Skip to content
IndiaStand
Topic brief · maintained 2026-07-05 · updated 2026-10-07

India's digital public infrastructure and data law

India has built population-scale digital public infrastructure — a digital identity, a real-time payments rail and a document layer used by hundreds of millions — and is now, belatedly, building the legal regime meant to govern the data that flows through it. This is the maintained topic brief on where that regime stands as of 7 October 2026: the IT Act and its intermediary rules (with a second 2026 amendment still in draft and the Sahyog takedown portal before the Supreme Court), the Digital Personal Data Protection Act of 2023 and its phased 2025 Rules (with the Data Protection Board still unstaffed), and the 2025 online-gaming law in force since May 2026.

Ministry of Electronics and Information TechnologyReserve Bank of India

The two halves of the story

India’s digital governance has advanced on two tracks that grew out of step with each other. The first is infrastructure — the population-scale systems often grouped as “India Stack”: Aadhaar digital identity, the Unified Payments Interface (UPI), and the DigiLocker document layer. The second is the legal regime meant to govern the data those systems generate. The infrastructure was built and scaled through the 2010s; the standalone data-protection law arrived only in 2023, and its operational rules only in late 2025. This brief tracks that second track catching up with the first, both administered largely by the Ministry of Electronics and Information Technology.

The infrastructure that exists

According to a reference overview of India Stack, the term brands a set of separately governed government-operated systems — identity (Aadhaar, run by the UIDAI under MeitY), payments (UPI, operated in the National Payments Corporation of India ecosystem overseen by the Reserve Bank of India), and documents (DigiLocker, under MeitY). The scale is what makes the regime consequential: public reporting places cumulative Aadhaar numbers issued above 1.4 billion as of mid-2025, and UPI volumes on the order of 18 billion transactions per month in 2025. These figures are attributed to that public reporting rather than presented as this desk’s own verification; the durable point is that the systems operate at national scale, which is why the rules governing their data matter.

The regulatory spine: the IT Act and the 2021 Rules

The foundational statute remains the Information Technology Act, 2000, India’s primary cyber-law, whose Section 79 grants online intermediaries conditional “safe harbour” from liability for third-party content. The conditions are set by subordinate rules. Per PRS Legislative Research, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 impose due-diligence obligations, grievance-redressal mechanisms and, for significant social-media intermediaries, additional requirements; a 2023 amendment extended the framework to online real-money gaming and provided for a government fact-check unit to flag content about government business. The fact-check-unit provision has been contested in court, and this brief characterises rather than adjudicates that dispute: media and free-expression groups challenged it as overbroad, while the government defended it as targeted at demonstrably false information about its own affairs. In a further amendment, per reference reporting, MeitY notified the IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026, which define “synthetically generated information” and require intermediaries to label AI-generated content; the amendment took effect on 20 February 2026.

Two further moves were open as of 7 October 2026. First, on 30 March 2026 MeitY published a draft Second Amendment that would make intermediary compliance with ministry clarifications, advisories, directions and SOPs a condition of safe harbour, and extend the Part III oversight mechanism administered by the Ministry of Information and Broadcasting to users who share news and current-affairs content. The Internet Freedom Foundation described it as an expansion of executive power over online speech; the government has presented the changes as clarificatory. IndiaStand has not located a final notification. Second, the government’s takedown channel — the Sahyog portal, through which notices are issued under Section 79(3)(b) of the IT Act and Rule 3(1)(d) of the 2021 Rules — is under constitutional challenge. A single judge of the Karnataka High Court upheld it in September 2025 and X Corp appealed; on 22 July 2026 the Supreme Court, on the Union’s transfer petitions, stayed that appeal and three related cases in the Karnataka and Bombay High Courts (LiveLaw). Petitioners argue the portal bypasses the Section 69A blocking safeguards; the Union argues that parallel challenges risk conflicting rulings and has asked for one hearing.

The data-protection law: DPDP Act 2023

India’s first standalone data-protection statute is the Digital Personal Data Protection Act, 2023. Per the Act as published by MeitY and reference records of its passage, it was passed by the Lok Sabha on 7 August 2023 and the Rajya Sabha on 9 August 2023, and received Presidential assent on 11 August 2023 as Act 22 of 2023. The Act establishes a consent-based framework: entities that process personal data (“Data Fiduciaries”) owe defined obligations to individuals (“Data Principals”), including notice, purpose limitation and security safeguards, and it provides for a regulator — the Data Protection Board of India — to adjudicate breaches and impose penalties. The Act was passed as a framework law, leaving much of its operational substance to rules to be notified later, which is why its practical force waited on those rules.

