The DPDP Rules, 2025
The Act sets the principles; the Rules set the mechanics. Everything from notice wording to breach timelines and consent manager registration is filled in here.
Summarised for practical use from the publicly notified DPDP Rules, 2025. Rule numbers and groupings are simplified for readability — confirm exact clause text against the official Gazette notification before relying on it for compliance decisions.
Notice, Consent & Consent Managers
How the itemised notice required by Section 5 of the Act must actually be presented, and how registered Consent Managers operate.
Sets out the operative detail behind Section 5 notice: it must independently itemise the personal data collected and the specific purpose for each item, be presented in clear language, and give the Data Principal a direct way to withdraw consent and reach the grievance officer — all without requiring her to hunt through a separate, unlinked privacy policy.
- A single generic consent checkbox for 'our privacy policy' does not satisfy this rule — each purpose needs its own itemised line.
- The withdrawal path and grievance contact must be reachable from the same notice screen, not several clicks away.
A Consent Manager must be an Indian-registered company meeting prescribed technical, financial and governance standards, and must maintain an interoperable, auditable record of every consent given, managed, and withdrawn through its platform.
- If you plan to operate as a Consent Manager (rather than just integrate with one), expect a formal registration process with the Board, not a self-certification.
- Most Data Fiduciaries will only need to integrate with a registered Consent Manager's API, not build one themselves.
Security Safeguards & Breach Intimation
The operational floor for 'reasonable security safeguards' under Section 8(5), and the mechanics of breach notification under Section 8(6).
Fleshes out Section 8(5) with a baseline: appropriate encryption or masking of personal data, access controls with logging, continuous monitoring for unauthorised access, contractual security obligations flowing down to Data Processors, and retention of relevant logs for at least one year for detection and investigation of breaches.
- A one-year log retention floor means your logging/SIEM retention policy needs to be checked against this explicitly, not just against your general IT policy.
- Processor contracts need security clauses that mirror your own obligations, not generic confidentiality language.
Requires intimation to the Board without undue delay once the Data Fiduciary becomes aware of a breach, describing its nature, extent and likely impact, followed by a more detailed report — including root cause, mitigating actions taken, and remedial steps — within a further prescribed window. Affected Data Principals must separately be told in clear language what happened and what they can do about it.
- Treat this as two separate deliverables: a fast initial notification, then a fuller root-cause report — don't wait to have every detail before sending the first one.
- Your incident response runbook should map directly onto these two deliverables plus the individual-facing notice.
Retention, Erasure & Publishing Requirements
When the Section 8(7) erasure clock starts running, and what a Data Fiduciary must publish about itself.
For classes of Data Fiduciary notified for this purpose (commonly understood to include large e-commerce, social media and gaming platforms), a defined period of Data Principal inactivity is treated as the point at which the specified purpose is deemed no longer served, triggering the Section 8(7) erasure duty — subject to giving the individual advance notice before deletion so she can act to retain the account.
- If you operate a consumer platform with dormant accounts, you likely need an inactivity-triggered erasure job, plus a pre-erasure notice window, not indefinite retention of stale accounts.
Requires the Data Protection Officer's (or equivalent contact person's) name and contact details to be prominently and clearly published on the Data Fiduciary's website or app, in every language in which the notice under Section 5 is offered.
- A grievance email buried in a PDF privacy policy is not enough — the contact needs to be visible on the site or app itself, matching every language you offer notices in.
Children's Data & Verifiable Consent
How Section 9's parental-consent requirement is meant to be operationalised, and where it's relaxed.
Verifiable parental or guardian consent may be obtained through reliable identity and age details already available with the Data Fiduciary, a virtual token mechanism linked to identity/age (such as through DigiLocker), or another government-notified mechanism, applying a risk-based approach depending on the volume and nature of processing.
- Expect to integrate with a token-based age/identity verification flow rather than a simple self-declared birthdate field for anything beyond low-risk processing.
Carves out defined, lower-risk contexts — such as healthcare and educational institutions performing functions strictly necessary for their core services, or platforms that can demonstrate verifiably safe processing — from the full weight of Section 9, subject to purpose limitation.
- This exemption is narrow and purpose-bound — it does not generally exempt marketing, analytics, or ad-tech layered on top of an otherwise-exempt core service.
Significant Data Fiduciary Obligations
The heavier operational load the Rules place on entities notified as Significant Data Fiduciaries under Section 10.
Requires a Significant Data Fiduciary to conduct a Data Protection Impact Assessment and an independent data audit at least annually, covering the proportionality of processing to the stated purpose, and to report significant observations to the Board.
- Build an annual DPIA/audit cycle into your compliance calendar now if you're a plausible SDF candidate — waiting for formal notification leaves too little runway.
Where algorithmic software is used for processing that could affect Data Principals, the Significant Data Fiduciary must undertake due diligence to verify it does not pose a risk to individual rights, and must comply with any Central Government direction restricting specified categories of personal data (and associated traffic data) from leaving India, based on the advice of a government-constituted committee.
- If you run recommendation, scoring, or automated-decision systems at scale, document your model risk-assessment process now — this is squarely what future audits will ask for.
Exercising Rights & Grievance Timelines
The practical mechanics behind Chapter III rights — how requests are made and within what time they must be answered.
A Data Fiduciary must publish an accessible means (in-app, on a website, or another prescribed channel) through which a Data Principal can submit access, correction, and erasure requests, and must respond within a prescribed reasonable timeframe proportionate to the nature of the request.
- A single rights-request intake form covering access, correction, erasure and consent-withdrawal in one place is the cleanest way to satisfy this and keep your SLA tracker simple.
Grievances raised by Data Principals must be acknowledged and substantively responded to within a prescribed period, with the Data Fiduciary or Consent Manager required to maintain records of grievances and their resolution for audit purposes.
- Log every grievance with a timestamp and resolution note even when resolved instantly by support staff — the record-keeping duty applies regardless of how quickly you actually resolve it.
Cross-Border Transfer & Research Exemptions
How Section 16 restrictions and Section 17 research exemptions are meant to be administered in practice.
Restrictions on transferring personal data to specified countries or territories are to be based on the recommendation of a government-constituted committee assessing factors bearing on India's national interest, and are to be notified before taking effect rather than applied retroactively without notice.
- Track the government's notified list directly rather than assuming any particular destination is or isn't restricted — this list can change and is the operative fact, not a general geopolitical assumption.
Sets conditions under which the Section 17 research/archiving/statistical exemption applies, generally requiring that processing follow a defined standard, not be used to make any decision specific to an individual, and that appropriate safeguards against re-identification be maintained.
- Document your anonymisation or pseudonymisation method for any dataset you're treating as exempt research data — the exemption turns on genuinely not being able to single out or decide about an individual, not merely on internal labelling as 'research'.
Data Protection Board — Procedure
The administrative rules under which the Board itself is expected to operate.
Establishes the Board's digital-first operating procedure, the terms of service, salary and allowances of its Chairperson and Members (set out in an accompanying Schedule), and the process for filing complaints and breach intimations electronically.
- Complaints and breach intimations are expected to be filed through an electronic portal, so organisations should assign clear internal ownership for monitoring and responding to Board correspondence.