DPDP NavigatorAct 2023 · Rules 2025
Delegated Legislation · Rules, 2025

The DPDP Rules, 2025

The Act sets the principles; the Rules set the mechanics. Everything from notice wording to breach timelines and consent manager registration is filled in here.

Summarised for practical use from the publicly notified DPDP Rules, 2025. Rule numbers and groupings are simplified for readability — confirm exact clause text against the official Gazette notification before relying on it for compliance decisions.

Security Safeguards & Breach Intimation

The operational floor for 'reasonable security safeguards' under Section 8(5), and the mechanics of breach notification under Section 8(6).

Rule 6 Reasonable security safeguards
Permalink

Fleshes out Section 8(5) with a baseline: appropriate encryption or masking of personal data, access controls with logging, continuous monitoring for unauthorised access, contractual security obligations flowing down to Data Processors, and retention of relevant logs for at least one year for detection and investigation of breaches.

What this means in practice
  • A one-year log retention floor means your logging/SIEM retention policy needs to be checked against this explicitly, not just against your general IT policy.
  • Processor contracts need security clauses that mirror your own obligations, not generic confidentiality language.
Rule 7 Intimation of personal data breach
Permalink

Requires intimation to the Board without undue delay once the Data Fiduciary becomes aware of a breach, describing its nature, extent and likely impact, followed by a more detailed report — including root cause, mitigating actions taken, and remedial steps — within a further prescribed window. Affected Data Principals must separately be told in clear language what happened and what they can do about it.

What this means in practice
  • Treat this as two separate deliverables: a fast initial notification, then a fuller root-cause report — don't wait to have every detail before sending the first one.
  • Your incident response runbook should map directly onto these two deliverables plus the individual-facing notice.

Retention, Erasure & Publishing Requirements

When the Section 8(7) erasure clock starts running, and what a Data Fiduciary must publish about itself.

Rule 8 Retention and erasure for specified classes of Data Fiduciary
Permalink

For classes of Data Fiduciary notified for this purpose (commonly understood to include large e-commerce, social media and gaming platforms), a defined period of Data Principal inactivity is treated as the point at which the specified purpose is deemed no longer served, triggering the Section 8(7) erasure duty — subject to giving the individual advance notice before deletion so she can act to retain the account.

What this means in practice
  • If you operate a consumer platform with dormant accounts, you likely need an inactivity-triggered erasure job, plus a pre-erasure notice window, not indefinite retention of stale accounts.
Rule 9 Publishing business contact information
Permalink

Requires the Data Protection Officer's (or equivalent contact person's) name and contact details to be prominently and clearly published on the Data Fiduciary's website or app, in every language in which the notice under Section 5 is offered.

What this means in practice
  • A grievance email buried in a PDF privacy policy is not enough — the contact needs to be visible on the site or app itself, matching every language you offer notices in.

Children's Data & Verifiable Consent

How Section 9's parental-consent requirement is meant to be operationalised, and where it's relaxed.

Rule 10 Verifiable consent for children and persons with disability
Permalink

Verifiable parental or guardian consent may be obtained through reliable identity and age details already available with the Data Fiduciary, a virtual token mechanism linked to identity/age (such as through DigiLocker), or another government-notified mechanism, applying a risk-based approach depending on the volume and nature of processing.

What this means in practice
  • Expect to integrate with a token-based age/identity verification flow rather than a simple self-declared birthdate field for anything beyond low-risk processing.
Rule 11 Exemptions for specified processing of children's data
Permalink

Carves out defined, lower-risk contexts — such as healthcare and educational institutions performing functions strictly necessary for their core services, or platforms that can demonstrate verifiably safe processing — from the full weight of Section 9, subject to purpose limitation.

What this means in practice
  • This exemption is narrow and purpose-bound — it does not generally exempt marketing, analytics, or ad-tech layered on top of an otherwise-exempt core service.

Significant Data Fiduciary Obligations

The heavier operational load the Rules place on entities notified as Significant Data Fiduciaries under Section 10.

Rule 12 Data Protection Impact Assessment and audit
Permalink

Requires a Significant Data Fiduciary to conduct a Data Protection Impact Assessment and an independent data audit at least annually, covering the proportionality of processing to the stated purpose, and to report significant observations to the Board.

What this means in practice
  • Build an annual DPIA/audit cycle into your compliance calendar now if you're a plausible SDF candidate — waiting for formal notification leaves too little runway.
Rule 12A Algorithmic due-diligence and data localisation
Permalink

Where algorithmic software is used for processing that could affect Data Principals, the Significant Data Fiduciary must undertake due diligence to verify it does not pose a risk to individual rights, and must comply with any Central Government direction restricting specified categories of personal data (and associated traffic data) from leaving India, based on the advice of a government-constituted committee.

What this means in practice
  • If you run recommendation, scoring, or automated-decision systems at scale, document your model risk-assessment process now — this is squarely what future audits will ask for.

Exercising Rights & Grievance Timelines

The practical mechanics behind Chapter III rights — how requests are made and within what time they must be answered.

Rule 14 Manner of exercising rights of access, correction and erasure
Permalink

A Data Fiduciary must publish an accessible means (in-app, on a website, or another prescribed channel) through which a Data Principal can submit access, correction, and erasure requests, and must respond within a prescribed reasonable timeframe proportionate to the nature of the request.

What this means in practice
  • A single rights-request intake form covering access, correction, erasure and consent-withdrawal in one place is the cleanest way to satisfy this and keep your SLA tracker simple.
Rule 15 Grievance redressal timelines
Permalink

Grievances raised by Data Principals must be acknowledged and substantively responded to within a prescribed period, with the Data Fiduciary or Consent Manager required to maintain records of grievances and their resolution for audit purposes.

What this means in practice
  • Log every grievance with a timestamp and resolution note even when resolved instantly by support staff — the record-keeping duty applies regardless of how quickly you actually resolve it.

Cross-Border Transfer & Research Exemptions

How Section 16 restrictions and Section 17 research exemptions are meant to be administered in practice.

Rule 17 Evaluation for cross-border transfer restrictions
Permalink

Restrictions on transferring personal data to specified countries or territories are to be based on the recommendation of a government-constituted committee assessing factors bearing on India's national interest, and are to be notified before taking effect rather than applied retroactively without notice.

What this means in practice
  • Track the government's notified list directly rather than assuming any particular destination is or isn't restricted — this list can change and is the operative fact, not a general geopolitical assumption.
Rule 18 Standards for research, archiving and statistical processing
Permalink

Sets conditions under which the Section 17 research/archiving/statistical exemption applies, generally requiring that processing follow a defined standard, not be used to make any decision specific to an individual, and that appropriate safeguards against re-identification be maintained.

What this means in practice
  • Document your anonymisation or pseudonymisation method for any dataset you're treating as exempt research data — the exemption turns on genuinely not being able to single out or decide about an individual, not merely on internal labelling as 'research'.

Data Protection Board — Procedure

The administrative rules under which the Board itself is expected to operate.

Rule 20 Digital-office procedure and Second Schedule terms
Permalink

Establishes the Board's digital-first operating procedure, the terms of service, salary and allowances of its Chairperson and Members (set out in an accompanying Schedule), and the process for filing complaints and breach intimations electronically.

What this means in practice
  • Complaints and breach intimations are expected to be filed through an electronic portal, so organisations should assign clear internal ownership for monitoring and responding to Board correspondence.