The Rules turned the principles of the DPDP Act 2023 into dated, countable obligations. Here is every one, and what each costs.
The Act said what must happen. The Rules say by when, in what form, and to whom.
The Digital Personal Data Protection Rules, 2025 were notified by the Ministry of Electronics and Information Technology on 14 November 2025. They are the operative instrument under the Digital Personal Data Protection Act, 2023: the Act creates the duties, and the Rules fix the deadlines, the formats and the thresholds that make those duties enforceable.
They are final, not draft. The obligations that touch most organisations phase in over eighteen months from notification, which puts the working deadline at 14 May 2027. Some provisions — those constituting and empowering the Data Protection Board — took effect earlier, because the Board has to exist before it can administer anything else.
The phase-in is staged rather than a single switch. Which provisions bind you first depends on what you process and at what scale — the retention thresholds in the Third Schedule, for instance, only apply above stated user counts.
Most of the Act survived intact. These are the places where the Rules replaced a principle with a number.
The Act said tell the Board. Rule 7 says tell the affected people without delay, tell the Board without delay, and give the Board full particulars within 72 hours. There is no severity threshold to hide behind — the duty attaches to any personal data breach, not only to the serious ones.
Rule 8 requires you to erase personal data once the purpose is served — but Rule 8(3) sets a one-year minimum for logs, and Rule 8(2) requires 48 hours’ notice to the person before you erase. The Third Schedule then forces erasure after three years of inactivity for platforms above stated user thresholds.
A tick-box saying “I am over 18” was never going to satisfy §9, and Rule 10 now says what does: reliable identity and age details you already hold, or a virtual token issued by an authorised entity, or a DigiLocker credential. The Fourth Schedule then exempts several sectors from it entirely.
Rule 3 requires a standalone, itemised notice in plain language — and a link not only to withdraw consent and exercise rights, but to complain to the Data Protection Board. That third link is the one almost every existing privacy policy is missing.
The provision, what it actually requires, and the maximum the Act’s Schedule sets for getting it wrong.
Give a standalone notice, in plain language, itemising the data you take and the purpose for each — with links to withdraw, to exercise rights, and to complain to the Board.
NoticeA “Consent Manager” is a Board-registered, India-incorporated entity acting for Data Principals. The title is defined, not descriptive — you cannot call yourself one without registering.
DefinitionsKeep personal data secure with safeguards reasonable for what it is — encryption, access control, logging, and the ability to detect and investigate.
SecurityOn any breach: tell affected people without delay, tell the Board without delay, and file full particulars within 72 hours. No severity threshold.
BreachErase when the purpose ends. Give 48 hours’ notice first. Keep logs a minimum of one year. Erase after three years’ inactivity where the Third Schedule applies.
RetentionVerify parental consent properly: reliable identity and age details already held, a virtual token from an authorised entity, or DigiLocker. Not a self-declared checkbox.
ChildrenClinical establishments, healthcare professionals, educational institutions, crèches and school transport are exempt from verifiable parental consent and the tracking ban — for those purposes only.
ChildrenIf you are named a Significant Data Fiduciary: a data protection impact assessment and an audit every twelve months, algorithmic due diligence, and localisation of data the government specifies.
SDFPublish how to make a request, and redress a grievance within 90 days. People can access, correct, erase and nominate — and you must be reachable to hear it.
RightsTransfer outside India is permitted except to countries the government restricts — a blacklist, not a whitelist. Disclose it in the notice.
Cross-borderPenalties are the maximums in the Act’s Schedule (§33). They are assessed per contravention and stack across them — there is no single aggregate cap.
Every one of these is a deadline or a threshold somebody will ask you about in a board meeting.
Initial intimation without delay; the full particulars inside 72 hours (Rule 7). The clock starts when you become aware, not when you finish investigating.
Rule 8(2) requires you to tell the person 48 hours before erasing their data, so they can object or re-engage first.
Rule 14(3) sets 90 days to redress a grievance. Note this attaches to grievances — a rights request is a different duty with its own response period.
Rule 8(3) and the Seventh Schedule set a one-year floor for logs. This one cuts against erasure — you cannot delete a record younger than the floor.
The Third Schedule forces erasure after three years of inactivity for e-commerce and social media above 2 crore users, and online gaming above 50 lakh.
Under 18 is a child under §9 — higher than most jurisdictions. Consent must come from a parent, verifiably, unless the Fourth Schedule exempts you.
DPDP penalties are set against the obligation you missed, not against your turnover. The largest is reserved for one failure in particular.
A common misreading: ₹250 crore is not a cap. It is the maximum for one category of failure. Penalties are assessed per contravention and stack across them, and the Board weighs what you did about it — §33(2)(e) makes mitigation an express factor.
The free Scorecard asks how your organisation actually works and returns a score, your exposure in rupees against these exact sections, and the three gaps that cost the most.
§9 is read as an absolute bar on processing a child’s data without a parent. Rule 12 and the Fourth Schedule say otherwise, for named purposes.
