India Unfolding
All sectorsVerified data
Data Protection & Cyber

Data Protection & Cyber

As India's digital economy exploded, so did the need to protect people's data. The journey ran from the Supreme Court's 2017 ruling that privacy is a fundamental right, to the Digital Personal Data Protection (DPDP) Act of 2023 — a comprehensive data-protection law — giving citizens rights over their personal data and setting duties and penalties for the companies that handle it. This timeline traces those milestones.

Sify data centre building viewed from Lemon Tree Hotel, Gachibowli, Hyderabad, Telangana
Sify data centre building viewed from Lemon Tree Hotel, Gachibowli, Hyderabad, Telangana · Timothy A. Gonsalves · CC BY-SA 4.0 · Wikimedia Commons
2023
DPDP Act passed
2017
Privacy = fundamental right
₹250 cr
Maximum penalty
Phased compliance under the DPDP Rules (Gazette, 13 Nov 2025)
2017
Right to Privacy is fundamental
In the landmark Puttaswamy judgment, the Supreme Court unanimously rules that privacy is a fundamental right under the Constitution — the foundation for data-protection law.
2022
Cybersecurity rules tighten
2023
Digital Personal Data Protection Act
2025
DPDP Rules notified
2026
Board posts advertised
2017
1milestones
20172026
Latest
Right to Privacy is fundamental
In the landmark Puttaswamy judgment, the Supreme Court unanimously rules that privacy is a fundamental right under the Constitution — the foundation for data-protection law.

Why it matters Strong data rights build trust in the digital economy, protect citizens from misuse and breaches, and are essential as more of life moves online.

  • Right to Privacy fundamental right (SC, 2017)
  • DPDP Act 2023; Rules published in the Gazette on 13 November 2025, with most duties applying after 18 months
  • Data Protection Board: a Chairperson and four Members; applications invited on 6 May 2026
  • Source: MeitY (Gazette and PIB); Supreme Court

History

As Aadhaar, UPI and smartphones put hundreds of millions of Indians online, questions grew over who controls their data. In 2017 the Supreme Court, in the Puttaswamy case, unanimously ruled that privacy is a fundamental right — the constitutional foundation for data law.

The DPDP Act

After years of drafts, India passed the Digital Personal Data Protection Act in 2023 — a comprehensive data-protection law. It gives people rights to access and erase their data, requires consent, and sets penalties and a Data Protection Board for companies that misuse personal data.

How it works

India's data-protection regime is built on consent. Under the DPDP Act, any organisation ('data fiduciary') must tell you clearly what personal data it collects and why, and can generally use it only with your permission — which you can withdraw. You get rights to access, correct and erase your data. A new Data Protection Board enforces the law, and a 'consent manager' system is meant to let people manage all their permissions in one place.

Outlook

The DPDP Rules were published in the Gazette on 13 November 2025 and take effect in stages. The rules on appointing and running the Data Protection Board applied at once; registration of consent managers, which must be companies incorporated in India with a net worth of at least ₹2 crore, begins one year after publication; and most other duties, including consent notices, security safeguards, breach intimation and a yearly impact assessment and audit for Significant Data Fiduciaries, apply 18 months after publication. On 6 May 2026, MeitY invited applications for the Board's Chairperson and four Members, to be recommended by search-cum-selection committees. The Board is to work as a digital office and finish each inquiry within six months, extendable by up to three months at a time, and penalties reach ₹250 crore for failing to keep reasonable security safeguards.

By the numbers

24 August 2017: Right to Privacy held fundamental by the Supreme Court. 6 hours to report cyber incidents to CERT-In (2022). 11 August 2023: DPDP Act enacted. 13 November 2025: DPDP Rules published, after 6,915 consultation inputs. 1 year to consent-manager registration and 18 months to most other duties. 1 + 4: Chairperson and Members sought for the Data Protection Board (6 May 2026). ₹250 crore maximum penalty. Sources: MeitY (Gazette G.S.R. 846(E); Board notice, 6 May 2026); PIB; Supreme Court; CERT-In.

Data current to: Milestones 2017–2026

Source: MeitY — Digital Personal Data Protection Rules, 2025 (Gazette notification G.S.R. 846(E), 13 November 2025), via PIB's backgrounder of 17 November 2025 (linked), and MeitY's notice of 6 May 2026 inviting applications for the Data Protection Board of India; with the Supreme Court's Puttaswamy judgment of 24 August 2017. The Act was enacted on 11 August 2023. Rules on the Board took effect on publication, consent-manager registration follows one year later, and most other duties, including consent notices, security safeguards and breach intimation, apply eighteen months after publication. The Board consists of a Chairperson and four other Members. Penalties reach ₹250 crore. Milestones 2017–2026. · link