AMLEGALS — Strategic Lawyering
HomeInsightsWhat DPDP Rules G.S.R. 846(E) Mean for Your India Operations
InternationalVibe Data Privacy

What DPDP Rules G.S.R. 846(E) Mean for Your India Operations

A Section-by-Section Operational Map of the DPDP Rules, 2025 for Foreign Businesses Operating in India

"The Central Government hereby makes the following rules, namely:— 1. Short title and commencement.— (1) These rules may be called the Digital Personal Data Protection Rules, 2025."

G.S.R. 846(E), Gazette of India, 13 November 2025
What DPDP Rules G.S.R. 846(E) Mean for Your India Operations

On 13 November 2025, the Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025 vide G.S.R. 846(E) in the Gazette of India. These 23 Rules operationalise the Digital Personal Data Protection Act, 2023 (DPDPA), which spans 44 Sections, and are accompanied by 7 Schedules. For foreign companies with India operations — whether through subsidiaries, joint ventures, GCCs, or SaaS deployments — these Rules convert abstract statutory obligations into concrete operational deadlines, technical specifications, and documentation requirements. This article maps each critical Rule to the operational action it demands from a foreign entity's India compliance function.

G.S.R. 846(E): What the Gazette Notification Contains

The notification published under G.S.R. 846(E) contains 23 Rules exercising powers under Section 40 of DPDPA read with Sections 5, 6, 8, 9, 10, 11, 13, 16, 17, 22, 24, 28, 30, 31, 36, and 37. The Rules were notified on 13 November 2025 and commence in phases: the institutional framework (including the Data Protection Board) commenced on 13 November 2025, Consent Manager obligations (Rule 4) commence on 13 November 2026, and the substantive obligations commence on 13 May 2027 — giving foreign operations roughly an 18-month build window. For foreign operations, the critical architecture spans: notice and consent infrastructure (Rules 3 to 4), processor governance (Rule 6), breach mechanics (Rule 7), retention and erasure (Rule 8), children's data (Rules 10-12), Significant Data Fiduciary obligations (Rule 13), and cross-border transfers (Rule 15).

Key Points

  • 23 Rules notified 13 November 2025
  • Substantive obligations: 13 May 2027
  • 18-month build window
  • Exercises powers under 16 DPDPA Sections

Rules 3-4: Consent Architecture — The Technical Mandate

Rule 3 prescribes the form and content of notice under Section 5 — it must be in clear, plain language, available in English and all 22 scheduled languages upon request. For foreign operations running centralised consent platforms (OneTrust, TrustArc, Cookiebot), this means India-specific consent flows cannot simply mirror GDPR templates. Rule 4 operationalises Consent Managers under Section 2(g) — registered intermediaries who manage consent on behalf of Data Principals. A foreign entity using a Consent Manager must verify its registration with the Data Protection Board. The consent record must capture: timestamp, notice version, language presented, mechanism used, and withdrawability confirmation.

Key Points

  • 22 scheduled language support required on request
  • Consent Manager registration verification mandatory
  • Consent records must include timestamp + notice version
  • GDPR consent templates are not DPDPA-compliant

Rule 6: Processor Contracts — What Your India Vendors Must Agree To

Rule 6 operationalises Section 8(2) — the Data Fiduciary's effectively non-delegable responsibility over processors. Every vendor processing personal data on behalf of a foreign entity's India operations must have a written contract specifying: processing scope, security safeguards, sub-processor controls, deletion obligations on termination, breach notification chain, and audit rights. The Rule does not permit incorporation by reference to a global DPA — the contract must address DPDPA-specific obligations independently. This has direct implications for outsourced HR (ADP, Workday), cloud infrastructure (AWS, Azure, GCP), and SaaS vendors (Salesforce, ServiceNow) servicing India operations.

Key Points

  • Written contract mandatory — oral agreements insufficient
  • Sub-processor controls required under Section 8(2)
  • Global DPA does not substitute DPDPA-specific terms
  • Deletion obligation on contract termination

Rule 7: Breach Notification — The Parallel Reporting Regime

Rule 7 prescribes the form and manner of breach notification under Section 8(6). On becoming aware of a breach, the Data Fiduciary must notify affected Data Principals without delay and give the Data Protection Board an initial intimation without delay, followed by a detailed report within 72 hours (or such longer period as the Board may allow). For foreign operations, this creates a parallel reporting obligation alongside CERT-In's 6-hour cyber incident reporting requirement under Directions of 2022. The notification must contain: nature of the breach, categories and approximate number of Data Principals affected, likely consequences, and measures taken. A foreign entity's global incident response playbook must be augmented with India-specific notification templates, escalation trees, and Board communication protocols.

Key Points

  • Dual notification: Board + Data Principals
  • Parallel obligation with CERT-In 6-hour reporting
  • Notification must specify affected categories and numbers
  • India-specific incident response playbook required

Rules 10-12: Children's Data — Verification and Prohibitions

Rule 10 mandates verifiable parental or guardian consent for processing data of individuals under 18 years. Section 9 of the DPDPA prohibits tracking, behavioural monitoring, and targeted advertising directed at children. Rule 11 provides for verifiable consent by the lawful guardian of a person with disability, and Rule 12 provides specific exemptions for prescribed classes of Data Fiduciaries and processing purposes. For foreign operations running consumer-facing platforms (e-commerce, gaming, ed-tech, social media), this requires: age-gate implementation at the India entry point, parental consent collection infrastructure, complete suppression of behavioural ad targeting for minor users, and separate data retention policies for children's data. The age threshold of 18 (versus GDPR's 16 or COPPA's 13) catches many foreign platforms that have calibrated their systems to lower thresholds.

