⇓ More from ICTworks

India’s Data Law Is Stricter Than GDPR: Please Prepare Now

By Guest Writer on August 18, 2026

india dpdp data privacy law

India’s Digital Personal Data Protection Rules take full effect on 13 May 2027. If your program collects data from anyone in India, you have nine months, and your consent checkbox will not suffice.

The sector read the November 2025 notification as GDPR arriving in South Asia.

I read the statute and the Rules against that framing and came out somewhere else.

India’s law puts a heavier consent burden on implementers than GDPR does, and a lighter accountability burden on the Indian state than the Right to Information Act did before it. Both facts should change how you plan for 2027.

Sign Up Now for more digital development policy insights

DPDP Has Two Lawful Bases. GDPR Gave You Six

Section 4 of the DPDP Act permits processing on consent or on “certain legitimate uses.” That second category is a closed list in Section 7, and it is not what the phrase sounds like to a European ear. It covers:

  • voluntary provision of data,
  • State delivery of subsidies and benefits,
  • court orders,
  • employment,
  • medical emergencies,
  • epidemics,
  • disasters.

It does not include legitimate interests. It does not include performance of a contract. There is no general vital interests basis. Article 6 of GDPR gives you six bases, including contract, legal obligation, vital interests, public task, and legitimate interests.

Most humanitarian and development data policies I read lean on legitimate interests or vital interests to cover the gap between what informed consent can do and what service delivery requires.

That is the architecture the ICRC handbook describes and the one we walked through in how to add informed consent to your responsible data practices. In India, outside an emergency, an epidemic, or a disaster, that architecture is gone. Consent carries the entire load.

You Carry the DPDP Burden of Proof

Rule 3 requires the notice to be understandable independently of any other document you have given the person. It must contain:

  • an itemised description of the personal data,
  • the specific purposes,
  • a specific description of the goods or services enabled by that processing,
  • a working link for withdrawal, rights, and complaints to the Board

A privacy policy does not satisfy this. A terms-of-service link does not satisfy this.

Then Section 6(10) requires proof.

Where consent is the basis of processing and a question arises in a proceeding, the data fiduciary is obliged to prove notice was given and consent obtained. You have to produce which notice, in which version, at which timestamp, for which person. That is versioned content management with an immutable audit trail, not a boolean column in your OpenMRS instance.

Language is where the sector is being sold a number the statute does not clearly support.

Sections 5(3) and 6(3) give the data principal the option to access the notice and the consent request in English or any language in the Constitution’s Eighth Schedule. Vendors read that as a mandate to publish in all 22 and sell translation accordingly. At least one Indian practice reads “or” as giving the individual a choice rather than requiring simultaneous publication in 22 languages.

Neither the Rules nor the Board have settled it. If you serve Bhojpuri or Mundari speakers, the Eighth Schedule does not help you either way.

Failing to take reasonable security safeguards carries a penalty of up to ₹250 crore, roughly $28 million, under the Schedule to the Act.

DPDP Requires You to Keep Data, Not Delete It

Rule 8(3) requires every data fiduciary to retain personal data, associated traffic data, and processing logs for a minimum of one year, for the purposes in the Seventh Schedule.

Those purposes are:

  • use by the State in the interest of sovereignty and security,
  • performance of functions under law,
  • assessment for designating Significant Data Fiduciaries.

Rule 6(1)(e) adds a parallel one-year log retention duty on security grounds. A privacy law with a mandatory retention floor written to enable government access is doing something other than data minimisation.

Section 36 of the Act, read with Rule 23, lets the Central Government require any data fiduciary to furnish information it calls for, and lets it order you not to tell the affected person where disclosure would prejudicially affect sovereignty or security. The Reporters’ Collective and journalist Nitin Sethi are challenging exactly that pairing in the Supreme Court.

One correction to a claim circulating in compliance briefings.

The three-year inactivity deletion clock and the 48-hour pre-erasure notice in Rules 8(1) and 8(2) apply only to the Third Schedule classes: e-commerce entities and social media intermediaries with at least two crore registered users, and online gaming intermediaries with at least fifty lakh.

