DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr

Quick Answer

How do the DPDP Rules 2025 differ from the DPDP Act 2023? The DPDP Act 2023 sets out the broad legal framework — rights, obligations, and maximum penalties — while the DPDP Rules 2025 operationalise it with exact formats, timelines, criteria, and mechanisms that businesses must actually implement. For example, the Act requires a consent notice; the Rules (Rule 3) specify the exact language, itemised purpose format, multilingual requirements, and the precise mechanism to withdraw consent. Without reading the Rules alongside the Act, compliance is impossible.

🇮🇳 DPDP Act 2023 DPDP Rules 2025 Updated Jun 2026

DPDP Rules 2025 vs DPDP Act 2023: What Changed and What It Means for Your Business

The Act creates the law. The Rules make it operational. Here's exactly what the DPDP Rules 2025 add, specify, or restrict — across 8 critical compliance areas — compared to what the Act alone says.

Operational Detail (Rules add precise format/mechanism)
New Framework (Rules create full system)
Tiered Obligations (Rules add criteria/thresholds)
Process & Timeline (Rules specify steps/deadlines)
Showing all 8 comparisons

1. Consent Notice

OPERATIONAL DETAIL
📜 DPDP Act 2023

Section 5: Data Fiduciary must give a notice before or at time of consent, in plain language, stating the personal data to be collected and the purpose of processing. Notice must be accessible in multiple languages.

⚙️ DPDP Rules 2025

Rule 3: Specifies exact notice format — itemised list of each category of personal data, itemised list of each purpose, hyperlink or button to each purpose's description, and a dedicated mechanism (not buried in settings) to withdraw consent per purpose. Notice must be in English and each scheduled language the Data Principal prefers.

WHAT THIS MEANS FOR YOUR BUSINESS

A generic "we collect your data for service purposes" privacy policy no longer qualifies. You must rebuild consent notices with per-purpose itemisation, per-category data lists, and a standalone withdrawal mechanism — not just a toggle buried in account settings.

2. Consent Manager

NEW FRAMEWORK
📜 DPDP Act 2023

Section 6(1): Introduces the concept of a "Consent Manager" — a registered entity through which Data Principals can give, manage, review, and withdraw consent across multiple Data Fiduciaries. No further operational detail provided in the Act itself.

⚙️ DPDP Rules 2025

Rules 4–6: Full Consent Manager framework — registration requirements, minimum net worth criteria (₹12 Cr), interoperability standards so a Data Principal can use any Consent Manager to interact with any Fiduciary, liability allocation between Consent Manager and Fiduciary, technology standards for consent artefact storage, and audit requirements. Registration deadline: 13 November 2026.

WHAT THIS MEANS FOR YOUR BUSINESS

If you plan to operate as a Consent Manager (a new regulated business model), registration is mandatory by 13 November 2026. As a Data Fiduciary, you must integrate with registered Consent Managers and accept consent artefacts they issue — you cannot refuse a valid artefact from any registered Consent Manager.

3. Data Retention

OPERATIONAL DETAIL
📜 DPDP Act 2023

Section 8(7): Data Fiduciary must erase personal data — and instruct Data Processors to erase it — once the purpose for which it was collected is fulfilled or the Data Principal withdraws consent, unless retention is required by law. No specific timelines prescribed in the Act.

⚙️ DPDP Rules 2025

Rule 8: Prescribes a deemed-retention period of 3 years from the date the Data Principal last interacted with the Fiduciary for purposes such as providing goods or services, unless the Data Principal actively confirms continued use. Once no interaction for 3 years, erasure must happen within 30 days of the deemed-period end, unless other law mandates longer retention.

WHAT THIS MEANS FOR YOUR BUSINESS

You cannot hold customer data indefinitely "just in case." Any user who has not interacted with your platform for 3 years must have their data erased within 30 days of that period ending. You need automated inactivity monitoring and deletion workflows — this cannot be done manually at scale.

4. Significant Data Fiduciary (SDF)

TIERED OBLIGATIONS
📜 DPDP Act 2023

Section 10: Central Government may designate certain Data Fiduciaries as "Significant Data Fiduciaries" (SDFs) based on volume of personal data processed, sensitivity, national security risk, public order risk, or sovereignty risk. SDFs face additional obligations: DPIAs, DPO appointment, Data Auditor engagement.

⚙️ DPDP Rules 2025

Rules 12–13: Specifies quantitative criteria for SDF designation — processing personal data of more than 10 lakh Data Principals, or sensitive personal data of more than 1 lakh Data Principals. Defines DPO eligibility (senior management, India-based), DPIA scope and timeline (annual, or on material change), and Data Auditor independence requirements. SDFs must publish compliance reports.

