AMLEGALS — Strategic Lawyering
Subordinate Legislation · 23 Rules

DPDP Rules 2025

Where the Act ends, the Rules begin.

DPDPA 2023 sets the principles. The Digital Personal Data Protection Rules 2025 operationalise them — prescribing notice content, breach reporting timelines, Consent Manager registration, DPIA frameworks, and the procedure of the Data Protection Board. Without the Rules, the Act is silent.

22

Rules prescribed under DPDP Rules 2025

Subordinate legislation
72 hrs

Maximum window to notify the Board of a breach

Rule 7
₹2 Cr

Minimum net worth for Consent Manager registration

Rule 4
§ 40

Rule-making authority of the Central Government

DPDPA 2023
Why the Rules Matter

The Act sets the principles. The Rules tell you what to actually do.

Read the Act in isolation and most obligations remain abstract. Section 5 says a notice must be given. Rule 3 tells you what the notice must contain. Section 8 says breaches must be notified. Rule 7 tells you the form, content, and 72-hour window.

The DPDP Rules 2025 turn principles into operational requirements. They prescribe what Consent Managers must look like, how DPIAs must be conducted, what reasonable security safeguards entail, and how the Data Protection Board will conduct inquiries.

A compliance programme that has not been re-mapped against the Rules is a compliance programme built on assumptions. The Rules close interpretive gaps that the Act deliberately left open.

Rule-by-Rule Breakdown

The 12 operationally critical Rules

Of the 22 prescribed Rules, twelve directly drive day-to-day compliance operations. Each Rule below identifies its operational impact and the specific section of the Act it operationalises.

Rule3

Notice by Data Fiduciary to Data Principal

Prescribes the minimum content of the notice required under Section 5 — specific purpose, categories of personal data, manner of withdrawing consent, contact details of grievance officer, and rights exercise mechanism.

Rule4

Registration and Obligations of Consent Manager

Establishes the framework for Consent Managers under Section 6(9) — ₹2 crore minimum net worth (First Schedule), interoperability requirements, audit obligations, and the duties of Consent Managers in respect of Data Principals and Data Fiduciaries. Consent Manager provisions commence on 13 November 2026.

Rule5

Processing for Subsidies, Benefits, Services, and Functions by the State

Operationalises the legitimate use under Section 7(b) for the State and its instrumentalities. Specifies the standards (Second Schedule) for processing in connection with subsidies, benefits, certificates, licences, and permits.

Rule6

Reasonable Security Safeguards

Mandates technical and organisational measures — encryption, access controls, periodic audits, incident response procedures, monitoring, retention of logs for at least one year, and other safeguards proportionate to the volume and sensitivity of data processed.

Rule7

Intimation of Personal Data Breach

Specifies the two-stage breach intimation under Section 8(6). On becoming aware of a breach, a Data Fiduciary must intimate every affected Data Principal without delay and give the Board an initial intimation without delay, followed by a detailed report to the Board within 72 hours (or such longer period as the Board may allow on request).

Rule8

Time Period for Erasure of Personal Data

Operationalises Section 8(7)-(8). Prescribes retention limits (Third Schedule) after which personal data shall be erased once the purpose is no longer served — including a default position for e-commerce, online gaming and social media intermediaries above specified user thresholds — with 48 hours' prior notice to the Data Principal before erasure.

Rule9

Contact Information of Person Responsible

Requires every Data Fiduciary to publish on its website or app, and in every notice, the business contact information of the Data Protection Officer (where applicable) or other person able to answer questions about the processing of personal data.

Rule10

Verifiable Consent for Processing of Children's Personal Data

Prescribes how a Data Fiduciary must obtain verifiable consent of a parent before processing a child's personal data (Section 9), including due-diligence checks on the identity and age of the parent using reliable identity details or a virtual token mapped to such details (for example, via a Digital Locker service provider).

Rule11

Processing of Personal Data of Persons with Disability

Prescribes how a Data Fiduciary is to verify that a person acting on behalf of an individual with disability who has a lawful guardian is duly appointed under the applicable law before processing that individual's personal data.