Your health or education program is almost certainly not in that class. The one-year retention floor applies to you regardless.

The State Wrote Itself Out of the Hard Parts

Section 17(4) disapplies the erasure obligation in Section 8(7) and the erasure right in Section 12(3) where processing is done by the State or an instrumentality of the State. The government does not have to delete.

Section 17(2)(a) lets the Central Government exempt any instrumentality it notifies from the entire Act, in the interests of sovereignty, security, friendly relations with foreign states, public order, or preventing incitement.

Section 44(3) replaced the personal information exemption in the RTI Act with the flat words “information which relates to personal information,” removing the public interest override that let information officers disclose personal data when accountability demanded it.

More than 120 opposition MPs petitioned for its repeal. On 16 February 2026 the Supreme Court issued notice on three petitions and referred the core questions to a larger bench while declining to stay the framework. Some commentary calls that bench a five-judge Constitution Bench. The account I am relying on does not specify a number.

There is no journalism exemption anywhere in the Act and no general public interest exemption. The research exemption in Section 17(2)(b) requires that the data not be used to take any decision specific to an individual, which rules out most monitoring that feeds back into who gets served.

The Schedule also sets a penalty of up to ₹10,000 on a data principal who breaches her Section 15 duties, which include not registering a “false or frivolous” complaint. Section 28(12) lets the Board impose costs on a complainant it deems frivolous.

India built a privacy law that can fine the person whose privacy it protects for complaining about you.

Nobody Shipped an Open Source Version

Searching GitHub, the FOSS United showcase, and the Digital Public Goods registry in August 2026, I found one serious candidate and one dead reference build.

  • TSI DPDP CMS is Apache 2.0, Java 17, built against MeitY’s own business requirements document, covering multilingual policies, consent artefacts, a verifier API, a withdrawal dashboard, and grievance intake. It is maintained by a very small team targeting Indian MSMEs.
  • ProjectEKA’s consent-manager is the MIT-licensed reference implementation behind ABDM’s health information exchange, useful as a schema donor for the DEPA consent artefact, not as a deployable system.

MeitY tried to close the gap. NeGD and MeitY Startup Hub ran Code for Consent: The DPDP Innovation Challenge, and in July 2026 IDfy won, with Jio Platforms as runner-up. IDfy’s Privy is commercial, Jio is Reliance, and neither has released code I can find. The government funded the attempt and the market absorbed it.

Registering as a formal Consent Manager is not the escape hatch. Part A of the First Schedule requires an Indian incorporated company with a net worth of at least ₹2 crore. Registration opens 13 November 2026. No NGO is doing that.

What May 2027 Demands

Donors should fund an audited open source DPDP consent stack for the social sector, or pay TSI Coop to harden what exists, in the next two quarters rather than after the first enforcement action. The alternative is every implementer separately buying an enterprise privacy suite designed for banks with cookie banners.

Donors should also stop requesting individual-level beneficiary data from Indian programs unless they can name the lawful basis. Rule 15 reserves the government’s power to set conditions on making personal data available to any foreign State or entity under its control, and a bilateral aid agency is a foreign State. No conditions have been notified yet. Plan as though they will be.

The Digital Public Goods Alliance should name DPDP-grade consent as a category gap in the registry, publicly. And everyone extending DHIS2, OpenMRS, or CommCare into India should publish their notice-versioning and withdrawal-propagation design now, while there is still time to converge on one artifact schema instead of forty.

Implementers should move their budget lines from engineering to Indian privacy counsel. Notice text and assisted-consent design are legal problems that generate technical requirements, not the reverse.

We have spent a decade calling informed consent the foundation of responsible data practice and treating it as a form to be signed. India is about to test whether we meant it and grade us on the evidence.

The government that wrote the exam exempted itself from the hardest section. Your program does not get that option.

Filed Under: Data
More About: , , , , ,

Written by
This Guest Post is an ICTworks community knowledge-sharing effort. We actively solicit original content and search for and re-publish quality ICT-related posts we find online. Please suggest a post (even your own) to add to our collective insight.
Stay Current with ICTworksGet Regular Updates via Email

Leave a Reply

*

*