Comprehensive Guide

DPDP Rules 2025
Complete Guide

The Digital Personal Data Protection Rules, 2025 were notified by MeitY on November 13, 2025, operationalizing India's landmark data protection framework. This guide provides a comprehensive breakdown of all 23 rules and their compliance requirements.

23 Rules
7 Schedules
3 Phases
₹250Cr Max Penalty
Understanding the Framework

What Are the DPDP Rules 2025?

The Digital Personal Data Protection Rules, 2025 are implementing regulations issued by the Ministry of Electronics and Information Technology (MeitY) under Section 40 of the Digital Personal Data Protection Act, 2023. Published via Gazette notification G.S.R. 846(E), these rules provide the operational framework for India's data protection regime.

Draft rules were published on January 3, 2025 for public consultation, with the final rules notified on November 13, 2025 after considering stakeholder objections and suggestions.

DPDP Act 2023 vs DPDP Rules 2025

AspectDPDP Act 2023DPDP Rules 2025
NatureParent legislation (44 sections)Implementing regulations (23 rules)
Enacted ByParliament of IndiaCentral Government (MeitY)
ContentRights, obligations, penaltiesProcedures, timelines, formats
AmendmentRequires Parliamentary processCentral Government notification
Phased Enforcement

When Do the DPDP Rules Come Into Effect?

The rules establish a phased implementation schedule, providing organizations with structured timelines for compliance readiness.

1
November 13, 2025
Immediate Effect

Phase 1

Rules 1, 2, 17-21

Foundation and governance framework

  • Short title and commencement (Rule 1)
  • Key definitions established (Rule 2)
  • Data Protection Board appointments (Rule 17)
  • Board procedures and digital office (Rules 19-20)
2
November 13, 2026
1 Year from Publication

Phase 2

Rule 4

Consent infrastructure development

  • Consent Manager registration opens
  • ₹2 crore net worth requirement
  • Platform interoperability standards
  • First Schedule obligations activate
3
May 13, 2027
18 Months from Publication

Phase 3

Rules 3, 5-16, 22-23

Full compliance obligations

  • Notice and consent requirements (Rule 3)
  • Security safeguards mandatory (Rule 6)
  • Breach notification protocols (Rule 7)
  • Cross-border transfer mechanisms (Rule 15)
Complete Analysis

All 23 DPDP Rules Explained

A comprehensive breakdown of each rule category, organized by functional area for easy reference and implementation planning.

Foundation

Rules 1-2
Rule 1
Short Title & Commencement

Establishes phased implementation timeline for different rule categories

Rule 2
Definitions

Defines "techno-legal measures", "user account", and "verifiable consent"

Notice & Consent

Rules 3-4
Rule 3
Notice Requirements

Itemized data description, specified purpose, withdrawal mechanism with comparable ease

Rule 4
Consent Manager Registration

Board registration, ₹2 crore net worth, interoperable platform, fiduciary duties

State Processing

Rules 5
Rule 5
State Processing Standards

Processing by State for subsidies, benefits, services, certificates, licences, or permits must follow Second Schedule standards including lawful processing, purpose limitation, data minimization, and security safeguards

Security & Breach

Rules 6-8
Rule 6
Security Safeguards

Encryption/tokenization, access controls, logging with 1-year retention, backups

Rule 7
Breach Notification

Immediate notification to Data Principals, 72-hour notification to Board with detailed report

Rule 8
Data Retention Periods

48-hour erasure notice, 3-year retention for large platforms per Third Schedule

Children & PWDs

Rules 10-12
Rule 10
Children's Data

Verifiable parental consent, identity verification via Digital Locker or government-issued details

Rule 11
Persons with Disability

Lawful guardian verification under RPwD Act 2016 or National Trust Act 1999

Rule 12
Exemptions

Healthcare, education, child safety tracking, transport monitoring per Fourth Schedule

Significant Data Fiduciary

Rules 13
Rule 13
Enhanced Obligations

Annual DPIA and audit, algorithmic risk assessment, data localization for specified categories

