Dowry abuse in Australia is written into family violence law. Here is what that means
India’s new data privacy law: what changes for Indian Australians and OCI holders

From 13 May 2027, an Indian business that fails to protect your personal data could face a penalty of up to ₹250 crore (₹2,500,000,000), and if that data leaks, the law will require it to tell you. For Indian Australians and Overseas Citizens of India who still run an Indian bank account, pay through UPI apps, keep an Indian SIM or hold an Indian insurance policy, that is the date most of India’s data protection law is scheduled to start applying.
A law passed in 2023, switched on in stages
The Digital Personal Data Protection Act, 2023 received presidential assent on 11 August 2023. None of it was in force until 13 November 2025, when the Ministry of Electronics and Information Technology (MeitY) published the Digital Personal Data Protection Rules, 2025 in the Gazette of India, along with a separate notification setting commencement dates for the Act itself.
The government chose an 18-month runway rather than a single start date. In a written Lok Sabha answer on 5 August 2026, Minister of State for Electronics and Information Technology Jitin Prasada said the Act and the Rules provide “a timeline for phased implementation of its provisions over an eighteen-month transition period”. Both notifications count each stage from 13 November 2025:
- 13 November 2025: the definitions, the establishment of the Data Protection Board of India and the Board’s procedures took effect on publication.
- 13 November 2026: the rule on registering consent managers (Rule 4) and the matching provisions of the Act, section 6(9) and section 27(1)(d), come into force.
- 13 May 2027: almost everything an ordinary user cares about, including notice and consent requirements, security safeguards, breach notification, individual rights and the penalty provisions (sections 3 to 17 apart from section 6(9), section 27 apart from clause (d) of subsection (1), sections 28 to 34, 36, 37 and 44(2) of the Act, and Rules 3, 5 to 16, 22 and 23).
The minister’s August 2026 answer still referred to the eighteen-month period. Treat 13 May 2027 as the scheduled date unless the government amends it by a further notification.
What a consent manager is
The Act defines a consent manager as a person registered with the Data Protection Board who acts as a single point of contact for individuals. Through one, you can “give, manage, review or withdraw” consent you have given to companies, in the words of section 6(7). Section 6(8) says a consent manager is accountable to the individual and must act on their behalf.
The Rules add that consent managers must be companies incorporated in India, and PIB describes the role as providing “a single, transparent and interoperable platform” for managing permissions. The Rules also require consent managers to avoid conflicts of interest with the businesses that collect the data.
The November 2026 milestone opens registration for these entities. It does not require anyone to use one: section 6(7) says you “may” act through a consent manager.
The rights you gain, and when
The individual rights all sit in sections 11 to 14 of the Act, which commence on 13 May 2027.
- Access (section 11): you can ask for a summary of the personal data a business is processing about you and the identities of the other businesses it has shared that data with.
- Correction and erasure (section 12): you can ask for inaccurate or incomplete data to be corrected, completed or updated, and for data to be erased, unless keeping it is necessary for the specified purpose or for compliance with the law.
- Grievance redressal (section 13): businesses and consent managers must offer a way to complain. Under Rule 14, each must publish a period of no more than ninety days for responding to grievances and put measures in place to meet it. PIB’s explainer says businesses must address all requests related to access, correction, updating or erasure within a maximum of ninety days. Section 13(3) requires you to use the company’s own grievance process first before approaching the Board.
- Nomination (section 14): you can nominate another individual to exercise your rights if you die or become incapacitated.
Consent itself also changes. Section 6(4) lets you withdraw consent at any time, and withdrawing must be comparable in ease to giving it. Notices must be available in English or any language in the Eighth Schedule of the Constitution, and the Rules require an itemised description of the data collected and the purpose.
The Act also places duties on individuals. Section 15 bars impersonation, suppressing material information when providing personal data for government-issued documents or proof of identity, and filing false or frivolous complaints, and the Schedule sets a penalty of up to ₹10,000 for breaching these duties.
If your data is breached
Section 8(6) and Rule 7 require a business that suffers a personal data breach to inform the Data Protection Board and every affected individual. PIB states that the business “must inform all affected individuals without delay”, in plain language, explaining what happened, the possible impact, the steps taken, and contact details for help. The business must also send the Board detailed information within 72 hours of becoming aware of the breach, unless the Board allows longer on a written request. These obligations apply from 13 May 2027.
Rule 7 says breach notices go to your user account or any mode of communication you registered with the business, and the Rules define a user account to include your registered email address and mobile number. If the details your Indian bank or telco holds are an old Indian number or an inbox you no longer check, those are still the details the Rules point to.

Does the data protection law cover you if you live in Australia?
Section 3 defines the Act’s reach by where processing happens and whom it serves; it does not mention citizenship. It applies to the processing of digital personal data within India, and also to processing outside India “if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India”. It does not apply to data an individual processes for personal or domestic purposes, or to data the person has made public themselves or that someone is legally required to publish.
One exemption matters here. Section 17(1)(d) switches off most obligations, including the individual rights in sections 11 to 14, where personal data of people not in India is processed “pursuant to any contract entered into with any person outside the territory of India by any person based in India”. The duty to take reasonable security safeguards still applies. Whether any particular service you use falls inside that exemption is a question for the provider or a lawyer.
Government services are treated differently. Section 7(b) lets the State process personal data without fresh consent to provide prescribed subsidies, benefits, services, certificates, licences or permits, if you previously consented to such processing or the data is held in a State database notified by the central government.
Penalties and the Board
The Schedule to the Act sets maximum penalties of up to ₹250 crore (₹2,500,000,000) for failing to take reasonable security safeguards, up to ₹200 crore (₹2,000,000,000) for failing to notify the Board or individuals of a breach, up to ₹200 crore for breaching obligations relating to children, up to ₹150 crore (₹1,500,000,000) for breaching the additional obligations of significant data fiduciaries, and up to ₹50 crore (₹500,000,000) for other breaches of the Act or Rules.
The Data Protection Board of India is the body that imposes these penalties. MeitY says the Board has a mandate to function as “an independent adjudicatory authority” and is designed to work digitally, and PIB says complaints will be lodged and tracked through an online portal and app. On 6 May 2026 the ministry invited applications for a chairperson and four members. Appeals from the Board go to the Telecom Disputes Settlement and Appellate Tribunal.
What to do before May 2027
The practical steps are housekeeping. Check that every Indian bank, UPI app, telco, insurer and government login holds a mobile number and email address you actually use from Australia. Keep a simple list of which Indian organisations hold your data, since the Act directs access requests to each business you gave consent to. From 13 May 2027, read the new consent notices rather than clicking through, and use each company’s grievance channel first if something goes wrong.
For a community that keeps one financial foot in India, the penalties are only part of the picture. The Act gives you the right to ask Indian businesses what they hold about you and whom they have shared it with, and the right to be told when a breach occurs. Both work only if the business can reach you and you know to ask.
This article is general information, not legal advice.