Key Points

  • Age threshold: 18 years (higher than GDPR/COPPA)
  • Verifiable parental consent — not just checkbox
  • Complete ban on behavioural targeting for children
  • Rule 12 exemptions for prescribed categories only

Rule 13: Significant Data Fiduciary — The Enhanced Compliance Tier

Rule 13 operationalises Section 10 — the enhanced obligations for entities notified as Significant Data Fiduciaries (SDFs). An SDF must appoint a Data Protection Officer resident in India, conduct periodic Data Protection Impact Assessments (DPIAs), undertake independent audits, and observe due diligence to verify that algorithmic software deployed for processing is not likely to pose a risk to the rights of Data Principals. For a foreign entity's India subsidiary that processes large volumes of personal data, SDF notification is a realistic possibility. The compliance cost differential between a standard Data Fiduciary and an SDF is substantial — DPO appointment, DPIA infrastructure, audit cycles, and Board reporting create an ongoing operational overhead that must be budgeted in the India compliance plan.

Key Points

  • DPO must be India-resident
  • Periodic DPIA mandatory for SDFs
  • Independent audit requirement
  • Algorithmic due diligence for processing software

Rule 15: Cross-Border Transfers — The Negative List Approach

The DPDPA adopts a permissive-with-exception model for cross-border data transfers under Section 16. Data may flow to any jurisdiction except those on the Central Government's restricted list (the "negative list"). As of this writing, the negative list has not been notified, meaning transfers to all jurisdictions remain permissible. However, sectoral regulators impose independent localisation requirements: RBI mandates domestic storage of payment system data; IRDAI requires insurance data within India; SEBI has specific data governance requirements. A foreign entity's data architecture must account for both the DPDPA framework and sectoral overlays — a transfer compliant under DPDPA may still violate RBI's circular on storage of payment data.

Key Points

  • Permissive model — transfers allowed unless restricted
  • Negative list not yet notified (as of July 2026)
  • RBI, IRDAI, SEBI impose independent localisation
  • Sectoral compliance required alongside DPDPA

Key Takeaways

1

Map each of the 23 Rules to your India entity's current processing activities within the build window ahead of 13 May 2027

2

Audit existing consent platforms (OneTrust, TrustArc) against Rule 3 language and format requirements

3

Renegotiate all India vendor contracts to include DPDPA-specific Rule 6 terms — global DPAs are insufficient

4

Build India-specific breach notification playbooks addressing both Rule 7 and CERT-In parallel obligations

5

Implement age-gate and parental consent infrastructure calibrated to the 18-year threshold under Rule 10

6

Assess SDF notification risk under Rule 13 and budget for DPO, DPIA, and audit infrastructure if applicable

7

Layer sectoral data localisation requirements (RBI, IRDAI, SEBI) over DPDPA's cross-border framework

Statutory References

DPDPA Section 40DPDP Rules 2025 Rule 3DPDP Rules 2025 Rule 4DPDP Rules 2025 Rule 6DPDP Rules 2025 Rule 7DPDP Rules 2025 Rule 8DPDP Rules 2025 Rule 10DPDP Rules 2025 Rule 11DPDP Rules 2025 Rule 12DPDP Rules 2025 Rule 13DPDP Rules 2025 Rule 14DPDP Rules 2025 Rule 15DPDPA Section 8(6)DPDPA Section 16CERT-In Directions 2022RBI Circular on Storage of Payment Data 2018
View DPDP Rules Deep Dive

Need Compliance Guidance?

Our data privacy practice provides tailored compliance assessments and implementation support.

Get in Touch
Insights & Answers

What practitioners and boards are asking

What are the DPDP Rules G.S.R. 846(E) and when do they come into force?

The DPDP Rules, 2025 were notified on 13 November 2025 vide G.S.R. 846(E) in the Gazette of India by the Ministry of Electronics and Information Technology. These 23 Rules, with 7 Schedules, operationalise the Digital Personal Data Protection Act, 2023. Commencement is phased, with the substantive obligations commencing on 13 May 2027, providing an approximately 18-month build window for organisations to build notice and consent infrastructure (Rules 3 to 4), security and processor governance (Rule 6), breach notification protocols (Rule 7), and Significant Data Fiduciary compliance (Rule 13).

How do the DPDP Rules 2025 affect foreign companies with India operations?

Foreign companies with India operations — through subsidiaries, joint ventures, GCCs, or SaaS deployments — must map each of the 23 Rules to their processing activities. Key impacts include: India-specific consent flows that cannot mirror GDPR templates (Rule 3), DPDPA-specific processor contracts that supplement global DPAs (Rule 6), parallel breach notification to the Data Protection Board and CERT-In (Rule 7), children's data protections with an 18-year age threshold (Rules 10-12), and cross-border transfer compliance layered with sectoral localisation requirements from RBI, IRDAI, and SEBI.