DPDP Act 2027: Data Protection Law, Privacy Rights, Consent and Breach Penalties


In this issue of Tech Tomorrow, we look at why your phone number has been collected freely at every counter for 25 years with no enforceable rules, what the new data protection law changes, and what you can do about it right now.
Before we dive in, if you're someone who enjoys understanding how technology, business, policy, and infrastructure shape the products and services you use every day, join the community if you haven't already. We publish one in-depth edition every two weeks. And if you're already a subscriber, thank you. Consider forwarding this to someone who'd enjoy thoughtful deep dives into the forces powering the country around them.
You buy a shirt at Pantaloons and the cashier asks for your phone number "to link with the bill." You give it without thinking twice.
And just like that, your number now sits in the store's point-of-sale system, which likely feeds a CRM, connects to a big loyalty database, and feeds an even bigger marketing platform. Now multiply this with every pharmacy, food delivery app, Wi-Fi login etc. That is millions of collection points, every day.
And for 25 years, no law has required companies to ask for this data clearly, or tell you how and where it will eventually be used. We recently covered how the spam pipeline works once your number is in the system. This is about what happens before that.
In 2025, Zomato became one of the first companies to reveal this ‘data sharing chain’ to customers. They started asking customers whether to share their number with restaurants for promotional updates or not; also clearly mentioning that "once shared, this info cannot be withdrawn."
So how did we get here? And how did an entire country's worth of phone numbers end up circulating with no one watching?
Until recently, the only law securing your data was Section 43A of the IT Act, 2000, along with a set of 2011 rules. Which only covered a narrow list of "sensitive" data, like passwords and health records. A bare phone number arguably fell outside its purview.
There was no dedicated regulator, standard breach-notification duty, or a penalty large enough to change anyone's behaviour. So the companies have collected phone numbers freely with almost nothing stopping them.
The breach record shows this gap cost clearly. In 2024, researchers found a threat actor selling several terabytes of Star Health Insurance data on Telegram covering over 3 crore customers. The insurance regulator eventually fined the company ₹3.39 crore, which has been one of the only penalties any Indian company has faced for a breach at this scale. And this isn’t an isolated incident. BigBasket lost data on 20 million users in 2020. Domino's India had 18 crore order records exposed in 2021, phone numbers and GPS locations included. Boat Lifestyle had 7.5 million customer records leaked in 2024. BSNL had SIM and network data exposed the same year.
A PIL filed in 2021 to force an investigation into these breaches led to a court notice to CERT-In but no public penalty followed.
Indian authorities have tried to legislate this once before. A data protection bill was introduced in 2019, and withdrawn in 2022 after a Joint Parliamentary Committee spent two years on it.
What replaced it is the Digital Personal Data Protection (DPDP) Act, which received Presidential assent in August 2023. The detailed rules were notified only on 13 November 2025, more than two years later. The substantive obligations, the ones that change how companies behave, don't kick in until 13 May 2027. That's nearly four years between a law being passed and a company being penalised for breaking it.
Now let’s talk about What happens when the DPDP Act comes into full force
Under the Act, any company or app collecting your data becomes a Data Fiduciary. And you're the Data Principal. A Fiduciary now requires your free, specific, informed consent, tied to one stated purpose, before it can process your data.
So, billing at the counter is one purpose. Marketing is another, different purpose. Going forward, a company cannot collect your phone number for one purpose and quietly use it for another.
The Act also creates four rights that didn't meaningfully exist before.

And then there are some other key provisions in the act worth knowing.
Firstly, if a breach happens, the company must notify you within 72 hours. Penalties for failing to keep your data secure go up to ₹250 crore; for failing to report a breach, up to ₹200 crore. Penalties to this scale are meant to make a company think twice before treating a customer database as loosely as an excel sheet.
That's the theory. Whether ₹250 crore actually changes behaviour depends on who's paying it. Under GDPR, the European law DPDP is loosely modelled on, fines go up to 4% of global turnover. That's what makes GDPR hurt.
Meta has been asked to pay over €1.2 billion in GDPR fines because the penalty scales with the company's size. DPDP uses fixed rupee caps instead. For a midsized Indian company, ₹250 crore would sting. For an Amazon or a Reliance, it's a line item.
The UK and US show what scaled enforcement looks like. The UK's ICO fined HelloFresh £140,000 and raised its maximum penalty to £17.5 million in 2026.
The US FTC has recovered over $178 million in civil penalties under its Do Not Call framework and reports spam complaints down 48% from 2021 peak.
India also has a history of rights that exist on paper and enforcement that doesn't follow. The 140 and 1600 number series were also designed to bring order to the call system. In practice, people still get promotional calls from 1600 numbers daily, from the very banks and insurers the system was built to regulate. The infrastructure was built. The misuse adapted around it.
Secondly, there's also a new construct called a Consent Manager, a registered intermediary with the Data Protection Board that gives you a single dashboard to see and control every consent you've given across different companies. Registration opens November 2026. It's designed to make withdrawing consent a one-click action.
Meanwhile, TRAI has started patching the consent gap from its end.

