The DPDP Rules 2025
The Act says what to do. The Rules say how to do it, whom to notify by when, and in what format. MeitY notified 22 Rules on 13 November 2025 after a ten-month consultation window. They come into force in three phases spread over 18 months, so the answer to "is this binding on me today" depends on which rule you're asking about.
01Not all 22 Rules are live today. Here's the phasing.
13 November 2025 · Rules 1, 2 and 17 to 21 in force.
These are the operational and Board-adjacent rules that had to work from day one. Rule 1 is the short title. Rule 2 lists definitions used across the Rules. Rules 17 to 21 cover the Board's proceedings, the search-cum-selection committee for Board appointments, the terms and conditions of service of the Chairperson and Members, salary and allowances, and the appellate mechanism before the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).
14 November 2026 · Rule 4 in force. Consent Manager registration opens.
Rule 4 sets the eligibility, registration, and conduct standards for Consent Managers under Section 2(g). The one-year gap between notification and effect exists so the Data Protection Board can be seated and can process the first tranche of registrations. Any organisation intending to operate a Consent Manager platform should file within the first 90 days.
14 May 2027 · Rules 3, 5 to 16, 22 and 23 in force. The substantive core.
This is the eighteen-month deadline every industry commentary treats as the DPDP compliance line. Rule 3 (consent notice format), Rule 5 (Data Fiduciary processing under the State), Rule 6 (security safeguards), Rule 7 (breach notification), Rule 8 (retention), Rule 9 (contact information for the Data Fiduciary), Rule 10 (verifiable parental consent), Rule 11 (persons with disabilities), Rule 12 (SDF obligations), Rule 13 (algorithm due diligence), Rule 14 (Data Principal rights), Rule 15 (cross-border transfer), Rule 16 (research exemptions), Rule 22 (Board procedure), Rule 23 (Rules review).
MeitY has floated a proposal to shorten this to twelve months, which would move the deadline to 13 November 2026. The proposal has not been notified. If it is, every substantive Rule below shifts to that date.
02All 22 Rules
| # | Rule | In force |
|---|---|---|
1 | Short title and commencement. The Rules may be called the Digital Personal Data Protection Rules, 2025. | 13 Nov 2025 |
2 | Definitions. Interpretation of terms used across the Rules. | 13 Nov 2025 |
3 | Consent notice. Contents and format of the notice under Section 5, in English and the 22 Eighth Schedule languages on request. | 14 May 2027 |
4 | Consent Manager registration. Eligibility, registration, and conduct standards. | 14 Nov 2026 |
5 | Processing by the State. Conditions where the State or its instrumentalities process personal data for a subsidy, benefit, service, certificate, licence or permit. | 14 May 2027 |
6 | Reasonable security safeguards. The minimum measures a Data Fiduciary must take to protect personal data. | 14 May 2027 |
7 | Personal data breach notification. Form, content and timelines for notifying the Board and affected Data Principals. | 14 May 2027 |
8 | Retention limits. Erasure of personal data after the purpose has been served or consent withdrawn. | 14 May 2027 |
9 | Contact information. Publication of the DPO or an authorised person for grievance handling and Data Principal enquiries. | 14 May 2027 |
10 | Verifiable parental consent. Mechanics of verifying that consent for a child's data comes from the parent or lawful guardian. | 14 May 2027 |
11 | Persons with disabilities. Verifiable guardian consent for persons with disabilities where a lawful guardian is appointed. | 14 May 2027 |
12 | SDF additional obligations. India-resident DPO, annual DPIA, annual independent audit, targeted localisation. | 14 May 2027 |
13 | Algorithm due diligence. SDFs must verify algorithmic software does not pose a risk to Data Principals' rights. | 14 May 2027 |
14 | Data Principal rights. How to request access, correction, erasure, nomination and grievance redress; timelines. | 14 May 2027 |
15 | Cross-border transfer. The negative-list mechanism for restricting transfers outside India. | 14 May 2027 |
16 | Research, archival and statistical exemptions. Conditions under which Section 17(2)(b) exemption applies. | 14 May 2027 |
17 | Board proceedings. The manner in which the Data Protection Board conducts proceedings. | 13 Nov 2025 |
18 | Search-cum-selection committee. Composition and process for recommending Chairperson and Member appointments. | 13 Nov 2025 |
19 | Terms and conditions of Board Members. Tenure, resignation, removal. | 13 Nov 2025 |
20 | Salary and allowances. Compensation of Chairperson and Members. | 13 Nov 2025 |
21 | Appeals to TDSAT. Procedure for appealing a Board order to the Telecom Disputes Settlement and Appellate Tribunal. | 13 Nov 2025 |
22 | Manner of publication. How the Board publishes orders and directions. | 14 May 2027 |
Rule numbering follows the Gazette Notification G.S.R. 846(E) dated 13 November 2025. Some private-sector guides count a "Rule 23" as the Rules review clause. Reference the underlying Gazette PDF for the authoritative numbering.
03The Rules that change how you operate
Consent notice format
Notice must be clear and plain, in English by default, in the 22 Eighth Schedule languages on request. Must state the personal data collected, the purpose, and how to exercise rights including withdrawal.
Breach notification
Notify the Board and each affected Data Principal. Rule 7 prescribes the form and the timeline. This is separate from the CERT-In 6-hour reporting obligation.
Retention limits
Erase personal data when the purpose is served or consent is withdrawn. Data Fiduciaries must publish their retention schedule where a specific one applies.
SDF obligations
India-resident DPO, annual DPIA, annual audit, and Rule 12(4) targeted localisation of specific data categories. Rule 13 adds algorithm due diligence. See Sec. 10.