Khabar 24h SIMPLE EXPLAINERS ON WORLD AFFAIRS, SCIENCE, HEALTH AND MORE.

KHABAR 24H

Simple explainers on world affairs, science, health and more.

All news under one minute

Technology Read in one minute

Your Data, Your Rules: What India’s New Privacy Law Actually Lets You Do

For years, Indians handed over their personal data to apps and websites with almost no legal say in the matter. Your name, phone number, location history, shopping habits and even biometric details were collected, stored and often shared with little transparency and no clear remedy. That is set to change with the Digital Personal Data Protection Act, 2023, the country’s first comprehensive law for digital personal data. It was passed by Parliament and received Presidential assent in August 2023, after which the government released draft rules for public consultation in January 2025 and notified the final DPDP Rules, 2025 in November 2025.

There is, however, an important caveat on timing. As of September 2026, the law is coming into force in three phases. The Data Protection Board of India has been established and is operational since November 2025, Consent Manager provisions take effect on 13 November 2026, and the substantive obligations and individual rights switch on around 13 May 2027. So the rights below are the law’s promise — confirmed in the statute — though their full enforcement is still a few months away.

Who the law covers: Data Principals and Data Fiduciaries

The Act calls you a Data Principal — the individual to whom personal data relates — and it calls the company or government body collecting and using your data a Data Fiduciary. It applies to digital personal data processed in India, and even to data processed outside India if the processing is connected to offering goods or services to people in India. This matters for everyone from a small neighbourhood shop with a customer database to multinational tech platforms.

Processing of your data is lawful only with your consent, or in specific situations the Act calls “legitimate uses”, such as the State providing benefits and subsidies, employers handling employment-related data, or responding to medical emergencies. The consent must be free, specific, informed, unconditional and unambiguous — no more pre-ticked boxes and blanket permissions hidden in fine print.

Your rights, in plain language

Once the rights provisions take effect, you get a meaningful toolkit. You have the right to know exactly what personal data a company holds about you and how it is being processed. You can ask for your data to be corrected, completed or updated if it is wrong. You can demand erasure of your data when it is no longer needed for the purpose for which it was collected, unless the law requires it to be kept.

You can also withdraw your consent at any time, and the Act says withdrawing must be as easy as giving it was — a single click if that is how you consented. You have a right to nominate someone to exercise your rights for you in case of death or incapacity, and a right to grievance redressal: companies must provide a way for you to complain, and if they do not resolve it, you can take your complaint to the Data Protection Board of India.

Protections for children and penalties for companies

The Act treats everyone under 18 as a child and imposes stricter duties: companies need verifiable consent from a parent or guardian before processing a child’s data, and they may not use it for tracking or behavioural monitoring or for targeted advertising directed at children. For serious fiduciary breaches, penalties run up to 250 crore rupees, tiered by the nature of the violation.

Cross-border transfers of data are generally permitted under a negative-list approach: data can flow out of India unless the government notifies restrictions for specific countries. Individuals, for their part, also carry duties — they must not register false complaints or furnish false particulars, with penalties up to 10,000 rupees.

  • Right to access: ask any company what personal data it holds on you and why.
  • Right to correction and erasure: fix wrong data, or have it deleted when no longer needed.
  • Right to withdraw consent: take back permission at any time, as easily as you gave it.
  • Right to nominate: name someone to act for your data rights after death or incapacity.
  • Right to grievance redressal: complain to the company first, then escalate to the Data Protection Board of India.
  • Children’s safeguards: verifiable parental consent, no tracking or targeted ads aimed at children.

Compiled by the Khabar 24h Editorial Desk from publicly available sources.

Avatar photo
Written by
Khabar 24h Editorial Desk

Khabar 24h Editorial Desk — our explainers are prepared by the Khabar 24h editorial team using AI-assisted research tools, and every piece is reviewed by a human editor before publishing. We do not claim original reporting: our work is turning complex topics into simple, accurate summaries. Spotted an error? Write to contact@khabar24h.com — our corrections policy aims for same-day review.

More from this author →

Leave a Reply

Your email address will not be published. Required fields are marked *