India Data-Protection Calendar

What has happened, and what is coming. Every entry carries a source — we publish a date only when it can be checked.

Upcoming

No confirmed future deadline is currently published. We list a compliance date only once it has been officially notified and can be linked to its source — a wrong deadline is worse than no deadline. Watch this page and the enforcement tracker as the DPDP Rules phase in.

Timeline

2025

  1. consultation
    Draft Digital Personal Data Protection Rules released for consultation

    MeitY published draft Rules covering notice, consent managers, breach notification, children's data verification and Board procedure, and invited public comments.

    Source ↗

2024

  1. enforcement
    WhatsApp / Meta — Competition Commission of India

    The CCI imposed a ₹213.14 crore penalty on Meta over WhatsApp's 2021 privacy policy and ordered a 5-year bar on sharing user data with other Meta companies for advertising.

    Source ↗
  2. enforcement
    LinkedIn — Irish Data Protection Commission

    The Irish DPC fined LinkedIn €310 million over unlawful processing of member data for targeted advertising — relevant to Indian IT/ITES firms serving EU data subjects.

    Source ↗
  3. enforcement
    Star Health & Allied Insurance — CERT-In / IRDAI

    A reported breach exposed policyholder health and personal data of Star Health customers, prompting CERT-In and IRDAI scrutiny and litigation over the alleged leak.

    Source ↗
  4. enforcement
    Manappuram Finance Limited; Ola Financial Services Pvt. Ltd.; Visa Worldwide Pte. Limited — Reserve Bank of India

    The RBI imposed monetary penalties on three payment system operators for violations of KYC and other regulatory guidelines under the Payment and Settlement Systems Act. Notices were issued, show‑cause hearings held, and

    Source ↗

2023

  1. milestone
    Digital Personal Data Protection Act, 2023 receives Presidential assent

    India's first comprehensive data-protection statute enters the statute book, with penalties of up to ₹250 crore per breach. Provisions commence on dates notified by the Central Government.

    Source ↗
  2. enforcement
    Meta Platforms — Irish Data Protection Commission

    The Irish DPC fined Meta €1.2 billion — the largest GDPR penalty to date — for transferring EU user data to the US without adequate safeguards. A benchmark for cross-border transfer risk.

    Source ↗

2022

  1. enforcement
    All body corporates & intermediaries — CERT-In

    CERT-In issued directions requiring cyber-incident reporting within 6 hours and 180-day log retention, effective 28 June 2022 — India's first strictly enforced breach-notification regime.

    Source ↗

2021

  1. enforcement
    Mastercard — Reserve Bank of India

    The RBI barred Mastercard from onboarding new domestic customers for failing to comply with the 2018 payment-data localisation directive. The ban was lifted in June 2022 after compliance.

    Source ↗
  2. enforcement
    American Express & Diners Club — Reserve Bank of India

    The RBI stopped American Express and Diners Club from onboarding new customers over payment-data localisation non-compliance; the restriction on Amex was lifted in August 2022.

    Source ↗

2017

  1. enforcement
    K.S. Puttaswamy v Union of India — High Court / Supreme Court

    A nine-judge Supreme Court bench unanimously held privacy to be a fundamental right, laying the constitutional foundation for India's data-protection regime.

    Source ↗