The DPDP Rules 2025,
rule by rule and date by date.
The DPDP Rules 2025 turn India's Digital Personal Data Protection Act into things you have to build: a notice format, security minimums, a 72-hour breach report, erasure clocks, parental consent and a grievance deadline. This is each rule in plain English, with the date it starts to bind. Not legal advice: read the Gazette text with your counsel before you rely on it.
Last updated Published by TryTrustableNot legal advice
The DPDP Rules 2025 are the Digital Personal Data Protection Rules, 2025, made by the Ministry of Electronics and Information Technology (MeitY) under section 40 of the DPDP Act and notified in the Gazette on 13 November 2025 as G.S.R. 846(E). They have 23 rules and seven Schedules and commence in three stages: Rules 1, 2 and 17 to 21 (definitions and the Data Protection Board) on publication; Rule 4 (Consent Managers) on 13 November 2026; and Rules 3, 5 to 16, 22 and 23, which carry almost every duty on businesses, on 13 May 2027.
What are the DPDP Rules 2025?
The Digital Personal Data Protection Act, 2023 sets the duties; it leaves much of the how to rules made under section 40. The DPDP Rules 2025 are those rules. They fix the notice format, the minimum security measures, the breach reporting timeline, when data must be erased, how parental consent is verified, what Significant Data Fiduciaries must do each year, how rights requests and grievances work, and how the Data Protection Board runs. Words the Rules do not define take their meaning from the Act, so the two are read together. The DPDP Act guide covers the Act's obligations; this page is the reference for the Rules.
Written to be useful, not to be legal advice. Verify against the Gazette text and anything the Board or MeitY publishes, with your counsel.
When were the DPDP Rules notified, and where is the Gazette text?
The final Rules were notified by MeitY in the Gazette of India (Extraordinary, Part II, Section 3(i)) as notification G.S.R. 846(E), dated 13 November 2025, and announced through a PIB release on 14 November 2025. They replaced the draft published for consultation as G.S.R. 02(E) on 3 January 2025. The notified text, in Hindi and English, is on the MeitY website. If you search for the DPDP Rules 2023, there are none: the Act is from 2023 and the Rules from 2025.
DPDP Rules timeline: when does each rule apply?
Rule 1 brings the Rules into force in three stages, counted from the day they were published. The Act's own sections were switched on by a separate notification on the same pattern, so the Board exists today but its powers to inquire and penalise for most breaches start on 13 May 2027. Our DPDP regulatory tracker records every change since.
| Date | Rules that commence | What it covers |
|---|---|---|
| 3 January 2025 | Draft only | Draft Rules published as G.S.R. 02(E) for 45 days of objections and suggestions. Not law. |
| 13 November 2025 | Rules 1, 2, 17, 18, 19, 20, 21 | Title and commencement, definitions, and the Data Protection Board: selection of members, their terms, meetings and inquiries, the Board as a digital office, its staff |
| 13 November 2026 | Rule 4 and the First Schedule | Registration and obligations of Consent Managers |
| 13 May 2027 | Rules 3, 5 to 16, 22, 23 | Notice, State processing, security safeguards, breach intimation, retention and erasure, contact details, children and persons with disability, Significant Data Fiduciaries, rights, cross-border transfer, research exemption, appeals, Government calls for information |
From Rule 1(2) to (4), counted from publication in the Gazette on 13 November 2025. One year after is 13 November 2026; eighteen months after is 13 May 2027.
Could the dates move? In January 2026 MeitY consulted on shortening the window for Significant Data Fiduciaries from eighteen months to twelve, which would bring their duties to 13 November 2026. As of our last check on 28 September 2026 no amending notification had been published, so the dates above stand. Large platforms, banks and insurers should plan as if it might happen.
What does each of the 23 DPDP Rules require?
