Digital Data Protection

07 September 2026

Editorial Note

August 2026 marks a decisive compliance inflection point for India’s data-protection regime. With the Digital Personal Data Protection (DPDP) Act, 2023 fully enacted and the DPDP Rules, 2025 notified in November 2025, organisations are now in the critical execution window ahead of Phase II (consent-manager registration from 13 November 2026) and full enforcement by May 2027. This newsletter curates the most significant July–August 2026 developments—domestic and global—and aligns them with actionable legal analysis under Indian law.

1. Government-Wide DPDP Compliance Push: Cabinet Secretary Directive

What happened:

On 20 August 2026, Cabinet Secretary T.V. Somanathan directed all Union ministries, state governments and UT administrations to prepare time-bound DPDP implementation plans, appoint senior oversight officials and nodal officers, and map citizen-data inventories.

Legal significance (India):

Accountability & Governance: The directive operationalises the DPDP Act’s core principles—purpose limitation, data minimisation, storage limitation, security safeguards and accountability—by embedding them into government machinery.

Data Inventory as Compliance Baseline: Departments must identify what personal data they hold, where it resides, processing purposes, access controls, and third-party sharing—mirroring the fiduciary obligations under Sections 4–9 of the DPDP Act.

Privacy-by-Design Mandate: Agencies are instructed to integrate privacy-by-design into digital services, foreshadowing how Significant Data Fiduciaries (SDFs) in the private sector will be expected to demonstrate systemic compliance.

Practical takeaway for counsel:

Treat the government’s internal compliance exercise as a template for client readiness—especially for public-sector vendors, PPPs, and regulated entities interfacing with government data.

2. Dark Patterns & Children’s Data: CCPA PhysicsWallah Order

What happened:

On 1 June 2026, the Central Consumer Protection Authority (CCPA) penalised PhysicsWallah Rs 5 lakh for dark patterns, including a pre-ticked donation checkbox and mandatory phone/email collection for free courses.

Legal alignment with DPDP Act:

Consent Quality: Pre-ticked boxes and bundled consent contradict the DPDP Act’s requirement for free, specific, informed, and unambiguous consent.

Data Minimisation & Purpose Limitation: Conditioning access to free content on surrender of contact details—without functional necessity—violates minimisation and purpose-limitation norms.

Children’s Data: Section 9(1) of the DPDP Act mandates verifiable parental consent for users under 18; platforms targeting students must audit age-gating and consent flows accordingly.

Litigation risk:

While the CCPA order arose under the Consumer Protection Act, 2019, similar conduct will attract DPDP penalties (up to Rs 250 crore for security failures; Rs 200 crore for breach-notification lapses) once full enforcement begins.

3. Data Sovereignty & Cross-Border Transfers: Cloud, AI, Negative List

What happened:

In late August 2026, commentary highlighted Indian enterprises prioritising data sovereignty in cloud procurement, driven by DPDP cross-border framework and geopolitical shifts.

Indian legal position:

Negative-List Approach: The DPDP Act permits cross-border transfers unless the Government of India restricts specific countries or categories—unlike blanket localisation mandates.

Sectoral Overlays: RBI (payment data), SEBI (cloud for market infrastructure), and UIDAI (Aadhaar vaults) impose stricter localisation—creating a layered compliance map.

AI & Sovereignty: As AI workloads scale, counsel must assess whether training data, model weights, or inference logs constitute personal data requiring DPDP-compliant safeguards and potential localisation.

Deal implication:

In cloud/AI contracts, ensure DPDP-aligned data-flow clauses, audit rights, and breach-notification timelines (72 hours under emerging best practice).

4. Global Context: GDPR, EU AI Act, India Timeline

Global developments (2026):

GDPR Re-Opening: The EU has initiated a review of the General Data Protection Regulation, potentially reshaping global compliance baselines.

EU AI Act Full Enforcement: As of 2 August 2026, the EU AI Act reaches full enforcement, affecting AI systems deployed by or into the EU—including Indian exporters and SaaS providers.

India’s phased enforcement roadmap:

Phase I (from 13 November 2025): Data Protection Board established; core fiduciary duties active.

Phase II (13 November 2026): Consent Manager registration opens (India-incorporated entities with Rs 2 crore+ net worth).

Phase III (12 May 2027): Full compliance mandatory—granular consent, one-click withdrawal, parental consent, encryption, 72-hour breach notification, automated deletion with proof.

Strategic note:

Multinationals should synchronise DPDP, GDPR, and EU AI Act compliance calendars to avoid conflicting obligations—especially around consent granularity, AI transparency, and cross-border transfers.

5. Constitutional Challenges: RTI, Press Freedom, Surveillance

What is pending:

The Supreme Court is examining whether DPDP Act amendments to the RTI Act unduly restrict access to information and investigative journalism, while also reviewing surveillance-related provisions.

Legal stakes:

RTI vs Privacy: Petitioners argue the DPDP Act RTI amendments over-broadly exempt personal information, weakening transparency.

Board Independence: Challenges also target the Data Protection Board structure and appellate mechanisms.

Watchlist for counsel:

A landmark ruling could recalibrate the balance between privacy, transparency, and state access—impacting public-interest litigation, media law, and government-data disclosures.

Compliance Checklist for August–November 2026

  • Map personal data flows (government-style inventory) across business units and vendors.
  • Audit consent mechanisms for dark patterns, bundling, and children data; implement verifiable parental consent where needed.
  • Review cross-border transfers against the negative list and sectoral localisation rules (RBI, SEBI, UIDAI).
  • Prepare for Consent Manager registration (Phase II, 13 November 2026)—assess eligibility and integration architecture.
  • Stress-test breach response for 72-hour notification readiness and vendor coordination.
  • Monitor Supreme Court proceedings on RTI/press freedom implications of the DPDP Act.

Looking Ahead

As India moves toward full DPDP enforcement by May 2027, the next 9–12 months will define compliance culture—shifting from policy drafting to operational proof. For legal teams, the priority is to embed privacy-by-design, evidence-ready consent logs, and cross-border governance into daily operations—before the consent-manager window opens in November 2026.

News & Deals

India Juris advised on a partial exit from Rentomojo

India Juris advised on an exit from Pee Safe

India Juris Advises on a Pre-Seed Investment

Publications

Product Liability in India

India’s Oil & Gas Regulatory Landscape

IBC Avoidance Transactions

Newsletters

Prohibition of Market Abuse in Securities Markets

Digital Data Protection

MoP&NG Amends Natural Gas Supply Regulation Framework