DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
✓ Notified 13 November 2025 · Updated June 2026

DPDP Rules 2025 — Complete Compliance Guide for Indian Businesses

23 Rules. 7 Schedules. 18-month window. ₹250 crore penalty exposure. Everything your business needs to know and do — in plain language.

23
Rules in Force
7
Schedules
18 mo
Compliance Window
₹250Cr
Max Penalty/Breach
May 2027
Enforcement Deadline

Quick Answer

What are the DPDP Rules 2025? The Digital Personal Data Protection Rules 2025 are the operational regulations under India's DPDP Act 2023, notified by MeitY on 13 November 2025. They comprise 23 rules and 7 schedules covering consent, security safeguards, breach notification (72 hours), data retention, children's data (verifiable parental consent), Significant Data Fiduciary obligations, and the Data Protection Board of India. Core business obligations apply 18 months after notification — the enforcement deadline is May 2027 — with penalties reaching ₹250 crore per violation.

On This Page

  1. What Are the DPDP Rules 2025?
  2. 18-Month Implementation Timeline
  3. Rule-by-Rule Breakdown & Action Steps
  4. Penalties & Enforcement
  5. Sector-Specific Obligations
  6. DPDP Rules 2025 vs GDPR vs IT Act 2000
  7. Your 8-Step Compliance Checklist
  8. Free DPDP Compliance Tools

What Are the DPDP Rules 2025?

The Digital Personal Data Protection Rules 2025 (DPDP Rules) are the subsidiary legislation issued under the Digital Personal Data Protection Act 2023 (DPDP Act). They were notified by the Ministry of Electronics and Information Technology (MeitY) in the Official Gazette on 13 November 2025 — two years after the parent Act received Presidential assent on 11 August 2023.

Where the DPDP Act set out broad principles — consent, purpose limitation, data principal rights, security obligations — the DPDP Rules translate those principles into specific, operational requirements. They specify exactly what a privacy notice must contain, how quickly a breach must be reported, what security controls must be in place, and how children's data must be protected.

The Rules comprise 23 rules and 7 schedules. The gazette notification was preceded by a draft published on 3 January 2025 that drew over 6,900 public inputs through consultations in Delhi, Mumbai, Bengaluru, Hyderabad, Kolkata, Guwahati, and Chennai. The final Rules reflect those inputs.

Who do the DPDP Rules apply to? Any entity — company, startup, government body, or individual — that processes digital personal data of Indian residents, whether based in India or overseas. There is no revenue threshold or size exemption under the Rules as currently notified. Every organisation that runs a website with a contact form, an app with user accounts, or an employee database is covered.

18-Month Implementation Timeline

The DPDP Rules do not come into force all at once. MeitY designed a phased rollout to give organisations time to build compliance infrastructure:

NOW

13 November 2025 — Immediate Effect (Rules 1, 2, 17–21)

Data Protection Board constitution and appointment process begins. Definitions come into force. All digital processes mandated. Appoint your Grievance Officer now — this obligation is immediate, not deferred.

12M

November 2026 — Consent Manager Registration (Rule 4)

Entities wishing to operate as Consent Managers must apply to the Data Protection Board. Minimum net worth of ₹2 crore required. Consent Manager ecosystem begins forming.

18M

May 2027 — Full Enforcement Begins (Rules 3, 5–16, 22–23)

All core obligations kick in: consent notices, security safeguards, breach reporting, children's data consent, data retention and erasure, data principal rights, DPIAs for SDFs, and cross-border transfer restrictions. This is the hard enforcement deadline — penalties begin here.

The 18 months will pass faster than organisations expect. Data inventory alone typically takes 4–8 weeks. Privacy notice rewrites require legal review. Consent mechanism redesign requires IT sprints. Vendor DPA negotiations can take months. The most prepared organisations began in Q1 2026. If you have not started, the window is closing.

Rule-by-Rule Breakdown & Action Steps

Below is a plain-language translation of each material Rule — what it requires, and what your business must actually do before May 2027.

