The DPDP Rules 2025 were notified on 13 November 2025 as G.S.R. 846(E), and they are what turn India’s Digital Personal Data Protection Act, 2023 into something you can actually be held to. The Rules do not all commence at once: rule 1 splits them across three dates, and the two that matter to most organizations are 13 November 2026 and 13 May 2027.
This guide sets out what the DPDP Rules 2025 require, which obligation starts when, and what a data fiduciary should have finished before each deadline.

The DPDP Rules 2025 commencement timetable
Rule 1 is short and decisive. Rules 1, 2 and 17 to 21 came into force on publication. Rule 4 comes into force one year after publication. Rules 3, 5 to 16, 22 and 23 come into force eighteen months after publication. Measured from 13 November 2025, that gives:
| Date | Rules in force | What it covers |
|---|---|---|
| 13 November 2025 | 1, 2, 17–21 | Definitions and the constitution and functioning of the Data Protection Board |
| 13 November 2026 | 4 | Registration and obligations of Consent Managers |
| 13 May 2027 | 3, 5–16, 22, 23 | Notice, security safeguards, breach intimation, retention, children’s data, Significant Data Fiduciary duties, data principal rights, transfers |
The eighteen-month tranche is where the substantive compliance burden sits. It is also the tranche people misread as “we have until 2027 to start”, which is the wrong conclusion — the work in it is systems work, not policy work.
What the DPDP Rules 2025 require of a data fiduciary
Notice that stands on its own (rule 3)
The notice must be presented and understandable independently of any other information the data fiduciary makes available. In plain language it has to give, at minimum, an itemized description of the personal data and the specified purposes, together with a description of the goods, services or uses enabled by the processing. It must also give the communication link and any other means by which the individual can withdraw consent — with an ease comparable to giving it — exercise their rights, and complain to the Board.
“Itemized” is the operative word. A notice that says “we collect personal information to improve our services” does not meet rule 3.
Security safeguards with a floor (rule 6)
Rule 6 is unusual among privacy laws in specifying a minimum set rather than only a reasonableness test. A data fiduciary must protect personal data by, at minimum:
- securing personal data through encryption, obfuscation, masking or virtual tokens mapped to that data;
- controlling access to the computer resources used by the fiduciary or its processor;
- maintaining visibility of access through logs, monitoring and review, so unauthorized access can be detected, investigated and remediated;
- keeping reasonable measures for continued processing if confidentiality, integrity or availability is compromised, such as backups;
- retaining those logs and the personal data for one year unless another law says otherwise;
- including appropriate security provisions in the contract with each data processor; and
- maintaining technical and organizational measures to ensure the safeguards are actually observed.
Breach intimation, twice over (rule 7)
On becoming aware of a personal data breach, the data fiduciary must inform each affected data principal without delay, in concise, clear and plain language, describing the breach’s nature, extent and timing, the consequences relevant to that individual, the mitigations implemented, the safety measures the individual can take, and a contact who can answer questions.
The Board is told twice: without delay, a description of the breach including nature, extent, timing, location and likely impact; then within seventy-two hours, updated and detailed information, the broad facts and circumstances, the measures implemented or proposed, and any findings about who caused it. The 72-hour clock can be extended only on a written request that the Board allows.
Erasure and the Third Schedule (rule 8)
Specified classes of data fiduciary must erase personal data once the specified purpose is deemed no longer served. The Third Schedule sets that period at three years for e-commerce entities with at least two crore registered users, online gaming intermediaries with at least fifty lakh registered users, and social media intermediaries with at least two crore registered users — measured from the individual’s last approach or the commencement of the Rules, whichever is latest. At least forty-eight hours before erasure, the individual must be told it is coming.
