Jurisdiction
India
- Source
- Editorial review of primary sources — not yet re-anchored
- Verified
- Evidence not verified
- Confidence
- Low
Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.
01Framework
India’s data-protection regime is real but mostly future-dated. The DPDP Rules were notified in November 2025 with phased commencement: consent managers from November 2026, the substantive obligations from May 2027. The AI content rules arrived first — the IT Rules were amended in February 2026 to require labelling and embedded provenance metadata for synthetically generated information, and that binds now. There is still no AI statute, and MeitY’s India AI Governance Guidelines are voluntary. India runs a negative-list transfer model rather than an adequacy one, and the sharpest live constraints are sectoral: RBI payment-data localisation and CERT-In’s six-hour incident reporting.
- Region
- South Asia
- ISO code
- IN
- Privacy framework
- The Digital Personal Data Protection Act, 2023 received assent in August 2023 and comes into force provision by provision, on dates the Central Government appoints. It is consent-based, with notice, security safeguards, breach notification, additional duties for Significant Data Fiduciaries, extraterritorial reach over processing connected with offering goods or services to people in India, and penalties up to 250 crore rupees. The DPDP Rules, 2025 supply the operative detail on a phased timetable: rules 1, 2 and 17 to 21 from publication in November 2025, the consent-manager rule one year later, and rules 3 and 5 to 16 — notice content, security safeguards, breach reporting, children’s verifiable consent, retention, Significant Data Fiduciary duties and cross-border transfer — eighteen months after publication. Until then the 2011 SPDI Rules and sectoral regimes remain the operative privacy law.
- AI-specific rules
- No AI statute. The binding AI rules are content rules. The IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 were amended in February 2026 to define synthetically generated information and to require intermediaries to block unlawful synthetic content, prominently label everything else, prefix an audio disclosure for audio, and embed permanent metadata or another provenance mechanism carrying a unique identifier. Significant social media intermediaries must additionally have users declare whether an upload is synthetic and verify that declaration. Governance-level AI policy is voluntary: MeitY’s India AI Governance Guidelines set out seven sutras — including Innovation over Restraint — and six pillars. In finance, the RBI’s FREE-AI committee report is a blueprint rather than a framework, and SEBI’s proposal to assign responsibility for AI tools is still a consultation.
- Last reviewed
- 20 Aug 2026
- Status
- published
Cross-border transfer
India runs a negative-list model, not an adequacy model. The DPDP Act lets the Central Government restrict transfers to a notified country or territory, and preserves any stricter sectoral law; the DPDP Rules add a requirement to meet whatever the government specifies about making personal data available to a foreign State or an entity under its control. That rule sits in the eighteen-month bucket and is not yet operative, and no country has been notified as restricted. So transfers out of India are permitted by default, and teams that arrive looking for an adequacy decision are looking for something that does not exist. The real constraints are sectoral and they bind today: the Reserve Bank requires the entire data relating to a payment system to be stored in a system only in India, and CERT-In requires ICT logs to be maintained within Indian jurisdiction.