RULE 3 — EFFECTIVE MAY 2027

Notice & Consent — What Your Privacy Notice Must Contain

Before collecting any personal data, a Data Fiduciary must provide a notice that is self-contained, clear, and plain — not buried in terms of service. The notice must specifically state:

Notice must be available in English and in any of the 22 scheduled languages as requested by the data principal.

Action required: Rewrite your Privacy Notice and all consent banners/pop-ups before May 2027. Generic boilerplate will not survive a Board inquiry. → Privacy Notice Generator · → Check if your existing policy is compliant
RULE 4 — EFFECTIVE NOVEMBER 2026

Consent Managers — A New Regulated Intermediary

Rule 4 creates a new category of registered intermediary — the Consent Manager — that helps individuals give, manage, review, and withdraw consent across multiple platforms from a single interface. Think of it as a privacy dashboard that spans all apps a user interacts with.

Action required: Assess whether integrating with a Consent Manager will simplify your multi-touchpoint consent management. Organisations collecting consent via website, app, WhatsApp, and offline forms should evaluate this now. → Consent Manager Readiness Check
RULE 6 — EFFECTIVE MAY 2027

Security Safeguards — Six Minimum Technical Controls Required

Every Data Fiduciary must implement "reasonable security safeguards" to prevent breaches. Unlike many laws that leave "reasonable" undefined, Rule 6 specifies exactly what is required:

Most Indian SMEs currently lack centralised access logging and tokenisation — these are the two most common compliance gaps identified in readiness assessments.

Action required: Commission a technical security audit against these six controls. Implement gaps before May 2027. For large data processors, tokenisation and log retention are the highest-effort items. → Security & SDF Assessment · → Breach Response Readiness
RULE 7 — EFFECTIVE MAY 2027

Data Breach Notification — 72 Hours to Board, Immediate to Individuals

This is one of the most operationally demanding rules. On becoming aware of a personal data breach, a Data Fiduciary must simultaneously:

Critical difference from GDPR: Under India's DPDP Rules, every personal data breach triggers the notification duty — there is no "low risk" threshold that exempts smaller incidents. Under GDPR, individual notification is only required for "high risk" breaches.

Action required: Build a documented Incident Response Plan with a 72-hour Board notification capability. This requires pre-drafted notification templates, a clear internal escalation chain, and breach classification criteria defined before an incident occurs. → Breach Notification Generator · → Breach Response Workflow
RULE 8 — EFFECTIVE MAY 2027

Data Retention & Erasure — Sector-Specific Timelines

Rule 8 introduces mandatory retention limits for large-scale Data Fiduciaries via the Third Schedule:

Scenario from the Rules: A user purchases an e-book and then deletes their account. The platform must still retain the transaction data (order details, payment information, logs) for at least one year for accountability purposes, even though the account is closed.

Action required: Map every data category to a retention period. Build automated deletion workflows and 48-hour notification triggers for inactive accounts. This is a significant engineering lift for platforms with large legacy databases. → Data Retention Schedule Builder
RULES 10 & 11 — EFFECTIVE MAY 2027

Children's Data & Persons with Disabilities — Verifiable Consent Required

Rule 10 imposes the most demanding consent requirements in the entire DPDP framework:

Exemptions exist for healthcare, safety, and educational processing (Fourth Schedule). For example: a clinical establishment may track a child's vital signs for healthcare; an educational institution may track location for safety.

Rule 11 applies similar verification requirements for legal guardians of persons with certain disabilities (autism, cerebral palsy, severe multiple disabilities), requiring court certification or designated authority confirmation before processing their data.

