Law / India

India

13 of 15 named instruments researched to a stage, across all six areas of law we track: 9 in force and 4 enacted but not yet in force. As of 12 September 2026.

When they take effect13 of 13 carry a date. Earlier is before 2015.
Before 2015: 4 instruments (4 in force) earlier 2015: 0 instruments 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 0 instruments ’20 2021: 1 instrument (1 in force) 2022: 1 instrument (1 in force) 2023: 0 instruments 2024: 0 instruments 2025: 2 instruments (2 in force) ’25 2026: 1 instrument (1 in force) 2027: 4 instruments (4 enacted but not yet in force) ’27 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 1
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law 2
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law1 instrument, 1 in force

Research summary (168 words)

India's one notified AI-transparency rule binding intermediaries is rule 3(3) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, inserted by amendment notified 10 February 2026, requiring detection and labelling of synthetically generated information.

India has no enacted AI-risk-obligations, AI-training-data, or general AI statute: the Digital India Act, announced by the Ministry of Electronics and Information Technology in March 2023 as the intended successor to the Information Technology Act, 2000, had not been introduced as a Bill in Parliament as of the date below, and the Artificial Intelligence (Ethics and Accountability) Bill, 2025, a private member's Bill introduced in the Lok Sabha in December 2025, had not progressed to committee stage.

The Ministry's India AI Governance Guidelines (November 2025) and its March 2024 advisory on deepfake labelling and synthetic-content disclosure are non-binding policy documents rather than notified rules, so neither is recorded as an instrument. Whether the Bharatiya Nyaya Sanhita, 2023 carries a deepfake-specific criminal provision reaching an ai_prohibited_practices finding is not resolved here.

AI transparency

Synthetically Generated Information Labelling Duty for Intermediaries

Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, rule 3(3), as inserted by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (G.S.R. 120(E), dated 10 February 2026)Official consolidated text of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules

In force 7 months, effective 10 February 2026. Binds private bodies.

What this law does

Rule 3(3), inserted into the Intermediary Guidelines and Digital Media Ethics Code Rules, 2021 by amendment notified 10 February 2026, applies where an intermediary offers a computer resource which may enable, permit, or facilitate the creation, generation, modification, alteration, publication, transmission, sharing, or dissemination of information as synthetically generated information.

Such an intermediary must ensure that any such information not falling within a listed prohibited category (such as child sexual exploitative material or content falsely depicting a real person or event) is prominently labelled, in the visual display or by a prefixed audio disclosure, so a viewer can immediately identify it as synthetically generated.

It must also embed that information with permanent metadata or another technical provenance mechanism, including a unique identifier, to the extent technically feasible. The intermediary must not enable removal, suppression or modification of that label or metadata.

"Synthetically generated information" is defined as audio, visual or audio-visual information artificially or algorithmically created, generated, modified or altered using a computer resource so that it appears real, authentic or true, subject to listed exclusions for routine or good-faith editing, formatting and accessibility work. This provision has applied since its own notification date, 10 February 2026, under the parent Rules' own commencement clause.

What it requires

Privacy law6 instruments, 2 in force, 4 enacted but not yet in force

Research summary (283 words)

India's Digital Personal Data Protection Act, 2023 (DPDPA, No. 22 of 2023) received Presidential assent on 11 August 2023, but its substantive chapters have not yet commenced.

Notification G.S.R. 843(E) (Gazette of India Extraordinary, Part II Sec. 3(i), 13 November 2025), issued under DPDPA s.1(2), appointed its own publication date, 13 November 2025, as the date on which s.1(2), s.2 (definitions), sections 18 to 26 (the Data Protection Board), section 35, sections 38 to 43, and section 44(1) and (3) came into force, and appointed eighteen months from that same publication date, 13 May 2027, as the date on which sections 3 to 5, section 6(1) to (8) and (10), sections 7 to 10, sections 11 to 17, section 27 (except (1)(d)), sections 28 to 34, 36, 37, and section 44(2), the entire lawful-basis, consent, data-subject-rights, and cross-border-transfer chapters, come into force.

The Act has no special or sensitive-category tier at all, so once its duties commence, a voiceprint or faceprint is governed as ordinary personal data under the same general consent and security rules as any other identifier, not as a distinct heightened category.

Section 3(c)(ii) carves out personal data the data principal has made or caused to be made publicly available, one of the broadest such carve-outs in the region, though it does not on its own terms rescue an identifier a service derives from that public material.

