The DPDP reference hub
In short
India's data protection regime sits in two instruments. The Digital Personal Data Protection Act 2023 (Act 22 of 2023) sets the obligations, the rights and the penalties. The Digital Personal Data Protection Rules 2025, notified on 13 November 2025 by gazette notification G.S.R. 846(E), set the operational detail: what a notice must contain, what security safeguards mean at a minimum, how a personal data breach is intimated, and how the Data Protection Board of India functions.
The Rules commence in three groups under Rule 1. Rules 1, 2 and 17 to 21 came into force on the date of publication. Rule 4 comes into force one year after publication. Rules 3, 5 to 16, 22 and 23 come into force eighteen months after publication.
01How this hub is organised
Each page answers one question, cites the section or rule it rests on, and links to the provisions that operationalise it. Explainer pages come first because they are what most readers arrive looking for. Section by section pages for the Act, rule by rule pages for the Rules and pages for the seven Schedules follow.
| Path | Contents |
|---|---|
| /explainers/ | Cross cutting topics: breach timelines, Significant Data Fiduciary status, consent managers, cross border transfer, children's data, penalties |
| /act/ | The 44 sections of the DPDP Act 2023 and the Schedule to the Act |
| /rules/ | The 23 rules of the DPDP Rules 2025 |
| /schedules/ | The seven Schedules to the Rules |
02What is in force today
Two points are worth separating, because they are commonly run together.
- In force now. Rules 1, 2 and 17 to 21, which cover commencement, definitions, the appointment of the Chairperson and Members, the procedure for meetings of the Board, the functioning of the Board as a digital office, and the terms of service of its officers and employees.
- Not yet in force. The operational obligations that most compliance programmes are built around, including Rule 3 on notice, Rule 6 on reasonable security safeguards, Rule 7 on intimation of personal data breach, Rule 13 on Significant Data Fiduciary obligations and Rule 15 on transfer outside India. These come into force eighteen months after publication. Rule 4, on Consent Manager registration, comes into force one year after publication.
Separately, and already in force, the CERT-In Directions of April 2022 require reporting of specified cyber incidents within six hours. A Data Fiduciary that suffers a personal data breach today is already inside a reporting obligation, whatever the DPDP commencement position.
03Explainer pages
The DPDP breach notification timeline
What Rule 7 of the DPDP Rules 2025 requires on becoming aware of a personal data breach, what goes to the Data Principal, what goes to the Data Protection Board, and when the seventy two hour window closes.
CERT-In six hours, DPDP seventy two hours
Two reporting clocks run from the same awareness anchor on the same incident. What each one requires, who it goes to, and why the collision is where most incident response plans break.
Significant Data Fiduciary status
How the Central Government designates a Significant Data Fiduciary under Section 10 of the DPDP Act 2023, and the additional obligations Rule 13 attaches to that designation.
Data Fiduciary and Data Processor
The distinction that determines who carries every obligation under the DPDP Act 2023, why India does not use the word controller, and where the boundary is most often drawn wrongly.
The Consent Manager framework
Registration conditions and obligations for Consent Managers under Rule 4 of the DPDP Rules 2025 and the First Schedule, including the net worth condition and the seven year record requirement.
Cross border transfer of personal data
How Section 16 of the DPDP Act 2023 and Rule 15 of the DPDP Rules 2025 govern transfer of personal data outside India, and how the Rule 13(4) restriction on Significant Data Fiduciaries differs.
Children's data and verifiable consent
What Section 9 of the DPDP Act 2023 requires for processing a child's personal data, how Rules 10 to 12 operationalise verifiable consent, and which classes and purposes the Fourth Schedule exempts.
The DPDP compliance timeline
The three commencement groups set by Rule 1 of the DPDP Rules 2025, which rules are in force now, and how to describe the phased timeline accurately.
The DPDP penalty structure
How Section 33 of the DPDP Act 2023 and the Schedule to the Act set monetary penalties, what the Board must consider before imposing one, and how an order is appealed.
04The DPDP Rules 2025, rule by rule
All twenty three rules, each page written from the operative text of the gazette notification.
Rule 1, short title and commencement
The commencement structure of the DPDP Rules 2025: which rules came into force on publication, which after one year and which after eighteen months.
Rule 2, definitions
The four expressions defined in the DPDP Rules 2025 and the rule that words not defined in the Rules carry their meaning from the DPDP Act 2023.
Rule 3, notice to the Data Principal
What a consent notice must contain under Rule 3 of the DPDP Rules 2025, including the standalone requirement, the itemised description of personal data and the withdrawal link.
Rule 4, Consent Manager registration
How a Consent Manager applies to the Data Protection Board for registration under Rule 4 of the DPDP Rules 2025, and the Board's powers of direction, suspension and cancellation.
