Compliance · India

The DPDP Rules, 2025: what actually changed.

India passed its data protection Act in August 2023 and then left it unusable for two years. The Rules notified on 13 November 2025 are what turned a statute into a set of dated obligations. This is the regulatory explainer — what changed, who it binds, and what the clock in rule 1 really says.

SemperWise Research Desk 8 min read Compliance
ISO 27001 SOC 2 DPDP HIPAA One control set · 31 mapped categories Access review Scan history Change log Training Evidence collected continuously, not before the audit

There are two documents, and confusing them is the source of most of the bad advice circulating in India right now. The Digital Personal Data Protection Act, 2023 was enacted on 11 August 2023. It set out the principles: consent, purpose limitation, data-principal rights, security safeguards, breach notification, penalties. What it did not do was say how any of it worked in practice, or when. Section 40 left that to rules the government had yet to write.

The Digital Personal Data Protection Rules, 2025 were notified in the Gazette of India on 13 November 2025 as G.S.R. 846(E). They are the operational half — the procedure, the thresholds, the timings and the machinery. They are also where the commencement dates live, which is why anyone still describing DPDP as "coming soon" has not read rule 1.

This piece is the regulatory explainer: what the Rules changed, who they reach, and the shape of the obligations. If what you want is the sequence of work rather than the law behind it, our DPDP countdown checklist covers that side instead — it is linked at the foot of this article, and the two are meant to be read together.

What the Rules actually changed

The Act described obligations. The Rules made them executable. The substantive additions are these:

  • A commencement schedule. Rule 1 splits the Rules into three tranches with different start dates, so the framework switches on in stages rather than all at once. Everything else on this page depends on that clause.
  • A constituted regulator. The provisions establishing the Data Protection Board of India — its composition, appointment process and procedure — took effect immediately on notification. There is now a body that can adjudicate, rather than a body described in a statute.
  • A Consent Manager framework. The Rules create a registered intermediary through which individuals can give, review, manage and withdraw consent across multiple Data Fiduciaries, with registration conditions including a minimum net worth of ₹2 crore.
  • Notice content, specified. The Act said notice must be clear. The Rules say what it has to contain and in what form, which is the difference between a principle and a compliance requirement.
  • Breach procedure, specified. Who is told, how fast, and what the follow-up report must contain — including the 72-hour detailed report to the Board that sits behind the immediate notification duty.
  • Verifiable consent mechanics for children. The Rules define what "verifiable consent" means for processing the data of anyone under 18, rather than leaving it as an aspiration.
  • Significant Data Fiduciary duties, made concrete. The annual Data Protection Impact Assessment, the independent data audit and the algorithmic due-diligence obligation are all specified for entities the government notifies as significant.

The commencement clock is written into rule 1

This is the part worth reading in the original, because it is short and unambiguous. Rule 1 divides the Rules into three groups and gives each a different trigger, all counted from publication in the Official Gazette:

  1. Immediately — rules 1, 2 and 17 to 21.

    Short title, definitions, and the provisions constituting the Data Protection Board of India: its composition, the selection and appointment machinery, terms of service and the Board’s own procedure. These have been in force since November 2025.

  2. One year later — rule 4.

    Registration of Consent Managers. Around 13 November 2026, an entity that wants to operate as a Consent Manager must be registered with the Board and meet the conditions the Rules set, including the ₹2 crore net-worth floor.

  3. Eighteen months later — rules 3, 5 to 16, 22 and 23.

    This is the tranche that costs money. Notice requirements, consent mechanics, data-principal rights procedures, reasonable security safeguards, breach notification, retention and erasure, children’s data, Significant Data Fiduciary duties and cross-border processing. Around 13 May 2027.

So the honest summary of "when does DPDP apply to me" is: the regulator already exists, the consent-intermediary market opens in late 2026, and the obligations that will require you to build something become enforceable in the middle of 2027. Nothing about that schedule is soft. It is a clause in a notified instrument, not a policy intention.

Who it applies to, including companies with no Indian office

The Act reaches the processing of digital personal data within India, and it reaches processing outside India where that processing is in connection with offering goods or services to data principals in India. There is no establishment test to hide behind and no headcount exemption. A SaaS company incorporated in Delaware with paying users in Bengaluru is inside the scope of a law it has never read.

The roles matter more than most organisations realise. A Data Fiduciary determines the purpose and means of processing and carries almost all of the obligations. A Data Processor processes on a Fiduciary’s behalf under contract. A Significant Data Fiduciary is a Fiduciary — or a class of them — that the government notifies as significant based on the volume and sensitivity of the personal data processed and the risk it carries, and it picks up four extra duties: a Data Protection Officer based in India, an annual Data Protection Impact Assessment, an independent data audit, and algorithmic due diligence.

Most organisations are both Fiduciary and Processor, for different activities, and determine it once at company level rather than per activity. That single shortcut produces more downstream errors than any other in a DPDP programme, because the obligations attach differently to each role.

The obligations, in the order you feel them

Not the order they appear in the statute — the order in which they turn up as work.

Notice and consent

A clear, plain-language notice, and consent that is free, specific, informed, unconditional and unambiguous. Consent is the primary basis, supported only by a short and closed list of legitimate uses. Withdrawal must be as easy as giving consent was, which is a build task rather than a drafting one.

Data-principal rights

Access, correction and erasure, grievance redressal, and nomination — the right to name someone to exercise your rights if you die or become incapacitated, which has no GDPR equivalent. Each one needs a published mechanism and someone who answers it.

Reasonable security safeguards

The obligation to prevent a breach in the first place. This is the limb an existing ISO 27001 programme covers best, and it is also the limb attached to the largest penalty in the Schedule.

