Cleo
CompanyLegal Data
Request a demo
Anaelle GuezNaomie Halioua
Request a demo
Cleo

AI-powered regulatory intelligence.

contact@cleolabs.co

Solutions

  • Product Compliance

Company

  • About
  • Research
  • Blog
  • Compliance Guides

Jurisdictions

  • 🇪🇺 European Union
  • 🇫🇷 France
  • 🇩🇪 Germany
  • 🇬🇧 United Kingdom
  • 🇺🇸 United States

Legal

  • Privacy
  • Terms
  • Security

Events

  • VivaTech ParisJun 11–14, 2026

© 2026 Cleo Labs. All rights reserved.

GDPREU DataSOC 2 Type IIISO 27001
🇮🇳

Regulatory compliance in India

India's DPDPA (Digital Personal Data Protection Act 2023) introduces GDPR-like obligations. The RBI, SEBI, and IRDAI regulate financial services with increasing digital focus.

Start free scan
Anaelle GuezNaomie Halioua
or book a call
0
Key regulations
0
Authorities tracked
24h
Alert latency

Authorities

Key regulatory authorities

Cleo monitors enforcement actions and guidance from these authorities in real time.

Data Protection Board of India

DPBI

www.meity.gov.in

Reserve Bank of India

RBI

www.rbi.org.in

Securities and Exchange Board of India

SEBI

www.sebi.gov.in

Frameworks

Regulations covered

Key regulatory frameworks monitored by Cleo in India.

DPDPA 2023Mapped
IT Act 2000Mapped
RBI Data LocalizationMapped
SEBI Cyber FrameworkMapped
Digital India Act (proposed)Mapped

By industry

Compliance by industry in India

Explore sector-specific regulatory requirements.

Retail & Consumer GoodsCosmetics & Personal CareElectronics & Connected DevicesFood & BeveragePet Care & Pet FoodSporting GoodsMedical DevicesDrugs & PharmaceuticalsInsuranceEnergy & Utilities
Retail & Consumer Goods
Cosmetics & Personal Care
Electronics & Connected Devices
Food & Beverage
Pet Care & Pet Food
Sporting Goods
Medical Devices
Drugs & Pharmaceuticals
Insurance
Energy & Utilities

Deep dives

Regulation deep dives

GDPR
EU AI Act
DORA
CSRD

Frequently asked questions

What is India's DPDPA and when does it apply?

The Digital Personal Data Protection Act 2023 introduces consent-based data processing, data fiduciary obligations, and significant penalties. Cleo tracks its phased implementation timeline.

Does India require data localization?

The RBI mandates that all payment system data be stored exclusively in India. The DPDPA allows cross-border transfers to approved countries but the government can restrict transfers to specific nations. SEBI also requires certain financial data to remain in India. Cleo maps applicable localization requirements by sector.

What are the penalties under India's DPDPA?

The DPDPA imposes penalties of up to INR 250 crore (approximately EUR 28 million) per violation. The Data Protection Board of India adjudicates complaints and can order compensation. Penalties apply to both data fiduciaries and data processors who fail to implement adequate security safeguards.

Ready to master compliance in India?

Start free scan and see your regulatory perimeter mapped by AI in minutes.

Start with 1 product
Start free scan
Anaelle GuezNaomie Halioua
or book a call