Back to DPDP Rules
Overview of DPDP Rules, 2025
Comprehensive overview of the Digital Personal Data Protection Rules, 2025 - notification, structure, phased commencement, and relationship with the parent Act.
7 min read
Notification and Commencement
The Digital Personal Data Protection Rules, 2025 were notified on November 13, 2025 via Gazette Notification No. 760. The 23 Rules operationalise the DPDPA, 2023 by providing detailed procedural and substantive requirements for compliance.
Enforcement is staggered into three phases:
• Immediate effect: Rules 1-2 (Short Title and Definitions) and Rules 17-21 (Board provisions)
• After 1 year (~November 14, 2026): Rule 4 (Consent Manager registration)
• After 18 months (~May 14, 2027): Rules 3, 5-16, 22-23 (operational provisions)
This phased approach provides organisations a compliance runway to prepare for operational requirements while the Board's procedural framework takes immediate effect.
Structure of the Rules
The 23 Rules are organised thematically:
Rules 1-2: Preliminary provisions (short title, definitions)
Rule 3: Privacy notice requirements
Rules 4-5: Consent Manager registration and obligations
Rule 6: Security safeguard requirements
Rule 7: Breach notification framework
Rule 8: Data retention thresholds
Rules 9-12: Children's data processing
Rule 13: Significant Data Fiduciary obligations
Rule 14: Grievance redressal mechanism
Rule 15: Cross-border transfer restrictions
Rule 16: Research exemption
Rules 17-21: Procedural framework for the Data Protection Board
Rules 22-23: Miscellaneous provisions
Correlation with the Parent Act
Each Rule directly corresponds to enabling provisions in the DPDPA, 2023:
• Rule 3 (Privacy Notice) -> Section 5 (Notice)
• Rules 4-5 (Consent Managers) -> Section 6 (Consent)
• Rule 6 (Security Safeguards) -> Section 8(5)
• Rule 7 (Breach Notification) -> Section 8(6)
• Rule 8 (Retention) -> Section 8(7)
• Rules 9-12 (Children's Data) -> Section 9
• Rule 13 (SDF Obligations) -> Section 10
• Rule 14 (Grievance) -> Section 13
• Rule 15 (Cross-Border) -> Section 16
• Rule 16 (Research) -> Section 17
• Rules 17-21 (Board) -> Sections 18-26
The Rules cannot exceed the scope of the parent Act - they operationalise and provide procedural detail for the Act's substantive provisions.
Key Regulatory Themes
Several cross-cutting themes emerge from the Rules:
1. Specificity over generality: The Rules provide concrete, measurable requirements (e.g., 72-hour breach report, 90-day grievance resolution, 3-year retention threshold) where the Act used broader language.
2. Technology-neutral approach: While mandating outcomes (encryption, access controls), the Rules generally avoid prescribing specific technologies, allowing organisations flexibility in implementation.
3. Proportionality: Requirements are calibrated to the nature, scope, and risk of processing - smaller entities with lower risk face fewer requirements than SDFs.
4. Phased compliance: The staggered commencement acknowledges the need for organisations to build compliance infrastructure over time.
5. Digital-first enforcement: The Board operates as a digital office, reflecting the Act's focus on digital personal data.
Related Resources
Frequently Asked Questions
On This Page
Quick ResourcesDisclaimer: The information on this page is for educational purposes only and does not constitute legal advice or solicitation.
