< Back to situation

[REVISION HISTORY]

India DPDP Act compliance rollout

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-07-29 14:05 UTC → 2026-08-18 20:02 UTC · added removed

Following the enforcement of the Digital Personal Data Protection (DPDP) Act and its 2025 rules, Indian businesses across sectors are adapting their practices to meet new fiduciary obligations. The hospitality industry is revising contracts after an 18‑month compliance window, treating hotels as "Data Fiduciaries" “Data Fiduciaries” and, for larger operators, as "Significant “Significant Data Fiduciaries." Fiduciaries.” This requires robust privacy clauses, stricter handling of guest and employee data, and ensuring that franchise partners, travel agencies, payment gateways and IT providers comply with the law. This shift mirrors the EU GDPR, requiring management of personal data for multiple stakeholders and addressing cross‑border data transfers and legacy records digitisation. Simultaneously, digital finance platforms offering instant personal loans are implementing DPDP‑driven safeguards. Apps must limit data collection to essential identity‑verification information, prohibit access to contacts or photo galleries, provide granular consent options, and use end‑to‑end encryption. The Reserve Bank of India oversees compliance for licensed lenders, differentiating them from unregulated shadow lenders. Together, these developments illustrate In the broad, sector‑wide impact of India's DPDP regime, compelling both hospitality social media sector, the regulatory framework is prompting new technical trials. Meta is currently testing privacy-protective age-confirmation methods on WhatsApp to help the platform distinguish between adults and fintech firms children. While the law does not explicitly mandate collecting dates of birth, draft implementation rules suggest that social media platforms may eventually need to embed comprehensive data‑privacy measures into their operations. utilize India’s Aadhaar-linked biometric identity infrastructure for more reliable age assurance. Non-compliance with the DPDP Act carries significant penalties, which can reach ₹250 crore.

Versions

  1. 2026-08-18 20:02 UTC India DPDP Act compliance rollout
  2. 2026-07-29 14:05 UTC India DPDP Act compliance rollout

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.