Because section 44(2), which would repeal IT Act section 43A and the Sensitive Personal Data or Information Rules, 2011, is itself among the provisions not yet commenced, the SPDI Rules 2011 remain India's operative sensitive-data regime today; they are not catalogued here as an instrument, for lack of a verified working primary URL.

Breach notification

Digital Personal Data Protection Act, 2023, breach notification duties

Digital Personal Data Protection Act, 2023 (DPDPA), No. 22 of 2023, breach notification, s.8(6)official statute and Rules text, Ministry of Electronics and Information Technology (MeitY)

In force in 232 days, effective 13 May 2027. Binds public and private bodies.

What this law does

Section 8(6) requires a Data Fiduciary to give the Board and each affected Data Principal intimation of a personal data breach, in the form and manner prescribed. Rule 7 fills in that detail: notify each affected Data Principal without delay, notify the Board without delay with an initial description, then supply a detailed follow-up report within 72 hours of becoming aware of the breach, or such longer period as the Board allows.

Neither provision is currently in force: s.8 sits in the sections-3-to-17 bucket, appointed by Notification G.S.R. 843(E) (13 November 2025) to commence eighteen months after its own publication date, 13 May 2027; Rule 7 sits in the parallel rules-3-to-16 bucket, appointed to the same 13 May 2027 date by the Rules' own Rule 1(4).

What it requires

Comprehensive regime

Digital Personal Data Protection Act, 2023, comprehensive regime and lawful basis

Digital Personal Data Protection Act, 2023 (DPDPA), No. 22 of 2023, ss.2(t), 4, 6, 7, 8official statute text, Ministry of Electronics and Information Technology (MeitY)

In force in 232 days, effective 13 May 2027. Binds public and private bodies.

What this law does

The DPDPA is India's first comprehensive personal-data statute, defining "personal data" broadly and technology-neutrally as any data about an identifiable individual (s.2(t)), with no separate sensitive or special-category tier for any kind of data, biometric included.

A Data Fiduciary must have a lawful basis under s.4 before processing, ordinarily the data principal's free, specific, informed, unconditional and unambiguous consent under s.6, or one of s.7's enumerated legitimate uses (voluntarily-provided data for a specified purpose, state functions, employment, medical emergency). A Data Fiduciary bears general erasure (s.8(7)) and security-safeguard (s.8(5)) duties.

None of ss.4, 6, 7, or 8 have commenced: Notification G.S.R. 843(E) (13 November 2025) appoints eighteen months from its own publication date, 13 May 2027, as their commencement date under clause (c); that calendar date is arithmetic on the notification's own offset, not a separately printed date. Section 2's definitions, by contrast, came into force on the notification's publication date itself, 13 November 2025, under clause (a).

What it requires

Digital Personal Data Protection Rules, 2025

G.S.R. 846(E), Digital Personal Data Protection Rules, 2025, notified 13 November 2025official Rules text, Gazette of India Extraordinary, Ministry of Electronics and Information Technology

In force 10 months, effective 13 November 2025. Binds public and private bodies.

What this law does

The Rules implement the DPDPA's app-facing detail: consent-notice form, security safeguards, breach notification (Rule 7), children's-data verification, and Significant Data Fiduciary duties including an annual Data Protection Impact Assessment and algorithmic-fairness assessment (Rule 13).

As notified, only Rules 1, 2, and 17 to 21, the Data Protection Board's own administrative machinery (member recruitment, meeting procedure, digital-office functioning, staff appointment), are currently in force. Rule 4 (Consent Manager registration) commences 13 November 2026; the app-facing bulk (Rules 3, 5 to 16, 22, and 23) commences 13 May 2027.

What it requires

Cross border transfer

Digital Personal Data Protection Act, 2023, cross-border transfer restrictions

Digital Personal Data Protection Act, 2023 (DPDPA), No. 22 of 2023, cross-border transfer, s.16official statute text, Ministry of Electronics and Information Technology (MeitY)

In force in 232 days, effective 13 May 2027. Binds public and private bodies.

What this law does

Section 16(1) sets a blacklist model: transfer of personal data outside India is permitted by default to any country or territory, except where the Central Government affirmatively notifies a restriction. This flips the 2019/2021 draft Bills' government-approved whitelist model. No data-localization mandate appears anywhere in the Act.

Section 16 sits inside the sections-3-to-17 bucket; Notification G.S.R. 843(E) (13 November 2025) appoints eighteen months from its own publication date, 13 May 2027, as this bucket's commencement date. No restricted-country list has been notified because the enabling section is not yet in force.

