# Data Privacy on Gaming Apps in India: The DPDP Act

Source: https://cricketin.org/guides/data-privacy-on-gaming-apps

[By Farhan Qureshi](/authors/payments-expert), Payments Expert. [Reviewed by Rajeev Sathe](/authors/editor-in-chief), Editor-in-Chief. Updated 31 Aug 2026. Editorial policy: https://cricketin.org/editorial-policy

18+ Betting money on cricket carries a direct risk of financial loss, and it can become an addiction. Real-money online gaming is banned across India under the PROG Act 2025, which came into force on 1 May 2026.

If betting is already costing you money you need, or sleep, or people close to you, the free Tele-MANAS helpline is **14416**, and it runs in 20 languages. Our [page on help for gambling harm](/guides/help-for-gambling-harm-india) lists what else exists.

---

What the DPDP Act 2023 gives you, when each part starts, what apps send about you, and why erasure requests on gaming apps often fail.

India's Digital Personal Data Protection Act, 2023 gives you rights over your data. You can see it, fix it and have it wiped ([Act text, MeitY](https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf)). Most of those rights are not live yet. Sections 11 to 17 start on 13 May 2027. That is eighteen months after the notice of 13 November 2025 ([G.S.R. 843(E)](https://cadp.in/resources/official-texts/dpdp-notification-commencement-2025/)).

This page gives the checked dates. It shows what a gaming app takes beyond your papers. It shows how long the app may keep it, and why a request to wipe it fails. It also shows why store rules never reach an app that skipped the store.

## The DPDP Act, in one page

India now has a data law. It is the Digital Personal Data Protection Act, 2023, Act 22 of 2023 ([Act text, MeitY](https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf)).

It calls you the Data Principal. It calls the firm that holds your data the Data Fiduciary. That word choice matters. A fiduciary is meant to hold a thing on your behalf.

The Act gives you four rights that matter here. You can ask what is held. You can get it fixed. You can ask for it to be wiped. You can raise a complaint ([Sections 11 to 13](https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf)).

The right to see covers more than a copy. You can ask for a summary of your data. You can also ask who it went to, by name ([Section 11](https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf)).

The Act puts duties on you too. Do not pose as someone else. Do not hide facts that matter. Do not file a false or silly complaint ([Section 15](https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf)).

## The dates, checked against the notification

Most of this is not live yet. That is the key fact on this page, and it is often reported wrongly.

The notice that starts the Act is G.S.R. 843(E). It is dated 13 November 2025 ([notification text](https://cadp.in/resources/official-texts/dpdp-notification-commencement-2025/)). It switches the Act on in three stages.

**Table 1. When each part of the DPDP Act starts working**

| Date | What starts | Why it matters to you |
|---|---|---|
| 13 November 2025 | Definitions, the Data Protection Board, rule-making powers | The regulator can be built; your rights are not live yet |
| 13 November 2026 | Consent manager provisions | A new type of intermediary for managing consent |
| 13 May 2027 | Sections 3 to 17, including all user rights, and Sections 28 to 34 | This is when you can actually demand access and erasure |

So what guards you until May 2027? The older set of rules. Section 43A of the IT Act stays in force, and so do the SPDI Rules of 2011. They run until the eighteen-month clock ends. Section 72A of the IT Act also stays ([Khaitan and Co](https://www.khaitanco.com/sites/default/files/2025-11/ERGO%20-%20Digital%20Personal%20%20Data%20Protection%20Rules%20-%2015%20November%202025.pdf)).

The Rules follow the same clock. Rules 3 and 5 to 16 of the DPDP Rules, 2025 apply after eighteen months ([Rules text, Rule 1](https://www.dpdpa.com/DPDP_Rules_2025_English_only.pdf)).

## The duties that land on the operator

Real duties arrive with the main sections. Here are the four that bite.

- **Security.** The firm must take fair steps to stop a breach ([Section 8(5)](https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf)).
- **Breach notice.** It must tell each person hit, with no delay. It must give the Board a full report within seventy-two hours ([Rule 7, DPDP Rules 2025](https://www.dpdpa.com/DPDP_Rules_2025_English_only.pdf)).
- **A published route.** It must show clearly how you use your rights ([Rule 14](https://www.dpdpa.com/DPDP_Rules_2025_English_only.pdf)).
- **A time limit on complaints.** The reply time must not go past ninety days ([Rule 14](https://www.dpdpa.com/DPDP_Rules_2025_English_only.pdf)).

