Readiness assessment

The Rules

The DPDP Rules, 2025, explained

The Act says what you must do; the Rules say how. Notified on 13 November 2025, the Digital Personal Data Protection Rules turn every DPDP obligation into something operational, from the exact wording of a consent notice to the security controls you keep, the clock that starts when you discover a breach, and the day certain data must be erased.

In short

The DPDP Rules, 2025 were notified on 13 November 2025 and make the Digital Personal Data Protection Act, 2023 workable. They set the standard for consent notices, the registration and duties of Consent Managers, the baseline security safeguards, breach-reporting timelines, retention and erasure, verifiable parental consent for children, how Data Principals exercise their rights, and the extra duties of Significant Data Fiduciaries. The Board and its machinery are live now; Consent Manager registration opens on 13 November 2026; the core notice, consent and rights obligations apply from 13 May 2027.

How the Rules govern the data lifecycle 1 · Collect Notice + valid consent Rule 3 · s5, s6 2 · Process Only for the stated purpose s4-s7 3 · Secure Reasonable safeguards Rule 6 · s8(5) 4 · Respond Rights + breach notice Rules 7, 11 5 · Erase When purpose ends Rule 8 · s8(7) Consent can be withdrawn at any point, which restarts the cycle
Every DPDP Rule attaches to a stage of the data lifecycle. Read the page in that order, or jump to a rule below.
13 Nov 2025
Live now

Rules notified. The Data Protection Board is established; definitions and its machinery are in force and complaints can be filed.

13 May 2027
Full compliance

Notice, consent, Data Principal rights, breach reporting, children’s-data and SDF duties all apply.

The Rules at a glance

RuleWhat it governsAct basisApplies from
Rule 3Content and clarity of the consent noticeSection 513 May 2027
Rule 4Registration and duties of Consent ManagersSection 6(9)13 Nov 2026
Rule 6Reasonable security safeguardsSection 8(5)13 May 2027
Rule 7Breach intimation to the Board and Data PrincipalsSection 8(6)13 May 2027
Rule 8Retention limits and erasureSection 8(7)13 May 2027
Rule 10Verifiable parental consent for childrenSection 913 May 2027
Rule 11How Data Principals exercise their rightsSections 11-1413 May 2027
Rule 12Extra duties of Significant Data FiduciariesSection 1013 May 2027
Rules 14-15Cross-border transfer restrictionsSection 16By notification
Rules 16-22Functioning of the Data Protection BoardChapters V-VII13 Nov 2025

Rule 3Notice to Data Principals

When you rely on consent, the notice you show is the legal document that makes that consent valid. Rule 3 says it must stand on its own, in clear and plain language, so a person can understand exactly what they are agreeing to before they agree. A link to a long, general privacy policy is not, by itself, the Rule 3 notice.

What the notice must contain

  • An itemised list of the personal data you will collect, described specifically rather than as “your information”.
  • The specific purpose for each item of data, so purposes are not bundled together.
  • How to withdraw consent, and it must be as easy to withdraw as it was to give.
  • How to exercise rights such as access, correction and erasure.
  • How to complain to the Data Protection Board, with a working link.
  • Availability in English and the Eighth Schedule languages of the Constitution.
Notice itemised data, purpose, rights Affirmative consent a clear, unbundled opt-in action Consent record proof of what was shown and agreed
Rule 3 in practice: the notice and the affirmative action both feed the consent record you may later have to produce.
What it means for you: build a purpose-by-purpose notice at the point of collection, version it, and treat withdrawal as a first-class action, not a buried setting.
Applies from 13 May 2027Act basis Section 5

Rule 4Consent Managers

Full guide: the DPDP Consent Manager: role, Rule 4 registration, obligations and how it differs from a CMP.

A Consent Manager is a statutory, Board-registered intermediary that lets a Data Principal give, review, manage and withdraw consent across many Data Fiduciaries from a single dashboard. Rule 4 and its Schedule set the conditions to register: an interoperable platform, fit-and-proper control, and duties to act in the Data Principal’s interest and keep auditable records. It is not a cookie tool, a consent-management platform (CMP) or a CRM field; it is a regulated role in the tradition of India’s Account Aggregator framework.

Data Principal gives and withdraws once Consent Manager Board-registered, interoperable Data Fiduciary A Data Fiduciary B Data Fiduciary C
One consent decision by the Data Principal is propagated to every connected Data Fiduciary, and a withdrawal flows the same way.

