DPDP Act compliance gets Cabinet Secretary’s push; ministries, states put on timeline
Central coordination for implementation of the Digital Personal Data Protection (DPDP) Act, 2023 has been escalated to the level of the Cabinet Secretariat, signalling a whole-of-government push on compliance
Ministries and state governments have been placed on a defined timeline for achieving compliance with the Act's obligations
The push follows the notification of the DPDP Rules, 2025, which operationalised the Act's implementation framework
The move is aimed at ensuring government departments — as significant handlers of citizens' personal data — meet the same data fiduciary obligations being rolled out for the private sector
Digital Personal Data Protection (DPDP) Act, 2023
India's first comprehensive data protection statute, the DPDP Act establishes rights for individuals over their personal data and obligations for entities that process it, replacing the fragmented approach previously under the Information Technology Act, 2000.
Key Details
- Enacted by Parliament in August 2023, following the withdrawal of the earlier Personal Data Protection Bill, 2019/2021
- Applies to processing of digital personal data within India, and to processing outside India if it relates to offering goods/services to individuals in India
- Key entities: "Data Fiduciary" (determines purpose/means of processing, equivalent to "data controller" in GDPR terminology), "Data Principal" (the individual to whom the data relates), and "Data Processor"
- Provides for a Data Protection Board of India (DPBI), established under Section 18, primarily to adjudicate non-compliance and impose penalties (up to ₹250 crore per instance)
- The DPDP Rules, 2025 were notified on 13 November 2025, operationalising provisions including Consent Managers, breach reporting timelines, and children's data safeguards
The Cabinet Secretary-led push directly concerns government ministries and states meeting their obligations as "Data Fiduciaries" under this Act — a category that includes government bodies, not just private companies.
Government as Data Fiduciary and Certain Exemptions
A distinctive feature of India's DPDP framework, compared to global data protection laws, is the scope for the government to exempt its own instrumentalities from parts of the Act — making the compliance push notable precisely because it is not legally mandatory in the same way for all state functions.
Key Details
- Section 17(2)(a) empowers the Central Government to exempt any "instrumentality of the State" from application of the Act in the interest of sovereignty, integrity, security of the state, friendly relations with foreign states, or maintenance of public order
- This is broader than exemptions typically available to private data fiduciaries, and has drawn scrutiny for potentially weakening accountability of government data processing
- Despite the exemption power, the government is voluntarily driving ministries and states toward baseline compliance (notice, consent, security safeguards) rather than relying on blanket exemption
- Comparable global frameworks: EU's GDPR (2016) generally applies to public authorities with more limited exemption scope than India's Section 17(2)(a)
The compliance timeline being pushed by the Cabinet Secretariat is significant precisely because government bodies could otherwise be exempted; the push signals an administrative choice to hold ministries/states to comparable standards as private data fiduciaries.
Consent Manager Framework
A unique architectural feature of India's DPDP regime enabling individuals to manage consent for data sharing across multiple platforms through registered intermediaries.
Key Details
- Consent Managers are registered with the Data Protection Board, must be technology-driven, interoperable platforms allowing Data Principals to give, manage, review, and withdraw consent
- Minimum net worth requirement of ₹2 crore for registration; must retain consent audit trails for at least seven years
- The Consent Manager framework under Rule 4 of the DPDP Rules, 2025 is set to become operational in November 2026
- Modelled conceptually on India's existing Account Aggregator framework in financial data sharing (RBI-regulated)
Government ministries and states being placed on a compliance timeline would need to align their data collection systems (e.g., for welfare schemes, e-governance platforms) with this consent architecture as it becomes operational.
- DPDP Act enacted: August 2023; DPDP Rules notified: 13 November 2025
- Data Protection Board of India established under: Section 18 of the DPDP Act
- Maximum penalty for non-compliance: up to ₹250 crore per instance
- Government exemption provision: Section 17(2)(a) — instrumentalities of the State may be exempted on specified grounds
- Consent Manager framework (Rule 4) operationalisation deadline: November 2026
- Full substantive compliance deadline across notice, consent, security safeguards, and breach reporting: May 2027