AMLEGALS — Strategic Lawyering
The Law at a Glance · 9 Chapters · 44 Sections · 23 Rules

DPDP Act 2023 & DPDP Rules 2025 — Full Provisions Reference

Every chapter, section, rule and schedule in one map — with the dates each obligation goes live.

The Digital Personal Data Protection Act received assent on 11 August 2023. The Digital Personal Data Protection Rules 2025 were notified on 13 November 2025 (Gazette G.S.R. 846(E)) — 23 rules and seven schedules, commencing in three phases. This page sets out the complete structure and links each part to a detailed briefing.

Phased Commencement

When each obligation goes live

13 Nov 2025
In force now

Rules 1, 2 and 17–21 — definitions and the Data Protection Board as a digital office. The Board is constituted and operational.

13 Nov 2026
One year on

Rule 4 — registration and obligations of Consent Managers.

13 May 2027
Core obligations

Rules 3, 5–16, 22 and 23 — notice, consent, security, breach intimation, erasure, children’s data, SDF duties, cross-border transfer and data-principal rights.

Part One · The Act

DPDP Act 2023 — 9 chapters, 44 sections

The marginal heading of every section with a plain-language note and the rule that operationalises it. For section-by-section analysis, see the section-by-section deep dive.

Chapter I

Preliminary

Sections 1–3
Section 1Short title and commencement

Names the Act and allows the Central Government to bring different provisions into force on different dates — the basis for the phased commencement now running through to 13 May 2027.

Section 2Definitions

Defines the core terms — personal data, data principal, data fiduciary, data processor, consent manager, personal data breach and Significant Data Fiduciary. The Act uses one category of personal data; it does not create a separate “sensitive data” class.

Section 3Application of the Act

Applies to digital personal data processed in India, and to processing outside India where it relates to offering goods or services to data principals in India.

Chapter II

Obligations of Data Fiduciary

Sections 4–10
Section 4Grounds for processing personal data

Permits processing only on the basis of consent or for certain legitimate uses.

Section 5Notice

Requires a clear notice — itemised purpose, the personal data sought, how to exercise rights and how to complain to the Board. Operationalised by Rule 3.

Section 6Consent

Consent must be free, specific, informed, unconditional and unambiguous, with withdrawal as easy as giving it (Section 6(4)). Sub-sections 6(7)–(9) establish the Consent Manager, operationalised by Rule 4.

Section 7Certain legitimate uses

Lists the legitimate uses for which consent is not separately required — including specified State functions, employment and medical emergencies.

Section 8General obligations of Data Fiduciary

Accountability, accuracy, reasonable security safeguards, erasure when the purpose is served (8(7)), and breach intimation (8(6)) — detailed by Rules 6, 7 and 8.

Section 9Processing of personal data of children

Requires verifiable parental consent and bars tracking, behavioural monitoring and targeted advertising directed at children. Operationalised by Rules 10, 11 and 12.

Section 10Additional obligations of Significant Data Fiduciary

A Data Fiduciary notified as an SDF must appoint an India-based Data Protection Officer (10(2)(a)), carry out a DPIA and independent audit, and exercise algorithmic due diligence — detailed by Rule 13.

Chapter III

Rights and Duties of Data Principal

Sections 11–15
Section 11Right to access information about personal data

A data principal may obtain a summary of their personal data being processed and the identities of other fiduciaries with whom it has been shared.

Section 12Right to correction and erasure of personal data

A right to correction, completion, updating and erasure of personal data.

Section 13Right of grievance redressal

A readily available means of registering grievances, to be answered within the period set by Rule 14 — not exceeding ninety days.

Section 14Right to nominate

A data principal may nominate another individual to exercise their rights in the event of death or incapacity.

Section 15Duties of Data Principal

Duties including not furnishing false particulars or impersonating others; breach may attract a penalty of up to ₹10,000, as determined by the Board after inquiry.

