DPDP Rules 2025

The DPDP Rules 2025,
rule by rule and date by date.

The DPDP Rules 2025 turn India's Digital Personal Data Protection Act into things you have to build: a notice format, security minimums, a 72-hour breach report, erasure clocks, parental consent and a grievance deadline. This is each rule in plain English, with the date it starts to bind. Not legal advice: read the Gazette text with your counsel before you rely on it.

G.S.R. 846(E)13 Nov 202513 Nov 202613 May 202723 rules7 Schedules

Last updated Published by TryTrustableNot legal advice

Short answer

The DPDP Rules 2025 are the Digital Personal Data Protection Rules, 2025, made by the Ministry of Electronics and Information Technology (MeitY) under section 40 of the DPDP Act and notified in the Gazette on 13 November 2025 as G.S.R. 846(E). They have 23 rules and seven Schedules and commence in three stages: Rules 1, 2 and 17 to 21 (definitions and the Data Protection Board) on publication; Rule 4 (Consent Managers) on 13 November 2026; and Rules 3, 5 to 16, 22 and 23, which carry almost every duty on businesses, on 13 May 2027.

01

What are the DPDP Rules 2025?

The Digital Personal Data Protection Act, 2023 sets the duties; it leaves much of the how to rules made under section 40. The DPDP Rules 2025 are those rules. They fix the notice format, the minimum security measures, the breach reporting timeline, when data must be erased, how parental consent is verified, what Significant Data Fiduciaries must do each year, how rights requests and grievances work, and how the Data Protection Board runs. Words the Rules do not define take their meaning from the Act, so the two are read together. The DPDP Act guide covers the Act's obligations; this page is the reference for the Rules.

Written to be useful, not to be legal advice. Verify against the Gazette text and anything the Board or MeitY publishes, with your counsel.

02

When were the DPDP Rules notified, and where is the Gazette text?

The final Rules were notified by MeitY in the Gazette of India (Extraordinary, Part II, Section 3(i)) as notification G.S.R. 846(E), dated 13 November 2025, and announced through a PIB release on 14 November 2025. They replaced the draft published for consultation as G.S.R. 02(E) on 3 January 2025. The notified text, in Hindi and English, is on the MeitY website. If you search for the DPDP Rules 2023, there are none: the Act is from 2023 and the Rules from 2025.

03

DPDP Rules timeline: when does each rule apply?

Rule 1 brings the Rules into force in three stages, counted from the day they were published. The Act's own sections were switched on by a separate notification on the same pattern, so the Board exists today but its powers to inquire and penalise for most breaches start on 13 May 2027. Our DPDP regulatory tracker records every change since.

DateRules that commenceWhat it covers
3 January 2025Draft onlyDraft Rules published as G.S.R. 02(E) for 45 days of objections and suggestions. Not law.
13 November 2025Rules 1, 2, 17, 18, 19, 20, 21Title and commencement, definitions, and the Data Protection Board: selection of members, their terms, meetings and inquiries, the Board as a digital office, its staff
13 November 2026Rule 4 and the First ScheduleRegistration and obligations of Consent Managers
13 May 2027Rules 3, 5 to 16, 22, 23Notice, State processing, security safeguards, breach intimation, retention and erasure, contact details, children and persons with disability, Significant Data Fiduciaries, rights, cross-border transfer, research exemption, appeals, Government calls for information

From Rule 1(2) to (4), counted from publication in the Gazette on 13 November 2025. One year after is 13 November 2026; eighteen months after is 13 May 2027.

Could the dates move? In January 2026 MeitY consulted on shortening the window for Significant Data Fiduciaries from eighteen months to twelve, which would bring their duties to 13 November 2026. As of our last check on 28 September 2026 no amending notification had been published, so the dates above stand. Large platforms, banks and insurers should plan as if it might happen.

04

What does each of the 23 DPDP Rules require?

Every rule in one table. The last column is the date it starts to bind.