On paper the fines are large. A failure to take fair steps on safety can cost up to 250 crore rupees. A failure to report a breach can cost up to 200 crore rupees ([Schedule to the Act](https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf)).

Now note the gap in scale. If you break your own duties under Section 15, the fine is up to 10,000 rupees ([Schedule](https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf)). The law is aimed at firms, not at users.

## What leaves your phone while you play

Papers are only part of it. Apps also send a stream of small facts about you.

Google Play has its own list of personal and sensitive user data. It covers payment and sign-in data, contacts and device location. It covers SMS and call data, the mic and the camera. It even covers a list of the other apps on your phone ([Google Play User Data policy](https://support.google.com/googleplay/android-developer/answer/10144311?hl=en)).

Ads are their own channel. Play makes apps use the advertising ID for ads. You can reset or delete that ID in Android settings ([Google Play advertising ID policy](https://support.google.com/googleplay/android-developer/answer/6048248?hl=en)). Delete it, and an app that asks for it gets a string of zeros ([Google](https://support.google.com/googleplay/android-developer/answer/6048248?hl=en)).

Android itself gates the touchy parts. App rights guard data such as location and contacts. They also guard acts such as recording sound ([Permissions on Android](https://developer.android.com/guide/topics/permissions/overview)). That gate only helps if you read the request.

## Store rules do not follow a sideloaded app

Here is the gap that catches people. Nearly every rule above is a Play rule.

Play wants a real privacy policy in the listing and in the app. It wants the app to fill in the Data safety section. It wants clear consent before data is taken. And it bans the sale of personal and sensitive user data ([Google Play User Data policy](https://support.google.com/googleplay/android-developer/answer/10144311?hl=en)).

Play also wants a real way out. You must be able to delete your account in the app and on a web page. Freezing an account is not good enough ([Google Play](https://support.google.com/googleplay/android-developer/answer/10144311?hl=en)).

An app that never went through the store agreed to none of that. Google's own study found over fifty times more malware from internet-sideloaded sources than on Play ([Android Developers Blog](https://android-developers.googleblog.com/2025/08/elevating-android-security.html)). Our [page on sideloading risk](/guides/apk-sideloading-risks) works through what else goes missing.

The same holds for the papers you hand over. UIDAI says not to share an Aadhaar photocopy with any organisation. It points to a masked version, which shows only the last four digits ([UIDAI advisory via PIB](https://www.pib.gov.in/PressReleasePage.aspx?PRID=1828797)). Our page on [what KYC really costs you](/guides/kyc-in-online-gaming-india) covers that side.

## How long your data is kept

There is a rule on this. It is narrower than most people think. "Delete my account" and "delete my data" are two different asks. A closed account can sit on a server for years.

The Third Schedule of the DPDP Rules, 2025 names online gaming firms with fifty lakh or more signed-up users in India. Each must wipe your data three years after you last came to them. Two narrow carve-outs apply. One is for account access. One is for access to virtual tokens ([Rule 8 and Third Schedule](https://www.dpdpa.com/DPDP_Rules_2025_English_only.pdf)).

The rule only bites at that size. And three years is a floor, not a promise of a quick wipe. Logs and traffic data are kept for at least one year as well ([Rule 8(3)](https://www.dpdpa.com/DPDP_Rules_2025_English_only.pdf)).

None of it binds a service that ignores Indian law to start with. That is the whole problem with this market, as our [page on offshore apps](/legal/offshore-betting-apps-india) sets out.

## Why deletion requests often fail

Section 12 gives you a right to have data wiped. The firm must wipe it unless it still needs the data for the job. It may also keep it if the law says so ([Section 12](https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf)).

Read that last part again. "Required by law" does much of the work here.

Then add the carve-outs. Section 17 lifts some duties when data is used to stop, find, probe or try a crime ([Section 17](https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf)). Your right to know who got your data has a carve-out too. It does not cover lawful sharing with agencies the law allows ([Section 11(2)](https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf)).

There is a trap in the steps as well. You must use up the firm's own complaint route before you go to the Board ([Section 13](https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf)). If the firm says nothing, you wait out the ninety-day window first ([Rule 14](https://www.dpdpa.com/DPDP_Rules_2025_English_only.pdf)).

Then comes the plain wall. To get data wiped, you must know who holds it. With no named firm, and a payment sent to an unrelated payee, that chain is already broken. Our [page on agent accounts](/guides/cricket-id-and-agent-accounts) follows that failure through.

