
India’s DPDP Act is entering an important phase in 2026 as the country’s new digital privacy framework moves towards wider implementation. The Digital Personal Data Protection Act, 2023, and the Digital Personal Data Protection Rules, 2025, establish new responsibilities for organisations handling personal data and new protections for individuals.
At the same time, the DPDP Act faces legal scrutiny over its impact on the Right to Information (RTI) Act, making privacy versus transparency one of the most important issues surrounding India’s new data-protection framework.
DPDP Act: Latest Update in 2026
The biggest development surrounding the DPDP Act is the continuing legal challenge over provisions that amended the RTI Act.
The Supreme Court is examining challenges to the law, including the change to Section 8(1)(j) of the RTI Act through Section 44(3) of the DPDP Act. The petitioners have raised concerns that the amendment could make it harder to obtain personal information through RTI applications even when disclosure may have a wider public-interest relevance.
The Supreme Court had earlier declined to stay the operation of the DPDP framework while the challenge continues.
IMPORTANT: The DPDP Act has not been cancelled or struck down. The legal challenge is ongoing.
DPDP Act 2026: Important Dates at a Glance
The DPDP framework is being implemented in phases rather than having every provision become effective at once.
| Date | What Happens |
|---|---|
| 11 August 2023 | DPDP Act received Presidential assent |
| 13 November 2025 | DPDP Rules, 2025 notified |
| 13 November 2025 | Rules 1, 2 and 17–21 came into force |
| 13 November 2026 | Rule 4 is scheduled to come into force |
| 13 May 2027 | Rules 3, 5–16 and 22–23 are scheduled to come into force |
| 2026–2027 | Remaining provisions of the wider framework are phased in according to the commencement notifications |
The official Rules specifically provide for one-year and 18-month implementation periods for different provisions.
Key Date to Remember
13 November 2026 is particularly important because Rule 4, dealing with Consent Managers, is scheduled to become effective one year after publication of the Rules.
The remaining major operational rules are scheduled for the 18-month phase in May 2027.
What Is the DPDP Act?
The Digital Personal Data Protection Act, 2023 is India’s principal legislation for regulating the processing of digital personal data.
The law aims to create a framework where organisations can use personal data for lawful purposes while individuals receive greater protection over their personal information.
The government says the framework is intended to balance individual data rights with legitimate data processing and innovation.
The framework applies to organisations known as Data Fiduciaries, which determine the purpose and means of processing personal data.
What Are the DPDP Rules 2025?
The Digital Personal Data Protection Rules, 2025 provide the practical framework needed to implement the Act.
The Rules cover areas including:
- Data-processing notices
- Consent management
- Security safeguards
- Personal data breaches
- Children’s personal data
- Consent Managers
- Rights of individuals
- Responsibilities of Data Fiduciaries
- The functioning of the Data Protection Board
The final Rules were notified by the Ministry of Electronics and Information Technology (MeitY) in November 2025.
DPDP Act and the RTI Controversy
One of the biggest concerns surrounding the DPDP Act is its effect on India’s transparency framework.
Section 44(3) of the Act amended Section 8(1)(j) of the RTI Act. The amended provision states that information relating to personal information can be exempted from disclosure.
The petition challenging this change argues that the amendment could have wider consequences for citizens seeking information from public authorities.
Why Does This Matter?
The issue involves a difficult balance:
| Privacy Concern | Transparency Concern |
| Personal information should be protected | Citizens need access to information held by public authorities |
| Unnecessary disclosure can harm individuals | Public-interest information may be important for accountability |
| Organisations need clear privacy safeguards | Journalists and RTI applicants need meaningful access to information |
The Supreme Court is therefore dealing with an important constitutional question: how should personal privacy be balanced against transparency and the right to information?
The challenge does not mean the RTI Act has disappeared. Rather, the dispute concerns the scope of the personal-information exemption after the DPDP amendment.
Major Privacy Risks Under the DPDP Act
The DPDP Act is designed to strengthen privacy, but its implementation also raises several concerns.
1. Government Data Access
One area of debate involves the circumstances in which government authorities can process or access personal data.
Critics argue that strong safeguards are necessary whenever government bodies handle large amounts of citizens’ personal information.
2. Privacy vs Public Interest
A major question is whether privacy protections could sometimes prevent disclosure of information that has genuine public importance.
This is particularly relevant to RTI applicants, journalists and researchers.
3. Impact on Investigative Journalism
Journalists often rely on information obtained through public records and RTI applications.
The controversy surrounding Section 44(3) has therefore raised concerns about whether broader personal-information exemptions could make certain investigations more difficult.
4. Compliance Burden for Businesses
Businesses that collect and process personal information will need to review their data practices.
