Back to DPDP Rules

Overview of DPDP Rules, 2025

Comprehensive overview of the Digital Personal Data Protection Rules, 2025 - notification, structure, phased commencement, and relationship with the parent Act.

7 min read

Notification and Commencement

The Digital Personal Data Protection Rules, 2025 were notified on November 13, 2025 via Gazette Notification No. 760. The 23 Rules operationalise the DPDPA, 2023 by providing detailed procedural and substantive requirements for compliance. Enforcement is staggered into three phases: • Immediate effect: Rules 1-2 (Short Title and Definitions) and Rules 17-21 (Board provisions) • After 1 year (~November 14, 2026): Rule 4 (Consent Manager registration) • After 18 months (~May 14, 2027): Rules 3, 5-16, 22-23 (operational provisions) This phased approach provides organisations a compliance runway to prepare for operational requirements while the Board's procedural framework takes immediate effect.

Structure of the Rules

The 23 Rules are organised thematically: Rules 1-2: Preliminary provisions (short title, definitions) Rule 3: Privacy notice requirements Rules 4-5: Consent Manager registration and obligations Rule 6: Security safeguard requirements Rule 7: Breach notification framework Rule 8: Data retention thresholds Rules 9-12: Children's data processing Rule 13: Significant Data Fiduciary obligations Rule 14: Grievance redressal mechanism Rule 15: Cross-border transfer restrictions Rule 16: Research exemption Rules 17-21: Procedural framework for the Data Protection Board Rules 22-23: Miscellaneous provisions

Correlation with the Parent Act

Each Rule directly corresponds to enabling provisions in the DPDPA, 2023: • Rule 3 (Privacy Notice) -> Section 5 (Notice) • Rules 4-5 (Consent Managers) -> Section 6 (Consent) • Rule 6 (Security Safeguards) -> Section 8(5) • Rule 7 (Breach Notification) -> Section 8(6) • Rule 8 (Retention) -> Section 8(7) • Rules 9-12 (Children's Data) -> Section 9 • Rule 13 (SDF Obligations) -> Section 10 • Rule 14 (Grievance) -> Section 13 • Rule 15 (Cross-Border) -> Section 16 • Rule 16 (Research) -> Section 17 • Rules 17-21 (Board) -> Sections 18-26 The Rules cannot exceed the scope of the parent Act - they operationalise and provide procedural detail for the Act's substantive provisions.

Key Regulatory Themes

Several cross-cutting themes emerge from the Rules: 1. Specificity over generality: The Rules provide concrete, measurable requirements (e.g., 72-hour breach report, 90-day grievance resolution, 3-year retention threshold) where the Act used broader language. 2. Technology-neutral approach: While mandating outcomes (encryption, access controls), the Rules generally avoid prescribing specific technologies, allowing organisations flexibility in implementation. 3. Proportionality: Requirements are calibrated to the nature, scope, and risk of processing - smaller entities with lower risk face fewer requirements than SDFs. 4. Phased compliance: The staggered commencement acknowledges the need for organisations to build compliance infrastructure over time. 5. Digital-first enforcement: The Board operates as a digital office, reflecting the Act's focus on digital personal data.

Frequently Asked Questions

Disclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.