Rule12

Exemptions for Certain Processing of Children's Data

Identifies the classes of Data Fiduciaries (Fourth Schedule — including certain healthcare, educational and childcare providers) and the purposes for which specified obligations relating to children's data, such as the restriction on tracking and targeted advertising, stand relaxed under Section 9(5).

Rule13

Additional Obligations of Significant Data Fiduciary

Prescribes the enhanced obligations of a Significant Data Fiduciary under Section 10 — appointing a Data Protection Officer based in India, a Data Protection Impact Assessment and independent audit once every twelve months with the findings reported to the Board, and due diligence to verify that algorithmic software deployed does not pose a risk to the rights of Data Principals.

Rule14

Rights of Data Principals and Manner of Exercise

Operationalises Sections 11-14. Requires Data Fiduciaries and Consent Managers to publish the means to exercise the rights of access, correction, erasure and nomination, to provide a grievance-redressal mechanism, and to respond to grievances within the period specified — not exceeding ninety days.

Rule15

Processing of Personal Data Outside India

Provides that a Data Fiduciary transferring personal data outside India must comply with any requirements the Central Government may specify, by general or special order, regarding making such data available to any foreign State or its agencies — read together with the transfer-restriction power under Section 16.

Rule16

Exemption for Research, Archiving or Statistical Purposes

Exempts processing of personal data necessary for research, archiving or statistical purposes from specified provisions of the Act, provided the processing is carried out in accordance with the standards set out in the Second Schedule and the data is not used to take any decision specific to a Data Principal.

Rule17-23

Data Protection Board, Appeals and Calling for Information

Establish the functioning of the Data Protection Board as a digital office (Rules 17-21), the manner of appeal to the Telecom Disputes Settlement and Appellate Tribunal (Rule 22), and the power of the Central Government or an authorised person to call for information from a Data Fiduciary or intermediary (Rule 23, read with the Seventh Schedule). The Board and these institutional provisions commenced on 13 November 2025.

Operational Sequencing

How sequencing affects exposure

The Rules can be implemented in any order, but enforcement risk does not distribute evenly. These priorities reflect what we counsel clients to address first.

Tier 1
Immediate — 30 days

Rule 3 (Notice content), Rule 7 (Breach response), Rule 6 (Security safeguards baseline), Rule 9 (DPO contact publishing)

Tier 2
30–90 days

Rule 14 (Rights exercise mechanism), Rule 13 (DPIA framework if SDF), Rule 8 (Erasure timelines)

Tier 3
90–180 days

Rule 4 (Consent Manager onboarding), Rule 10 (Children’s data verification), Rule 5 (State entity processing flows where applicable)

Tier 4
Continuous

Rule 15 (Cross-border transfer monitoring), Rules 17-23 (Board inquiry preparedness)

Operational Readiness

Request a Rules Implementation Briefing

Our practitioners will walk through your operational footprint, identify which of the 22 Rules apply to your operations, and frame an implementation roadmap mapped to enforcement risk.

Request a Rules Implementation Briefing

A senior practitioner will reach out within one working day.

Your information is handled in accordance with our privacy obligations. No spam, ever.

Insights & Answers

What practitioners and boards are asking

What are the DPDP Rules 2025?

The Digital Personal Data Protection Rules, 2025 (DPDP Rules) are subordinate legislation notified on 13 November 2025 (G.S.R. 846(E)) under DPDPA. They comprise 23 Rules and 7 Schedules operationalising the Act across notice requirements (Rule 3), Consent Manager registration and obligations (Rule 4), security safeguards (Rule 6), breach notification (Rule 7), retention and erasure (Rule 8), children data safeguards (Rule 10), Significant Data Fiduciary obligations including DPIA, audit and algorithmic due diligence (Rule 13), Data Principal rights (Rule 14), and cross-border transfers (Rule 15).

When do DPDP Rules 2025 take effect?

The DPDP Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)). Commencement is phased: institutional provisions, including the Data Protection Board, commenced on 13 November 2025; the Consent Manager framework (Rule 4) commences on 13 November 2026; and the substantive obligations commence on 13 May 2027. Organisations should treat the current period as the build window.