23 Rules. 7 Schedules. 18-month window. ₹250 crore penalty exposure. Everything your business needs to know and do — in plain language.
The Digital Personal Data Protection Rules 2025 (DPDP Rules) are the subsidiary legislation issued under the Digital Personal Data Protection Act 2023 (DPDP Act). They were notified by the Ministry of Electronics and Information Technology (MeitY) in the Official Gazette on 13 November 2025 — two years after the parent Act received Presidential assent on 11 August 2023.
Where the DPDP Act set out broad principles — consent, purpose limitation, data principal rights, security obligations — the DPDP Rules translate those principles into specific, operational requirements. They specify exactly what a privacy notice must contain, how quickly a breach must be reported, what security controls must be in place, and how children's data must be protected.
The Rules comprise 23 rules and 7 schedules. The gazette notification was preceded by a draft published on 3 January 2025 that drew over 6,900 public inputs through consultations in Delhi, Mumbai, Bengaluru, Hyderabad, Kolkata, Guwahati, and Chennai. The final Rules reflect those inputs.
Who do the DPDP Rules apply to? Any entity — company, startup, government body, or individual — that processes digital personal data of Indian residents, whether based in India or overseas. There is no revenue threshold or size exemption under the Rules as currently notified. Every organisation that runs a website with a contact form, an app with user accounts, or an employee database is covered.
The DPDP Rules do not come into force all at once. MeitY designed a phased rollout to give organisations time to build compliance infrastructure:
Data Protection Board constitution and appointment process begins. Definitions come into force. All digital processes mandated. Appoint your Grievance Officer now — this obligation is immediate, not deferred.
Entities wishing to operate as Consent Managers must apply to the Data Protection Board. Minimum net worth of ₹2 crore required. Consent Manager ecosystem begins forming.
All core obligations kick in: consent notices, security safeguards, breach reporting, children's data consent, data retention and erasure, data principal rights, DPIAs for SDFs, and cross-border transfer restrictions. This is the hard enforcement deadline — penalties begin here.
The 18 months will pass faster than organisations expect. Data inventory alone typically takes 4–8 weeks. Privacy notice rewrites require legal review. Consent mechanism redesign requires IT sprints. Vendor DPA negotiations can take months. The most prepared organisations began in Q1 2026. If you have not started, the window is closing.
Below is a plain-language translation of each material Rule — what it requires, and what your business must actually do before May 2027.
Before collecting any personal data, a Data Fiduciary must provide a notice that is self-contained, clear, and plain — not buried in terms of service. The notice must specifically state:
Notice must be available in English and in any of the 22 scheduled languages as requested by the data principal.
Rule 4 creates a new category of registered intermediary — the Consent Manager — that helps individuals give, manage, review, and withdraw consent across multiple platforms from a single interface. Think of it as a privacy dashboard that spans all apps a user interacts with.
Every Data Fiduciary must implement "reasonable security safeguards" to prevent breaches. Unlike many laws that leave "reasonable" undefined, Rule 6 specifies exactly what is required:
Most Indian SMEs currently lack centralised access logging and tokenisation — these are the two most common compliance gaps identified in readiness assessments.
This is one of the most operationally demanding rules. On becoming aware of a personal data breach, a Data Fiduciary must simultaneously:
Critical difference from GDPR: Under India's DPDP Rules, every personal data breach triggers the notification duty — there is no "low risk" threshold that exempts smaller incidents. Under GDPR, individual notification is only required for "high risk" breaches.
Rule 8 introduces mandatory retention limits for large-scale Data Fiduciaries via the Third Schedule:
Scenario from the Rules: A user purchases an e-book and then deletes their account. The platform must still retain the transaction data (order details, payment information, logs) for at least one year for accountability purposes, even though the account is closed.
Rule 10 imposes the most demanding consent requirements in the entire DPDP framework:
Exemptions exist for healthcare, safety, and educational processing (Fourth Schedule). For example: a clinical establishment may track a child's vital signs for healthcare; an educational institution may track location for safety.
Rule 11 applies similar verification requirements for legal guardians of persons with certain disabilities (autism, cerebral palsy, severe multiple disabilities), requiring court certification or designated authority confirmation before processing their data.
