DPDP Act 2023 & DPDP Rules 2025 — Full Provisions Reference
Every chapter, section, rule and schedule in one map — with the dates each obligation goes live.
The Digital Personal Data Protection Act received assent on 11 August 2023. The Digital Personal Data Protection Rules 2025 were notified on 13 November 2025 (Gazette G.S.R. 846(E)) — 23 rules and seven schedules, commencing in three phases. This page sets out the complete structure and links each part to a detailed briefing.
When each obligation goes live
Rules 1, 2 and 17–21 — definitions and the Data Protection Board as a digital office. The Board is constituted and operational.
Rule 4 — registration and obligations of Consent Managers.
Rules 3, 5–16, 22 and 23 — notice, consent, security, breach intimation, erasure, children’s data, SDF duties, cross-border transfer and data-principal rights.
DPDP Act 2023 — 9 chapters, 44 sections
The marginal heading of every section with a plain-language note and the rule that operationalises it. For section-by-section analysis, see the section-by-section deep dive.
Preliminary
Sections 1–3Names the Act and allows the Central Government to bring different provisions into force on different dates — the basis for the phased commencement now running through to 13 May 2027.
Defines the core terms — personal data, data principal, data fiduciary, data processor, consent manager, personal data breach and Significant Data Fiduciary. The Act uses one category of personal data; it does not create a separate “sensitive data” class.
Applies to digital personal data processed in India, and to processing outside India where it relates to offering goods or services to data principals in India.
Obligations of Data Fiduciary
Sections 4–10Permits processing only on the basis of consent or for certain legitimate uses.
Requires a clear notice — itemised purpose, the personal data sought, how to exercise rights and how to complain to the Board. Operationalised by Rule 3.
Consent must be free, specific, informed, unconditional and unambiguous, with withdrawal as easy as giving it (Section 6(4)). Sub-sections 6(7)–(9) establish the Consent Manager, operationalised by Rule 4.
Lists the legitimate uses for which consent is not separately required — including specified State functions, employment and medical emergencies.
Accountability, accuracy, reasonable security safeguards, erasure when the purpose is served (8(7)), and breach intimation (8(6)) — detailed by Rules 6, 7 and 8.
Requires verifiable parental consent and bars tracking, behavioural monitoring and targeted advertising directed at children. Operationalised by Rules 10, 11 and 12.
A Data Fiduciary notified as an SDF must appoint an India-based Data Protection Officer (10(2)(a)), carry out a DPIA and independent audit, and exercise algorithmic due diligence — detailed by Rule 13.
Rights and Duties of Data Principal
Sections 11–15A data principal may obtain a summary of their personal data being processed and the identities of other fiduciaries with whom it has been shared.
A right to correction, completion, updating and erasure of personal data.
A readily available means of registering grievances, to be answered within the period set by Rule 14 — not exceeding ninety days.
A data principal may nominate another individual to exercise their rights in the event of death or incapacity.
Duties including not furnishing false particulars or impersonating others; breach may attract a penalty of up to ₹10,000, as determined by the Board after inquiry.
Special Provisions
Sections 16–17Permits cross-border transfer except to countries the Central Government may restrict by notification — read with Rule 15.
Sets out exemptions, including for certain State instrumentalities and for research, archiving or statistical purposes (Rule 16, Second Schedule).
Data Protection Board of India
Sections 18–26Establishes the Data Protection Board of India as the adjudicatory and enforcement body.
Composition of the Board and the qualifications of its Chairperson and Members.
Terms and conditions of service — detailed by Rule 18 and the Fifth Schedule.
Grounds that disqualify a person from being appointed or continuing as a Member.
Procedure for resignation and for filling vacancies on the Board.
The Board functions as a digital office; procedure is detailed by Rules 17 to 21.
Appointment of officers and employees — detailed by Rule 20 and the Sixth Schedule.
Treats Members, officers and employees as public servants for the purposes of the law.
General powers of superintendence and direction over the Board’s administration.
Powers, Functions and Procedure of the Board
Sections 27–28Empowers the Board to inquire into breaches, direct remedial and mitigation measures and impose penalties under the Schedule.
The inquiry procedure, powers of a civil court in specified matters, and the requirement to act in accordance with natural justice.
Appeal and Alternate Dispute Resolution
Sections 29–32An appeal from a Board order lies to the Telecom Disputes Settlement and Appellate Tribunal — manner detailed by Rule 22.
Execution of the Tribunal’s orders, which have the force of a civil-court decree.
Allows the Board to refer a complaint for mediation or other dispute resolution.
Permits the Board to accept a voluntary undertaking from a person at any stage of proceedings.
Penalties and Adjudication
Sections 33–34The Board may impose monetary penalties set out in the Schedule — up to ₹250 crore, as determined after inquiry having regard to the factors in Section 33(2); the amounts are a ceiling, not a fixed charge.
Penalties recovered are credited to the Consolidated Fund of India.
Miscellaneous
Sections 35–44Protects actions taken in good faith under the Act.
Enables the Central Government to call for information from the Board or any Data Fiduciary or intermediary — read with Rule 23 and the Seventh Schedule.
Allows the Central Government to direct blocking of access to information in the interest of the general public in specified circumstances.
The Act is in addition to, and not in derogation of, other laws.
Bars civil courts from entertaining matters the Board is empowered to decide.
The rule-making power under which the DPDP Rules 2025 were notified.
Rules and specified notifications must be laid before Parliament.
Allows the Central Government to amend the Schedule of penalties, subject to limits in the Act.
A time-limited power to remove difficulties in giving effect to the Act.
Makes consequential amendments to other laws, including the Information Technology Act 2000 and the Right to Information Act 2005.
The Schedule sets the monetary penalties the Board may impose — up to ₹250 crore for failure to take reasonable security safeguards; up to ₹200 crore for breach of the obligation to intimate a personal data breach and of children’s-data obligations; up to ₹150 crore for breach of Significant Data Fiduciary duties; and up to ₹50 crore otherwise. Each amount is a ceiling, determined by the Board after inquiry having regard to the factors in Section 33(2).
DPDP Rules 2025 — 23 rules
Each rule with the date it commences. For a rule-by-rule breakdown, see the DPDP Rules 2025 analysis.
Seven schedules to the Rules
Conditions for registration of Consent Managers (Part A) and their ongoing obligations (Part B).
Standards for processing by the State under Section 7(b), and for research, archiving or statistical purposes.
Classes of Data Fiduciaries (large e-commerce, online gaming and social media intermediaries), purposes, and the inactivity periods after which personal data must be erased.
Classes of Data Fiduciaries (Part A) and purposes (Part B) exempt from specified obligations under Section 9.
Salaries, allowances and terms of service of the Chairperson and Members of the Board.
Terms and conditions of appointment and service of officers and employees of the Board.
Links specified purposes for information requests by the State or MeitY to the authorised person designated to handle them.
From provision to obligation
We translate each section and rule into the specific steps your organisation needs before 13 May 2027 — notice, consent, security, breach intimation, retention and, where you are notified as an SDF, the additional Rule 13 duties.
Request a provision-to-obligation walkthrough
Our data privacy counsel will respond within one working day.