Every rule in one table. The last column is the date it starts to bind.
| Rule | Subject | What it requires | From |
|---|---|---|---|
| 1 | Short title and commencement | Names the Rules and sets the three commencement stages | 13 Nov 2025 |
| 2 | Definitions | Defines user account (including profiles, handles, email address and mobile number), verifiable consent (Rules 10 and 11) and techno-legal measures | 13 Nov 2025 |
| 3 | Notice | A notice that stands on its own; an itemised description of the data; the specified purpose and the goods, services or uses it enables; a link and other means to withdraw consent (as easily as it was given), exercise rights and complain to the Board | 13 May 2027 |
| 4 | Consent Managers | Registration with the Board on the First Schedule conditions; Board may inquire, register or reject with reasons, direct, suspend or cancel | 13 Nov 2026 |
| 5 | State processing for benefits and services | The State and its instrumentalities follow the Second Schedule standards when processing for a subsidy, benefit, service, certificate, licence or permit | 13 May 2027 |
| 6 | Reasonable security safeguards | At minimum: encryption, obfuscation, masking or virtual tokens; access control; logs, monitoring and review; backups for continued processing; logs and data kept one year for investigation; security terms in processor contracts; technical and organisational measures | 13 May 2027 |
| 7 | Personal data breach intimation | Tell each affected person without delay, with five set particulars; tell the Board without delay, then give it a detailed report within 72 hours (or a longer period it allows on a written request) | 13 May 2027 |
| 8 | Retention and erasure | Third Schedule erasure after three years' inactivity for large platforms, with 48 hours' warning; every Data Fiduciary keeps data, traffic data and logs of processing for at least one year | 13 May 2027 |
| 9 | Contact information | Publish the business contact of the DPO, if any, or a person who can answer questions about processing, and give it in every response to a rights request | 13 May 2027 |
| 10 | Verifiable consent for children | Verify that the person consenting as parent is an identifiable adult, using details already held or details or a token from an authorised entity, including a Digital Locker provider | 13 May 2027 |
| 11 | Persons with disability | Verify that a lawful guardian was appointed by a court, designated authority or local level committee | 13 May 2027 |
| 12 | Exemptions for children's data | Classes (Fourth Schedule Part A) and purposes (Part B) exempt from section 9(1) and 9(3), on conditions | 13 May 2027 |
| 13 | Significant Data Fiduciaries | DPIA and audit every twelve months; report of significant observations to the Board; algorithmic due diligence; localisation of data the Government specifies | 13 May 2027 |
| 14 | Rights of Data Principals | Publish how to make a request and what identifier is needed; publish a grievance response period of no more than ninety days; nomination | 13 May 2027 |
| 15 | Transfer outside India | Transfers allowed, subject to requirements the Government sets by order on making data available to a foreign State or entities under its control | 13 May 2027 |
| 16 | Research, archiving, statistics | The Act does not apply to such processing done to the Second Schedule standards | 13 May 2027 |
| 17 | Appointment of Chairperson and Members | Two search-cum-selection committees, one chaired by the Cabinet Secretary (Chairperson), one by the MeitY Secretary (Members) | 13 Nov 2025 |
| 18 | Members' terms of service | Salary and conditions in the Fifth Schedule | 13 Nov 2025 |
| 19 | Board meetings and inquiries | Quorum of one third, majority voting, emergency action by the Chairperson; an inquiry finished within six months, extendable by up to three months at a time | 13 Nov 2025 |
| 20 | Board as a digital office | Proceedings may be run without anyone attending in person | 13 Nov 2025 |
| 21 | Board officers and employees | Appointed with Central Government approval; terms in the Sixth Schedule | 13 Nov 2025 |
| 22 | Appeal to the Appellate Tribunal | Appeals filed digitally, with the fee payable under the TRAI Act, 1997, paid by UPI or another RBI-authorised system | 13 May 2027 |
| 23 | Calling for information | The Government, through the authorised person in the Seventh Schedule, may require information from a Data Fiduciary or intermediary, and may bar disclosure on security grounds | 13 May 2027 |
Paraphrased from the notified text. Read the Gazette wording before relying on any line.
The rules that need systems, not documents
Most of the 23 rules can be met with a policy and a published page. Five cannot.
- Rule 3, notice. The notice has to stand on its own, itemise the data and give a withdrawal route as easy as consent. Proving later what a person saw means storing the notice version and language with each choice. The DPDP consent notice template covers the content.
- Rule 6, security. Logging and monitoring that can detect unauthorised access, backups, and logs kept for a year. These are controls you operate, and evidence you keep.
- Rule 7, breach. Two clocks: without delay to each person and the Board, and a detailed report to the Board within 72 hours. India also has CERT-In's six-hour rule; see CERT-In and DPDP breach reporting compared.
- Rule 8, retention. A one-year floor for processing records and, for the largest platforms, an inactivity erasure job with a 48-hour warning. See DPDP retention and erasure.