Action required: If your platform has any child users — gaming, edtech, social, parenting apps — you must implement age verification and parental consent flows before May 2027. This is a complex technical implementation. Start now. → Children's Data Compliance Guide
RULE 13 — EFFECTIVE MAY 2027

Significant Data Fiduciaries — Annual DPIA and Audit Mandatory

The Central Government may designate certain organisations as Significant Data Fiduciaries (SDFs) based on the volume and sensitivity of data processed, risk to data principals, or national security implications. SDFs face enhanced obligations under Rule 13:

Action required: Assess whether your organisation may be designated an SDF. Indicators include: processing data of 10M+ individuals, handling sensitive data (health, financial, biometric), or operating critical digital infrastructure. Begin building DPIA capability now. → SDF Assessment Tool · → DPIA Builder
RULE 14 — EFFECTIVE MAY 2027

Data Principal Rights — 90-Day Grievance Response

Every Data Fiduciary must establish and publish a mechanism for data principals to exercise their rights:

Action required: Appoint a Grievance Officer immediately (this is already in force). Build a rights request process — even a dedicated email address with a 90-day tracking system is a valid starting point. → Rights Portal Setup · → DSAR Tracker · → Grievance Officer Kit
RULE 15 — EFFECTIVE MAY 2027

Cross-Border Data Transfers — Government Approval Required

Personal data may leave India's borders only when the destination country or territory has been specifically approved by the Central Government. This is a significant departure from GDPR's adequacy-based model:

The government has not yet published its approved country list — this list is expected before the May 2027 enforcement deadline. Organisations should begin mapping all international data flows now so they can assess which require approval.

Action required: Identify every international data flow — AWS/Azure region, analytics vendors, offshore teams, group company data sharing. Prepare to either localise data storage or seek government approval for each flow. → Cross-Border Transfer Guide

Penalties & Enforcement

The Data Protection Board of India has the power to investigate violations and impose financial penalties. The penalty structure under the DPDP Act 2023 is graduated by violation type:

₹250 Cr
Failure to implement security safeguards leading to a breach, or failure to notify individuals of a breach
₹200 Cr
Violation of children's data obligations — processing child data without verifiable parental consent (Rule 10)
₹200 Cr
Failure to notify the Data Protection Board of a breach within the required timeline (Rule 7)
₹150 Cr
Violation of additional obligations for Significant Data Fiduciaries (Rule 13)
₹50 Cr
Violation of consent notice requirements or failure to maintain a Grievance Officer (Rules 3, 14)
₹10,000
Failure to maintain accuracy of personal data at data principal's request

What factors does the Board consider? Severity and nature of the violation, duration, type of personal data involved, number of data principals affected, whether the fiduciary gained any benefit from the violation, whether remedial action was taken, and prior violations. Prompt voluntary disclosure and remediation are treated as mitigating factors.

When does enforcement begin? The Data Protection Board is expected to be constituted by late 2026. Early enforcement focus will likely be on large-scale consumer data breaches and children's data violations — the highest-penalty categories with the most public visibility.

Use the DPDP Penalty Calculator to estimate your organisation's maximum penalty exposure based on your data processing activities.

Sector-Specific Obligations Under DPDP Rules 2025

While the DPDP Rules 2025 apply universally, certain sectors face elevated obligations or specific compliance challenges. Click your sector below:

💻

IT & Software Companies

Dual role: Fiduciary for own employees and users; Processor for client data. DPAs with every client are mandatory.

🏥

Healthcare & Hospitals

Health data is the highest-risk category. Explicit patient consent, multilingual notices, and a patient rights portal required.

💳

Fintech & BFSI

Financial + KYC + Aadhaar data. 72-hour breach reporting is operationally critical. Strict access control mandatory.

☁️

SaaS Platforms

Two compliance tracks: Fiduciary for own users; Processor for customer data processed through the platform.

📋

BPO / KPO Companies

Data Processor obligations. Must process only under documented client instructions. Security audits required.

🛒

E-Commerce Platforms

3-year inactivity erasure for 20M+ user platforms (Rule 8, Schedule 3). Complex retention workflows needed.

🎓

Education & EdTech

Verifiable parental consent for all students under 18. Age verification implementation required before May 2027.

🏭

Manufacturing

Employee biometric and CCTV consent, supply chain vendor DPAs, and HR data retention schedules.