Rights & Transfers

Rules 14-16
Rule 14
Data Principal Rights

Rights exercise mechanism, 90-day grievance redressal, nomination facility

Rule 15
Cross-Border Transfers

Subject to Central Government requirements for foreign state data sharing

Rule 16
Research Exemption

Processing for research/archiving/statistics per Second Schedule standards

Data Protection Board

Rules 17-21
Rules 17-18
Appointments & Terms

Search-cum-Selection Committee process, ₹4.5L/month Chairperson salary

Rules 19-20
Procedures

Meeting quorum (1/3 members), digital office functioning, techno-legal measures

Rule 21
Staff Appointments

Officers on deputation up to 5 years per Sixth Schedule

Appeals & Information

Rules 22-23
Rule 22
Appeals

Digital filing to Appellate Tribunal, UPI/RBI-authorized payment methods

Rule 23
Information Calling

Government power to require information per Seventh Schedule purposes

Critical Thresholds

Key Compliance Numbers

Essential deadlines and thresholds that organizations must know for DPDP compliance.

72 hours
Breach notification to Board
90 days
Grievance resolution deadline
1 year
Minimum log retention
₹2 crore
Consent Manager net worth
₹250 crore
Maximum penalty
6 months
Board inquiry completion

Platform User Thresholds (Third Schedule)

2 Crore
E-commerce entities
50 Lakh
Online gaming intermediaries
2 Crore
Social media intermediaries

Platforms exceeding these user thresholds must erase personal data after 3 years of inactivity

Detailed Requirements

The Seven Schedules

The DPDP Rules 2025 include seven schedules containing detailed requirements, conditions, and operational parameters.

1
First ScheduleConsent Manager

Registration conditions (Part A) and operational obligations (Part B)

2
Second ScheduleProcessing Standards

Standards for State processing under Section 7(b) and research exemption

3
Third ScheduleData Retention

Erasure timelines for e-commerce (2Cr users), gaming (50L users), social media

4
Fourth ScheduleChild Data Exemptions

Healthcare, education, transport tracking, safety monitoring exemptions

5
Fifth ScheduleBoard Member Terms

Salaries, allowances, provident fund, travel, medical assistance

6
Sixth ScheduleBoard Staff Terms

Deputation terms, gratuity, leave travel concession

7
Seventh ScheduleInformation Calling

Purposes and authorised persons for government data requests

Authoritative References

Official Sources

For authoritative text of the DPDP Rules 2025, always refer to the official Gazette of India notification. The rules were published under notification number G.S.R. 846(E) dated November 13, 2025.

Gazette of India: G.S.R. 846(E)
MeitY Digital India Portal
Data Protection Board (upon establishment)
Common Questions

Frequently Asked Questions

What are the DPDP Rules 2025?

The DPDP Rules 2025 are implementing regulations notified by MeitY on November 13, 2025, under Section 40 of the Digital Personal Data Protection Act, 2023. They contain 23 rules and 7 schedules that operationalize the Act's provisions.

When do the DPDP Rules come into force?

The rules come into force in three phases: Rules 1, 2, 17-21 took effect immediately (November 13, 2025); Rule 4 comes into force on November 13, 2026; and Rules 3, 5-16, 22-23 come into force on May 13, 2027.

What is the difference between DPDP Act and DPDP Rules?

The DPDP Act 2023 is the parent legislation enacted by Parliament that establishes rights, obligations, and penalties. The DPDP Rules 2025 are subordinate regulations made by the Central Government that provide operational details, procedures, timelines, and formats.

What are the penalties under DPDP Rules?

Penalties are specified in the DPDP Act Schedule: up to ₹250 crore for security safeguard failures, up to ₹200 crore for breach notification failures, up to ₹200 crore for children's data violations, and up to ₹150 crore for Significant Data Fiduciary non-compliance.

Who is a Significant Data Fiduciary?

A Significant Data Fiduciary is any Data Fiduciary notified by the Central Government based on volume/sensitivity of data processed, risk to Data Principals, impact on sovereignty/security, risk to electoral democracy, and public order considerations.

Expert Guidance

Need Help Interpreting the Rules?

Our team of legal and compliance experts can help you understand how the DPDP Rules 2025 apply to your specific organizational context.