Chapter IV

Special Provisions

Sections 16–17
Section 16Processing of personal data outside India

Permits cross-border transfer except to countries the Central Government may restrict by notification — read with Rule 15.

Section 17Exemptions

Sets out exemptions, including for certain State instrumentalities and for research, archiving or statistical purposes (Rule 16, Second Schedule).

Chapter V

Data Protection Board of India

Sections 18–26
Section 18Establishment of the Board

Establishes the Data Protection Board of India as the adjudicatory and enforcement body.

Section 19Composition and qualifications for appointment

Composition of the Board and the qualifications of its Chairperson and Members.

Section 20Salary, allowances and term of office

Terms and conditions of service — detailed by Rule 18 and the Fifth Schedule.

Section 21Disqualifications for appointment and continuation

Grounds that disqualify a person from being appointed or continuing as a Member.

Section 22Resignation by Members and filling of vacancies

Procedure for resignation and for filling vacancies on the Board.

Section 23Proceedings of the Board

The Board functions as a digital office; procedure is detailed by Rules 17 to 21.

Section 24Officers and employees of the Board

Appointment of officers and employees — detailed by Rule 20 and the Sixth Schedule.

Section 25Members and officers to be public servants

Treats Members, officers and employees as public servants for the purposes of the law.

Section 26Powers of the Chairperson

General powers of superintendence and direction over the Board’s administration.

Chapter VI

Powers, Functions and Procedure of the Board

Sections 27–28
Section 27Powers and functions of the Board

Empowers the Board to inquire into breaches, direct remedial and mitigation measures and impose penalties under the Schedule.

Section 28Procedure to be followed by the Board

The inquiry procedure, powers of a civil court in specified matters, and the requirement to act in accordance with natural justice.

Chapter VII

Appeal and Alternate Dispute Resolution

Sections 29–32
Section 29Appeal to Appellate Tribunal

An appeal from a Board order lies to the Telecom Disputes Settlement and Appellate Tribunal — manner detailed by Rule 22.

Section 30Orders of Appellate Tribunal

Execution of the Tribunal’s orders, which have the force of a civil-court decree.

Section 31Alternate dispute resolution

Allows the Board to refer a complaint for mediation or other dispute resolution.

Section 32Voluntary undertaking

Permits the Board to accept a voluntary undertaking from a person at any stage of proceedings.

Chapter VIII

Penalties and Adjudication

Sections 33–34
Section 33Penalties

The Board may impose monetary penalties set out in the Schedule — up to ₹250 crore, as determined after inquiry having regard to the factors in Section 33(2); the amounts are a ceiling, not a fixed charge.

Section 34Sums realised to be credited to the Consolidated Fund of India

Penalties recovered are credited to the Consolidated Fund of India.

Chapter IX

Miscellaneous

Sections 35–44
Section 35Protection of action taken in good faith

Protects actions taken in good faith under the Act.

Section 36Power to call for information

Enables the Central Government to call for information from the Board or any Data Fiduciary or intermediary — read with Rule 23 and the Seventh Schedule.

Section 37Power of Central Government to issue directions

Allows the Central Government to direct blocking of access to information in the interest of the general public in specified circumstances.

Section 38Consistency with other laws

The Act is in addition to, and not in derogation of, other laws.

Section 39Bar of jurisdiction

Bars civil courts from entertaining matters the Board is empowered to decide.

Section 40Power to make rules

The rule-making power under which the DPDP Rules 2025 were notified.

Section 41Laying of rules and certain notifications

Rules and specified notifications must be laid before Parliament.

Section 42Power to amend the Schedule

Allows the Central Government to amend the Schedule of penalties, subject to limits in the Act.

Section 43Power to remove difficulties

A time-limited power to remove difficulties in giving effect to the Act.

Section 44Amendments to certain Acts

Makes consequential amendments to other laws, including the Information Technology Act 2000 and the Right to Information Act 2005.