This can include:
- How consent is obtained
- What information is collected
- Why the information is collected
- How long data is retained
- How personal data is secured
- How users can exercise their rights
- How organisations respond to data breaches
What Changes for Ordinary Internet Users?
For everyday users, the DPDP Act is ultimately about greater accountability over personal information.
Whenever people create online accounts, use apps, shop online or provide information to digital services, organisations may process their personal data.
The new framework is intended to make organisations more transparent about this processing.
The Rules also require notices to be clear, standalone and understandable, including information about what personal data is being collected and the purpose for which it is processed.
In Simple Terms
You should increasingly know:
- What data an organisation is collecting
- Why it needs that data
- How your consent is being handled
- How you can withdraw consent
- How you can exercise your data-related rights
- How organisations are expected to protect your information
What Is a Consent Manager?
A Consent Manager is an important part of the DPDP framework.
It is intended to provide a mechanism through which individuals can give, manage, review and withdraw consent for the processing of their personal data.
The Rules prescribe requirements for Consent Managers, including registration and operational safeguards.
Rule 4 is scheduled to become effective on 13 November 2026, making the date an important milestone for the consent-management framework.
DPDP Act: What Businesses Need to Prepare For
Businesses handling personal data should not wait until the final implementation date to begin preparing.
Important Compliance Areas
| Area | What Businesses Should Review |
| Consent | How users provide and withdraw consent |
| Privacy Notices | Whether notices are clear and understandable |
| Security | Measures used to protect personal data |
| Data Retention | Whether unnecessary data is retained |
| Third Parties | How vendors and processors handle data |
| Data Breaches | Internal procedures for responding to incidents |
| Children’s Data | Additional safeguards where applicable |
| User Rights | Processes for handling requests and complaints |
MeitY has described the phased implementation as a way to provide organisations with time to prepare for compliance.
Why the DPDP Act Matters in 2026
The importance of the DPDP Act goes beyond privacy policies and corporate compliance.
It affects three major areas:
1. Citizens — who want greater control over their personal information.
2. Businesses — which need to change how they collect, process and protect data.
3. Government and public institutions — which must balance privacy with transparency and access to information.
That makes 2026 an important transition period for India’s digital-data ecosystem.
DPDP Act 2026: What Happens Next?
The next major developments will involve both implementation and litigation.
Businesses will continue preparing for the phased implementation of the Rules, while the Supreme Court’s proceedings could determine how some of the controversial provisions are interpreted or applied.
For now, there is no court ruling cancelling the DPDP Act.
The framework remains India’s central data-protection law, while questions surrounding privacy, RTI access and constitutional rights continue to be debated.
FAQs
What is the DPDP Act?
The Digital Personal Data Protection Act, 2023 is India’s main legislation governing the processing and protection of digital personal data.
When were the DPDP Rules notified?
The Digital Personal Data Protection Rules, 2025 were notified by MeitY on 13 November 2025.
When will Rule 4 of the DPDP Rules take effect?
Rule 4 is scheduled to come into force one year after the Rules were published, making 13 November 2026 the relevant date.
What is the biggest controversy around the DPDP Act?
One of the biggest controversies concerns the amendment to Section 8(1)(j) of the RTI Act, which has triggered legal challenges over privacy and transparency.
Has the Supreme Court struck down the DPDP Act?
No. The Supreme Court has not struck down the DPDP Act. Challenges to parts of the framework remain under consideration.
What does the DPDP Act mean for businesses?
Businesses handling personal data will need to prepare for requirements relating to consent, notices, security, data handling, user rights and other compliance obligations.
What does the DPDP Act mean for citizens?
The framework is intended to strengthen protection of digital personal data and give individuals greater control and transparency over how organisations process their information.
Conclusion
The DPDP Act: Major Privacy Risks & New Rules for 2026 story is about more than a new set of privacy regulations.
India is attempting to build a stronger framework for protecting personal data while continuing to support digital businesses and innovation. But the ongoing RTI controversy shows that data protection can directly intersect with transparency, journalism and citizens’ right to information.
With the framework being introduced in phases, 13 November 2026 and May 2027 are important dates to watch.
The final impact of the law will also depend on how the Supreme Court deals with the constitutional challenges surrounding the DPDP Act and its changes to the RTI framework.
Follow KhabarKhojo on Instagram for the latest news updates, breaking stories and important headlines.
📲 Instagram: @officialkhabarkhojo
Also read more of such a news on our Technology page.
More Stories
Modi Putin BRICS Summit 2026: Positive Power Shift
Gujarat Bank Strike 2026: Major 3-Day Shutdown Alert
iPhone 18 Launch: Exciting Apple Reveal With Powerful New Features