Enactment
Effective 2023-08-11 · verified 2026-07-31Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023); Presidential assent 11 August 2023; Gazette ID CG-DL-E-12082023-248045.
Source: Official Gazette text (MeitY PDF) ↗We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.
The compliance facts practitioners keep re-verifying — DPDP phasing, CERT-In obligations, Aadhaar and insurance audit duties — in one register, each entry with its primary source and a last-verified date. Free to cite and reuse with attribution.
Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023); Presidential assent 11 August 2023; Gazette ID CG-DL-E-12082023-248045.
Source: Official Gazette text (MeitY PDF) ↗Digital Personal Data Protection Rules, 2025 notified 13 November 2025 as G.S.R. 843(E), Gazette of India Extraordinary Part II s.3(i).
Note: Gazette date corroborated across multiple law-firm analyses; the PIB document filename carries the press-release date (17 Nov), not the notification date.
Source: MeitY / PIB — DPDP Rules 2025 ↗Provisions constituting and empowering the Data Protection Board (ss.18–26), definitions, and procedural rules took effect on 13 November 2025.
Source: DPDP Rules 2025 (phased commencement) ↗Section 6(9) (verifiable parental consent) and section 27(1)(d) (publication duty) commence one year from notification — November 2026.
Source: DPDP Rules 2025 (phased commencement) ↗Notice and consent standards, data fiduciary duties, children's data and data principal rights commence eighteen months from notification — May 2027. Published analyses split on 12 vs 13 May; confirm the exact day with counsel before relying on it.
Source: DPDP Rules 2025 (phased commencement) ↗The Schedule to the Act caps monetary penalties at up to ₹250 crore per instance for the highest tier (failure to take reasonable security safeguards to prevent a personal data breach), with lower tiers at ₹200 crore, ₹150 crore and below; the Data Protection Board determines penalties on the facts.
Note: Amount verified directly against the Gazette PDF text ('may extend to two hundred and fifty crore rupees'). Enforcement follows the phased commencement (see dpdp-phase-3).
Source: DPDP Act 2023, the Schedule (official Gazette text) ↗Under Rule 7 of the DPDP Rules 2025, a data fiduciary must intimate the Data Protection Board of a personal data breach without delay on becoming aware, follow with a detailed report within 72 hours (extendable by the Board), and notify affected data principals of the breach in plain language.
Note: Timelines corroborated across multiple legal publishers. Enforcement follows the phased commencement (see dpdp-phase-3). Runs in parallel with CERT-In’s 6-hour incident reporting — the same incident triggers both.
Source: DPDP Rules 2025, Rule 7 ↗Every consent request must be accompanied or preceded by a notice informing the data principal of: (i) the personal data and the purpose of processing; (ii) the manner of exercising rights under s.6(4) (withdrawal) and s.13 (grievance redressal); and (iii) the manner of making a complaint to the Data Protection Board. For consents given before commencement, notice must follow as soon as reasonably practicable.
Note: Contents verified directly against the Gazette PDF text. Notice must be available in English or any Eighth Schedule language.
Source: DPDP Act 2023, section 5 (official Gazette text) ↗Directions under Section 70B(6), IT Act 2000 issued 28 April 2022; effective 28 June 2022. Apply to service providers, intermediaries, data centres, body corporates and government organisations.
Source: CERT-In Directions (official PDF) ↗Specified cyber incidents must be reported to CERT-In within 6 hours of noticing.
Source: CERT-In Directions (official PDF) ↗ICT system logs must be maintained for a rolling 180 days, within Indian jurisdiction.
Source: CERT-In Directions (official PDF) ↗System clocks must be synchronised to NIC or NPL time sources.
Source: CERT-In Directions (official PDF) ↗Data centres, VPS, cloud and VPN providers must register and retain accurate subscriber/customer records for 5 years after cancellation or withdrawal of service.
Source: CERT-In Directions (official PDF) ↗Authentication User Agencies and eKYC User Agencies must have operations audited annually (and on need) by a certified information systems auditor; the report is shared with UIDAI on request.
Source: UIDAI AUA/KUA Agreement (v4.0) ↗Insurance Self-Network Platforms require IRDAI permission (with pre-launch security testing) and an annual audit by an auditor holding a recognised IS-audit qualification (e.g. CISA, or CA with DISA); adverse findings affecting policyholders are reported to IRDAI with an action plan.
Note: Summarised from IRDAI's ISNP framework; corroborated across multiple compliance publishers.
Source: IRDAI ↗PCI DSS v4.0.1 is the current standard published by the PCI Security Standards Council.