What changed in November 2025: the DPDP Rules

The operational turn came on 13 November 2025, when MeitY notified the Digital Personal Data Protection Rules, 2025. Per MeitY and the government’s own announcement, the Rules operationalise the 2023 Act in phases rather than all at once: an initial set of provisions — definitions, and the machinery to establish the Data Protection Board — took effect on notification; the provisions governing consent managers take effect twelve months after notification; and the substantive compliance obligations on data fiduciaries take effect eighteen months after notification. Government material states the final Rules followed a public consultation that drew about 6,900 stakeholder inputs. In calendar terms, consent-manager registration opens on 13 November 2026 and the substantive fiduciary duties apply from 13 May 2027. Compliance trackers report a January 2026 MeitY proposal to compress the window to twelve months for large (“significant”) data fiduciaries; IndiaStand has not located an amending notification as of 7 October 2026.

The regulator itself lags the rulebook. MeitY began selecting the Board’s Chairperson and four Members with a communication dated 6 May 2026 seeking nominations; a LiveLaw analysis of 1 August 2026 reported that no Chairperson or Member had been appointed, even as a High Court had directed a litigant to the Board. As of 7 October 2026 the regime is therefore live but only partly in force: the Board exists in law, its members are not yet in place, and the core compliance duties are within their transition window.

A new statute: online gaming

One area moved from rules to statute. The Promotion and Regulation of Online Gaming Act, 2025 bans online money games — whether of chance, skill or both — together with their advertising and payment processing, and recognises e-sports and online social games. Per the government’s explainer, the Act and the Promotion and Regulation of Online Gaming Rules, 2026 came into force on 1 May 2026, constituting an Online Gaming Authority of India under MeitY to determine whether a game is a prohibited money game, run a registration regime for e-sports and notified social games, and hear complaints. It replaces the 2023 IT Rules approach, under which real-money gaming was to be verified by self-regulatory bodies.

The unsettled edges

Beyond the open IT Rules amendment and the Sahyog litigation described above, two threads remain open and are tracked here without prediction. First, the proposed Digital India Act, floated in 2023 as a wholesale replacement for the ageing IT Act, 2000: as of the latest available reference reporting no draft bill has been released publicly, and it remains at the consultation stage, with the government having in the interim pursued amendments to the existing IT Rules rather than a new statute. Second, the interaction between the DPDP regime and existing laws — including the Right to Information Act, which the DPDP Act amends, and the IT Rules’ content-governance provisions — where civil-society groups and government have taken differing positions on transparency and exemptions. This brief characterises those positions as they are stated by their holders and does not forecast an outcome.

Who owns this topic (and why we’re here)

The explainer field for “India Stack / DPDP / IT Rules” is dominated by two kinds of source: law-firm and consultancy client alerts (Nishith Desai, Shardul Amarchand Mangaldas, DLA Piper and similar), which are precise but written for compliance officers and paywalled by audience; and exam-prep and current-affairs portals aimed at UPSC aspirants, which are broad but often undated and quick to go stale as rules change. Encyclopedic reference pages sit in between and lag the notifications. What that field lacks is a single, plainly written, continuously maintained state-of-play that separates what is in force from what is notified but not yet operative, attributes each claim to an official or reference source, and is dated. That is the gap this desk fills: an institution-first account — built around what MeitY actually administers — kept current as each phase of the DPDP Rules commences.

Maintained topic brief. Analysis by IndiaStand — it characterises the state of play and the range of positions actually held, attributes each claim, and makes no forecast and no recommendation.

Sources

  1. Digital Personal Data Protection Act, 2023 (MeitY) · India
  2. Digital Personal Data Protection Rules, 2025 (MeitY) · India
  3. PIB: DPDP Rules, 2025 Notified · India
  4. IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 — PRS Legislative Research · India
  5. MeitY notifies the IT Amendment Rules 2026 (Khaitan & Co, reference) · India
  6. India Stack (reference overview) · India
  7. MeitY: nominations for Chairperson and Members of the Data Protection Board (6 May 2026) · India
  8. LiveLaw: India's Data Protection Board — established in law, absent in fact (1 Aug 2026) · India
  9. Mondaq: MeitY plans to cut short DPDP compliance timeline · India
  10. IFF: first read on the draft IT Rules Second Amendment, 2026 · India
  11. LiveLaw: Supreme Court stays HC proceedings against the Sahyog portal (22 Jul 2026) · India
  12. PIB: A New Era of Online Gaming Governance (Online Gaming Rules, 2026) · India

For organisations

Need this for a decision your organisation is making?

We establish what is documented, what changed, who is responsible, where evidence conflicts and what remains unknown. We do not give investment, legal or policy advice — the decision stays with you or your adviser. Services · Methodology