DPDP Rules 2025
Where the Act ends, the Rules begin.
DPDPA 2023 sets the principles. The Digital Personal Data Protection Rules 2025 operationalise them — prescribing notice content, breach reporting timelines, Consent Manager registration, DPIA frameworks, and the procedure of the Data Protection Board. Without the Rules, the Act is silent.
Rules prescribed under DPDP Rules 2025
Subordinate legislationMaximum window to notify the Board of a breach
Rule 7Minimum net worth for Consent Manager registration
Rule 4Rule-making authority of the Central Government
DPDPA 2023The Act sets the principles. The Rules tell you what to actually do.
Read the Act in isolation and most obligations remain abstract. Section 5 says a notice must be given. Rule 3 tells you what the notice must contain. Section 8 says breaches must be notified. Rule 7 tells you the form, content, and 72-hour window.
The DPDP Rules 2025 turn principles into operational requirements. They prescribe what Consent Managers must look like, how DPIAs must be conducted, what reasonable security safeguards entail, and how the Data Protection Board will conduct inquiries.
A compliance programme that has not been re-mapped against the Rules is a compliance programme built on assumptions. The Rules close interpretive gaps that the Act deliberately left open.
The 12 operationally critical Rules
Of the 22 prescribed Rules, twelve directly drive day-to-day compliance operations. Each Rule below identifies its operational impact and the specific section of the Act it operationalises.
Notice by Data Fiduciary to Data Principal
Prescribes the minimum content of the notice required under Section 5 — specific purpose, categories of personal data, manner of withdrawing consent, contact details of grievance officer, and rights exercise mechanism.
Registration and Obligations of Consent Manager
Establishes the framework for Consent Managers under Section 6(9) — ₹2 crore minimum net worth (First Schedule), interoperability requirements, audit obligations, and the duties of Consent Managers in respect of Data Principals and Data Fiduciaries. Consent Manager provisions commence on 13 November 2026.
Processing for Subsidies, Benefits, Services, and Functions by the State
Operationalises the legitimate use under Section 7(b) for the State and its instrumentalities. Specifies the standards (Second Schedule) for processing in connection with subsidies, benefits, certificates, licences, and permits.
Reasonable Security Safeguards
Mandates technical and organisational measures — encryption, access controls, periodic audits, incident response procedures, monitoring, retention of logs for at least one year, and other safeguards proportionate to the volume and sensitivity of data processed.
Intimation of Personal Data Breach
Specifies the two-stage breach intimation under Section 8(6). On becoming aware of a breach, a Data Fiduciary must intimate every affected Data Principal without delay and give the Board an initial intimation without delay, followed by a detailed report to the Board within 72 hours (or such longer period as the Board may allow on request).
Time Period for Erasure of Personal Data
Operationalises Section 8(7)-(8). Prescribes retention limits (Third Schedule) after which personal data shall be erased once the purpose is no longer served — including a default position for e-commerce, online gaming and social media intermediaries above specified user thresholds — with 48 hours' prior notice to the Data Principal before erasure.
Contact Information of Person Responsible
Requires every Data Fiduciary to publish on its website or app, and in every notice, the business contact information of the Data Protection Officer (where applicable) or other person able to answer questions about the processing of personal data.
Verifiable Consent for Processing of Children's Personal Data
Prescribes how a Data Fiduciary must obtain verifiable consent of a parent before processing a child's personal data (Section 9), including due-diligence checks on the identity and age of the parent using reliable identity details or a virtual token mapped to such details (for example, via a Digital Locker service provider).
Processing of Personal Data of Persons with Disability
Prescribes how a Data Fiduciary is to verify that a person acting on behalf of an individual with disability who has a lawful guardian is duly appointed under the applicable law before processing that individual's personal data.
Exemptions for Certain Processing of Children's Data
Identifies the classes of Data Fiduciaries (Fourth Schedule — including certain healthcare, educational and childcare providers) and the purposes for which specified obligations relating to children's data, such as the restriction on tracking and targeted advertising, stand relaxed under Section 9(5).
