DPDP Rules 2025 — Explained

All 23 Rules and 7 Schedules of the Digital Personal Data Protection Rules, 2025, in plain English. Type to filter instantly.

Phased Enforcement Timeline

13 Nov 2025
Board (DPBI) established; Rules 1–2 & 16–21 live.
13 Nov 2026
Consent Manager registration (Rule 4) live.
13 May 2027
Full compliance: notice, security, breach, retention, children, SDF, rights, transfer.
Rule 1

Short Title and Commencement

Names the rules and sets a staggered commencement.

The rules are officially the Digital Personal Data Protection Rules, 2025, notified on 13–14 November 2025. They commence in phases:

  • Immediately (13 Nov 2025): Rules 1, 2 and the rules governing the Data Protection Board (Rules 16–21) — so the Board can be set up first.
  • After 12 months (13 Nov 2026): Rule 4 (Consent Managers).
  • After 18 months (13 May 2027): The core compliance rules — notice, security, breach reporting, retention, children’s data, SDF duties, data-principal rights and cross-border transfer.
Permalink to Rule 1
Rule 2

Definitions

Defines the core terms used throughout the Act and Rules.

  • Data Principal: the individual the personal data is about (for a child, the parent/lawful guardian).
  • Data Fiduciary: any person who, alone or with others, decides the purpose and means of processing personal data.
  • Data Processor: a person who processes personal data on behalf of a Data Fiduciary.
  • Significant Data Fiduciary (SDF): a fiduciary (or class) notified by the Government based on volume/sensitivity of data and risk.
  • Consent Manager: a Board-registered entity that lets a Data Principal give, manage, review and withdraw consent through an interoperable platform.
  • Board: the Data Protection Board of India (DPBI).
Permalink to Rule 2
Rule 3

Notice Given by Data Fiduciary to Data Principal

The privacy notice must be clear, standalone and itemised.

Every request for consent must be accompanied by a clear, plain-language notice, presented independently of other information. It must:

  • Itemise the personal data being collected and the specific purpose of processing;
  • Describe the goods/services or use enabled by that processing;
  • Explain how to withdraw consent (as easily as it was given), how to exercise rights, and how to complain to the Board;
  • Be available in English or any language in the Eighth Schedule of the Constitution.
Permalink to Rule 3
Rule 4

Registration and Obligations of Consent Manager

Consent Managers register with the Board and must meet a net-worth and audit-trail bar.

A Consent Manager must be a company registered with the Data Protection Board and meet the conditions in Schedule I, including:

  • A minimum net worth of ₹2 crore;
  • A secure, neutral, interoperable platform that lets users give/review/withdraw consent;
  • Maintaining consent records / audit trails for at least 7 years;
  • Avoiding conflicts of interest and acting in a fiduciary capacity toward the Data Principal.

This rule takes effect 12 months after notification (13 Nov 2026).

Permalink to Rule 4
Rule 5

Processing by the State for Subsidies, Benefits & Services

Government processing for welfare must follow the standards in Schedule II.

When the State or its instrumentalities process personal data to provide a subsidy, benefit, service, certificate, licence or permit, they must follow the standards in Schedule II — lawful processing, purpose limitation, accuracy, security safeguards, defined retention and accountability.

Permalink to Rule 5
Rule 6

Reasonable Security Safeguards

Mandatory technical and organisational measures, including encryption.

Every Data Fiduciary (and its processors) must implement reasonable security safeguards, which include:

  • Encryption, obfuscation or masking of personal data, and virtual tokens where appropriate;
  • Access control to computer resources;
  • Logs and monitoring to detect and investigate unauthorised access (retained for a defined period);
  • Backups for continuity, and contractual security obligations on Data Processors.
Permalink to Rule 6
Rule 7

Intimation of Personal Data Breach

Notify affected users immediately and the Board within 72 hours.

On becoming aware of a personal data breach, a Data Fiduciary must:

  • Without delay, inform each affected Data Principal — describing the breach, likely consequences, mitigation measures, and safety steps the user can take;
  • Give the Board an initial intimation without delay, followed by a detailed report within 72 hours (extendable on request) covering facts, impact, mitigation and remedial actions.
Permalink to Rule 7
Rule 8

Retention & Erasure (When the Purpose Is No Longer Served)

Default 3-year erasure for large e-commerce, social media and gaming platforms.

Personal data must be erased once the purpose is no longer served and there is no legal requirement to keep it. For certain large platforms listed in Schedule III — notably e-commerce and social media intermediaries with ≥ 2 crore users, and online gaming intermediaries with ≥ 50 lakh users — data is deemed no longer needed 3 years after the Data Principal’s last interaction (or from rule commencement, whichever is later). The fiduciary must also notify the user 48 hours before erasure so they can re-engage.

Permalink to Rule 8
Rule 9

Contact Information for Processing Questions

A published contact point (DPO or designated person) is mandatory.

Every Data Fiduciary must prominently publish the contact details of a Data Protection Officer (for SDFs) or another person able to answer questions about processing — on its website/app and in every privacy notice.

Permalink to Rule 9
Rule 10

Verifiable Consent for a Child’s Data

Parental consent must be obtained and verified before processing a child’s data.

Before processing the personal data of a child (under 18), a Data Fiduciary must obtain verifiable consent of a parent/lawful guardian. The parent’s identity and adulthood must be checked using reliable identity details already held, a virtual token, or a Digital Locker / authorised identity service. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited.

Permalink to Rule 10
Rule 11

Verifiable Consent for Persons with Disabilities

Guardian consent, with verification of the guardian’s authority.