RuleSubjectWhat it requiresFrom
1Short title and commencementNames the Rules and sets the three commencement stages13 Nov 2025
2DefinitionsDefines user account (including profiles, handles, email address and mobile number), verifiable consent (Rules 10 and 11) and techno-legal measures13 Nov 2025
3NoticeA notice that stands on its own; an itemised description of the data; the specified purpose and the goods, services or uses it enables; a link and other means to withdraw consent (as easily as it was given), exercise rights and complain to the Board13 May 2027
4Consent ManagersRegistration with the Board on the First Schedule conditions; Board may inquire, register or reject with reasons, direct, suspend or cancel13 Nov 2026
5State processing for benefits and servicesThe State and its instrumentalities follow the Second Schedule standards when processing for a subsidy, benefit, service, certificate, licence or permit13 May 2027
6Reasonable security safeguardsAt minimum: encryption, obfuscation, masking or virtual tokens; access control; logs, monitoring and review; backups for continued processing; logs and data kept one year for investigation; security terms in processor contracts; technical and organisational measures13 May 2027
7Personal data breach intimationTell each affected person without delay, with five set particulars; tell the Board without delay, then give it a detailed report within 72 hours (or a longer period it allows on a written request)13 May 2027
8Retention and erasureThird Schedule erasure after three years' inactivity for large platforms, with 48 hours' warning; every Data Fiduciary keeps data, traffic data and logs of processing for at least one year13 May 2027
9Contact informationPublish the business contact of the DPO, if any, or a person who can answer questions about processing, and give it in every response to a rights request13 May 2027
10Verifiable consent for childrenVerify that the person consenting as parent is an identifiable adult, using details already held or details or a token from an authorised entity, including a Digital Locker provider13 May 2027
11Persons with disabilityVerify that a lawful guardian was appointed by a court, designated authority or local level committee13 May 2027
12Exemptions for children's dataClasses (Fourth Schedule Part A) and purposes (Part B) exempt from section 9(1) and 9(3), on conditions13 May 2027
13Significant Data FiduciariesDPIA and audit every twelve months; report of significant observations to the Board; algorithmic due diligence; localisation of data the Government specifies13 May 2027
14Rights of Data PrincipalsPublish how to make a request and what identifier is needed; publish a grievance response period of no more than ninety days; nomination13 May 2027
15Transfer outside IndiaTransfers allowed, subject to requirements the Government sets by order on making data available to a foreign State or entities under its control13 May 2027
16Research, archiving, statisticsThe Act does not apply to such processing done to the Second Schedule standards13 May 2027
17Appointment of Chairperson and MembersTwo search-cum-selection committees, one chaired by the Cabinet Secretary (Chairperson), one by the MeitY Secretary (Members)13 Nov 2025
18Members' terms of serviceSalary and conditions in the Fifth Schedule13 Nov 2025
19Board meetings and inquiriesQuorum of one third, majority voting, emergency action by the Chairperson; an inquiry finished within six months, extendable by up to three months at a time13 Nov 2025
20Board as a digital officeProceedings may be run without anyone attending in person13 Nov 2025
21Board officers and employeesAppointed with Central Government approval; terms in the Sixth Schedule13 Nov 2025
22Appeal to the Appellate TribunalAppeals filed digitally, with the fee payable under the TRAI Act, 1997, paid by UPI or another RBI-authorised system13 May 2027
23Calling for informationThe Government, through the authorised person in the Seventh Schedule, may require information from a Data Fiduciary or intermediary, and may bar disclosure on security grounds13 May 2027

Paraphrased from the notified text. Read the Gazette wording before relying on any line.

05

The rules that need systems, not documents

Most of the 23 rules can be met with a policy and a published page. Five cannot.

  • Rule 3, notice. The notice has to stand on its own, itemise the data and give a withdrawal route as easy as consent. Proving later what a person saw means storing the notice version and language with each choice. The DPDP consent notice template covers the content.
  • Rule 6, security. Logging and monitoring that can detect unauthorised access, backups, and logs kept for a year. These are controls you operate, and evidence you keep.
  • Rule 7, breach. Two clocks: without delay to each person and the Board, and a detailed report to the Board within 72 hours. India also has CERT-In's six-hour rule; see CERT-In and DPDP breach reporting compared.
  • Rule 8, retention. A one-year floor for processing records and, for the largest platforms, an inactivity erasure job with a 48-hour warning. See DPDP retention and erasure.
  • Rule 10, children. A parent verification step before a child's account is created. See DPDP children's data.

