How do the DPDP Rules 2025 differ from the DPDP Act 2023? The DPDP Act 2023 sets out the broad legal framework — rights, obligations, and maximum penalties — while the DPDP Rules 2025 operationalise it with exact formats, timelines, criteria, and mechanisms that businesses must actually implement. For example, the Act requires a consent notice; the Rules (Rule 3) specify the exact language, itemised purpose format, multilingual requirements, and the precise mechanism to withdraw consent. Without reading the Rules alongside the Act, compliance is impossible.
The Act creates the law. The Rules make it operational. Here's exactly what the DPDP Rules 2025 add, specify, or restrict — across 8 critical compliance areas — compared to what the Act alone says.
Section 5: Data Fiduciary must give a notice before or at time of consent, in plain language, stating the personal data to be collected and the purpose of processing. Notice must be accessible in multiple languages.
Rule 3: Specifies exact notice format — itemised list of each category of personal data, itemised list of each purpose, hyperlink or button to each purpose's description, and a dedicated mechanism (not buried in settings) to withdraw consent per purpose. Notice must be in English and each scheduled language the Data Principal prefers.
A generic "we collect your data for service purposes" privacy policy no longer qualifies. You must rebuild consent notices with per-purpose itemisation, per-category data lists, and a standalone withdrawal mechanism — not just a toggle buried in account settings.
Section 6(1): Introduces the concept of a "Consent Manager" — a registered entity through which Data Principals can give, manage, review, and withdraw consent across multiple Data Fiduciaries. No further operational detail provided in the Act itself.
Rules 4–6: Full Consent Manager framework — registration requirements, minimum net worth criteria (₹12 Cr), interoperability standards so a Data Principal can use any Consent Manager to interact with any Fiduciary, liability allocation between Consent Manager and Fiduciary, technology standards for consent artefact storage, and audit requirements. Registration deadline: 13 November 2026.
If you plan to operate as a Consent Manager (a new regulated business model), registration is mandatory by 13 November 2026. As a Data Fiduciary, you must integrate with registered Consent Managers and accept consent artefacts they issue — you cannot refuse a valid artefact from any registered Consent Manager.
Section 8(7): Data Fiduciary must erase personal data — and instruct Data Processors to erase it — once the purpose for which it was collected is fulfilled or the Data Principal withdraws consent, unless retention is required by law. No specific timelines prescribed in the Act.
Rule 8: Prescribes a deemed-retention period of 3 years from the date the Data Principal last interacted with the Fiduciary for purposes such as providing goods or services, unless the Data Principal actively confirms continued use. Once no interaction for 3 years, erasure must happen within 30 days of the deemed-period end, unless other law mandates longer retention.
You cannot hold customer data indefinitely "just in case." Any user who has not interacted with your platform for 3 years must have their data erased within 30 days of that period ending. You need automated inactivity monitoring and deletion workflows — this cannot be done manually at scale.
Section 10: Central Government may designate certain Data Fiduciaries as "Significant Data Fiduciaries" (SDFs) based on volume of personal data processed, sensitivity, national security risk, public order risk, or sovereignty risk. SDFs face additional obligations: DPIAs, DPO appointment, Data Auditor engagement.
Rules 12–13: Specifies quantitative criteria for SDF designation — processing personal data of more than 10 lakh Data Principals, or sensitive personal data of more than 1 lakh Data Principals. Defines DPO eligibility (senior management, India-based), DPIA scope and timeline (annual, or on material change), and Data Auditor independence requirements. SDFs must publish compliance reports.
If you serve more than 10 lakh users, you likely qualify as an SDF. Begin building DPIA capabilities, identifying a DPO-eligible senior manager, and selecting an independent Data Auditor now — these take 6–12 months to operationalise properly. Do not wait for formal designation notification.
Section 16: Central Government may restrict transfer of personal data to countries or territories outside India by notification. No blanket localisation mandate — whitelist approach implied. Transfer to non-restricted countries is permitted subject to conditions. Sector-specific regulations (RBI, SEBI, IRDAI) continue to apply separately.
Rule 16: Establishes the whitelist of permitted countries (to be notified separately). Conditions for transfer include: Data Processing Agreements (DPAs) must provide equivalent data protection to DPDP standards; Data Fiduciary remains accountable for overseas processor compliance; Fiduciary must be able to facilitate Data Principal rights requests even for data held overseas. Sensitive personal data transfers face additional conditions.
Map all cross-border data flows immediately — including third-party SaaS, cloud providers (AWS, GCP, Azure), offshore development teams, and analytics platforms. Update vendor DPAs to include DPDP-equivalent standards. You remain accountable for your offshore processors even if the processing happens outside India.
Sections 18–27: Establishes the Data Protection Board of India (DPBI) as a quasi-judicial body. Powers include investigating complaints, conducting inquiries, issuing directions, and imposing penalties up to ₹250 Cr. Digital-first complaint mechanism. Appeals to Telecom Disputes Settlement & Appellate Tribunal (TDSAT).