WHAT THIS MEANS FOR YOUR BUSINESS

If you serve more than 10 lakh users, you likely qualify as an SDF. Begin building DPIA capabilities, identifying a DPO-eligible senior manager, and selecting an independent Data Auditor now — these take 6–12 months to operationalise properly. Do not wait for formal designation notification.

5. Cross-Border Data Transfers

TIERED OBLIGATIONS
📜 DPDP Act 2023

Section 16: Central Government may restrict transfer of personal data to countries or territories outside India by notification. No blanket localisation mandate — whitelist approach implied. Transfer to non-restricted countries is permitted subject to conditions. Sector-specific regulations (RBI, SEBI, IRDAI) continue to apply separately.

⚙️ DPDP Rules 2025

Rule 16: Establishes the whitelist of permitted countries (to be notified separately). Conditions for transfer include: Data Processing Agreements (DPAs) must provide equivalent data protection to DPDP standards; Data Fiduciary remains accountable for overseas processor compliance; Fiduciary must be able to facilitate Data Principal rights requests even for data held overseas. Sensitive personal data transfers face additional conditions.

WHAT THIS MEANS FOR YOUR BUSINESS

Map all cross-border data flows immediately — including third-party SaaS, cloud providers (AWS, GCP, Azure), offshore development teams, and analytics platforms. Update vendor DPAs to include DPDP-equivalent standards. You remain accountable for your offshore processors even if the processing happens outside India.

6. Data Protection Board (DPB)

NEW FRAMEWORK
📜 DPDP Act 2023

Sections 18–27: Establishes the Data Protection Board of India (DPBI) as a quasi-judicial body. Powers include investigating complaints, conducting inquiries, issuing directions, and imposing penalties up to ₹250 Cr. Digital-first complaint mechanism. Appeals to Telecom Disputes Settlement & Appellate Tribunal (TDSAT).

⚙️ DPDP Rules 2025

Rules 17–22: Full complaint process specified — complaint filing portal, mandatory 48-hour acknowledgement, 30-day preliminary examination period, notice to Data Fiduciary, Data Fiduciary response within 21 days, DPBI decision within 6 months of inquiry start. Voluntary undertaking mechanism (allow Fiduciary to settle before formal inquiry). Prescribed form for complaint submission with evidence attachments.

WHAT THIS MEANS FOR YOUR BUSINESS

A digital-first complaint portal with prescribed timelines means any user can file a complaint in minutes. You have 21 days to respond once notified. You need an internal escalation process to receive DPBI notices, compile evidence, and respond within deadline — this requires legal and compliance team readiness, not just technical controls.

7. Grievance Officer

PROCESS & TIMELINE
📜 DPDP Act 2023

Section 13: Every Data Fiduciary must designate a Grievance Officer to address Data Principal complaints. Contact details of GO must be published. GO handles complaints before they can be escalated to DPBI. No timeline specified in the Act itself for GO response.

⚙️ DPDP Rules 2025

Rule 14: Prescribes mandatory timelines — GO must acknowledge complaint within 48 hours of receipt; GO must resolve (or provide substantive response) within 30 days of receipt. GO must be an individual (not a role or department), India-based for SDFs. Contact mechanism must be accessible from the same interface used to give consent. Failure to meet timelines is a separately penalisable offence.

WHAT THIS MEANS FOR YOUR BUSINESS

A "contact us" form with a 90-day SLA no longer qualifies. You need a dedicated GO with a 48-hour acknowledgement and 30-day resolution SLA. Ensure your GO's contact details appear directly in your consent interface — buried in a footer privacy policy is insufficient under the Rules.

8. Children's Data

OPERATIONAL DETAIL
📜 DPDP Act 2023

Section 9: Verifiable parental consent required before processing personal data of children (under 18). Profiling, tracking, and behavioural advertising targeting children are explicitly prohibited. Age-appropriate design required. Government may notify categories of Data Fiduciaries exempt from parental consent for certain categories of processing.

⚙️ DPDP Rules 2025

Rule 11: Specifies age verification mechanism — Data Fiduciary must implement reliable age verification using a virtual token issued by government-backed Digital Locker (DigiLocker or equivalent), or through a Consent Manager with age-verification capability. Parent/guardian identity verification: through same token system. Exemptions: health/education services for children may be exempt if processing is necessary for child's welfare (Rules specify categories).

WHAT THIS MEANS FOR YOUR BUSINESS

A self-declared age checkbox or "I confirm I am 18+" toggle does not satisfy the Rules. You must integrate with DigiLocker or a registered Consent Manager's age-verification flow — a significant technical integration. EdTech, gaming, FMCG loyalty programs, and any service accessible to children must prioritise this immediately given the ₹200 Cr penalty exposure.

