Rules

DPDP Rules 2025 explained: what each rule requires

Audience: founders, compliance owners, product and engineering leads · Last reviewed: October 2026

The Digital Personal Data Protection Rules, 2025 turn the framework in the DPDP Act, 2023 into concrete operating requirements. This guide walks through every rule in order and says, with citations, what each asks of you.

Terms the Rules do not define carry their meaning from the Act (Rule 2(2)), so read each rule with the section it implements.

When each rule comes into force

Rule 1 splits commencement into three phases, all counted from publication in the Official Gazette on 13 November 2025:

PhaseRulesFrom
ImmediateRules 1, 2 and 17 to 21 (definitions and the Data Protection Board)13 November 2025 (Rule 1(2))
One yearRule 4 (Consent Managers)One year after publication, around 13 November 2026 (Rule 1(3))
Eighteen monthsRules 3, 5 to 16, 22 and 23 (most Data Fiduciary duties)Eighteen months after publication, around 13 May 2027 (Rule 1(4))

For how the Act's own sections phase in, see the DPDP law status and timeline.

Rules 2 and 3: definitions and notice

Rule 2 defines a few working terms. A “user account” includes profiles, handles, email addresses and mobile numbers used to access your service (Rule 2(1)(c)). “Verifiable consent” means consent obtained as set out in Rule 10 (children) or Rule 11 (persons with disability who have a lawful guardian) (Rule 2(1)(d)).

Rule 3 sets the content of the notice required by section 5. The notice must be understandable on its own, independent of other information you publish (Rule 3(a)). In clear and plain language it must give, at minimum, an itemised description of the personal data and the specified purpose, with a specific description of the goods, services or uses the processing enables (Rule 3(b)). It must also give a communication link to your website or app, and describe how the person can withdraw consent as easily as she gave it, exercise her rights, and complain to the Board (Rule 3(c)).

Read: how to draft a DPDP privacy notice

Rules 4 and 5: Consent Managers and State processing

Rule 4 lets a person who meets the conditions in Part A of the First Schedule apply to the Board for registration as a Consent Manager (Rule 4(1)). The Board may register or reject the application (Rule 4(2)), and a registered Consent Manager must meet the obligations in Part B of the First Schedule (Rule 4(3)). The Board can direct corrective measures, and can suspend or cancel registration after a hearing (Rule 4(4) and 4(5)). See our Consent Managers guide for the full conditions.

Rule 5 applies when the State or its instrumentalities process personal data to provide a subsidy, benefit, service, certificate, licence or permit under section 7(b). That processing must follow the standards in the Second Schedule (Rule 5(1)).

Rules 6 and 7: security and breach intimation

Rule 6 lists the minimum “reasonable security safeguards” behind section 8(5): encryption, obfuscation, masking or tokenisation; access control; logging, monitoring and review; continuity measures such as backups; retention of logs and personal data for one year to support detection and investigation; security clauses in Data Processor contracts; and technical and organisational measures to make it all effective (Rule 6(1)(a) to (g)). Our security safeguards guide turns this into a control checklist.

Rule 7 sets the form of breach intimation under section 8(6). Each affected Data Principal must be told, without delay and through her user account or a registered contact mode, what happened, the likely consequences for her, what you are doing to mitigate, what she can do to protect herself, and who to contact (Rule 7(1)). The Board must receive a description without delay (Rule 7(2)(a)) and, within seventy-two hours of becoming aware, or a longer period the Board allows on written request, a detailed report covering causes, mitigation, findings about who caused the breach, remedial steps and the notifications sent to Data Principals (Rule 7(2)(b)).

Read: DPDP incident response playbook

Rules 8 and 9: retention and contact details

Rule 8 fixes when a purpose is deemed no longer served for three classes in the Third Schedule: e-commerce entities with at least two crore registered users in India, online gaming intermediaries with at least fifty lakh, and social media intermediaries with at least two crore. For them, personal data must be erased three years after the user last approached them or exercised her rights, or after the Rules commenced, whichever is latest, except for account access and stored virtual tokens (Rule 8(1), Third Schedule). The user must be warned at least forty-eight hours before erasure (Rule 8(2)). Separately, every Data Fiduciary must keep personal data, traffic data and processing logs for at least one year for the purposes in the Seventh Schedule, then erase them unless another law requires longer (Rule 8(3)).