Consent Manager vs the tools people confuse it with

 Consent ManagerCMP / cookie toolCRM field
What it isA regulated intermediarySoftware you deployA field in your database
Registered with the BoardYes, requiredNoNo
Works across companiesYes, interoperableNo, per-siteNo, per-company
Acts for the personYes, by dutyNoNo
What it means for you: you do not become a Consent Manager just because you collect consent. If you are a Data Fiduciary, understand how consent obtained through a Consent Manager will reach you; if you plan to offer the service, watch for the registration window.
Registration opens 13 Nov 2026Act basis Section 6(9)

Rule 6Reasonable security safeguards

Every Data Fiduciary must protect the personal data it holds with reasonable security safeguards. This duty is not deferred in spirit, it underpins everything else, and a failure to take reasonable safeguards carries the single highest penalty in the Act. In practice the Rules point to a baseline you should be able to evidence.

SafeguardWhat it does
Encryption or maskingProtects data at rest and in transit so a leak is not immediately usable
Access controlsLeast-privilege access so only the right people reach personal data
Logging and monitoringRecords who did what, so events can be detected and investigated
Backups and continuityLets you restore data and keep operating after an incident
Processor obligationsContractual security terms binding anyone who processes data for you
Breach detectionThe ability to notice and reconstruct a breach when it happens
Risk

A failure of reasonable security safeguards is the one breach that can attract a penalty of up to ₹250 crore, decided by the Board after inquiry. Treat security as the floor, not a later phase.

What it means for you: map where personal data lives, apply encryption and least-privilege access, keep audit logs, and put security terms in every processor contract.
Act basis Section 8(5)

Rule 7Breach intimation

When you become aware of a personal data breach, two clocks start. You must tell the affected Data Principals, in plain language, and you must tell the Data Protection Board, first with the essential facts and then with a fuller account within the window the Rules set. Because the trigger is awareness, your ability to detect and reconstruct an incident matters as much as the notice itself.

Detect become aware Assess and contain scope, impact, stop it Notify Data Principals what, impact, what to do Notify the Board initial intimation Detailed follow-up to the Board, within the window
Detection feeds two parallel notices; the Board also receives a fuller follow-up once the facts are established.

What the notice to people must say

  • What happened, described in clear language.
  • The likely consequences for the person.
  • What you are doing to mitigate and contain it.
  • What they can do to protect themselves.
What it means for you: prepare breach-notice templates for both the Board and Data Principals now, and rehearse who decides, who drafts, and who sends.
Act basis Section 8(6)

Rule 8Retention and erasure

The default is simple: keep personal data only while the purpose it was collected for is still live, then erase it, unless a law requires you to retain it. On top of that, the Rules require certain large, consumer-facing classes of Data Fiduciary to erase personal data after a defined period of user inactivity, after giving the person advance notice.

Collect tied to a purpose Keep while the purpose is live Trigger purpose ends · withdrawal · inactivity Erase delete, unless a law requires keeping
Retention is a lifecycle, not a fixed number of years. A trigger, including inactivity for some platforms, moves data to erasure.
What it means for you: set a retention rule per purpose, automate deletion when the purpose ends or consent is withdrawn, and if you are a large consumer platform, build the inactivity-based erasure and its advance notice.
Act basis Section 8(7)

Rule 10Children’s data

Before processing the data of a child, defined as anyone under 18, you must obtain verifiable parental consent using reliable signals of identity and age, and you must not track children, monitor their behaviour, or direct advertising at them. Rule 10 does not mandate a single government method such as DigiLocker; it asks for due diligence appropriate to the context. The Fourth Schedule relaxes some checks for specified classes, such as certain health and education services, but not the core duty to protect children.

Is the user under 18? assess age reliably Yes No Verifiable parental consent reliable identity + age signals Standard consent rules apply No tracking, profiling or ads directed at children
DigiLocker is not required. You choose an age-assurance method appropriate to your service.
What it means for you: if children can use your service, design an age-assurance and parental-consent flow, and switch off behavioural tracking and targeted ads for them.
Act basis Section 9

Rule 11Data Principal rights

The Rules require you to publish an easy, usable way for people to exercise their rights, with readable timelines for your response. DPDP creates a right to access information, not a GDPR-style right to an explanation of automated decisions.