For a person with a disability who has a lawful guardian, the fiduciary must obtain the guardian’s verifiable consent, confirming the guardianship is valid under law (e.g., appointed by a court or designated authority) before processing.

Permalink to Rule 11
Rule 12

Exemptions for Certain Child-Data Processing

Limited carve-outs (e.g. healthcare, education, safety) in Schedule IV.

Some classes of fiduciaries and purposes — listed in Schedule IV, such as certain healthcare, educational, childcare and child-safety activities — are exempt from parts of the children’s-data restrictions (for instance, the ban on tracking) to the extent necessary for that purpose.

Permalink to Rule 12
Rule 13

Additional Obligations of Significant Data Fiduciaries (SDFs)

Annual DPIA & audit, algorithm due diligence, DPO and localisation duties.

An SDF must additionally:

  • Conduct an annual Data Protection Impact Assessment (DPIA) and an annual independent audit, and report findings to the Board;
  • Appoint a Data Protection Officer (DPO) based in India, reporting to the board/management;
  • Exercise due diligence on algorithmic software to ensure it does not pose risks to data-principal rights;
  • Comply with any Government restrictions on transferring certain personal/traffic data abroad.
Permalink to Rule 13
Rule 14

Rights of Data Principals

Access, correction, erasure, grievance and nomination rights, with published timelines.

You have the right to:

  • Access a summary of your data and the processing;
  • Correction, completion, updating and erasure of your data;
  • Grievance redressal from the fiduciary/consent manager; and
  • Nominate someone to exercise your rights in case of death or incapacity.

Fiduciaries must publish the means to exercise these rights and the time period for responding to requests and grievances.

Permalink to Rule 14
Rule 15

Transfer of Personal Data Outside India

Transfers allowed, but subject to Government restrictions and conditions.

Personal data may be transferred outside India, but a Data Fiduciary must meet any requirements the Central Government specifies when making data available to a foreign State or its agencies, and must respect any country-specific restrictions the Government notifies. SDFs may face additional localisation requirements (see Rule 13).

Permalink to Rule 15
Rule 16

Exemption for Research, Archiving & Statistics

Research/archival/statistical processing is exempt if done per prescribed standards.

Processing for research, archiving or statistical purposes is exempt from most obligations of the Act, provided it follows the standards prescribed (consistent with the Schedule II safeguards) and the data is not used to take decisions specific to a Data Principal.

Permalink to Rule 16
Rule 17

Appointment of the Chairperson & Members of the Board

A search-cum-selection committee recommends appointments to the Board.

The Chairperson and Members of the Data Protection Board of India are appointed by the Central Government on the recommendation of a search-cum-selection committee. The Board is to consist of four members (including the Chairperson) with expertise in data governance, law, technology and administration.

Permalink to Rule 17
Rule 18

Salary, Allowances & Service Conditions of Members

Pay and conditions of service are set out in Schedule V.

The salary, allowances and conditions of service of the Chairperson and Members are specified in Schedule V, securing the Board’s independence and defining tenure-related terms.

Permalink to Rule 18
Rule 19

Board Meetings & Authentication of Orders

Defines meeting procedure and how the Board’s digital orders are authenticated.

This rule sets the procedure for Board meetings and how its orders, directions and instruments are authenticated — designed for a digital-first body issuing digitally signed decisions.

Permalink to Rule 19
Rule 20

Functioning of the Board as a Digital Office

The Board operates digitally — online complaints and hearings.

The Board functions as a digital office: citizens can file complaints online and track cases through a dedicated portal and mobile app, and the Board may conduct proceedings using techno-legal measures without requiring physical presence.

Permalink to Rule 20
Rule 21

Terms of Service of Board Officers & Employees

Employment terms for the Board’s officers/staff (Schedule VI).

The appointment and service conditions of the Board’s officers and employees are governed by this rule and Schedule VI.

Permalink to Rule 21
Rule 22

Appeal to the Appellate Tribunal

Appeals go to TDSAT and are filed digitally.

A person aggrieved by a Board order may appeal to the Appellate Tribunal (TDSAT). Appeals are filed and heard digitally, and the applicable fee structure mirrors the TRAI/TDSAT framework.

Permalink to Rule 22
Rule 23

Calling for Information from Fiduciaries/Intermediaries

Authorised bodies may require information per Schedule VII.

The Central Government (or an authorised person) may require a Data Fiduciary or intermediary to furnish information for purposes specified in Schedule VII (e.g., sovereignty, security or to discharge functions under the Act), subject to the listed safeguards.

Permalink to Rule 23

Penalties at a Glance

ContraventionMaximum Penalty
Failure to take reasonable security safeguards (prevent breach)Up to ₹250 crore
Failure to notify the Board/users of a personal data breachUp to ₹200 crore
Non-fulfilment of obligations regarding children’s dataUp to ₹200 crore
Non-fulfilment of additional SDF obligationsUp to ₹150 crore
Breach of any other provision / a Data Principal’s dutiesUp to ₹50 crore / up to ₹10,000

The Board sets the exact amount within these caps based on the nature, gravity, duration and impact of the breach and any mitigating factors.

The 7 Schedules

  • Schedule I — Conditions & duties of Consent Managers (net worth, audit trails).
  • Schedule II — Standards for State processing of personal data.
  • Schedule III — Retention periods by class of fiduciary (the 3-year erasure table).
  • Schedule IV — Classes/purposes exempt from certain child-data obligations.
  • Schedule V — Salary & service terms of Board Chairperson and Members.
  • Schedule VI — Service terms of the Board’s officers and employees.
  • Schedule VII — Purposes for which information may be called from fiduciaries.
No rules match your search. Try “consent”, “breach”, “children” or “penalty”.
Test yourself & earn a certificate