Step 2 of 4 in the reading path · Previous: What is the DPDP Act
What are the DPDP Rules, 2025?
Verified August 2026
The Digital Personal Data Protection Rules, 2025 are the Government's instructions for how the DPDP Act works in practice. They were notified on 13 November 2025. There are 23 rules and seven Schedules. The rules about the Data Protection Board are in force; Consent Manager registration starts in November 2026; the rules that bind companies start on 13 May 2027.
Where the Rules come from
Section 40 of the Act lets the Central Government make rules to carry out the Act. The Government used that power on 13 November 2025 and notified the Rules as G.S.R. 846(E). Section 41 requires the Rules to be laid before Parliament, which can modify or annul them. A corrigendum of 11 December 2025 corrected typographical errors and changed no requirement.
The Act and the Rules were designed to work as a pair. The Act states each obligation. The matching rule states how the obligation is met. Section 5 of the Act requires a notice before consent; Rule 3 lists what the notice must contain. Section 6(9) requires a Consent Manager to register with the Board; Rule 4 and the First Schedule set the conditions of registration. A company that reads only the Act knows what it must do, but not how.
When each rule starts
Rule 1(2) brings the Rules into force in three stages. The stages match the Act's own commencement notification, G.S.R. 843(E) of the same date.
| Rules | What they cover | Status |
|---|---|---|
| Rules 1, 2, 17–21 | Title, definitions, and the appointment, salaries, meetings, digital office and staff of the Data Protection Board. | In force |
| Rule 4 | Registration and obligations of Consent Managers, with the First Schedule. | 13 Nov 2026 |
| Rules 3, 5–16, 22, 23 | Everything that binds companies: notice, security, breach intimation, erasure, children's data, Significant Data Fiduciaries, rights, cross-border transfer, appeals. | 13 May 2027 |
The 23 rules, in plain words
| Rule | What it does |
|---|---|
| Rule 1 | Names the Rules and phases their commencement. |
| Rule 2 | Defines the terms the Rules use. |
| Rule 3 | Sets what a notice to a Data Principal must contain, serving the notice duty in section 5. |
| Rule 4 | Sets how a Consent Manager registers and operates, serving section 6(9). The First Schedule carries the nine conditions of registration, including incorporation in India and a net worth of at least ₹2 crore, and the continuing obligations, including consent records kept for at least seven years. |
| Rule 5 | Sets the standards for the State processing personal data to provide subsidies, benefits, services, certificates, licences and permits, with the Second Schedule. |
| Rule 6 | Sets the reasonable security safeguards, including a one-year retention of access logs under Rule 6(1)(e). |
| Rule 7 | Sets how a personal data breach is intimated to the affected people and the Board. |
| Rule 8 | Sets when a purpose is deemed no longer served, which starts the erasure duty. The Third Schedule sets a three-year dormancy trigger for the largest platforms, with a 48-hour notice before erasure. |
| Rule 9 | Requires published contact information for a person who can answer questions about processing. |
| Rule 10 | Sets how verifiable consent of a parent is obtained before processing a child's data, serving section 9(1). |
| Rule 11 | Sets verifiable consent where a person with a disability has a lawful guardian. |
| Rule 12 | Exempts named classes of processing from parts of the children's-data obligations, with the Fourth Schedule. |
| Rule 13 | Sets the additional obligations of a Significant Data Fiduciary under section 10, including the localisation power in Rule 13(4). |
| Rule 14 | Sets how Data Principals exercise their rights, including the 90-day outer limit for a grievance. |
| Rule 15 | Governs transfer of personal data outside India, serving section 16. |
| Rule 16 | Carries the exemption for research, archiving and statistical purposes under section 17(2)(b). |
| Rules 17–21 | Set the Board's appointments, salaries, meeting procedure, functioning as a digital office, and staff. |
| Rule 22 | Sets the procedure for an appeal to the Appellate Tribunal. |
| Rule 23 | Lets the Government call for information from a Data Fiduciary or intermediary, with the Seventh Schedule. |
The seven Schedules
The First Schedule carries the Consent Manager conditions and obligations. The Second sets standards for State processing. The Third sets the erasure classes and time periods. The Fourth carries the children's-data exemptions. The Fifth sets the Chairperson's and Members' terms. The Sixth covers the Board's officers and employees. The Seventh lists the purposes and authorised persons for calling information.
Where to read the Rules
Primary source. The Rules as published by India Code under the Act's page, in English and Hindi, together with the commencement notification and the corrigendum of 11 December 2025. Every date on this page comes from those documents. Full citations are on the Sources page.
An amendment to the Rules. A notification under Rule 13(4) naming localisation classes. The first Consent Manager registration under Rule 4. Any gazetted change to the commencement dates in Rule 1(2).
Next in the reading path: Whom does the Act apply to →