India now has a dedicated data protection statute, the Digital Personal Data Protection Act, 2023. It replaced the earlier patchwork under Section 43A of the IT Act and the 2011 rules.
The structure
- You are the Data Principal. The organisation processing your data is the Data Fiduciary.
- Processing generally requires your consent, which must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and preceded by a plain-language notice.
- Certain legitimate uses permit processing without consent, including where you voluntarily provide data for a specified purpose, and for defined State functions, employment purposes, medical emergencies and disasters.
Your rights
- Right to access a summary of your personal data being processed and the identities of those it has been shared with
- Right to correction, completion, updating and erasure
- Right to grievance redressal, which you must ordinarily exhaust with the Data Fiduciary before approaching the Board
- Right to nominate another person to exercise your rights in the event of death or incapacity
- Right to withdraw consent at any time, with the same ease with which it was given
This is the part that matters and it is widely misreported. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, and they switch the regime on in phases. Taking effect immediately: the definitions, the establishment of the Data Protection Board, and the Government's rule-making powers. After one year, from 13 November 2026: registration and operation of consent managers. After eighteen months, from 13 May 2027: the core provisions on consent, the obligations of Data Fiduciaries, and the remaining powers of the Board. So the substantive duties, and the machinery to enforce your rights against a company, largely arrive in 2027.
What to do in practice, today
- Write to the organisation's grievance contact or Data Protection Officer, exercising the specific right and setting a deadline. Many companies are already building compliance ahead of the deadline and will act on a well-framed request.
- For unsolicited commercial calls and messages, use the TRAI DND mechanism, which works now.
- Where the misuse involves a breach of your account, impersonation or financial loss, the Information Technology Act offences and the cybercrime portal remain the faster and currently more effective remedies.
- Escalation to the Data Protection Board becomes the route once the corresponding provisions commence.
Note that the Act carries significant financial penalties on Data Fiduciaries for breaches, but it does not create a direct right to compensation for the individual, which is a genuine gap compared with some other regimes.