Full compliance deadline: 13 May 2027—days left
India Data Law

Step 2 of 4 in the reading path · Previous: What is the DPDP Act

What are the DPDP Rules, 2025?

Verified August 2026

The Digital Personal Data Protection Rules, 2025 are the Government's instructions for how the DPDP Act works in practice. They were notified on 13 November 2025. There are 23 rules and seven Schedules. The rules about the Data Protection Board are in force; Consent Manager registration starts in November 2026; the rules that bind companies start on 13 May 2027.

Where the Rules come from

Section 40 of the Act lets the Central Government make rules to carry out the Act. The Government used that power on 13 November 2025 and notified the Rules as G.S.R. 846(E). Section 41 requires the Rules to be laid before Parliament, which can modify or annul them. A corrigendum of 11 December 2025 corrected typographical errors and changed no requirement.

The Act and the Rules were designed to work as a pair. The Act states each obligation. The matching rule states how the obligation is met. Section 5 of the Act requires a notice before consent; Rule 3 lists what the notice must contain. Section 6(9) requires a Consent Manager to register with the Board; Rule 4 and the First Schedule set the conditions of registration. A company that reads only the Act knows what it must do, but not how.

When each rule starts

Rule 1(2) brings the Rules into force in three stages. The stages match the Act's own commencement notification, G.S.R. 843(E) of the same date.

RulesWhat they coverStatus
Rules 1, 2, 17–21Title, definitions, and the appointment, salaries, meetings, digital office and staff of the Data Protection Board.In force
Rule 4Registration and obligations of Consent Managers, with the First Schedule.13 Nov 2026
Rules 3, 5–16, 22, 23Everything that binds companies: notice, security, breach intimation, erasure, children's data, Significant Data Fiduciaries, rights, cross-border transfer, appeals.13 May 2027

The 23 rules, in plain words

RuleWhat it does
Rule 1Names the Rules and phases their commencement.
Rule 2Defines the terms the Rules use.
Rule 3Sets what a notice to a Data Principal must contain, serving the notice duty in section 5.
Rule 4Sets how a Consent Manager registers and operates, serving section 6(9). The First Schedule carries the nine conditions of registration, including incorporation in India and a net worth of at least ₹2 crore, and the continuing obligations, including consent records kept for at least seven years.
Rule 5Sets the standards for the State processing personal data to provide subsidies, benefits, services, certificates, licences and permits, with the Second Schedule.
Rule 6Sets the reasonable security safeguards, including a one-year retention of access logs under Rule 6(1)(e).
Rule 7Sets how a personal data breach is intimated to the affected people and the Board.
Rule 8Sets when a purpose is deemed no longer served, which starts the erasure duty. The Third Schedule sets a three-year dormancy trigger for the largest platforms, with a 48-hour notice before erasure.
Rule 9Requires published contact information for a person who can answer questions about processing.
Rule 10Sets how verifiable consent of a parent is obtained before processing a child's data, serving section 9(1).
Rule 11Sets verifiable consent where a person with a disability has a lawful guardian.
Rule 12Exempts named classes of processing from parts of the children's-data obligations, with the Fourth Schedule.
Rule 13Sets the additional obligations of a Significant Data Fiduciary under section 10, including the localisation power in Rule 13(4).
Rule 14Sets how Data Principals exercise their rights, including the 90-day outer limit for a grievance.
Rule 15Governs transfer of personal data outside India, serving section 16.
Rule 16Carries the exemption for research, archiving and statistical purposes under section 17(2)(b).
Rules 17–21Set the Board's appointments, salaries, meeting procedure, functioning as a digital office, and staff.
Rule 22Sets the procedure for an appeal to the Appellate Tribunal.
Rule 23Lets the Government call for information from a Data Fiduciary or intermediary, with the Seventh Schedule.

The seven Schedules

The First Schedule carries the Consent Manager conditions and obligations. The Second sets standards for State processing. The Third sets the erasure classes and time periods. The Fourth carries the children's-data exemptions. The Fifth sets the Chairperson's and Members' terms. The Sixth covers the Board's officers and employees. The Seventh lists the purposes and authorised persons for calling information.

Where to read the Rules

Primary source. The Rules as published by India Code under the Act's page, in English and Hindi, together with the commencement notification and the corrigendum of 11 December 2025. Every date on this page comes from those documents. Full citations are on the Sources page.

What would change this page

An amendment to the Rules. A notification under Rule 13(4) naming localisation classes. The first Consent Manager registration under Rule 4. Any gazetted change to the commencement dates in Rule 1(2).

Next in the reading path: Whom does the Act apply to →