Home / DPDP Rules 2025
G.S.R. 846(E) · 13 Nov 2025 · MeitY

The DPDP Rules 2025

The Act says what to do. The Rules say how to do it, whom to notify by when, and in what format. MeitY notified 22 Rules on 13 November 2025 after a ten-month consultation window. They come into force in three phases spread over 18 months, so the answer to "is this binding on me today" depends on which rule you're asking about.

Verified 8 Sep 2026 Gazette G.S.R. 846(E) 12 min read 18-month clock may shorten

01Not all 22 Rules are live today. Here's the phasing.

13 November 2025 · Rules 1, 2 and 17 to 21 in force.

These are the operational and Board-adjacent rules that had to work from day one. Rule 1 is the short title. Rule 2 lists definitions used across the Rules. Rules 17 to 21 cover the Board's proceedings, the search-cum-selection committee for Board appointments, the terms and conditions of service of the Chairperson and Members, salary and allowances, and the appellate mechanism before the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).

14 November 2026 · Rule 4 in force. Consent Manager registration opens.

Rule 4 sets the eligibility, registration, and conduct standards for Consent Managers under Section 2(g). The one-year gap between notification and effect exists so the Data Protection Board can be seated and can process the first tranche of registrations. Any organisation intending to operate a Consent Manager platform should file within the first 90 days.

14 May 2027 · Rules 3, 5 to 16, 22 and 23 in force. The substantive core.

This is the eighteen-month deadline every industry commentary treats as the DPDP compliance line. Rule 3 (consent notice format), Rule 5 (Data Fiduciary processing under the State), Rule 6 (security safeguards), Rule 7 (breach notification), Rule 8 (retention), Rule 9 (contact information for the Data Fiduciary), Rule 10 (verifiable parental consent), Rule 11 (persons with disabilities), Rule 12 (SDF obligations), Rule 13 (algorithm due diligence), Rule 14 (Data Principal rights), Rule 15 (cross-border transfer), Rule 16 (research exemptions), Rule 22 (Board procedure), Rule 23 (Rules review).

MeitY has floated a proposal to shorten this to twelve months, which would move the deadline to 13 November 2026. The proposal has not been notified. If it is, every substantive Rule below shifts to that date.

02All 22 Rules

# Rule In force
1Short title and commencement. The Rules may be called the Digital Personal Data Protection Rules, 2025.13 Nov 2025
2Definitions. Interpretation of terms used across the Rules.13 Nov 2025
3Consent notice. Contents and format of the notice under Section 5, in English and the 22 Eighth Schedule languages on request.14 May 2027
4Consent Manager registration. Eligibility, registration, and conduct standards.14 Nov 2026
5Processing by the State. Conditions where the State or its instrumentalities process personal data for a subsidy, benefit, service, certificate, licence or permit.14 May 2027
6Reasonable security safeguards. The minimum measures a Data Fiduciary must take to protect personal data.14 May 2027
7Personal data breach notification. Form, content and timelines for notifying the Board and affected Data Principals.14 May 2027
8Retention limits. Erasure of personal data after the purpose has been served or consent withdrawn.14 May 2027
9Contact information. Publication of the DPO or an authorised person for grievance handling and Data Principal enquiries.14 May 2027
10Verifiable parental consent. Mechanics of verifying that consent for a child's data comes from the parent or lawful guardian.14 May 2027
11Persons with disabilities. Verifiable guardian consent for persons with disabilities where a lawful guardian is appointed.14 May 2027
12SDF additional obligations. India-resident DPO, annual DPIA, annual independent audit, targeted localisation.14 May 2027
13Algorithm due diligence. SDFs must verify algorithmic software does not pose a risk to Data Principals' rights.14 May 2027
14Data Principal rights. How to request access, correction, erasure, nomination and grievance redress; timelines.14 May 2027
15Cross-border transfer. The negative-list mechanism for restricting transfers outside India.14 May 2027
16Research, archival and statistical exemptions. Conditions under which Section 17(2)(b) exemption applies.14 May 2027
17Board proceedings. The manner in which the Data Protection Board conducts proceedings.13 Nov 2025
18Search-cum-selection committee. Composition and process for recommending Chairperson and Member appointments.13 Nov 2025
19Terms and conditions of Board Members. Tenure, resignation, removal.13 Nov 2025
20Salary and allowances. Compensation of Chairperson and Members.13 Nov 2025
21Appeals to TDSAT. Procedure for appealing a Board order to the Telecom Disputes Settlement and Appellate Tribunal.13 Nov 2025
22Manner of publication. How the Board publishes orders and directions.14 May 2027

Rule numbering follows the Gazette Notification G.S.R. 846(E) dated 13 November 2025. Some private-sector guides count a "Rule 23" as the Rules review clause. Reference the underlying Gazette PDF for the authoritative numbering.

03The Rules that change how you operate

Rule 3

Consent notice format

Notice must be clear and plain, in English by default, in the 22 Eighth Schedule languages on request. Must state the personal data collected, the purpose, and how to exercise rights including withdrawal.

Rule 7

Breach notification

Notify the Board and each affected Data Principal. Rule 7 prescribes the form and the timeline. This is separate from the CERT-In 6-hour reporting obligation.

Rule 8

Retention limits

Erase personal data when the purpose is served or consent is withdrawn. Data Fiduciaries must publish their retention schedule where a specific one applies.

Rule 12

SDF obligations

India-resident DPO, annual DPIA, annual audit, and Rule 12(4) targeted localisation of specific data categories. Rule 13 adds algorithm due diligence. See Sec. 10.

Ready to comply with the substantive Rules? dcomply ships 27 modules that map 1:1 to Rules 3 to 16, including the Consent Management Rule 3 stack, Breach Notification Rule 7, and Retention Rule 8.