RightWhat it lets a person doHow you enable it
AccessGet a summary of their data and how it is processedA request channel that queries your systems
CorrectionFix, complete or update inaccurate dataAn edit and verification workflow
ErasureHave data deleted when it is no longer neededDeletion that reaches every store and processor
GrievanceRaise a complaint and get a responseA named channel with a response SLA
NominationAppoint someone to act on their behalfA way to register and honour a nominee
What it means for you: stand up a rights-request channel with owners and SLAs, and connect it to the systems that actually hold the data so requests can be fulfilled.
Act basis Sections 11-14

Rule 12Significant Data Fiduciaries

The Central Government can designate an organisation a Significant Data Fiduciary based on the volume and sensitivity of the data it processes and the risk it poses. An SDF carries extra duties on top of every other rule on this page.

Volume of data Sensitivity Risk to rights Govt designates you an SDF Appoint a DPO in India Independent audits Data Protection Impact Assessments Algorithmic due diligence
Designation is a government decision based on scale and risk; the four extra duties follow from it.
What it means for you: assess whether you are likely to be designated an SDF, and if so, plan for a DPO, a DPIA cadence and an independent audit.
Act basis Section 10

Rules 14-15Cross-border transfers

DPDP takes a relatively open stance: personal data may generally be transferred outside India, but the Central Government may restrict transfers to specified countries or territories, and certain classes of data or Data Fiduciary may face additional conditions. Sectoral rules, such as the Reserve Bank of India’s directions in financial services, can impose stricter localisation on top of DPDP.

  • Default: transfer is allowed unless restricted.
  • Restriction lever: the government may name countries or territories that are off-limits for transfer.
  • Sectoral overlay: RBI and other regulators can require you to keep certain data in India regardless of DPDP.
What it means for you: keep a register of where your data flows and which processors are offshore, and watch for government notifications restricting specific destinations.
Act basis Section 16

Rules 16-22The Data Protection Board

The remaining Rules set up how the Data Protection Board of India works: a digital-first regulator that receives complaints, conducts inquiries, and can impose penalties after due process. Its decisions can be appealed. The Board and its core machinery are already live as of 13 November 2025.

Complaint or breach filed with the Board Inquiry digital-first due process Penalty by gravity, up to the cap Appeal to the Tribunal TDSAT
The Board acts after due process, and its orders can be appealed to the Telecom Disputes Settlement and Appellate Tribunal.

Not sure which rules bite first for you?

Take the free readiness check and get a prioritised view of your gaps in about two minutes.

Check where you stand →

Common questions about the DPDP Rules 2025

When did the DPDP Rules 2025 come into force?
The Rules were notified on 13 November 2025, when the Data Protection Board was established. Consent Manager registration opens on 13 November 2026, and the core obligations, including notice, consent, Data Principal rights and breach reporting, apply from 13 May 2027.
Are the DPDP Rules different from the DPDP Act?
Yes. The Digital Personal Data Protection Act, 2023 sets the principles and obligations; the DPDP Rules, 2025 provide the operational detail that makes them workable, such as what a notice must contain and how a breach must be reported.
Do the DPDP Rules require a cookie banner?
No. There is no cookie-specific rule. But where an online identifier is personal data and you rely on consent to process it, the Rule 3 notice and Section 6 consent requirements apply.
What security measures do the Rules require?
Reasonable security safeguards: a baseline that points to encryption or masking, access controls, logging and monitoring, backups for continuity, and security obligations on your processors. A failure here carries the Act’s highest penalty, up to ₹250 crore.
Who must erase data after a period of inactivity?
The default is to keep data only while its purpose is live. On top of that, the Rules require certain large consumer-facing classes, such as major e-commerce, online gaming and social-media platforms, to erase personal data after a defined period of user inactivity, with advance notice to the person.
Do the Rules mandate DigiLocker for children’s consent?
No. Rule 10 requires verifiable parental consent using reliable identity and age signals, but it does not require any single government method such as DigiLocker. You choose an approach appropriate to your context.
When do I need to appoint a Data Protection Officer?
A DPO based in India is required if the Central Government designates you a Significant Data Fiduciary. Other Data Fiduciaries must still publish a contact for answering questions about their processing, but are not required to appoint a formal DPO.

This page summarises the DPDP Rules, 2025 in plain language for general understanding. It is not legal advice. For the authoritative text, refer to the Rules as notified in the Gazette of India and the Digital Personal Data Protection Act, 2023.