Source: PCI SSC document library ↗PCI DSS v3.2.1 retired 31 March 2024. v4.0.1 (a limited revision — no requirements added or removed) was published 11 June 2024, and v4.0 retired 31 December 2024, leaving v4.0.1 the only active version. The 51 future-dated v4.x requirements became mandatory in assessments from 31 March 2025.
Source: PCI Security Standards Council (official blog) ↗OWASP Application Security Verification Standard v5.0.0 (May 2025): ~350 requirements across 17 chapters, three verification levels (L1–L3).
Source: OWASP ASVS project ↗SEBI issued the Cybersecurity and Cyber Resilience Framework circular on 20 August 2024. Compliance timelines were extended more than once; for most regulated entities (excluding MIIs, KRAs and QRTAs) the final compliance date became 31 August 2025, with recurring half-yearly cyber-audit and reporting cycles thereafter.
Note: Extension history corroborated across law-firm analyses (circulars of 31 March 2025 and 30 June 2025).
Source: SEBI — CSCRF FAQs (official PDF, June 2025) ↗RBI circular DPSS.CO.OD No.2785/06.08.005/2017-2018 (6 April 2018) requires payment system providers to store the entire data relating to their payment systems only in India, with compliance within six months (by October 2018). End-to-end transaction data is covered.
Note: Circular number cited for retrieval via RBI's notification search; we deliberately avoid deep-linking RBI's session-bound URLs.
Source: Reserve Bank of India (circular DPSS.CO.OD No.2785/06.08.005/2017-2018) ↗Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices (RBI/DoS/2023-24/107) issued 7 November 2023; effective 1 April 2024. Requires an IT governance framework, information/cyber security policies and periodic IT risk assurance for regulated entities.
Note: Direction number cited for retrieval via RBI notification search; RBI deep links are session-bound.
Source: Reserve Bank of India (Master Direction RBI/DoS/2023-24/107) ↗Master Direction on Outsourcing of Information Technology Services (RBI/2023-24/102) issued 10 April 2023; effective 1 October 2023. Governs material IT outsourcing by regulated entities, including vendor risk, audit rights and concentration risk.
Note: Direction number cited for retrieval via RBI notification search.
Source: Reserve Bank of India (Master Direction RBI/2023-24/102) ↗Issued 18 February 2021: minimum security standards for digital payment channels — internet banking, mobile payments and card payments — binding scheduled commercial banks, small finance banks, payments banks and card-issuing NBFCs.
Note: Direction cited by title and date for retrieval via RBI notification search.
Source: Reserve Bank of India (Master Direction, 18 Feb 2021) ↗RBI’s Cyber Security Framework in Banks (2 June 2016) requires scheduled commercial banks to report cyber incidents to RBI within 2 to 6 hours of detection, alongside board-approved cyber security policy, SOC capability and cyber crisis management plans.
Source: Reserve Bank of India (notification, 2 June 2016) ↗The IAF three-year transition window for ISO/IEC 27001:2013 certificates ended 31 October 2025 — certificates not transitioned to the 2022 revision by that date lapsed.
Note: Deadline corroborated across accredited certification bodies (BSI, SGS, LRQA); iso.org blocks automated verification.
Source: ISO/IEC 27001 (iso.org) ↗NIST released Cybersecurity Framework 2.0 on 26 February 2024 — the first major revision since 2014, adding the Govern function and broadening applicability beyond critical infrastructure.
Source: NIST (official release announcement) ↗IRDAI issued the Information and Cyber Security Guidelines, 2023 on 24 April 2023 — a data-centric, risk-based security framework for insurers and regulated intermediaries, superseding the 2017 guidelines.
Source: IRDAI (official document) ↗ISO/IEC 42001:2023 — the first AI management system (AIMS) standard — was published in December 2023 by ISO/IEC.
Note: iso.org blocks automated verification; publication corroborated across accredited bodies and major assurance firms.
Source: ISO/IEC 42001 (iso.org) ↗Regulation (EU) 2024/1689 entered into force on 1 August 2024. Governance rules and obligations for general-purpose AI (GPAI) model providers apply from 2 August 2025 (with transition for models already on the market).
Source: EU AI Act — official text (EUR-Lex 2024/1689) ↗The Saudi Central Bank (SAMA) issued its Cyber Security Framework v1.0 in May 2017, applying to SAMA-regulated banks, insurers and finance companies; principle-based, drawing on ISO, Basel and PCI DSS.