Rule 14 is close behind: a published way to make requests, the identifier you need, and a grievance period of no more than ninety days that you actually meet.

06

What is in the Schedules to the DPDP Rules?

Seven Schedules carry the detail that the rules point to.

ScheduleUsed byWhat it contains
FirstRule 4Part A: nine conditions to register as a Consent Manager (Indian company, net worth of at least Rs 2 crore, certified interoperable platform and others). Part B: thirteen obligations once registered
SecondRules 5 and 16Standards for State processing under section 7(b) and for research, archiving and statistics: lawful, purpose-limited, minimal, accurate, retained only as needed, secured, accountable
ThirdRule 8(1)Three-year erasure for e-commerce entities and social media intermediaries with at least two crore registered users in India, and online gaming intermediaries with at least fifty lakh
FourthRule 12Part A: five classes (healthcare, allied healthcare, educational institutions, creches, school transport). Part B: six purposes, such as confirming a user is not a child
FifthRule 18Board members' salary (Rs 4.5 lakh a month for the Chairperson, Rs 4 lakh for Members), provident fund, travel and other terms
SixthRule 21Terms for the Board's officers and employees, mainly on deputation
SeventhRules 8(3) and 23Purposes for which the Government may call for information (security of the State, functions under law, assessing whether to notify an SDF) and who may ask

From the Schedules to the DPDP Rules 2025.

07

DPDP Rules applicability: who do they apply to?

The Rules apply to whoever the Act applies to: anyone processing digital personal data in India, and anyone outside India processing it in connection with offering goods or services to people in India. Some rules have a narrower audience. Rule 4 binds only registered Consent Managers. Rule 8(1) binds only the three Third Schedule classes. Rule 13 binds only Significant Data Fiduciaries, which the Central Government notifies under section 10; we had found none notified as of 28 September 2026. Rules 5 and 16 concern State processing and research. Rules 17 to 21 govern the Board itself. Check your own position with the DPDP applicability checker and, for SDF exposure, the Significant Data Fiduciary guide.

08

How TryTrustable helps with the DPDP Rules

The DPDP Act is one of the frameworks modelled in the platform, mapped onto the same control library as ISO 27001, SOC 2 and GDPR. For the rules that touch your website and app, Consent by TryTrustable shows a versioned notice, holds non-essential trackers back until a choice, records each choice with the notice version and language in a tamper-evident ledger, relays withdrawals to your processors with every delivery logged, and puts a privacy-request link on the banner. Rights requests land in a queue with deadlines set by request type. It does not verify parents' identity, is not a registered Consent Manager, and does not make you compliant on its own: your people and processes still do that. The DPDP compliance checklist turns the Rules into a work plan.

Questions

The things people ask us

When were the DPDP Rules notified?

On 13 November 2025, when MeitY published them in the Gazette as G.S.R. 846(E). PIB announced them on 14 November 2025. The draft had been published on 3 January 2025 as G.S.R. 02(E).

What is the DPDP Rules effective date?

There are three. Rules 1, 2 and 17 to 21 took effect on 13 November 2025. Rule 4 on Consent Managers takes effect on 13 November 2026. Rules 3, 5 to 16, 22 and 23, which carry the main duties on businesses, take effect on 13 May 2027.

Are the DPDP Rules in force now?

Partly. As of 6 October 2026 only Rules 1, 2 and 17 to 21, about definitions and the Data Protection Board, are in force. Consent Manager registration starts on 13 November 2026, and notice, security, breach, retention, children's data, SDF and rights duties on 13 May 2027.

What is the breach reporting deadline under the DPDP Rules?

Rule 7 requires a Data Fiduciary to tell each affected person and the Board without delay, and to give the Board a detailed report within 72 hours of becoming aware, or a longer period the Board allows on a written request.

Where can I read the DPDP Rules 2025 issued by MeitY?

On the MeitY website, which hosts the Gazette notification G.S.R. 846(E) in Hindi and English. Read the notified text, not the January 2025 draft, which was a consultation version and is not the law.

Book a walkthrough

Get ready for 13 May 2027, not the week before.

Thirty minutes on your notice, consent record, breach clocks and rights queue against the DPDP Rules, with your own site scanned live.