### What to send, and what to keep

You can still write today. Keep the ask short and dated. Then keep proof that you sent it.

- Ask for a summary of the data held on you, and the names it went to.
- Ask for a wipe of each paper you uploaded.
- Give the email and phone number tied to the account.
- Save the sent email and any reply, with dates.

None of this forces a reply before 13 May 2027. It builds a record you can use later.

## What this law does not fix

Data law and gaming law are two tracks. Mixing them up gives false comfort.

The DPDP Act makes no game lawful. Section 5 of the PROG Act 2025 bans offering a money game service. Section 7 bans any move of funds for one ([Act text, MeitY](https://www.meity.gov.in/static/uploads/2025/10/8a7f103cefc68ed8aaa2ebc9a2ed7c13.pdf)). It has been law since 1 May 2026 ([Nishith Desai analysis](https://nishithdesai.com/research-and-articles/hotline/gaming-law-wrap/setting-the-rules-of-the-game-indias-online-gaming-law-comes-into-force-15586)).

It does not get your money back either. It is a data law, not a refund route. And it cannot un-share a paper that is already copied to a server abroad.

That last point deserves weight. Rights work on records a firm still holds. A copy that has moved on is out of reach.

Can the Data Protection Board take a complaint against an operator based outside India? And how would an order be enforced? This needs a published Board decision or MeitY guidance. Neither exists yet.

## What is not on this page

No app names. No settings walkthrough for hiding what you do. No tips on dodging checks.

Privacy tools do not change the law, and we will not pretend they do. Section 6 of the PROG Act bans ads for a money game, direct or indirect ([MeitY](https://www.meity.gov.in/static/uploads/2025/10/8a7f103cefc68ed8aaa2ebc9a2ed7c13.pdf)). Our [page on the ad rules](/legal/advertising-rules-online-gaming) explains that. The rest of our explainers live in the [guides hub](/guides).

## Questions people ask

### Can I demand my data from a gaming app today?

Not yet. Sections 11 to 17 of the DPDP Act start eighteen months after 13 November 2025. That date is 13 May 2027 ([G.S.R. 843(E)](https://cadp.in/resources/official-texts/dpdp-notification-commencement-2025/); [Khaitan and Co](https://www.khaitanco.com/sites/default/files/2025-11/ERGO%20-%20Digital%20Personal%20%20Data%20Protection%20Rules%20-%2015%20November%202025.pdf)). Until then the IT Act rules apply.

### How fast must a company tell me about a data breach?

With no delay, once the duty is live. It must also give the Data Protection Board a full report within seventy-two hours ([Rule 7, DPDP Rules 2025](https://www.dpdpa.com/DPDP_Rules_2025_English_only.pdf)).

### Does an app have to delete my data if I ask?

Section 12 says yes. But it may keep the data if it still needs it for the first purpose. It may also keep it if the law says so ([Act text](https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf)). Those carve-outs are wide, and Section 17 adds more.

### What is the advertising ID, and can I switch it off?

It is the ID that Play makes apps use for ads. You can reset it or delete it in Android settings. Apps that ask for it then get a string of zeros ([Google Play advertising ID policy](https://support.google.com/googleplay/android-developer/answer/6048248?hl=en)).

### Do gaming apps have to erase old accounts?

Only the larger ones. The rule names online gaming firms with fifty lakh or more signed-up users in India. They must wipe your data three years after your last contact, with a few carve-outs ([Third Schedule, DPDP Rules 2025](https://www.dpdpa.com/DPDP_Rules_2025_English_only.pdf)).

## More from the guides

- [DLS Method Explained](/guides/dls-method-explained)
- [Expected Value in Betting](/guides/expected-value-explained)
- [Fancy Bets in Cricket Explained](/guides/fancy-bets-explained)
- [Help for Gambling Harm in India](/guides/help-for-gambling-harm-india)
- [How Bookmakers Set Cricket Odds](/guides/how-bookmakers-set-odds)
- [How Cricket Odds Work](/guides/how-cricket-odds-work)
- [How DRS Works in Cricket](/guides/how-drs-works)
- [How Net Run Rate Works](/guides/how-net-run-rate-works)
- [How Pitch Conditions Change a Cricket Match](/guides/how-pitch-conditions-work)
- [Offshore Betting Apps in India](/legal/offshore-betting-apps-india)
- [Is Online Cricket Betting Legal in India](/legal/online-betting-law-india)
- [Caribbean Premier League 2026 — live schedule and table](/leagues/cpl)