The Schedule to the Act

The Schedule sets the monetary penalties the Board may impose — up to ₹250 crore for failure to take reasonable security safeguards; up to ₹200 crore for breach of the obligation to intimate a personal data breach and of children’s-data obligations; up to ₹150 crore for breach of Significant Data Fiduciary duties; and up to ₹50 crore otherwise. Each amount is a ceiling, determined by the Board after inquiry having regard to the factors in Section 33(2).

Part Two · The Rules

DPDP Rules 2025 — 23 rules

Each rule with the date it commences. For a rule-by-rule breakdown, see the DPDP Rules 2025 analysis.

Rule 1Short title and commencementIn force
Rule 2DefinitionsIn force
Rule 3Notice given by Data Fiduciary to Data Principal13 May 2027
Rule 4Registration and obligations of Consent Manager13 Nov 2026
Rule 5Processing for subsidies, benefits, services and functions by the State13 May 2027
Rule 6Reasonable security safeguards13 May 2027
Rule 7Intimation of personal data breach13 May 2027
Rule 8Time period for erasure of personal data13 May 2027
Rule 9Contact information of person responsible for queries13 May 2027
Rule 10Verifiable consent for processing of children's personal data13 May 2027
Rule 11Processing of personal data of persons with disability13 May 2027
Rule 12Exemptions for certain processing of children's data13 May 2027
Rule 13Additional obligations of Significant Data Fiduciary13 May 2027
Rule 14Rights of Data Principals and manner of exercise13 May 2027
Rule 15Processing of personal data outside India13 May 2027
Rule 16Exemption for research, archiving or statistical purposes13 May 2027
Rule 17Data Protection Board as a digital officeIn force
Rule 18Terms and conditions of service of Chairperson and MembersIn force
Rule 19Proceedings and functioning of the BoardIn force
Rule 20Officers and employees of the BoardIn force
Rule 21Meetings and authentication of ordersIn force
Rule 22Manner of appeal to the Appellate Tribunal13 May 2027
Rule 23Calling for information from Data Fiduciary or intermediary13 May 2027
Part Three · The Schedules

Seven schedules to the Rules

First ScheduleConsent Manager

Conditions for registration of Consent Managers (Part A) and their ongoing obligations (Part B).

Second ScheduleStandards for State and research processing

Standards for processing by the State under Section 7(b), and for research, archiving or statistical purposes.

Third ScheduleErasure timelines

Classes of Data Fiduciaries (large e-commerce, online gaming and social media intermediaries), purposes, and the inactivity periods after which personal data must be erased.

Fourth ScheduleExemptions for children's data

Classes of Data Fiduciaries (Part A) and purposes (Part B) exempt from specified obligations under Section 9.

Fifth ScheduleService terms of Chairperson and Members

Salaries, allowances and terms of service of the Chairperson and Members of the Board.

Sixth ScheduleService terms of Board officers

Terms and conditions of appointment and service of officers and employees of the Board.

Seventh ScheduleAuthorised persons for information requests

Links specified purposes for information requests by the State or MeitY to the authorised person designated to handle them.

Map the law to your operations

From provision to obligation

We translate each section and rule into the specific steps your organisation needs before 13 May 2027 — notice, consent, security, breach intimation, retention and, where you are notified as an SDF, the additional Rule 13 duties.

Request a provision-to-obligation walkthrough

Our data privacy counsel will respond within one working day.

Your information is handled in accordance with our privacy obligations. No spam, ever.

the DPDP Act 2023 and DPDP Rules 2025: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to the DPDP Act 2023 and DPDP Rules 2025?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on the DPDP Act 2023 and DPDP Rules 2025 under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on the DPDP Act 2023 and DPDP Rules 2025 under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on the DPDP Act 2023 and DPDP Rules 2025?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for the DPDP Act 2023 and DPDP Rules 2025 rather than a generic checklist.

How do I get a first view of my DPDPA exposure on the DPDP Act 2023 and DPDP Rules 2025?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about the DPDP Act 2023 and DPDP Rules 2025 · DPDPA Exposure Assessment