Rules 17–22: Full complaint process specified — complaint filing portal, mandatory 48-hour acknowledgement, 30-day preliminary examination period, notice to Data Fiduciary, Data Fiduciary response within 21 days, DPBI decision within 6 months of inquiry start. Voluntary undertaking mechanism (allow Fiduciary to settle before formal inquiry). Prescribed form for complaint submission with evidence attachments.
A digital-first complaint portal with prescribed timelines means any user can file a complaint in minutes. You have 21 days to respond once notified. You need an internal escalation process to receive DPBI notices, compile evidence, and respond within deadline — this requires legal and compliance team readiness, not just technical controls.
Section 13: Every Data Fiduciary must designate a Grievance Officer to address Data Principal complaints. Contact details of GO must be published. GO handles complaints before they can be escalated to DPBI. No timeline specified in the Act itself for GO response.
Rule 14: Prescribes mandatory timelines — GO must acknowledge complaint within 48 hours of receipt; GO must resolve (or provide substantive response) within 30 days of receipt. GO must be an individual (not a role or department), India-based for SDFs. Contact mechanism must be accessible from the same interface used to give consent. Failure to meet timelines is a separately penalisable offence.
A "contact us" form with a 90-day SLA no longer qualifies. You need a dedicated GO with a 48-hour acknowledgement and 30-day resolution SLA. Ensure your GO's contact details appear directly in your consent interface — buried in a footer privacy policy is insufficient under the Rules.
Section 9: Verifiable parental consent required before processing personal data of children (under 18). Profiling, tracking, and behavioural advertising targeting children are explicitly prohibited. Age-appropriate design required. Government may notify categories of Data Fiduciaries exempt from parental consent for certain categories of processing.
Rule 11: Specifies age verification mechanism — Data Fiduciary must implement reliable age verification using a virtual token issued by government-backed Digital Locker (DigiLocker or equivalent), or through a Consent Manager with age-verification capability. Parent/guardian identity verification: through same token system. Exemptions: health/education services for children may be exempt if processing is necessary for child's welfare (Rules specify categories).
A self-declared age checkbox or "I confirm I am 18+" toggle does not satisfy the Rules. You must integrate with DigiLocker or a registered Consent Manager's age-verification flow — a significant technical integration. EdTech, gaming, FMCG loyalty programs, and any service accessible to children must prioritise this immediately given the ₹200 Cr penalty exposure.
Assess your organisation's readiness across all DPDP Act and Rules requirements
Complete checklist covering Act + Rules obligations — download as PDF
Calculate your maximum penalty exposure by violation type under the Act
India's data protection regime operates on a two-layer legal architecture. The Digital Personal Data Protection Act 2023 (DPDP Act) — notified on 11 August 2023 — is the primary legislation passed by Parliament. It sets out the fundamental rights of Data Principals, the obligations of Data Fiduciaries and Processors, the structure of the Data Protection Board of India, and the maximum penalty schedule. However, the Act deliberately leaves significant operational detail to delegated legislation.
The DPDP Rules 2025, issued by the Central Government under Section 40 of the Act, fill this operational gap. They specify the exact formats, timelines, criteria, and mechanisms that make the Act's broad principles implementable. Without the Rules, compliance with the Act is impossible — you cannot design a consent notice, register as a Consent Manager, or respond to a DPBI inquiry without the procedural detail the Rules provide.
Most compliance teams spend time reading the Act but underestimate how much the Rules shift the implementation burden. Consider consent: the Act says "give a notice in plain language before collecting data." The Rules say that notice must include an itemised list of every purpose, a hyperlink to each purpose's description, and a standalone withdrawal mechanism accessible from the same interface — not a page buried in account settings. The operational gap between "give a notice" and "itemised, linked, purpose-by-purpose withdrawal in the consent interface" is enormous.
The same pattern repeats across all 8 areas covered in this comparison. The Act creates the obligation; the Rules define what meeting that obligation actually requires in practice.
One of the most significant innovations in the Rules is the Consent Manager framework (Rules 4–6). A Consent Manager is a new type of registered intermediary — similar in concept to an Account Aggregator in the financial sector — that allows a Data Principal to give, manage, review, and withdraw consent across multiple Data Fiduciaries through a single interface.
This creates both a new regulated business opportunity (operating as a Consent Manager) and a new compliance obligation (accepting consent artefacts from any registered Consent Manager). Data Fiduciaries who build proprietary consent management systems must ensure those systems can interoperate with external Consent Managers by the 13 November 2026 deadline.
The Rules make the Significant Data Fiduciary (SDF) designation concrete for the first time. Under the Act, SDF status was a concept with no operational criteria. The Rules set quantitative thresholds: 10 lakh Data Principals for general personal data, or 1 lakh Data Principals for sensitive personal data. Organisations meeting these thresholds should begin preparing for SDF obligations — Data Protection Impact Assessments, Data Protection Officer appointment, and Data Auditor engagement — even before formal designation, as the implementation lead time is significant.
Get our complete 20-page guide covering all 8 comparison areas with implementation checklists, template notices, and a DPDP Rules readiness assessment for your sector.
Free download. No spam. We respond within 1 business day.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.