All 23 Rules and 7 Schedules of the Digital Personal Data Protection Rules, 2025, in plain English. Type to filter instantly.
Names the rules and sets a staggered commencement.
The rules are officially the Digital Personal Data Protection Rules, 2025, notified on 13–14 November 2025. They commence in phases:
Defines the core terms used throughout the Act and Rules.
The privacy notice must be clear, standalone and itemised.
Every request for consent must be accompanied by a clear, plain-language notice, presented independently of other information. It must:
Consent Managers register with the Board and must meet a net-worth and audit-trail bar.
A Consent Manager must be a company registered with the Data Protection Board and meet the conditions in Schedule I, including:
This rule takes effect 12 months after notification (13 Nov 2026).
Government processing for welfare must follow the standards in Schedule II.
When the State or its instrumentalities process personal data to provide a subsidy, benefit, service, certificate, licence or permit, they must follow the standards in Schedule II — lawful processing, purpose limitation, accuracy, security safeguards, defined retention and accountability.
Mandatory technical and organisational measures, including encryption.
Every Data Fiduciary (and its processors) must implement reasonable security safeguards, which include:
Notify affected users immediately and the Board within 72 hours.
On becoming aware of a personal data breach, a Data Fiduciary must:
Default 3-year erasure for large e-commerce, social media and gaming platforms.
Personal data must be erased once the purpose is no longer served and there is no legal requirement to keep it. For certain large platforms listed in Schedule III — notably e-commerce and social media intermediaries with ≥ 2 crore users, and online gaming intermediaries with ≥ 50 lakh users — data is deemed no longer needed 3 years after the Data Principal’s last interaction (or from rule commencement, whichever is later). The fiduciary must also notify the user 48 hours before erasure so they can re-engage.
A published contact point (DPO or designated person) is mandatory.
Every Data Fiduciary must prominently publish the contact details of a Data Protection Officer (for SDFs) or another person able to answer questions about processing — on its website/app and in every privacy notice.
Parental consent must be obtained and verified before processing a child’s data.
Before processing the personal data of a child (under 18), a Data Fiduciary must obtain verifiable consent of a parent/lawful guardian. The parent’s identity and adulthood must be checked using reliable identity details already held, a virtual token, or a Digital Locker / authorised identity service. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited.
Guardian consent, with verification of the guardian’s authority.
For a person with a disability who has a lawful guardian, the fiduciary must obtain the guardian’s verifiable consent, confirming the guardianship is valid under law (e.g., appointed by a court or designated authority) before processing.
Limited carve-outs (e.g. healthcare, education, safety) in Schedule IV.
Some classes of fiduciaries and purposes — listed in Schedule IV, such as certain healthcare, educational, childcare and child-safety activities — are exempt from parts of the children’s-data restrictions (for instance, the ban on tracking) to the extent necessary for that purpose.
Annual DPIA & audit, algorithm due diligence, DPO and localisation duties.
An SDF must additionally:
Access, correction, erasure, grievance and nomination rights, with published timelines.
You have the right to:
Fiduciaries must publish the means to exercise these rights and the time period for responding to requests and grievances.
Transfers allowed, but subject to Government restrictions and conditions.
Personal data may be transferred outside India, but a Data Fiduciary must meet any requirements the Central Government specifies when making data available to a foreign State or its agencies, and must respect any country-specific restrictions the Government notifies. SDFs may face additional localisation requirements (see Rule 13).
Research/archival/statistical processing is exempt if done per prescribed standards.
Processing for research, archiving or statistical purposes is exempt from most obligations of the Act, provided it follows the standards prescribed (consistent with the Schedule II safeguards) and the data is not used to take decisions specific to a Data Principal.
A search-cum-selection committee recommends appointments to the Board.
The Chairperson and Members of the Data Protection Board of India are appointed by the Central Government on the recommendation of a search-cum-selection committee. The Board is to consist of four members (including the Chairperson) with expertise in data governance, law, technology and administration.
Pay and conditions of service are set out in Schedule V.
The salary, allowances and conditions of service of the Chairperson and Members are specified in Schedule V, securing the Board’s independence and defining tenure-related terms.
Defines meeting procedure and how the Board’s digital orders are authenticated.
This rule sets the procedure for Board meetings and how its orders, directions and instruments are authenticated — designed for a digital-first body issuing digitally signed decisions.
The Board operates digitally — online complaints and hearings.
The Board functions as a digital office: citizens can file complaints online and track cases through a dedicated portal and mobile app, and the Board may conduct proceedings using techno-legal measures without requiring physical presence.
Employment terms for the Board’s officers/staff (Schedule VI).
The appointment and service conditions of the Board’s officers and employees are governed by this rule and Schedule VI.
Appeals go to TDSAT and are filed digitally.
A person aggrieved by a Board order may appeal to the Appellate Tribunal (TDSAT). Appeals are filed and heard digitally, and the applicable fee structure mirrors the TRAI/TDSAT framework.
Authorised bodies may require information per Schedule VII.
The Central Government (or an authorised person) may require a Data Fiduciary or intermediary to furnish information for purposes specified in Schedule VII (e.g., sovereignty, security or to discharge functions under the Act), subject to the listed safeguards.
| Contravention | Maximum Penalty |
|---|---|
| Failure to take reasonable security safeguards (prevent breach) | Up to ₹250 crore |
| Failure to notify the Board/users of a personal data breach | Up to ₹200 crore |
| Non-fulfilment of obligations regarding children’s data | Up to ₹200 crore |
| Non-fulfilment of additional SDF obligations | Up to ₹150 crore |
| Breach of any other provision / a Data Principal’s duties | Up to ₹50 crore / up to ₹10,000 |
The Board sets the exact amount within these caps based on the nature, gravity, duration and impact of the breach and any mitigating factors.