The exemption is purpose-bound. A hospital treating a child is exempt for treatment — not for marketing to their parents.
Where consent is required, Rule 10 sets the standard: identity and age details you reliably hold, a virtual token from an authorised entity, or DigiLocker.
Rule 4 and the First Schedule define it as a registered entity. Most tools described as consent managers are not one, including ours.
Under the Act and Rule 4, a Consent Manager is a specific thing: an entity incorporated in India, registered with the Data Protection Board, meeting the net-worth and interoperability conditions in the First Schedule, and acting on behalf of the Data Principal — a neutral intermediary through which a person can give, review and withdraw consent across many fiduciaries from one place.
A tool that a company uses to collect and evidence consent from its own customers is a Data Fiduciary’s tool. It serves the organisation, not the individual, and it does not require registration. Both are legitimate; they are simply different roles under the same statute.
RuleExpert’s consent module is the second kind. We are not a Board-registered Consent Manager, we do not claim to be, and any vendor telling you their software makes you one has misread Rule 4.
Nothing else in the Rules can be satisfied until you know what personal data you hold and where it lives.
Every system, what personal data is in it, whose it is, and who owns the system. You cannot erase, disclose or secure what you have not located — which is why a weak map caps a DPDP compliance score however good everything else looks.
Standalone, itemised, plain language, and three links: withdraw, exercise rights, complain to the Board. This is the cheapest item on the list and the most visible to a regulator.
72 hours, 48 hours, 90 days and the one-year floor are only met by a process that runs. A calendar reminder is not a control; an owner and an audit trail is.
The Digital Personal Data Protection Rules, 2025 were notified on 14 November 2025. They are final rules, not a draft. The obligations that affect most organisations phase in over eighteen months from notification, putting the working deadline at 14 May 2027. The phase-in is staged rather than a single switch — provisions constituting the Data Protection Board took effect earlier, because the Board must exist before it can administer the rest.
The Act creates the duties; the Rules make them operable. The Digital Personal Data Protection Act, 2023 says you must give notice, take consent, secure data, report breaches and honour rights. The Rules, 2025 say what a notice must contain, how parental consent is verified, how many hours you have to report a breach, how long logs must be kept, and what a Significant Data Fiduciary must audit. Penalties live in the Act’s Schedule; deadlines and formats live in the Rules.
Rule 7 requires three things. Tell the affected Data Principals without delay. Tell the Data Protection Board without delay. Then give the Board the full particulars — what happened, the extent, the likely consequences and what you have done — within 72 hours. There is no severity threshold: the duty attaches to any personal data breach, so an organisation cannot decide a breach was too small to report.
No — there is no cookie-specific provision anywhere in the Act or the Rules. Cookies matter only where they process personal data, and then the ordinary rules apply: a §5 notice that itemises what you collect and why, and §6 consent that is free, specific, informed and as easy to withdraw as it was to give. In practice that means a cookie banner which pre-ticks non-essential categories fails §6, but it fails it as consent, not as a cookie rule.
₹250 crore, for failing to take reasonable security safeguards under §8(5). Breach notification and children’s data failures carry ₹200 crore each, Significant Data Fiduciary duties ₹150 crore, and most other contraventions ₹50 crore. A common misreading is that ₹250 crore caps total exposure — it does not. Penalties are assessed per contravention and stack across them, and §33(2) directs the Board to weigh the nature of the breach and what you did to mitigate it.
Yes. There is no revenue threshold, no headcount threshold and no exemption for startups. If you determine the purpose and means of processing personal data of people in India, you are a Data Fiduciary and the whole Act applies. What scale changes is whether you are additionally named a Significant Data Fiduciary under §10, which adds impact assessments, annual audits and localisation on top — and whether the Third Schedule’s inactivity-erasure thresholds catch you.
Neither, though the overlap is real. GDPR work gives you a head start on mapping, security and rights handling. What it does not give you is the DPDP-specific machinery: notice in the languages the Act requires, verifiable parental consent under Rule 10 with 18 as the age of a child rather than 13–16, the 72-hour Board filing with no severity threshold, the blacklist model for cross-border transfer under Rule 15, and penalties calculated from India’s Schedule rather than a percentage of global turnover.
The Data Protection Board of India. A Data Principal must generally come to you first — which is why Rule 3 requires your notice to carry a link to your grievance channel — and Rule 14(3) gives you 90 days to redress it. If you do not, or they are unsatisfied, they can complain to the Board directly, and your notice has to tell them that too. The Board can inquire, direct remedial measures and impose the Schedule penalties.
Real client quotes, attributed by role and sector — we never name a client.
Working across
Five minutes, no login, no card. A score against these exact sections, your exposure in rupees, and the three gaps that cost the most.
Thank you — we have it. Someone will reply by email, usually within one working day.
Nothing else is needed from you. If it is urgent, email tushar@ruleexpert.com and it will reach the same people.