Additional Obligations of Significant Data Fiduciary
Prescribes the enhanced obligations of a Significant Data Fiduciary under Section 10 — appointing a Data Protection Officer based in India, a Data Protection Impact Assessment and independent audit once every twelve months with the findings reported to the Board, and due diligence to verify that algorithmic software deployed does not pose a risk to the rights of Data Principals.
Rights of Data Principals and Manner of Exercise
Operationalises Sections 11-14. Requires Data Fiduciaries and Consent Managers to publish the means to exercise the rights of access, correction, erasure and nomination, to provide a grievance-redressal mechanism, and to respond to grievances within the period specified — not exceeding ninety days.
Processing of Personal Data Outside India
Provides that a Data Fiduciary transferring personal data outside India must comply with any requirements the Central Government may specify, by general or special order, regarding making such data available to any foreign State or its agencies — read together with the transfer-restriction power under Section 16.
Exemption for Research, Archiving or Statistical Purposes
Exempts processing of personal data necessary for research, archiving or statistical purposes from specified provisions of the Act, provided the processing is carried out in accordance with the standards set out in the Second Schedule and the data is not used to take any decision specific to a Data Principal.
Data Protection Board, Appeals and Calling for Information
Establish the functioning of the Data Protection Board as a digital office (Rules 17-21), the manner of appeal to the Telecom Disputes Settlement and Appellate Tribunal (Rule 22), and the power of the Central Government or an authorised person to call for information from a Data Fiduciary or intermediary (Rule 23, read with the Seventh Schedule). The Board and these institutional provisions commenced on 13 November 2025.
How sequencing affects exposure
The Rules can be implemented in any order, but enforcement risk does not distribute evenly. These priorities reflect what we counsel clients to address first.
Rule 3 (Notice content), Rule 7 (Breach response), Rule 6 (Security safeguards baseline), Rule 9 (DPO contact publishing)
Rule 14 (Rights exercise mechanism), Rule 13 (DPIA framework if SDF), Rule 8 (Erasure timelines)
Rule 4 (Consent Manager onboarding), Rule 10 (Children’s data verification), Rule 5 (State entity processing flows where applicable)
Rule 15 (Cross-border transfer monitoring), Rules 17-23 (Board inquiry preparedness)
Request a Rules Implementation Briefing
Our practitioners will walk through your operational footprint, identify which of the 22 Rules apply to your operations, and frame an implementation roadmap mapped to enforcement risk.
Request a Rules Implementation Briefing
A senior practitioner will reach out within one working day.
The Workforce Question
The Rules created the procedure. Procedure is performed by people. Why workforce architecture is now the binding constraint.
Read →Compliance Checklist
42 obligations across 7 domains — every checkpoint mapped to a Rule.
Read →Consent Management
How Rule 4 redefines consent infrastructure for every Data Fiduciary.
Read →Penalty Risk Assessment
Rule 14 procedure and Section 33 penalty determination decoded.
Read →What practitioners and boards are asking
What are the DPDP Rules 2025?
The Digital Personal Data Protection Rules, 2025 (DPDP Rules) are subordinate legislation notified on 13 November 2025 (G.S.R. 846(E)) under DPDPA. They comprise 23 Rules and 7 Schedules operationalising the Act across notice requirements (Rule 3), Consent Manager registration and obligations (Rule 4), security safeguards (Rule 6), breach notification (Rule 7), retention and erasure (Rule 8), children data safeguards (Rule 10), Significant Data Fiduciary obligations including DPIA, audit and algorithmic due diligence (Rule 13), Data Principal rights (Rule 14), and cross-border transfers (Rule 15).
When do DPDP Rules 2025 take effect?
The DPDP Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)). Commencement is phased: institutional provisions, including the Data Protection Board, commenced on 13 November 2025; the Consent Manager framework (Rule 4) commences on 13 November 2026; and the substantive obligations commence on 13 May 2027. Organisations should treat the current period as the build window.