Rule 5, processing by the State
How Rule 5 of the DPDP Rules 2025 applies the Second Schedule standards to processing by the State and its instrumentalities for a subsidy, benefit, service, certificate, licence or permit.
Rule 6, reasonable security safeguards
The seven minimum security safeguards a Data Fiduciary must take under Rule 6 of the DPDP Rules 2025, including the one year log retention floor and the contractual obligation on Data Processors.
Rule 7, intimation of personal data breach
The text of the two intimation obligations in Rule 7 of the DPDP Rules 2025: to each affected Data Principal without delay, and to the Data Protection Board without delay and then in detail within seventy two hours.
Rule 8, erasure and the retention floor
The Third Schedule erasure periods, the forty eight hour warning before erasure, and the one year minimum retention of personal data, traffic data and logs under Rule 8 of the DPDP Rules 2025.
Rule 9, publishing contact information
The obligation on every Data Fiduciary under Rule 9 of the DPDP Rules 2025 to publish the business contact information of the Data Protection Officer, if applicable, or of a person who can answer questions about processing.
Rule 10, verifiable parental consent
How a Data Fiduciary verifies that an individual identifying herself as a parent is an identifiable adult under Rule 10 of the DPDP Rules 2025, and the four illustrated cases in the rule.
Rule 11, consent through a lawful guardian
What a Data Fiduciary must verify under Rule 11 of the DPDP Rules 2025 when obtaining verifiable consent from the lawful guardian of a person with disability.
Rule 12, children's data exemptions
The classes of Data Fiduciary and the purposes for which Sections 9(1) and 9(3) of the DPDP Act 2023 do not apply, under Rule 12 and the Fourth Schedule.
Rule 13, Significant Data Fiduciary obligations
The four additional obligations Rule 13 of the DPDP Rules 2025 places on a Significant Data Fiduciary, including the annual assessment and audit and the report to the Board.
Rule 14, exercising Data Principal rights
What a Data Fiduciary and a Consent Manager must publish for Data Principals to exercise their rights under Rule 14 of the DPDP Rules 2025, and the ninety day grievance redressal period.
Rule 15, transfer outside India
What Rule 15 of the DPDP Rules 2025 actually says about transferring personal data outside India, and what it leaves to be specified by the Central Government.
Rule 16, research and archiving exemption
How Rule 16 of the DPDP Rules 2025 disapplies the Act to processing necessary for research, archiving or statistical purposes, conditional on the Second Schedule standards.
Rule 17, appointment to the Board
The two Search-cum-Selection Committees that recommend individuals for appointment as Chairperson and as Members of the Data Protection Board under Rule 17 of the DPDP Rules 2025.
Rule 18, terms of service of the Board
How Rule 18 of the DPDP Rules 2025 applies the Fifth Schedule to the salary, allowances and other terms and conditions of service of the Chairperson and other Members of the Data Protection Board.
Rule 19, meetings and inquiry timelines
Quorum, voting, circulation, emergency action and the six month inquiry period under Rule 19 of the DPDP Rules 2025.
Rule 20, the Board as a digital office
How Rule 20 of the DPDP Rules 2025 allows the Data Protection Board to conduct proceedings without requiring physical presence, and what power it expressly preserves.
Rule 21, officers and employees
How the Data Protection Board appoints its officers and employees under Rule 21 of the DPDP Rules 2025, and the Sixth Schedule terms that apply to them.
Rule 22, appeal to the Appellate Tribunal
How an appeal against an order or direction of the Data Protection Board is filed under Rule 22 of the DPDP Rules 2025, including the fee and the digital filing requirement.
Rule 23, calling for information
The Central Government's power under Rule 23 of the DPDP Rules 2025 to require information from a Data Fiduciary or intermediary for the purposes in the Seventh Schedule, and the confidentiality direction that can accompany it.
05Common questions
Is the DPDP Act in force?
The Act was brought into force in phases by gazette notification G.S.R. 843(E) dated 13 November 2025, issued the same day as the Rules. The provisions carrying the main obligations on Data Fiduciaries take effect on the phased commencement described in Rule 1 of the Rules.
Which gazette notifications should be cited?
G.S.R. 843(E), 844(E), 845(E) and 846(E), all dated 13 November 2025. G.S.R. 846(E) contains the Rules. A corrigendum, G.S.R. 892(E) dated 10 December 2025, is reported in secondary sources and should be read alongside the principal notification.
Does this site publish the official text?
No. This hub summarises and explains. Read the gazette notification for the operative text.
Ask an AI assistant about this page
Each button opens the assistant with the prompt below already written.
Answers are generated by third party systems and are not published or verified by this site. Check anything load bearing against the gazette text.