Key DPDP Compliance Deadlines

13 Nov 2026
CONSENT MANAGER REGISTRATION
Entities wishing to operate as Consent Managers must register with the DPBI by this date. Data Fiduciaries must ensure their consent mechanisms are compatible with registered Consent Managers.
13 May 2027
FULL ENFORCEMENT DEADLINE
All DPDP Act and DPDP Rules obligations come into full effect. Non-compliance after this date carries penalties up to ₹250 Cr. All 8 areas in this comparison must be fully implemented.

What you should be doing right now (Jun 2026)

  • Consent notice audit. Benchmark your current consent notices against Rule 3's itemised format requirements. Most notices will need a complete rebuild.
  • Data inventory & retention mapping. Identify all data stores with personal data and map last-interaction dates — you need this to implement the 3-year retention rule (Rule 8).
  • SDF self-assessment. Count unique Data Principals in your systems. If approaching 10 lakh, begin DPO identification and DPIA capability building now.
  • Cross-border transfer mapping. List every third-party tool, cloud service, and offshore team that receives personal data from India — and update their DPAs.
  • Children's data review. If any part of your service is accessible to under-18s, begin DigiLocker integration planning immediately. This has the longest implementation lead time.

Free Tools to Help You Comply

Understanding the DPDP Act vs DPDP Rules: The Two-Layer Framework

India's data protection regime operates on a two-layer legal architecture. The Digital Personal Data Protection Act 2023 (DPDP Act) — notified on 11 August 2023 — is the primary legislation passed by Parliament. It sets out the fundamental rights of Data Principals, the obligations of Data Fiduciaries and Processors, the structure of the Data Protection Board of India, and the maximum penalty schedule. However, the Act deliberately leaves significant operational detail to delegated legislation.

The DPDP Rules 2025, issued by the Central Government under Section 40 of the Act, fill this operational gap. They specify the exact formats, timelines, criteria, and mechanisms that make the Act's broad principles implementable. Without the Rules, compliance with the Act is impossible — you cannot design a consent notice, register as a Consent Manager, or respond to a DPBI inquiry without the procedural detail the Rules provide.

Why the DPDP Rules 2025 Matter More Than the Act for Day-to-Day Compliance

Most compliance teams spend time reading the Act but underestimate how much the Rules shift the implementation burden. Consider consent: the Act says "give a notice in plain language before collecting data." The Rules say that notice must include an itemised list of every purpose, a hyperlink to each purpose's description, and a standalone withdrawal mechanism accessible from the same interface — not a page buried in account settings. The operational gap between "give a notice" and "itemised, linked, purpose-by-purpose withdrawal in the consent interface" is enormous.

The same pattern repeats across all 8 areas covered in this comparison. The Act creates the obligation; the Rules define what meeting that obligation actually requires in practice.

DPDP Rules 2025 and the Consent Manager Ecosystem

One of the most significant innovations in the Rules is the Consent Manager framework (Rules 4–6). A Consent Manager is a new type of registered intermediary — similar in concept to an Account Aggregator in the financial sector — that allows a Data Principal to give, manage, review, and withdraw consent across multiple Data Fiduciaries through a single interface.

This creates both a new regulated business opportunity (operating as a Consent Manager) and a new compliance obligation (accepting consent artefacts from any registered Consent Manager). Data Fiduciaries who build proprietary consent management systems must ensure those systems can interoperate with external Consent Managers by the 13 November 2026 deadline.

How the DPDP Rules 2025 Affect Significant Data Fiduciaries

The Rules make the Significant Data Fiduciary (SDF) designation concrete for the first time. Under the Act, SDF status was a concept with no operational criteria. The Rules set quantitative thresholds: 10 lakh Data Principals for general personal data, or 1 lakh Data Principals for sensitive personal data. Organisations meeting these thresholds should begin preparing for SDF obligations — Data Protection Impact Assessments, Data Protection Officer appointment, and Data Auditor engagement — even before formal designation, as the implementation lead time is significant.

Download the Full DPDP Act vs Rules Comparison Guide

Get our complete 20-page guide covering all 8 comparison areas with implementation checklists, template notices, and a DPDP Rules readiness assessment for your sector.

Free download. No spam. We respond within 1 business day.

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
DPDP Vendor DPA ChecklistDPDP Vendor Training GuideDPDP Voluntary Undertaking (Section 32)CA Firm DPDP Revenue Calculator IndiaSee all Reference & Checklists tools →📝 How Long Can I Keep Personal Data DPDP📝 DPDP for Coworking Flex Space