Regulators
Primary sources
- LegislationDigital Personal Data Protection Act, 2023
- LegislationDigital Personal Data Protection Rules, 2025 (G.S.R. 846(E))
- LegislationIT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 — consolidated text including the 2026 synthetic-media amendment
- Regulator guidanceIndia AI Governance Guidelines
- LegislationRBI — Storage of Payment System Data
- Regulator guidanceRBI — FREE-AI committee report
- Regulator pageSEBI — consultation on assigning responsibility for the use of artificial intelligence tools
02Regulations and guidance
| Instrument | Status |
|---|---|
| DPDP ActIndia’s data-protection statute: consent-based processing, notice, security safeguards, breach notification, Significant Data Fiduciary duties, extraterritorial reach over services offered to people in India, and penalties up to 250 crore rupees. It commences provision by provision, and the operative detail sits in the DPDP Rules. | Partly in force |
| DPDP RulesThe operative rules under the DPDP Act, phased over eighteen months. They cover notice content, consent managers, security safeguards, breach reporting, verifiable consent for children, retention, Significant Data Fiduciary duties and cross-border transfers. | Partly in force |
| India AI Governance GuidelinesMeitY’s voluntary AI governance framework under the IndiaAI Mission. Seven sutras — Trust, People First, Innovation over Restraint, Fairness and Equity, Accountability, Understandable by Design, and Safety, Resilience and Sustainability — with six pillars across enablement, regulation and oversight. | In force |
| IT Rules 2021Intermediary due-diligence conditions for safe harbour under the Information Technology Act, as amended in February 2026. Grievance officers, publication of terms, takedown on actual knowledge, content preservation — and now a definition of synthetically generated information with duties to block, prominently label and embed permanent provenance metadata. | In force |
| FREE-AI ReportA Reserve Bank committee blueprint for AI in the financial sector, organised around seven sutras and operationalised through twenty-six recommendations across six strategic pillars. Recommendations only — it is not a binding RBI framework and no corresponding direction has issued. | Proposed |
| RBI Payment Data LocalisationRequires payment system providers to store the entire data relating to their payment systems in a system only in India, including full end-to-end transaction detail. For the foreign leg of a transaction the data may also be stored abroad. A hard localisation rule that survives the DPDP Act’s more permissive transfer regime. | In force |
| SEBI AI responsibility consultationA SEBI consultation proposing that regulated entities bear responsibility for the outputs, privacy and security of AI tools they use, whether built in-house or procured. Still a consultation; no corresponding regulation has followed. | Proposed |
03Common enterprise issues
Personal data
DPDP is notified but mostly not yet in force
Commencement is phased: the framework rules from November 2025, consent managers a year later, and notice content, security safeguards, breach reporting, Significant Data Fiduciary duties and the transfer rule eighteen months after publication. Designing to DPDP now is sensible; asserting that it applies now is wrong.
Transparency
Synthetic media must be labelled and carry provenance metadata — today
Since February 2026 an intermediary whose computer resource generates synthetic audio, image or video must prominently label the output, prefix an audio disclosure for audio, and embed permanent metadata or a provenance mechanism carrying a unique identifier. Routine editing, formatting and accessibility uses are carved out.
Security
CERT-In’s six-hour clock and in-India log residency apply now
Reporting is due within six hours of noticing an incident or being told of one, with no confirmation threshold, and ICT logs must be enabled and kept for a rolling 180 days within Indian jurisdiction. Storing logs only outside India does not comply. This has applied since 2022.
Cross-border transfers
There is no adequacy list to check
Teams import GDPR intuitions and go looking for an adequacy decision. Transfers out of India are permitted unless the government notifies a restricted country, and none has been notified. The constraints that actually bite are payment-data localisation and log residency, and both survive the DPDP transfer regime.
Sector rules
Financial-sector AI rules are still recommendations
The RBI FREE-AI report is a committee blueprint of seven sutras and twenty-six recommendations, not a binding framework, and SEBI’s proposal on responsibility for AI tools remains a consultation. The enforceable RBI constraint today is payment-data localisation, which is a data-location question rather than an AI one.
04Vendor restrictions
Restrictions we have written down and the page each one must be checked against. A restriction becomes a verified claim only once the sync job has fetched that page and found the phrase it declares; until then it is an editorial note with a link, and says so.
No vendor restriction has been recorded for this jurisdiction.
05Stacks with notes for this jurisdiction
No published stack carries a compliance note for this jurisdiction yet.
06Evidence
Every instrument above that we have fetched and anchored carries a footnote. The rest link to their primary source but have not been fetched and hashed yet, and are marked ASSESSMENT rather than FACT.
No sources were recorded for this answer. Nothing on this page should be treated as verified.
Improve this page
Sign in to contribute
From the field
0 deployments · 0 questions
Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.