Rule 9 requires you to publish prominently on your website or app the business contact information of your Data Protection Officer (if applicable) or a person who can answer questions about processing, and to mention it in every response to a rights request.

Rules 10 to 12: children and persons with disability

Rule 10 requires technical and organisational measures to obtain verifiable consent of a parent before processing a child's personal data, with due diligence that the parent is an identifiable adult. You can rely on reliable identity and age details you already hold, or on details or a virtual token voluntarily provided, including through a Digital Locker service provider (Rule 10(1) and 10(2)). Rule 11 requires due diligence that a person claiming to be the lawful guardian of a person with disability was appointed by a court, a designated authority or a local level committee (Rule 11(1)); see our guide to guardian consent. Rule 12 and the Fourth Schedule exempt listed classes (such as clinical establishments and educational institutions) and listed purposes from section 9(1) and 9(3), each subject to conditions.

Read: children's data rules under DPDP

Rules 13 to 16: SDFs, rights, transfers and research

Rule 13 requires a Significant Data Fiduciary to carry out a Data Protection Impact Assessment and an audit once in every twelve months (Rule 13(1)), have the assessor report significant observations to the Board (Rule 13(2)), check that its algorithmic software does not pose a risk to Data Principals' rights (Rule 13(3)), and keep personal data specified by the Central Government, with its traffic data, inside India (Rule 13(4)).

Rule 14 requires Data Fiduciaries and Consent Managers to publish how people can make rights requests and what identifiers they need (Rule 14(1)), to publish a grievance response period not exceeding ninety days and build systems to meet it (Rule 14(3)), and to let people nominate one or more individuals (Rule 14(4)).

Rule 15 allows transfer of personal data outside India subject to any requirements the Central Government specifies by general or special order about making data available to a foreign State or entities it controls. Our cross-border transfer guide explains how this sits with section 16. Rule 16 takes processing necessary for research, archiving or statistical purposes outside the Act, provided it follows the Second Schedule standards.

Rules 17 to 23: the Board, appeals and information requests

Rules 17 to 21 cover the Board's appointments, service terms, meetings and digital functioning. The key line for businesses is Rule 19(9): the Board must complete an inquiry within six months of receiving the intimation or complaint, extendable in writing by up to three months at a time. Rule 22 requires appeals to the Appellate Tribunal to be filed digitally, with a fee matching TRAI Act appeals; the sixty-day appeal window is in section 29(2). Rule 23 lets the Central Government, through authorised persons in the Seventh Schedule, call for information from Data Fiduciaries or intermediaries (Rule 23(1)).

Next, turn this map into tasks with owners using the DPDP compliance checklist.

Frequently asked questions

When did the DPDP Rules 2025 come into force?

They were notified on 13 November 2025. Rules 1, 2 and 17 to 21 took effect that day, Rule 4 takes effect one year later, and Rules 3, 5 to 16, 22 and 23 take effect eighteen months after publication (Rule 1(2) to 1(4)).

What is the 72-hour rule under the DPDP Rules?

Rule 7(2)(b) requires a Data Fiduciary to send the Board a detailed report on a personal data breach within seventy-two hours of becoming aware of it, or within a longer period the Board allows on a written request. A shorter initial description must go to the Board without delay under Rule 7(2)(a).

Do the DPDP Rules set a deadline for answering grievances?

Rule 14(3) requires Data Fiduciaries and Consent Managers to publish a response period for grievances that does not exceed ninety days, and to put technical and organisational measures in place to meet it.

Do the Rules require all personal data to stay in India?

No general localisation rule applies. Rule 15 allows transfers subject to requirements the Central Government may specify. Rule 13(4) separately requires Significant Data Fiduciaries to keep personal data specified by the Central Government, and its traffic data, within India.

Practical next step

Take the phase-three rules (Rules 3 and 5 to 16) and give each one an owner and a due date before the eighteen-month mark. Then run a quick external check of your public pages.

Advertisement