Rules

DPDP Rules 2025, explained

What the DPDP Rules mean for your business — the operational detail behind the Act, the phased timeline, and the obligations you need to act on.

By DreamyHook Consultancy ServicesUpdated 8 min read

The DPDP Act, 2023 sets the principles. The DPDP Rules turn those principles into operational requirements — the practical detail your systems and processes actually have to meet. This guide explains what the Rules cover and what to do about them.

Status note (dated): Draft DPDP Rules were published for consultation in January 2025. The Government has signalled finalization and phased notification since. Because exact figures and dates can change between draft and final text, treat specific numbers below as drawn from the draft and confirm them against the official notified Rules before relying on them.

Why the Rules matter more than the Act, day to day

The Act tells you what (get valid consent, protect data, honor rights). The Rules tell you how — the format of notices, the timelines for responding to requests, what counts as "reasonable" security, and the precise duties of Significant Data Fiduciaries. Compliance work lives in the Rules.

What the Rules address

The Rules detail how notices must be presented — clear, itemized, available in English and the languages of the Eighth Schedule — and how consent and withdrawal must work. They also set the framework for Consent Managers, the registered intermediaries who will let people manage consents in one place. We design for this in Consent & Notice Management.

Security safeguards

The Rules describe the kind of reasonable security measures expected — including encryption, access control, logging, and the retention of processing logs for a defined period — so that "reasonable safeguards" isn't left to guesswork. We build these in Technical Implementation.

Breach notification

The Rules set out how and when to notify the Data Protection Board of India and affected Data Principals after a personal data breach, including the information your notification must contain. A tested runbook is essential — see our breach-readiness work in Managed Compliance.

Data Principal rights

The Rules specify how Data Fiduciaries must enable and respond to rights requests — access, correction, erasure, grievance — within defined timelines. Automating this is the only way to stay reliable at scale: see Data Principal Rights Automation.

Children's data

The Rules address verifiable parental consent and the mechanics of age assurance, alongside the Act's prohibition on tracking, behavioural monitoring, and targeted advertising directed at children. This is especially important for edtech, healthtech, and online gaming.

Significant Data Fiduciaries

For organizations notified as SDFs, the Rules detail the added duties — appointing a DPO based in India, conducting an annual Data Protection Impact Assessment, and undergoing an annual independent audit. See What is a Significant Data Fiduciary?.

Retention and erasure

The draft Rules introduced default retention limits for large platforms — for example, erasing personal data after roughly three years of user inactivity (with advance notice) for large e-commerce, online gaming, and social-media intermediaries above notified user thresholds. Confirm the thresholds and periods against the final text.

What to do now

  1. Map your obligations to the Rules, not just the Act — that's where the work is. Start with a readiness audit.
  2. Prioritize by the timeline — build the deadline-critical controls first.
  3. Use the compliance checklist to track progress.

Want a personalized read on which Rule obligations bite hardest for you? Take the free DPDP Quick Scan.

General information, not legal advice. Always confirm against the official notified Rules.

Frequently asked questions

Draft DPDP Rules were released for public consultation in January 2025. The government has indicated the Rules are being finalized and notified on a phased basis — confirm the current status of any provision against the official notification.

The Rules don't change the Act's principles — they add the operational detail: how consent notices should work, breach-notification timelines, SDF obligations, children's-data mechanics, and more.

See how this applies to you

The Quick Scan turns this guide into a personalized snapshot — your risk, your likely SDF status, and your top gaps — in five minutes.

Take the free Quick Scan

The deadline isn't moving. Start today.

Get your free DPDP Quick Scan — no obligation, instant results. See where you stand in five minutes.