What it requires

Data subject rights

Digital Personal Data Protection Act, 2023, data subject rights

Digital Personal Data Protection Act, 2023 (DPDPA), No. 22 of 2023, data subject rights, ss.11-14official statute text, Ministry of Electronics and Information Technology (MeitY)

In force in 232 days, effective 13 May 2027. Binds public and private bodies.

What this law does

Once in force, a data principal may demand a summary of their processed personal data and the identities of the Fiduciaries and Processors it was shared with (s.11), correction, completion, updating and erasure (s.12), grievance redressal against the Fiduciary in the first instance with a complaint to the Board only after that process is exhausted (s.13), and a right to nominate another individual to exercise these rights on death or incapacity (s.14).

No express portability or objection right appears in the Act text as read. None of this currently binds; Notification G.S.R. 843(E) (13 November 2025) appoints eighteen months from its own publication date, 13 May 2027, as Chapter III's commencement date.

What it requires

Enforcement supervision

Digital Personal Data Protection Act, 2023, Data Protection Board and penalties

Digital Personal Data Protection Act, 2023 (DPDPA), Data Protection Board and penalties, ss.18-26, 33, 39official statute text, Ministry of Electronics and Information Technology (MeitY)

In force 10 months, effective 13 November 2025. Binds public and private bodies.

What this law does

The Data Protection Board of India (Chapter VI, ss.18-26) is established and administratively operational, and section 39's ouster of civil-court jurisdiction over any matter the Board is empowered to decide is also in force, both since 13 November 2025 under Notification G.S.R. 843(E), clause (a).

Its penalty powers, set out in the Schedule under s.33(1), are exclusively civil monetary: up to Rs 250 crore for a failure to take reasonable security safeguards, up to Rs 200 crore for failing to notify a breach, up to Rs 200 crore for a children's-data violation, up to Rs 150 crore for a Significant Data Fiduciary violation, and up to Rs 10,000 for a data principal's own breach of their s.15 duties (impersonation, suppressing material information, frivolous complaints).

No provision found authorizes the Board to award compensation to an affected data principal directly; its penalties are payable to government. Section 33 (the penalty Schedule) and the rest of the complaint and appeal machinery (ss.27-34, except s.27(1)(d)) have not commenced; Notification G.S.R. 843(E), clause (c), appoints eighteen months from its own publication date, 13 May 2027, as their commencement date.

What it requires

Scraping law2 instruments, 2 in force

Research summary (186 words)

India binds any person to a computer-misuse regime under the Information Technology Act, 2000, whose section 43 imposes civil compensation, payable to the affected person and uncapped since a 2009 amendment removed the original one-crore-rupee ceiling, for unauthorised access to, or downloading, copying or extracting data from, a computer resource, and whose section 66 makes the same conduct a criminal offence when done dishonestly or fraudulently.

The Copyright Act, 1957 protects a compilation or database only as a literary work under its ordinary originality standard; India has no separate sui generis database right.

Its section 52(1)(a) confines fair dealing, for any work other than a computer programme, to private or personal use including research, criticism or review, and the reporting of current events, and names no exception for text-and-data-mining or AI-model training, while its section 65A separately criminalises circumventing an effective technological protection measure with intent to infringe.

Section 66B (punishment for dishonestly receiving a stolen computer resource or communication device) addresses receipt of a device already known to be stolen rather than the act of scraping a public page, and is not described further here.

Computer misuse

Information Technology Act, Unauthorized Access and Computer-Related Offences

Information Technology Act 2000 (No. 21 of 2000), as amended by the Information Technology (Amendment) Act, 2008 (No. 10 of 2009), ss. 43, 66Official text of the Information Technology Act, 2000, as amended, India Code (Ministry of Law and Justice, Legislative Department)

In force since 17 October 2000. Binds public and private bodies.

What this law does

Section 43 makes any person who, without the permission of a computer resource's owner or the person in charge of it, accesses or secures access to it, or downloads, copies or extracts data from it, liable to pay damages by way of compensation to the person so affected; the 2009 amendment that substituted this closing language removed the original one-crore-rupee ceiling, so the civil compensation now carries no cap. Section 66 makes the same conduct, done dishonestly or fraudulently, a criminal offence punishable with imprisonment for a term which may extend to three years or a fine which may extend to five lakh rupees, or both.

The Act has applied since its own commencement, 17 October 2000, per the Central Government's notification under section 1(3).

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (678 words)

India's product-security and cyber-resilience posture rests on two currently in-force instruments, plus several sector regimes this profile defers because their bound party is a licensed or government-designated status no declared LexLint activity can express.

