The Rules
The Act says what you must do; the Rules say how. Notified on 13 November 2025, the Digital Personal Data Protection Rules turn every DPDP obligation into something operational, from the exact wording of a consent notice to the security controls you keep, the clock that starts when you discover a breach, and the day certain data must be erased.
In short
The DPDP Rules, 2025 were notified on 13 November 2025 and make the Digital Personal Data Protection Act, 2023 workable. They set the standard for consent notices, the registration and duties of Consent Managers, the baseline security safeguards, breach-reporting timelines, retention and erasure, verifiable parental consent for children, how Data Principals exercise their rights, and the extra duties of Significant Data Fiduciaries. The Board and its machinery are live now; Consent Manager registration opens on 13 November 2026; the core notice, consent and rights obligations apply from 13 May 2027.
Rules notified. The Data Protection Board is established; definitions and its machinery are in force and complaints can be filed.
Consent Manager registration opens under Rule 4, and the penalty machinery begins to operate.
Notice, consent, Data Principal rights, breach reporting, children’s-data and SDF duties all apply.
| Rule | What it governs | Act basis | Applies from |
|---|---|---|---|
| Rule 3 | Content and clarity of the consent notice | Section 5 | 13 May 2027 |
| Rule 4 | Registration and duties of Consent Managers | Section 6(9) | 13 Nov 2026 |
| Rule 6 | Reasonable security safeguards | Section 8(5) | 13 May 2027 |
| Rule 7 | Breach intimation to the Board and Data Principals | Section 8(6) | 13 May 2027 |
| Rule 8 | Retention limits and erasure | Section 8(7) | 13 May 2027 |
| Rule 10 | Verifiable parental consent for children | Section 9 | 13 May 2027 |
| Rule 11 | How Data Principals exercise their rights | Sections 11-14 | 13 May 2027 |
| Rule 12 | Extra duties of Significant Data Fiduciaries | Section 10 | 13 May 2027 |
| Rules 14-15 | Cross-border transfer restrictions | Section 16 | By notification |
| Rules 16-22 | Functioning of the Data Protection Board | Chapters V-VII | 13 Nov 2025 |
When you rely on consent, the notice you show is the legal document that makes that consent valid. Rule 3 says it must stand on its own, in clear and plain language, so a person can understand exactly what they are agreeing to before they agree. A link to a long, general privacy policy is not, by itself, the Rule 3 notice.
Go deeper: Section 5 · How to write a privacy notice · Consent management guide
Full guide: the DPDP Consent Manager: role, Rule 4 registration, obligations and how it differs from a CMP.
A Consent Manager is a statutory, Board-registered intermediary that lets a Data Principal give, review, manage and withdraw consent across many Data Fiduciaries from a single dashboard. Rule 4 and its Schedule set the conditions to register: an interoperable platform, fit-and-proper control, and duties to act in the Data Principal’s interest and keep auditable records. It is not a cookie tool, a consent-management platform (CMP) or a CRM field; it is a regulated role in the tradition of India’s Account Aggregator framework.
| Consent Manager | CMP / cookie tool | CRM field | |
|---|---|---|---|
| What it is | A regulated intermediary | Software you deploy | A field in your database |
| Registered with the Board | Yes, required | No | No |
| Works across companies | Yes, interoperable | No, per-site | No, per-company |
| Acts for the person | Yes, by duty | No | No |
Go deeper: Consent Manager (glossary) · Section 6
Every Data Fiduciary must protect the personal data it holds with reasonable security safeguards. This duty is not deferred in spirit, it underpins everything else, and a failure to take reasonable safeguards carries the single highest penalty in the Act. In practice the Rules point to a baseline you should be able to evidence.
| Safeguard | What it does |
|---|---|
| Encryption or masking | Protects data at rest and in transit so a leak is not immediately usable |
| Access controls | Least-privilege access so only the right people reach personal data |
| Logging and monitoring | Records who did what, so events can be detected and investigated |
| Backups and continuity | Lets you restore data and keep operating after an incident |
| Processor obligations | Contractual security terms binding anyone who processes data for you |
| Breach detection | The ability to notice and reconstruct a breach when it happens |
A failure of reasonable security safeguards is the one breach that can attract a penalty of up to ₹250 crore, decided by the Board after inquiry. Treat security as the floor, not a later phase.
Go deeper: Section 8
When you become aware of a personal data breach, two clocks start. You must tell the affected Data Principals, in plain language, and you must tell the Data Protection Board, first with the essential facts and then with a fuller account within the window the Rules set. Because the trigger is awareness, your ability to detect and reconstruct an incident matters as much as the notice itself.
Go deeper: Section 8 · The breach notification rule
The default is simple: keep personal data only while the purpose it was collected for is still live, then erase it, unless a law requires you to retain it. On top of that, the Rules require certain large, consumer-facing classes of Data Fiduciary to erase personal data after a defined period of user inactivity, after giving the person advance notice.
Go deeper: Data retention (glossary) · Section 8
Before processing the data of a child, defined as anyone under 18, you must obtain verifiable parental consent using reliable signals of identity and age, and you must not track children, monitor their behaviour, or direct advertising at them. Rule 10 does not mandate a single government method such as DigiLocker; it asks for due diligence appropriate to the context. The Fourth Schedule relaxes some checks for specified classes, such as certain health and education services, but not the core duty to protect children.
Go deeper: Children’s data (glossary) · Section 9
The Rules require you to publish an easy, usable way for people to exercise their rights, with readable timelines for your response. DPDP creates a right to access information, not a GDPR-style right to an explanation of automated decisions.
| Right | What it lets a person do | How you enable it |
|---|---|---|
| Access | Get a summary of their data and how it is processed | A request channel that queries your systems |
| Correction | Fix, complete or update inaccurate data | An edit and verification workflow |
| Erasure | Have data deleted when it is no longer needed | Deletion that reaches every store and processor |
| Grievance | Raise a complaint and get a response | A named channel with a response SLA |
| Nomination | Appoint someone to act on their behalf | A way to register and honour a nominee |
Go deeper: Section 11 (access) · Section 12 (correction and erasure)
The Central Government can designate an organisation a Significant Data Fiduciary based on the volume and sensitivity of the data it processes and the risk it poses. An SDF carries extra duties on top of every other rule on this page.
Go deeper: SDF (glossary) · Section 10 · Who qualifies as an SDF
DPDP takes a relatively open stance: personal data may generally be transferred outside India, but the Central Government may restrict transfers to specified countries or territories, and certain classes of data or Data Fiduciary may face additional conditions. Sectoral rules, such as the Reserve Bank of India’s directions in financial services, can impose stricter localisation on top of DPDP.
Go deeper: Cross-border transfer (glossary) · Section 16
The remaining Rules set up how the Data Protection Board of India works: a digital-first regulator that receives complaints, conducts inquiries, and can impose penalties after due process. Its decisions can be appealed. The Board and its core machinery are already live as of 13 November 2025.
Go deeper: Browse the full Act, Chapters V-VII
Take the free readiness check and get a prioritised view of your gaps in about two minutes.
Check where you stand →The Rules sit on top of the Act and feed straight into how you prepare. These pages take it further.
This page summarises the DPDP Rules, 2025 in plain language for general understanding. It is not legal advice. For the authoritative text, refer to the Rules as notified in the Gazette of India and the Digital Personal Data Protection Act, 2023.