- Rule 10, children. A parent verification step before a child's account is created. See DPDP children's data.
Rule 14 is close behind: a published way to make requests, the identifier you need, and a grievance period of no more than ninety days that you actually meet.
What is in the Schedules to the DPDP Rules?
Seven Schedules carry the detail that the rules point to.
| Schedule | Used by | What it contains |
|---|---|---|
| First | Rule 4 | Part A: nine conditions to register as a Consent Manager (Indian company, net worth of at least Rs 2 crore, certified interoperable platform and others). Part B: thirteen obligations once registered |
| Second | Rules 5 and 16 | Standards for State processing under section 7(b) and for research, archiving and statistics: lawful, purpose-limited, minimal, accurate, retained only as needed, secured, accountable |
| Third | Rule 8(1) | Three-year erasure for e-commerce entities and social media intermediaries with at least two crore registered users in India, and online gaming intermediaries with at least fifty lakh |
| Fourth | Rule 12 | Part A: five classes (healthcare, allied healthcare, educational institutions, creches, school transport). Part B: six purposes, such as confirming a user is not a child |
| Fifth | Rule 18 | Board members' salary (Rs 4.5 lakh a month for the Chairperson, Rs 4 lakh for Members), provident fund, travel and other terms |
| Sixth | Rule 21 | Terms for the Board's officers and employees, mainly on deputation |
| Seventh | Rules 8(3) and 23 | Purposes for which the Government may call for information (security of the State, functions under law, assessing whether to notify an SDF) and who may ask |
From the Schedules to the DPDP Rules 2025.
DPDP Rules applicability: who do they apply to?
The Rules apply to whoever the Act applies to: anyone processing digital personal data in India, and anyone outside India processing it in connection with offering goods or services to people in India. Some rules have a narrower audience. Rule 4 binds only registered Consent Managers. Rule 8(1) binds only the three Third Schedule classes. Rule 13 binds only Significant Data Fiduciaries, which the Central Government notifies under section 10; we had found none notified as of 28 September 2026. Rules 5 and 16 concern State processing and research. Rules 17 to 21 govern the Board itself. Check your own position with the DPDP applicability checker and, for SDF exposure, the Significant Data Fiduciary guide.
How TryTrustable helps with the DPDP Rules
The DPDP Act is one of the frameworks modelled in the platform, mapped onto the same control library as ISO 27001, SOC 2 and GDPR. For the rules that touch your website and app, Consent by TryTrustable shows a versioned notice, holds non-essential trackers back until a choice, records each choice with the notice version and language in a tamper-evident ledger, relays withdrawals to your processors with every delivery logged, and puts a privacy-request link on the banner. Rights requests land in a queue with deadlines set by request type. It does not verify parents' identity, is not a registered Consent Manager, and does not make you compliant on its own: your people and processes still do that. The DPDP compliance checklist turns the Rules into a work plan.
The things people ask us
When were the DPDP Rules notified?
On 13 November 2025, when MeitY published them in the Gazette as G.S.R. 846(E). PIB announced them on 14 November 2025. The draft had been published on 3 January 2025 as G.S.R. 02(E).
What is the DPDP Rules effective date?
There are three. Rules 1, 2 and 17 to 21 took effect on 13 November 2025. Rule 4 on Consent Managers takes effect on 13 November 2026. Rules 3, 5 to 16, 22 and 23, which carry the main duties on businesses, take effect on 13 May 2027.
Are the DPDP Rules in force now?
Partly. As of 6 October 2026 only Rules 1, 2 and 17 to 21, about definitions and the Data Protection Board, are in force. Consent Manager registration starts on 13 November 2026, and notice, security, breach, retention, children's data, SDF and rights duties on 13 May 2027.
What is the breach reporting deadline under the DPDP Rules?
Rule 7 requires a Data Fiduciary to tell each affected person and the Board without delay, and to give the Board a detailed report within 72 hours of becoming aware, or a longer period the Board allows on a written request.
Where can I read the DPDP Rules 2025 issued by MeitY?
On the MeitY website, which hosts the Gazette notification G.S.R. 846(E) in Hindi and English. Read the notified text, not the January 2025 draft, which was a consultation version and is not the law.
Get ready for 13 May 2027, not the week before.
Thirty minutes on your notice, consent record, breach clocks and rights queue against the DPDP Rules, with your own site scanned live.