consent and notice obligations take effect May 13, 2027 — roughly an 18-month runway.
- It is consent-first: consent is the primary lawful basis, with limited alternatives.
- It is extraterritorial — it applies to businesses outside India that serve Indian users.
What the DPDP Act is
The Digital Personal Data Protection Act, 2023 establishes India's legal framework for protecting personal data in digital form. The Act itself passed in 2023, but it delegated the operational detail to subordinate rules — the DPDP Rules, 2025 — which the Ministry of Electronics and Information Technology notified on November 14, 2025. Together they create a regime built around consent: organizations (data fiduciaries) must generally obtain clear, informed, unambiguous consent before processing the personal data of individuals (data principals).
The model mirrors the GDPR in important ways — extraterritorial scope, strong individual rights, breach notification, special protection for children — but leans harder on consent as the lawful basis, since it offers fewer alternatives like the GDPR's "legitimate interests."
The phased timeline
This is the part most relevant to planning. The DPDP framework is deliberately staggered:
| Date | What takes effect |
|---|---|
| Nov 13, 2025 | Data Protection Board of India established; administrative provisions begin. |
| Nov 13, 2026 | Registration opens for consent managers. |
| May 13, 2027 | Core substantive obligations — consent, privacy notice, and security requirements — take effect. |
In other words, the obligations that affect how your website collects consent are not yet in force — they arrive in May 2027. That runway is an advantage: you can build a compliant consent layer calmly now rather than retrofitting under deadline pressure.
Who it applies to
The Act applies to the processing of digital personal data within India, and — crucially — to processing outside India where it's connected to offering goods or services to individuals in India. This extraterritorial reach mirrors the GDPR: a business based anywhere in the world can fall in scope simply by serving Indian users. For a website with meaningful Indian traffic, that's a real consideration, not a hypothetical.
What it requires
Once the core obligations take effect, data fiduciaries will need to:
- Obtain valid consent that is free, specific, informed, unconditional, and unambiguous, given by clear affirmative action — before processing.
- Provide a clear, itemized notice at or before the consent request: what personal data is processed, the specific purposes, and how to withdraw consent or exercise rights.
- Make withdrawal as easy as giving consent, with a clear mechanism to do so.
- Limit processing to the stated purpose; new purposes require fresh consent.
- Implement reasonable security safeguards and notify the Board and affected individuals of breaches.
- Obtain verifiable guardian consent for children (under 18) and persons with disabilities.
A distinctive Indian feature is the consent manager — a Board-registered entity that gives individuals a single, interoperable platform to give, manage, review, and withdraw consent. The registration framework for these is scheduled for around November 2026.
How ConsentPixel helps
ConsentPixel is built around exactly the mechanics the DPDP Act centers on: capturing clear, affirmative consent before processing; presenting notice of what's collected and why; making withdrawal straightforward; and keeping a logged, timestamped record of each consent decision. Because the Act treats consent as the primary lawful basis, that prevention-first, consent-gated approach maps closely to what India will require.
An honest framing on timing and scope: the DPDP's core obligations don't take effect until May 2027, so this is preparation, not a present emergency — and some parts of the framework, like the consent-manager ecosystem and broader organizational data-handling duties, extend beyond the website consent layer that ConsentPixel provides. What ConsentPixel does is let you get the consent-and-notice foundation right now, well ahead of the deadline, as part of the same single pixel that handles your GDPR and other global obligations.
Frequently asked questions
The Digital Personal Data Protection Act, 2023 is India's first comprehensive data-protection law. Its implementing rules (the DPDP Rules, 2025) were notified in November 2025, and the framework is rolling out in phases. It establishes a consent-first regime: organizations, called data fiduciaries, must generally obtain clear, informed consent before processing the personal data of individuals, called data principals.
It is phased. The Data Protection Board of India was established on November 13, 2025. Consent-manager registration opens around November 13, 2026. The core substantive obligations — consent, privacy notice, and security requirements — take effect on May 13, 2027, giving organizations roughly an 18-month runway to prepare.
Any data fiduciary that processes digital personal data in India — and, importantly, organizations outside India that process personal data in connection with offering goods or services to individuals in India. Like the GDPR, its reach is extraterritorial, so a business based elsewhere can be in scope simply by serving Indian users.
A distinctive feature of the Indian framework: a consent manager is an entity registered with the Data Protection Board that gives individuals a single, accessible, interoperable platform to give, manage, review, and withdraw consent across services. Registration provisions are scheduled to come into force around November 2026.
ConsentPixel supports the consent and notice mechanics the DPDP Act centers on — obtaining clear affirmative consent before processing, presenting itemized notice of what's collected and why, enabling easy withdrawal, and logging consent. Because the core obligations don't take effect until May 2027, ConsentPixel helps you prepare your consent layer now; some DPDP duties (such as the consent-manager framework and broader data-handling obligations) extend beyond the website consent layer.
See where your site stands
ConsentPixel blocks trackers until consent, monitors every page, and logs every decision — from a single pixel. Find out where your site stands in about 10 seconds.
Scan your site free