Section 43A of the Information Technology Act, 2000 (inserted by the Information Technology (Amendment) Act, 2008 (Act 10 of 2009), with effect from 27 October 2009) makes a body corporate, the Act's own broad term for any company, firm, sole proprietorship, or other association of individuals engaged in commercial or professional activities, liable to pay uncapped compensation to a person it injures by negligently failing to implement 'reasonable security practices and procedures' over sensitive personal data or information.

The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (G.S.R. 313(E), in force since their own publication on 11 April 2011) define that standard: a documented information security programme, deemed satisfied by certification to IS/ISO/IEC 27001.

This baseline duty is repealed once section 44(2) of the Digital Personal Data Protection Act, 2023 commences, currently scheduled for 13 May 2027 under Notification G.S.R. 843(E), and remains India's operative reasonable-security statute until then, exactly as this jurisdiction's privacy row already records.

Separately, the Indian Computer Emergency Response Team's Directions of 28 April 2022 (No. 20(3)/2022-CERT-In, issued under Information Technology Act section 70B(6), effective 27 June 2022, 60 days after issuance on the Directions' own stated offset) require 'any service provider, intermediary, data centre, body corporate and Government organisation' to report a broad enumerated list of cyber incidents to CERT-In within six hours of noticing them, to synchronise every ICT system clock to the Network Time Protocol servers of the National Informatics Centre or the National Physical Laboratory, and to enable and securely retain logs of all ICT systems for a rolling 180 days within Indian jurisdiction.

Because 'body corporate' and 'intermediary' are the Act's own general terms for essentially any commercial or professional actor operating a computer resource in India, rather than a licensed or sector-specific status like a financial entity or an essential entity, this reaches an ordinary developer distributing software or a mobile app in India, and the row is flagged on that basis rather than deferred; the Directions separately impose a narrower five-year customer-record and KYC retention duty on data centres, virtual private server providers, cloud service providers, virtual private network service providers, and virtual asset service providers specifically, and that narrower bound-party class is named here rather than flagged, since no declared activity identifies it.

No enacted Indian statute sets security requirements a connected device or software product must meet before it is placed on the market, so the product-requirements research dimension is a researched absence.

The Reserve Bank of India's and the Securities and Exchange Board of India's own sector cybersecurity frameworks for banks, non-banking financial companies, and regulated market intermediaries, and the National Critical Information Infrastructure Protection Centre's regime for a government-designated 'protected system' under Information Technology Act section 70, each bind a licensed or government-designated status no declared LexLint activity can express; none is described here, so none is filed as an instrument, and each is named so a reader knows it exists.

CERT-In's Directions are enforced through Information Technology Act section 70B(7) (imprisonment for up to one year, a fine of up to one lakh rupees, or both, for non-compliance with a CERT-In direction), and the section 43A compensation duty through section 46's Adjudicating Officer (jurisdiction up to five crore rupees, above which the competent civil court hears the claim); no published enforcement record specific to either duty is confirmed in the primary text.

India's breach-notification duty for personal data is this jurisdiction's own privacy row, Digital Personal Data Protection Act, 2023 section 8(6) and Rule 7, not yet in force and scheduled for 13 May 2027; the DPDPA's separate general security-safeguards duty on a Data Fiduciary, section 8(5), is a controller security-of-processing article inside that comprehensive regime and stays there too, following the standing rule that such a provision is privacy even though it is triggered by a system holding personal data.

Security baseline statutes

Information Technology Act, Compensation for Failure to Protect Data, and Sensitive Personal Data or Information Rules, Reasonable Security Practices

Information Technology Act 2000 (No. 21 of 2000), s.43A; Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (G.S.R. 313(E), 11 April 2011), rr. 3, 4, 5, 6, 8Official Gazette notification text, mirrored via WIPO Lex

In force since 11 April 2011. Binds private bodies.

What this law does

A body corporate, meaning any company, firm, sole proprietorship, or other association of individuals engaged in commercial or professional activities, that possesses, deals in, or handles sensitive personal data or information, meaning a password, a financial account or payment-instrument detail, a physical, physiological, or mental health condition, sexual orientation, a medical record or history, or biometric information, in a computer resource it owns, controls, or operates, must implement and maintain reasonable security practices and procedures: a comprehensive, documented information security programme with managerial, technical, operational, and physical control measures commensurate with the information assets it protects.

