What was notified, and when it bites
The Digital Personal Data Protection Act was passed in 2023, but an Act without rules is mostly unenforceable. The Digital Personal Data Protection Rules were notified on 14 November 2025, with a phased runway giving most obligations an 18-month deadline.
So the substantive compliance date for most businesses falls in 2027, with Consent Manager registration and the Data Protection Board arriving ahead of the main deadline. Some obligations bite sooner than others.
The part that matters if you are a student
A child, under this law, is anyone who has not completed eighteen years. That is a materially stricter line than the UK or the EU, where the age of consent for online services is 13 to 16.
Before processing a child's personal data, a business needs VERIFIABLE parental consent. A tick-box saying “I am over 18” is not verifiable consent. The Rules contemplate real verification of the parent's identity and their relationship to the child, including through a Digital Locker service.
And then there is the part that is hardest to work around: tracking, behavioural monitoring and targeted advertising directed at children are prohibited, and parental consent is not a defence to them. The Fourth Schedule to the Rules does carve out specified classes of data fiduciary and purpose — healthcare, educational institutions, and child-safety uses — so it is not absolute, but no ordinary consumer app falls inside it.
What rights you get
You can ask any business what personal data it holds about you and who it has shared it with. You can ask for corrections. You can ask for erasure when the purpose has been served.
You can nominate someone to exercise these rights if you are unable to. And withdrawing consent has to be as easy as giving it — if signing up took one tap and leaving takes an email chain, that is not compliance.
Every business must publish contact details for someone who can answer questions about its processing, and there is a Data Protection Board to complain to.
Two things worth doing this week
Look at the apps on your phone that asked for contacts, storage or location permission and could not possibly need them. Loan apps are the notorious case: contact-list access is what makes harassment of your family possible later.
Check what a service says it does with your data before you sign up, not after. A financial education site does not need your PAN. A game does not need your contact list. When the ask does not match the service, that mismatch is the signal.