If you live in India, the legal relationship between you and every app, bank, hospital, and cloud service holding your personal data changed this year. The Digital Personal Data Protection Rules, finalized in November 2025 under the 2023 DPDP Act, are now taking effect in phases — and most of the coverage so far has been written for businesses figuring out how to comply, not for the people whose data the law is actually about.
That’s a gap worth closing. The DPDP Act is the first comprehensive data protection law India has had, and it gives individuals — referred to in the law as “Data Principals” — a specific, enforceable set of rights over photos, documents, health records, and other personal data sitting in apps and cloud accounts. Most people have never been told what those rights are, let alone how to use them.
What the DPDP Act Actually Covers
The DPDP Act applies to “personal data” processed digitally — which is a broad category. It includes obvious things like your name, phone number, and ID documents, but also photos, location history, health records, financial documents, and any other digital information that can identify you.
Any company or app that collects or processes this data is a “Data Fiduciary” under the law, whether it’s a bank, a photo storage app, a hospital’s patient portal, or a delivery service that keeps your address on file. The law applies regardless of where the company is headquartered, as long as it processes the personal data of people in India.
This is a meaningful shift from the prior situation, where India had data protection obligations scattered across IT rules and sector-specific regulations, with no single law spelling out what companies owed individuals or what happened when they didn’t deliver.
The Phased Timeline Worth Knowing
The DPDP Rules don’t take full effect all at once, and the timeline matters because it tells you what’s enforceable right now versus what’s still being phased in.
Already in force: Core obligations around data security and breach handling have begun applying, and the Data Protection Board of India — the body responsible for enforcement — has started operating.
November 13, 2026: The Consent Manager Framework becomes operational. This is the mechanism through which individuals will be able to see, manage, and withdraw consent across multiple apps and services from a single interface, similar in spirit to how account aggregators work in Indian banking.
May 13, 2027: Full compliance becomes mandatory for all substantive provisions, marking the end of the 18-month transition period companies were given to get their data practices in order.
In practical terms, this means some of the strongest individual protections — like a unified consent dashboard — aren’t fully live yet. But the underlying rights, including the right to access and erase your data, already exist in the law.
What Rights You Actually Have
Strip away the compliance language, and the DPDP Act gives individuals a handful of concrete rights that are worth knowing by name, because they’re the ones you’ll need to invoke if something goes wrong.
The right to access. You can ask any Data Fiduciary what personal data they hold about you, what they’re using it for, and who they’ve shared it with. Companies are required to respond.
The right to correction and erasure. If your data is inaccurate, outdated, or no longer needed for the purpose it was collected, you can request that it be corrected or deleted. This is the same underlying concept as the GDPR’s “right to be forgotten,” adapted into Indian law.
The right to withdraw consent. Consent given for data processing isn’t permanent. You can withdraw it, and the law requires that withdrawing consent be at least as easy as giving it — a provision aimed directly at apps that bury opt-outs behind multiple menus while making sign-up a single tap.
The right to nominate. A genuinely novel feature of Indian law: you can nominate another individual to exercise your data rights on your behalf in the event of death or incapacity. This has real relevance for photos and personal files — it gives a formal legal path for a family member to manage a deceased person’s digital accounts, something most privacy laws don’t address directly.
The right to file a complaint. If a company doesn’t respond to your request, or mishandles your data, you can escalate to the Data Protection Board of India, which has the authority to investigate and impose penalties.
Breach Notification: A 72-Hour Clock
One of the most consequential rules for individuals is the breach notification requirement. When a Data Fiduciary experiences a personal data breach, it now has 72 hours to notify both the Data Protection Board and the affected individuals.
This matters because, historically, breach disclosure in India has been inconsistent — some companies disclosed promptly, many didn’t disclose at all unless forced to by media reporting or regulatory pressure. A hard 72-hour requirement, backed by penalties for non-compliance, changes the incentive structure. Companies that previously might have quietly patched a vulnerability without telling affected users now have a legal deadline to meet.
The Rules also require Data Fiduciaries to maintain real security measures — encryption, access controls, access logging, and regular backups — specifically so they can detect and respond to breaches within that window. A company that can’t tell what happened can’t notify anyone about it.
Penalties That Are Actually Large
Data protection laws are sometimes criticized for having rights on paper and no real enforcement behind them. The DPDP Act’s penalty structure is designed to avoid that criticism: fines for serious violations can reach ₹250 crore — roughly $30 million USD — per instance, with the Data Protection Board empowered to investigate complaints and order remedial action.
For context, that puts India’s maximum penalties in a similar range to the heaviest GDPR fines issued in the EU, which gives the law real teeth rather than being a purely symbolic gesture. Companies that have treated user data carelessly because the cost of being careless was negligible now have a different calculation to make.
Cross-Border Data and What “Compliant” Means
A provision that affects which apps and cloud services are realistic options going forward: the Rules place requirements on cross-border data transfers, and on cloud and SaaS providers acting as data processors for Indian users. These providers now need contractual protections in place — covering the scope of processing, security obligations, how they’ll assist with individual rights requests, and what happens to data when a contract ends.
In practice, this means the question “is this app GDPR compliant?” — which privacy-conscious users have asked for years about EU law — now has an Indian equivalent worth asking too: is this service set up to meet DPDP obligations, including breach notification, data deletion, and processor agreements with any third parties it uses?
It’s a reasonable question to put directly to any app holding your photos, documents, or personal records, and a company that can’t answer it clearly is telling you something about how seriously it takes the law.
What This Means in Practice
None of this requires you to do anything dramatic. But it does change what’s reasonable to expect from any service holding your personal data, and what’s reasonable to ask before trusting one with years of photos and documents.
Ask what happens to your data if you delete your account. The DPDP Act’s erasure provisions mean a company should have a clear, time-bound answer — not a vague “we may retain some data indefinitely.”
Check whether opt-out is actually as easy as opt-in. If signing up for data sharing takes one tap and withdrawing it takes five menus and a support ticket, that’s now arguably a Consent Manager problem worth flagging once the framework is live in November 2026, and worth noticing today.
Know that breach notification is now a legal floor, not a courtesy. If a service you use is breached, you’re entitled to be told within 72 hours, by law — not whenever it becomes convenient or unavoidable to disclose.
Treat “Data Fiduciary” claims with the same scrutiny as any other compliance language. A privacy policy that says “DPDP compliant” should be backed by specifics: how access requests work, how long deletion takes, who the company shares data with. Vague language is a signal, not a reassurance.
daftei is built around the same underlying commitments the DPDP Act is now putting into law for everyone: data is encrypted with AES-256 at rest and TLS 1.3 in transit, deletion follows a defined 30-day grace window before permanent erasure, and the service is already GDPR and CCPA compliant — the same posture extends naturally to DPDP obligations. Files and personal data are never sold, and never used to train third-party AI models.