🛡️

Insurance & IT Vendors

IRDAI + DPDP dual compliance. Health data, KYC, and TPA data all require explicit consent frameworks.

📊

CA & Audit Firms

Become a DPDP compliance partner. Earn 15% referral commission on all client projects. Partner with NitiBharat.

DPDP Rules 2025 vs GDPR vs IT Act 2000

If your organisation already complies with GDPR or the old IT Act SPDI Rules, here is what changes under DPDP Rules 2025:

AspectDPDP Rules 2025EU GDPRIT Act 2000 (SPDI Rules)
ScopeDigital personal data of Indian residents (anywhere)All personal data of EU residents (anywhere)Sensitive personal data only (6 defined categories)
Consent StandardFree, specific, informed, unconditional, unambiguousFreely given, specific, informed, unambiguousReasonable security practices — no consent standard
Breach NotificationImmediate to individuals; 72hr to Board; ALL breaches72hr to authority; individuals only for "high risk" breachesNo mandatory notification requirement
Max Penalty₹250 crore (~€27M) per violation€20M or 4% of global annual turnover₹5 crore
Rights Response Time90 days for grievances1 month (extendable to 3 months)30 days for access requests
DPO Required?Only for Significant Data FiduciariesFor high-risk controllers and large processorsNot required
Children's AgeUnder 18 — verifiable parental consentUnder 16 (member states may lower to 13)Not addressed
Cross-Border TransfersGovernment-approved countries only (list pending)Adequacy decisions / SCCs / BCRsNo restriction
Data LocalisationSpecified categories (to be notified) must stay in IndiaNo blanket localisation requirementNo localisation requirement

The most important difference: India's DPDP Rules require breach notification to every affected individual for all breaches, not just high-risk ones. This is a significantly higher operational standard than GDPR and means organisations need automated breach-triggered notification capabilities, not just manual processes. → Full DPDP vs GDPR comparison | → DPDP vs IT Act comparison

Your 8-Step DPDP Rules 2025 Compliance Checklist

Use this checklist to audit where your organisation stands today. Every item must be complete before May 2027:

Use our DPDP Implementation Tracker to monitor progress across all 8 steps and generate a board-ready status report.

Free DPDP Rules 2025 Compliance Tools

NitiBharat has built India's largest suite of DPDP compliance tools — free and paid — to help organisations navigate every aspect of the Rules:

DPDP Readiness Score →
Score 0–100 across 7 compliance dimensions. Free.
Applicability Checker →
Does the DPDP Act 2023 apply to your business? Free.
Penalty Calculator →
Estimate your maximum penalty exposure. Free.
Deadline Countdown →
Days until the May 2027 enforcement date. Free.
Policy Checker →
Validate your Privacy Policy against Rule 3. Free.
Compliance Checklist →
8-step checklist with progress tracking. Free.
Compliance Calendar →
All DPDP deadlines and milestones. Free.
Maturity Assessment →
Level 1–5 privacy maturity rating. Free.
Compliance ROI Calculator →
Justify your compliance investment. Free.
Vendor Risk Scorecard →
Assess third-party data compliance. ₹1,499.
DPIA Builder →
Data Protection Impact Assessment tool. ₹1,499.
Privacy Policy Generator →
Full DPDP-compliant policy document. ₹2,499.

Need Expert Help Before May 2027?

Get a professional DPDP Readiness Assessment — a structured evaluation of your compliance posture with a gap analysis, risk heatmap, and 90-day action plan. Fixed price. No retainers.

Book a Free Consultation Take the Free Score First →
Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
DPDP Rules 2025 Gap Analysis ReportDPDP Rules 2025 vs DPDP Act 2023: What Changed and…DPDP Vendor DPA ChecklistBPO Employee Monitoring DPDP Compliance CheckerSee all Reference & Checklists tools →📝 What Rights Do Individuals Have DPDP📝 DPDP for Recruitment Staffing