Breach notification

Notify the Board and every affected data principal without delay, then file a detailed report with the Board within 72 hours. Two clocks, one of which starts before you have finished working out what happened.

Retention and erasure

Erase personal data when consent is withdrawn or the purpose is served, unless retention is legally required — with advance notice to the data principal before deletion in the cases the Rules specify.

Children’s data

Verifiable parental or guardian consent for anyone under 18, and no tracking, behavioural monitoring or targeted advertising directed at children. Notified exemptions exist for defined purposes such as healthcare and education.

Processor contracts

Processing by a Processor must sit under a valid contract. Vendor paperwork written before November 2025 almost certainly does not contain what the Act now requires.

Grievance and accountability

A published grievance mechanism, a responsive point of contact, and accuracy obligations where the data is used to make decisions about the individual. There is no general DPO mandate outside Significant Data Fiduciaries.

The penalty schedule is graded, and the grading tells you what matters

The Act’s Schedule sets maximums, not tariffs. What is worth noticing is the shape of it: the largest number is attached to failing to prevent a breach, and the second largest to failing to tell anyone about one. The legislature priced prevention and honesty above everything else.

₹250 CrFailure to take reasonable security safeguards
₹200 CrFailure to notify a personal data breach
₹150 CrBreach of additional SDF obligations
₹50 CrBreach of any other provision

Breaching children’s-data obligations also carries up to ₹200 crore, and a data principal who breaches their own duties under the Act can be penalised up to ₹10,000 — a small number that exists mainly to discourage vexatious complaints. These are flat rupee ceilings rather than a percentage of global turnover, which makes them proportionally harsher on a mid-sized Indian company than GDPR’s formula would be.

The Board sets the actual amount by weighing the nature, gravity and duration of the violation, the type of personal data involved, whether the violation caused harm, and the cooperation and mitigation that followed. That last factor is the one organisations control. Documented good-faith readiness is the specific thing the Board looks at, which is the practical argument for building the evidence trail before you need it. Appeals from the Board go to TDSAT, and from there to the Supreme Court.

Why GDPR and ISO 27001 leave a gap

Both help. Neither finishes the job, and the organisations most likely to be caught out are the ones already carrying a certificate, because the certificate creates a reasonable but wrong assumption that the work is done. The differences that generate net-new build work:

  • No legitimate-interest catch-all. DPDP runs on consent plus a short list of legitimate uses. Processing you justify today under GDPR’s legitimate interest has no equivalent home here.
  • No general DPO mandate — but real grievance machinery. GDPR requires a DPO in broader circumstances; DPDP requires one only for Significant Data Fiduciaries, while requiring everyone to publish and operate a grievance mechanism.
  • A different children’s threshold. Under 18 in India, against GDPR’s 16 with member-state discretion down to 13. A consent flow built for Europe is under-scoped by several years of users.
  • Cross-border transfer is inverted. DPDP works on a restriction model — transfers are permitted unless the government restricts the destination — rather than GDPR’s adequacy and standard-clauses allow-list. Easier in practice, but the compliance artefact is different.
  • Nomination has no equivalent. The right to nominate another individual to exercise your rights is genuinely new, and no existing rights workflow accounts for it.
  • Breach reporting is a separate pipeline. Different regulator, different clock, different report content. A GDPR Article 33 runbook is a starting point, not a substitute.
  • Consent Manager integration is a decision nobody has made yet. There is no analogue in either framework, and the registration regime opens in late 2026.

What to do in 2026, not in May 2027

Eighteen months sounds generous until you cost the work. Data mapping alone takes weeks in a mid-sized organisation. Rights workflows have to be built, staffed and tested. A breach playbook is worth nothing until it has been rehearsed at least once, and detection capable of surfacing a breach inside 72 hours is an engineering programme, not a policy. Working backwards from May 2027, the useful sequence is:

  1. Map the processing.

    Every activity, purpose, basis, location, recipient and retention period, across product, HR, marketing, support and third-party tools. Nothing else can be planned until this exists, and it is the artefact clients most often try to skip.

  2. Determine your role per activity.

    Fiduciary, Processor, or both — reasoned activity by activity rather than declared once for the company. Flag the volume and sensitivity that could put Significant Data Fiduciary designation in reach.

  3. Run a clause-by-clause gap assessment.

    Against the Act and the 2025 Rules, RAG-rated, each gap written as a thing to build with an owner and an effort estimate attached.

  4. Fix notice and consent first.

    It is the highest-volume change, it touches product and marketing, and it has the longest lead time because it needs engineering rather than legal drafting.

  5. Build the rights workflow and test it.

    Run a real access request, then a correction, then an erasure, end to end through your own systems. Whatever breaks is what you would have discovered in front of a regulator.

  6. Rehearse the breach playbook.

    Tabletop it against the without-delay notification and the 72-hour report. If your logging would not tell you inside 72 hours, that is the finding, and it belongs in the engineering backlog.

  7. Rewrite processor contracts.

    Every vendor that touches personal data on your behalf needs terms that reflect the Act. Long lead time, low urgency-signal, so it slips unless it is started early.

  8. Keep watching the Board.

    The framework is new and guidance will move. Someone needs to own tracking notifications rather than assuming the position is stable until 2027.

This article is general information, not legal advice, and is current as of 12 August 2026. Statutory dates and penalty figures are taken from the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as notified. Re-check them against Data Protection Board of India notifications before relying on them, and take contested questions of interpretation to counsel.

SemperWise Research Desk

Compliance & Regulatory Research

Tracks primary sources — regulator notifications, standards bodies and audit guidance — and turns them into practical checklists our delivery teams use on live engagements. Every figure is checked against its original source before publication.

Next step

Talk to us about your next assessment.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.