India — Cyber Threat Profile

India is phasing in the Digital Personal Data Protection (DPDP) Act, 2023, whose commencement notification and implementing DPDP Rules, 2025 were notified on 14 November 2025. Procedural provisions, including establishment of the Data Protection Board of India (DPB), took effect on 14 November 2025; the consent-manager framework becomes operative on 14 November 2026; and substantive Data Fiduciary obligations, data-principal rights — with a ninety-day outer limit for responding to requests — and the Board's powers to inquire into breaches, issue directions and impose penalties of up to ₹250 crore all commence on 14 May 2027. As of August 2026 the Board has no chairperson or members; MeitY invited applications in May 2026. Until May 2027 the IT Act's SPDI framework remains the operative data-protection regime, after which the DPDP Act also reaches processing outside India connected with offering goods or services to individuals in India. The FY 2026-27 Union Budget allocates ₹790 crore to MeitY's Cyber Security Projects scheme and ₹10 crore to the Board.

Latest India coverage

Threat actors targeting India

Most targeted sectors

Recent claimed incidents

Read the full analysis on IntelFusions