The Central Government may designate certain organisations as Significant Data Fiduciaries (SDFs) based on the volume and sensitivity of data processed, risk to data principals, or national security implications. SDFs face enhanced obligations under Rule 13:
Every Data Fiduciary must establish and publish a mechanism for data principals to exercise their rights:
Personal data may leave India's borders only when the destination country or territory has been specifically approved by the Central Government. This is a significant departure from GDPR's adequacy-based model:
The government has not yet published its approved country list — this list is expected before the May 2027 enforcement deadline. Organisations should begin mapping all international data flows now so they can assess which require approval.
The Data Protection Board of India has the power to investigate violations and impose financial penalties. The penalty structure under the DPDP Act 2023 is graduated by violation type:
What factors does the Board consider? Severity and nature of the violation, duration, type of personal data involved, number of data principals affected, whether the fiduciary gained any benefit from the violation, whether remedial action was taken, and prior violations. Prompt voluntary disclosure and remediation are treated as mitigating factors.
When does enforcement begin? The Data Protection Board is expected to be constituted by late 2026. Early enforcement focus will likely be on large-scale consumer data breaches and children's data violations — the highest-penalty categories with the most public visibility.
Use the DPDP Penalty Calculator to estimate your organisation's maximum penalty exposure based on your data processing activities.
While the DPDP Rules 2025 apply universally, certain sectors face elevated obligations or specific compliance challenges. Click your sector below:
Dual role: Fiduciary for own employees and users; Processor for client data. DPAs with every client are mandatory.
Health data is the highest-risk category. Explicit patient consent, multilingual notices, and a patient rights portal required.
Financial + KYC + Aadhaar data. 72-hour breach reporting is operationally critical. Strict access control mandatory.
Two compliance tracks: Fiduciary for own users; Processor for customer data processed through the platform.
Data Processor obligations. Must process only under documented client instructions. Security audits required.
3-year inactivity erasure for 20M+ user platforms (Rule 8, Schedule 3). Complex retention workflows needed.
Verifiable parental consent for all students under 18. Age verification implementation required before May 2027.
Employee biometric and CCTV consent, supply chain vendor DPAs, and HR data retention schedules.
IRDAI + DPDP dual compliance. Health data, KYC, and TPA data all require explicit consent frameworks.
Become a DPDP compliance partner. Earn 15% referral commission on all client projects. Partner with NitiBharat.
If your organisation already complies with GDPR or the old IT Act SPDI Rules, here is what changes under DPDP Rules 2025:
| Aspect | DPDP Rules 2025 | EU GDPR | IT Act 2000 (SPDI Rules) |
|---|---|---|---|
| Scope | Digital personal data of Indian residents (anywhere) | All personal data of EU residents (anywhere) | Sensitive personal data only (6 defined categories) |
| Consent Standard | Free, specific, informed, unconditional, unambiguous | Freely given, specific, informed, unambiguous | Reasonable security practices — no consent standard |
| Breach Notification | Immediate to individuals; 72hr to Board; ALL breaches | 72hr to authority; individuals only for "high risk" breaches | No mandatory notification requirement |
| Max Penalty | ₹250 crore (~€27M) per violation | €20M or 4% of global annual turnover | ₹5 crore |
| Rights Response Time | 90 days for grievances | 1 month (extendable to 3 months) | 30 days for access requests |
| DPO Required? | Only for Significant Data Fiduciaries | For high-risk controllers and large processors | Not required |
| Children's Age | Under 18 — verifiable parental consent | Under 16 (member states may lower to 13) | Not addressed |
| Cross-Border Transfers | Government-approved countries only (list pending) | Adequacy decisions / SCCs / BCRs | No restriction |
| Data Localisation | Specified categories (to be notified) must stay in India | No blanket localisation requirement | No localisation requirement |
The most important difference: India's DPDP Rules require breach notification to every affected individual for all breaches, not just high-risk ones. This is a significantly higher operational standard than GDPR and means organisations need automated breach-triggered notification capabilities, not just manual processes. → Full DPDP vs GDPR comparison | → DPDP vs IT Act comparison
Use this checklist to audit where your organisation stands today. Every item must be complete before May 2027:
Use our DPDP Implementation Tracker to monitor progress across all 8 steps and generate a board-ready status report.
NitiBharat has built India's largest suite of DPDP compliance tools — free and paid — to help organisations navigate every aspect of the Rules:
Get a professional DPDP Readiness Assessment — a structured evaluation of your compliance posture with a gap analysis, risk heatmap, and 90-day action plan. Fixed price. No retainers.
Book a Free Consultation Take the Free Score First →One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.