Significant Data Fiduciary duties (rule 13)
Once every twelve months from designation, a Significant Data Fiduciary must undertake a Data Protection Impact Assessment and an audit, and have the person carrying them out furnish a report of significant observations to the Board. It must also exercise due diligence to verify that technical measures including algorithmic software do not pose a risk to data principals’ rights, and observe any restriction the Central Government specifies on transferring particular categories of personal data and its traffic data outside India.
Rights, response times and contacts (rules 9 and 14)
Every data fiduciary must publish the business contact information of its Data Protection Officer, if applicable, or of a person who can answer questions about processing — and repeat it in every response to a rights request. The means of making a rights request must be published, nomination must be supported, and the grievance redressal system must respond within a reasonable period not exceeding ninety days.
What to do before each DPDP Rules 2025 deadline
Before 13 November 2026. Rule 4 is narrow — it governs who may register as a Consent Manager and what they must do. If you intend to be one, the registration conditions in Part A of the First Schedule and the obligations in Part B are the entire task. If you do not, the date still matters: it is when a compliant consent-collection route becomes available to build against.
Before 13 May 2027. This is the real programme. In rough order of lead time:
- Data inventory. You cannot write an itemized notice without knowing what you collect, so the record of processing comes first.
- Notice and consent rebuild. Independent notice, itemized data, purpose-specific, with withdrawal as easy as consent.
- Logging and retention. Rule 6 requires one year of logs and personal data; rule 8 requires deletion after the specified period. Those two pull in opposite directions and need designing together.
- Breach runbook. A 72-hour detailed report to the Board is not achievable without a rehearsed process, named owners and a template.
- Processor contracts. Rule 6(1)(f) makes security terms a contractual requirement, so the paper has to be re-papered.
- Children’s data. Verifiable parental consent under rules 10 and 11, with “adult” defined as eighteen years or over.
The penalties under the Act give the ordering some weight: up to ₹250 crore for failure to maintain reasonable security safeguards, up to ₹200 crore for failing to notify a breach or for breaching obligations relating to children, and up to ₹50 crore for other contraventions.
Frequently asked questions
When do the DPDP Rules 2025 actually bite?
13 May 2027 for most substantive obligations, 13 November 2026 for the Consent Manager rule, and immediately for the Board’s own constitution and procedure.
Is there a 72-hour breach deadline?
Yes, but only for the second, detailed intimation to the Data Protection Board. The first intimation to the Board, and the intimation to every affected individual, is “without delay”.
Does DPDP require data localization?
Not generally. Rule 15 allows transfers outside India subject to requirements the Central Government may specify about making data available to foreign States. A localization restriction can be imposed on a Significant Data Fiduciary for specified categories under rule 13(4).
Who is a Significant Data Fiduciary?
One notified as such by the Central Government, or included in a notified class. The additional duties in rule 13 — annual DPIA and audit, algorithmic due diligence, transfer restrictions — apply from that designation.
How does this compare with GDPR?
The shape is familiar but the details are not interchangeable. The 72-hour clock runs to the regulator’s detailed report rather than the first notification, the minimum security measures are enumerated, and there is a hard one-year log retention floor that GDPR has no equivalent of.
Where this leaves you
The DPDP Rules 2025 are more prescriptive than the Act suggested they would be, and the eighteen-month runway is aimed squarely at engineering work: itemized notices, enumerated safeguards, a one-year log floor, scheduled erasure with advance warning, and a breach process that can produce a detailed report to a regulator inside three days. Start with the inventory, because every other obligation is derived from it, and treat 13 May 2027 as the date the systems have to be finished, not the date the project starts.
References
- Digital Personal Data Protection Rules, 2025 — G.S.R. 846(E), Gazette of India, 13 November 2025.
- Digital Personal Data Protection Act, 2023 — the Act the Rules give effect to.
More on privacy compliance
- The DPDP Rules 2025 — you are here
- India’s DPDP Act explained
- Records of processing activities
- Personal data breach notification
The policies, registers and breach templates behind this are in the DPDP Act Toolkit, or start with the free ISO templates.