Reading the DPDP Rules Alongside the Act: A Section-by-Section Cross-Reference
The Act sets the framework; the Rules supply the operational detail. Reading them together, rather than in isolation, is the only way to get a complete picture.
Why the Act and Rules need to be read together
The DPDP Act, consistent with its design as a comparatively short, framework-style statute, delegates a substantial amount of operational detail to rules made under the central government's rule-making power. Reading the Act in isolation gives an accurate but incomplete picture, since obligations that sound general in the Act, reasonable security safeguards, breach notification timelines, consent notice content, are given more concrete procedural shape in the Rules.
The draft DPDP Rules, 2025 were released for public consultation in January 2025, with the Rules subsequently finalised and notified later in 2025 alongside a phased timeline for different provisions to take effect. Because the Rules can be amended over time and phased commencement can shift, treating the current Rules text as the operative supplement to the Act, rather than assuming the January 2025 draft is final, is the safer working assumption.
Consent and notice provisions
The Act's consent framework under Sections 5 through 7 establishes the requirement for clear, itemised notice and free, specific, informed, unconditional, and unambiguous consent, but leaves matters like the precise format, language accessibility requirements, and standardised elements of a valid notice to be filled in by the Rules. Organisations building consent capture flows should treat the Act's language as the governing principle and the Rules as the implementation checklist, rather than trying to design a compliant notice from the Act's text alone.
Security safeguards and breach notification
Section 8(5)'s reasonable security safeguards standard and Section 8(6)'s breach intimation duty are both areas where the Act sets the obligation but the Rules are expected to add operative detail, such as breach notification timelines and the categories of information a breach notice to the Board and to affected Data Principals must contain. This is one of the more consequential cross-references to track closely, since penalty exposure under both provisions is among the highest in the Schedule, and the practical compliance bar depends heavily on what the Rules specify.
Significant Data Fiduciary and cross-border provisions
Section 10's Significant Data Fiduciary framework and Section 16's cross-border transfer mechanism both rely on the Rules, and on separate government notifications, for their practical activation, the criteria and process for designation in the first case, and the restricted-country list in the second. Neither provision can be fully assessed by reading the Act section alone; both require checking whether, and what, has actually been notified under the corresponding rule-making or notification power.
Where to go next
The /act and /rules pages on this site are structured to be read side by side for exactly this reason, and the Timeline Explorer indicates which Act provisions and corresponding Rules are already in force versus still pending, which is often the single most useful piece of information for a compliance team trying to prioritise its work.