Source: SAMA — Cyber Security Framework (official PDF) ↗Saudi Arabia's National Cybersecurity Authority first issued the Essential Cybersecurity Controls as ECC-1:2018; the updated ECC-2:2024 restructures the framework into 4 domains, 28 subdomains and 108 main controls, binding government entities and critical-infrastructure operators.
Note: ECC-2:2024 structure corroborated across multiple assurance publishers; the NCA portal hosts the controlled document.
Source: National Cybersecurity Authority (Saudi Arabia) ↗The CMMC Program rule (32 CFR Part 170) was published 15 October 2024 and took effect 16 December 2024. The acquisition rule (48 CFR) took effect 10 November 2025, starting a phased rollout that adds CMMC requirements to DoD contracts in four annual phases.
Note: 48 CFR effective date corroborated across defence-contracting counsel and assessor publications.
Source: US Federal Register — CMMC Program rule (32 CFR 170) ↗UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data was issued in 2021 and came into effect on 2 January 2022. The DIFC and ADGM financial free zones run their own data-protection regimes in place of the federal law.
Source: UAE legislation portal / official summaries ↗SWIFT launched the Customer Security Programme in 2016. Connected organisations attest annually against the Customer Security Controls Framework (CSCF, revised yearly), and from 2021 an independent assessment became mandatory for attestations rather than pure self-attestation.
Source: SWIFT — Customer Security Programme (official) ↗Qatar's National Cyber Security Agency mandates the National Information Assurance Policy for government entities and critical infrastructure; the current revision is v2.1 (May 2023), superseding v2.0.
Note: Version and date corroborated across Qatar-focused GRC publishers; the NCSA portal hosts the controlled document.
Source: NCSA Qatar (official portal) ↗Regulation (EU) 2016/679 entered into force 24 May 2016 and has applied across all EU member states since 25 May 2018. Breach notification to the supervisory authority is required without undue delay and, where feasible, within 72 hours (Art. 33).
Source: GDPR — official text (EUR-Lex 2016/679) ↗Compliance with the HIPAA Security Rule was required from 20 April 2005 for most covered entities; small health plans had until 20 April 2006.
Source: US HHS — HIPAA Security Rule ↗ISO 22301:2019 (business continuity management systems) was published 30 October 2019, replacing the 2012 first edition.
Note: iso.org blocks automated verification; date corroborated across certification bodies.
Source: ISO 22301:2019 (iso.org) ↗Entries are never silently edited — corrections and additions append here, so anything cited from this register can be audited later.
2026-08-01 — v1.6.0: added DPDP notice contents (s.5(1), verified from the Gazette), HIPAA Security Rule compliance date, and ISO 22301:2019 publication.
2026-08-01 — v1.5.0: added DPDP Rules breach-notification timeline (Rule 7: without delay + 72-hour detailed report), RBI Cyber Security Framework for Banks (2 June 2016; 2-6 hour incident reporting), and GDPR application date (25 May 2018).
2026-08-01 — v1.4.0: added SWIFT CSP (launched 2016; independent assessment mandatory from 2021), Qatar NIA Policy v2.1 (May 2023), and RBI Digital Payment Security Controls Master Direction (Feb 2021).
2026-08-01 — v1.3.0: added SAMA Cyber Security Framework (May 2017), Saudi NCA ECC-1:2018 / ECC-2:2024, US CMMC programme and acquisition rule dates, and UAE PDPL (Federal Decree-Law 45/2021).
2026-08-01 — v1.2.0: added RBI IT Governance Master Direction (Nov 2023), RBI IT Outsourcing Master Direction (Apr 2023), IRDAI Information & Cyber Security Guidelines 2023, ISO/IEC 42001:2023 publication, EU AI Act commencement and GPAI dates.
2026-08-01 — v1.1.0: added DPDP penalty schedule (verified from the Gazette), SEBI CSCRF issuance and timelines, RBI payment-data localisation, PCI DSS v4.x lifecycle dates, ISO/IEC 27001:2022 transition end, NIST CSF 2.0 release.
2026-08-01 — Initial public release: DPDP Act & Rules phasing, CERT-In Directions obligations, Aadhaar AUA/KUA and IRDAI ISNP audit duties, PCI DSS and OWASP ASVS current versions.
Licensed CC BY 4.0 — reuse anything here with attribution to CyberSigma. Every entry is verified against its stated source before publication; where an official portal cannot be read directly, the entry says how it was corroborated. Maintained by the CERT-In empanelled, PCI QSA-authorised team at CyberSigma. Spotted an error or a missing obligation? Tell us — corrections land in the changelog.