Certification to the international Standard IS/ISO/IEC 27001 is deemed to satisfy this duty as a matter of law. That certification must be audited by an independent, government-approved auditor at least once a year. The same Rules require the body corporate to publish a privacy policy on its website. The body corporate must also appoint a Grievance Officer.

Section 43A of the Information Technology Act makes a body corporate negligent in implementing or maintaining this programme liable to pay uncapped compensation to any person it causes wrongful loss or wrongful gain.

What it requires

Vulnerability and incident reporting

CERT-In Cyber Security Directions, Incident Reporting, Logging and Time Synchronisation

Directions under section 70B(6) of the Information Technology Act 2000, No. 20(3)/2022-CERT-In (Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology, 28 April 2022)Official CERT-In directions text, Indian Computer Emergency Response Team, Ministry of Electronics and Information Technology

In force since 27 June 2022. Binds public and private bodies.

What this law does

Any service provider, intermediary, data centre, body corporate, or Government organisation that operates a computer resource in India must synchronise all its ICT system clocks to the Network Time Protocol servers of the National Informatics Centre or the National Physical Laboratory, or an equivalent source that does not deviate from them. The same entities must enable logs of all their ICT systems and retain them securely within Indian jurisdiction on a rolling 180-day basis.

They must also designate a Point of Contact for CERT-In. They must mandatorily report a broad enumerated list of cyber security incidents to CERT-In within six hours of noticing the incident or being notified of it. That enumerated list includes a data breach, a data leak, and an attack through a malicious or fake mobile app.

Data centres, virtual private server providers, cloud service providers, virtual private network service providers, and virtual asset service providers face an additional duty to register and retain specified customer KYC and transaction records for five years.

What it requires

Age gating law1 instrument, 1 in force

Research summary (171 words)

India binds a publisher of online curated content (an on-demand audio-visual catalogue transmitted over the internet) to an age-classification and access-control duty under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. No social-media minor-access restriction, app-store age-verification requirement, or age-appropriate design code binding a private service was found.

The Cinematograph Act, 1952, as amended by the Cinematograph (Amendment) Act, 2023, empowers the Central Board of Film Certification to classify a cinema film into "U", "U/A" (with a marker), "A" or "S" certificate categories before public exhibition, but its own text, as read in an amendment-consolidated copy carrying OCR artefacts, states a certification and labelling duty running to the Board rather than a point-of-admission access-control duty running to a cinema exhibitor; the numeric UA sub-markers the 2023 amendment introduced are populated by the delegated Cinematograph (Certification) Rules, 2024, whose provisions are not described here.

A labelling or certification duty alone, without a located access-control duty on a private exhibitor or distributor, is not recorded as an instrument here.

Adult content age verification (AV)

Online Curated Content Age Classification and Access-Control Duty

Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, rules 8-9 and Appendix, Code of Ethics Part II(B)-(D)Official consolidated text of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules

In force since 25 February 2021. Binds private bodies.

What this law does

Rule 8 binds a publisher of online curated content, defined as one who, performing a significant role in determining the content made available, makes available to users a computer resource enabling access to online curated content over the internet. Rule 9 requires that publisher to observe the Code of Ethics in the Appendix.

That Code classifies all such content into a "U" rating suitable for all ages, with tiered "U/A 7+", "U/A 13+" and "U/A 16+" ratings viewable below the stated age with parental guidance. It also sets an "A" rating restricted to adults, a person the Rules define as eighteen years or older. A publisher making available content classified U/A 13+ or higher must ensure access control mechanisms, including parental locks, are available for it.

A publisher making available "A"-rated content must implement a reliable age-verification mechanism for its viewership. Every publisher offering "A"-rated content must take all efforts to restrict a child's access to it through appropriate access-control measures. The Rules have applied since their own commencement, 25 February 2021, the date of their Official Gazette publication.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (135 words)

India has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the Copyright Act, 1957 governs news reproduction entirely through its ordinary fair-dealing exceptions.

Section 52(1)(a)(iii) excuses, as fair dealing, the reporting of current events and current affairs, and section 52(1)(m) separately excuses the reproduction in a newspaper, magazine or other periodical of an article on current economic, political, social or religious topics unless the author has expressly reserved the right of reproduction, an opt-out rather than an unconditional exception.

Section 39(b) extends the same fair-dealing protection, for the reporting of current events, to excerpts of a broadcast or of a recorded performance. Reproducing a headline or a short extract beyond what these enumerated exceptions cover is governed by the ordinary infringement analysis under sections 51 and 63 rather than by any aggregation-specific statute.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.