[{"data":1,"prerenderedAt":277},["ShallowReactive",2],{"dpdp-\u002Fdpdp-act\u002Fdpdp-rules-2025":3},{"id":4,"title":5,"author":6,"body":7,"category":246,"date":247,"description":248,"draft":249,"extension":250,"eyebrow":246,"faq":251,"h1":258,"keywords":259,"meta":263,"navigation":264,"ogTitle":265,"path":266,"readingTime":267,"relatedArticles":268,"relatedServices":269,"seo":272,"stem":273,"tags":274,"updated":275,"__hash__":276},"dpdp\u002Fdpdp-act\u002Fdpdp-rules-2025.md","DPDP Rules 2025, Explained","DreamyHook Consultancy Services",{"type":8,"value":9,"toc":230},"minimark",[10,19,36,41,53,57,62,79,83,90,94,105,109,116,120,141,145,164,168,175,179,218,225],[11,12,13,14,18],"p",{},"The DPDP Act, 2023 sets the principles. The ",[15,16,17],"strong",{},"DPDP Rules"," turn those principles into operational requirements — the practical detail your systems and processes actually have to meet. This guide explains what the Rules cover and what to do about them.",[20,21,22],"blockquote",{},[11,23,24,27,28,31,32,35],{},[15,25,26],{},"Status note (dated):"," Draft DPDP Rules were published for consultation in ",[15,29,30],{},"January 2025",". The Government has signalled finalization and phased notification since. Because exact figures and dates can change between draft and final text, treat specific numbers below as drawn from the draft and ",[15,33,34],{},"confirm them against the official notified Rules"," before relying on them.",[37,38,40],"h2",{"id":39},"why-the-rules-matter-more-than-the-act-day-to-day","Why the Rules matter more than the Act, day to day",[11,42,43,44,48,49,52],{},"The Act tells you ",[45,46,47],"em",{},"what"," (get valid consent, protect data, honor rights). The Rules tell you ",[45,50,51],{},"how"," — the format of notices, the timelines for responding to requests, what counts as \"reasonable\" security, and the precise duties of Significant Data Fiduciaries. Compliance work lives in the Rules.",[37,54,56],{"id":55},"what-the-rules-address","What the Rules address",[58,59,61],"h3",{"id":60},"consent-and-notice-mechanics","Consent and notice mechanics",[11,63,64,65,68,69,72,73,78],{},"The Rules detail how notices must be presented — clear, itemized, available in English and the languages of the Eighth Schedule — and how consent and ",[15,66,67],{},"withdrawal"," must work. They also set the framework for ",[15,70,71],{},"Consent Managers",", the registered intermediaries who will let people manage consents in one place. We design for this in ",[74,75,77],"a",{"href":76},"\u002Fservices\u002Fconsent-management","Consent & Notice Management",".",[58,80,82],{"id":81},"security-safeguards","Security safeguards",[11,84,85,86,78],{},"The Rules describe the kind of reasonable security measures expected — including encryption, access control, logging, and the retention of processing logs for a defined period — so that \"reasonable safeguards\" isn't left to guesswork. We build these in ",[74,87,89],{"href":88},"\u002Fservices\u002Ftechnical-implementation","Technical Implementation",[58,91,93],{"id":92},"breach-notification","Breach notification",[11,95,96,97,100,101,78],{},"The Rules set out how and when to notify the ",[15,98,99],{},"Data Protection Board of India"," and affected Data Principals after a personal data breach, including the information your notification must contain. A tested runbook is essential — see our breach-readiness work in ",[74,102,104],{"href":103},"\u002Fservices\u002Fmanaged-compliance","Managed Compliance",[58,106,108],{"id":107},"data-principal-rights","Data Principal rights",[11,110,111,112,78],{},"The Rules specify how Data Fiduciaries must enable and respond to rights requests — access, correction, erasure, grievance — within defined timelines. Automating this is the only way to stay reliable at scale: see ",[74,113,115],{"href":114},"\u002Fservices\u002Fdata-principal-rights","Data Principal Rights Automation",[58,117,119],{"id":118},"childrens-data","Children's data",[11,121,122,123,126,127,131,132,136,137,78],{},"The Rules address ",[15,124,125],{},"verifiable parental consent"," and the mechanics of age assurance, alongside the Act's prohibition on tracking, behavioural monitoring, and targeted advertising directed at children. This is especially important for ",[74,128,130],{"href":129},"\u002Findustries\u002Fedtech","edtech",", ",[74,133,135],{"href":134},"\u002Findustries\u002Fhealthtech","healthtech",", and ",[74,138,140],{"href":139},"\u002Findustries\u002Fonline-gaming","online gaming",[58,142,144],{"id":143},"significant-data-fiduciaries","Significant Data Fiduciaries",[11,146,147,148,151,152,155,156,159,160,78],{},"For organizations notified as SDFs, the Rules detail the added duties — appointing a ",[15,149,150],{},"DPO based in India",", conducting an ",[15,153,154],{},"annual Data Protection Impact Assessment",", and undergoing an ",[15,157,158],{},"annual independent audit",". See ",[74,161,163],{"href":162},"\u002Fdpdp-act\u002Fsignificant-data-fiduciary","What is a Significant Data Fiduciary?",[58,165,167],{"id":166},"retention-and-erasure","Retention and erasure",[11,169,170,171,174],{},"The draft Rules introduced ",[15,172,173],{},"default retention limits for large platforms"," — for example, erasing personal data after roughly three years of user inactivity (with advance notice) for large e-commerce, online gaming, and social-media intermediaries above notified user thresholds. Confirm the thresholds and periods against the final text.",[37,176,178],{"id":177},"what-to-do-now","What to do now",[180,181,182,193,206],"ol",{},[183,184,185,188,189,78],"li",{},[15,186,187],{},"Map your obligations to the Rules",", not just the Act — that's where the work is. Start with a ",[74,190,192],{"href":191},"\u002Fservices\u002Freadiness-audit","readiness audit",[183,194,195,198,199,205],{},[15,196,197],{},"Prioritize by the"," ",[74,200,202],{"href":201},"\u002Fdpdp-act\u002Ftimeline-deadlines",[15,203,204],{},"timeline"," — build the deadline-critical controls first.",[183,207,208,198,211,217],{},[15,209,210],{},"Use the",[74,212,214],{"href":213},"\u002Fdpdp-act\u002Fcompliance-checklist",[15,215,216],{},"compliance checklist"," to track progress.",[11,219,220,221,78],{},"Want a personalized read on which Rule obligations bite hardest for you? Take the free ",[74,222,224],{"href":223},"\u002Fquick-scan","DPDP Quick Scan",[20,226,227],{},[11,228,229],{},"General information, not legal advice. Always confirm against the official notified Rules.",{"title":231,"searchDepth":232,"depth":232,"links":233},"",3,[234,236,245],{"id":39,"depth":235,"text":40},2,{"id":55,"depth":235,"text":56,"children":237},[238,239,240,241,242,243,244],{"id":60,"depth":232,"text":61},{"id":81,"depth":232,"text":82},{"id":92,"depth":232,"text":93},{"id":107,"depth":232,"text":108},{"id":118,"depth":232,"text":119},{"id":143,"depth":232,"text":144},{"id":166,"depth":232,"text":167},{"id":177,"depth":235,"text":178},"Rules","2026-01-20","What the DPDP Rules mean for your business — the operational detail behind the Act, the phased timeline, and the obligations you need to act on.",false,"md",[252,255],{"q":253,"a":254},"When were the DPDP Rules released?","Draft DPDP Rules were released for public consultation in January 2025. The government has indicated the Rules are being finalized and notified on a phased basis — confirm the current status of any provision against the official notification.",{"q":256,"a":257},"Do the Rules change what the Act requires?","The Rules don't change the Act's principles — they add the operational detail: how consent notices should work, breach-notification timelines, SDF obligations, children's-data mechanics, and more.","DPDP Rules 2025, explained",[260,261,262],"DPDP Rules 2025","DPDP Rules explained","DPDP implementation",{},true,null,"\u002Fdpdp-act\u002Fdpdp-rules-2025","8 min read",[201,213],[270,271],"technical-implementation","consent-management",{"title":5,"description":248},"dpdp-act\u002Fdpdp-rules-2025",[],"2026-05-22","uZTzEmpF7zdOOaHxAM9GmUtRNBc8gl8JOYIBdD3Z9ME",1780230335953]