In December 2025, it launched a joint pilot with the RBI called Digital Consent Acquisition (DCA), where customers of 11 major banks can review and revoke consents previously recorded against their number.
As of August 2026, the pilot has not expanded beyond banking and is not nationally live.
The Act itself also arrived lighter than what was originally proposed. The 2019 bill that was withdrawn had provisions that didn't make it into the final law.
Data portability is gone. The GDPR-style "right to be forgotten," which in Europe lets you ask companies to suppress information about you, was narrowed to a simpler right to erasure. You can ask Pantaloons to delete your number, but you can't compel the five brokers who already bought it from Pantaloons to do the same.
And there's no private right of action. If a company leaks your data, you can't sue them directly in court. Your only route is a complaint to the Data Protection Board, whose members are government-appointed, not an independent tribunal you elect or choose.
Section 17 of the Act also lets the Central Government exempt its own agencies from most consent requirements through a simple gazette notification. That provision is currently being challenged before the Supreme Court, which has issued notice to the government but declined to stay the law while the case proceeds.
None of this makes the Act pointless. But it would be dishonest to call it a guaranteed fix.
What it is currently is a serious first attempt with real penalties, sitting alongside real exemptions and structural weaknesses that are still being fought out in court.
How it turns out once the deadlines pass, whether the fines actually land, whether consent collection changes at the counter, we'll track with real numbers in a future issue.
The whole thing rolls out in phases, with the full compliance deadline set for 13 May 2027. No grace period is expected after that date.

While the law catches up, the telecom and device side hasn't been sitting idle.
Airtel, Vi and Jio now run network-level AI spam detection that flags suspicious calls automatically, no app needed.
On the device side, Apple sends unrecognised numbers to voicemail, Google's Pixel phones can answer unknown calls with an AI voice and transcribe them, and Samsung's Smart Call flags suspected spam mid-call.
These help, but the device features sit behind ₹30,000+ handsets, which puts them out of reach for most Indian buyers.
Now, you must be asking yourself if there is anything you can do today to reduce the calls, without waiting for any of this?

The simplest thing is at the billing counter - No Indian law requires you to give your phone number to get a bill. The Consumer Affairs Ministry said exactly this in a May 2023 advisory. The Chandigarh State Consumer Disputes Redressal Commission ruled in 2024 that forcing a number for billing is an unfair trade practice. You lose loyalty points and return tracking, but you keep control of where your number goes.
Reporting misuse - If a 1600 number tries to sell you something, report it through 1909. That number is traceable to a specific bank or insurer.
Register on DND through the TRAI DND app or by texting "START 0" to 1909, with category-level preferences for banking, real estate, and education calls. Report spam through 1909 or the Chakshu platform on Sanchar Saathi.
Getting a second number that keeps essential and optional communication apart - Get a new number, link it only to handpicked essential services and contacts that matter.
If you have parents or help at home who answer every call and share their number at every counter, pass this on: stores can’t refuse you a bill for not sharing your number; 140 and 1600 series calls, and neither will ask for an OTP over a call, and if something feels wrong, note the number and report it on 1909.
For 25 years, your phone number has been collected at every counter with no enforceable rules about what happens next. For the first time, there's a law that says the number you gave away is still yours, and a regulator that's supposed to enforce it. Whether it changes anything depends on whether companies treat ₹250 crore as a cost of doing business or a reason to stop. The cashier, though, is still asking.
Give us your honest feedback
|
😍 Loved it, more like this!
|
🙂 Good, could be better
|
😕 Not relevant to me
|


Access Control
Smart Sensors And Automation
Network Adapters and Accessories
PoE Switches
Point To Point Wireless Radio
Routers
IP Cameras
Memory Cards
NVR
Smart WiFi Cameras
Desktop & Laptop RAMs
Internal and External Hard Drives
NAS Storage & Enclosures
SSD and NVMe Drives
USB Flash Drives