Notified 14 November 2025
The DPDP Rules 2025, rule by rule
The Rules turned the principles of the DPDP Act 2023 into dated, countable obligations. Here is every one, and what each costs.
Check where you stand — free Jump to the rules No login, no card. Five minutes to a score and your exposure in rupees.
— until the phase-in ends 10 rules that change how you operate ₹250 Cr for a single security failure
The short answer
What the DPDP Rules 2025 are
The Act said what must happen. The Rules say by when, in what form, and to whom.
The Digital Personal Data Protection Rules, 2025 were notified by the Ministry of Electronics and Information Technology on 14 November 2025. They are the operative instrument under the Digital Personal Data Protection Act, 2023: the Act creates the duties, and the Rules fix the deadlines, the formats and the thresholds that make those duties enforceable.
They are final, not draft. The obligations that touch most organisations phase in over eighteen months from notification, which puts the working deadline at 14 May 2027. Some provisions — those constituting and empowering the Data Protection Board — took effect earlier, because the Board has to exist before it can administer anything else.
The phase-in is staged rather than a single switch. Which provisions bind you first depends on what you process and at what scale — the retention thresholds in the Third Schedule, for instance, only apply above stated user counts.
What changed
Four things that were vague and now are not
Most of the Act survived intact. These are the places where the Rules replaced a principle with a number.
1
A breach now has a clock on it
The Act said tell the Board. Rule 7 says tell the affected people without delay, tell the Board without delay, and give the Board full particulars within 72 hours. There is no severity threshold to hide behind — the duty attaches to any personal data breach, not only to the serious ones.
2
Erasure has both a floor and a ceiling
Rule 8 requires you to erase personal data once the purpose is served — but Rule 8(3) sets a one-year minimum for logs, and Rule 8(2) requires 48 hours’ notice to the person before you erase. The Third Schedule then forces erasure after three years of inactivity for platforms above stated user thresholds.
3
Parental consent has to be verifiable
A tick-box saying “I am over 18” was never going to satisfy §9, and Rule 10 now says what does: reliable identity and age details you already hold, or a virtual token issued by an authorised entity, or a DigiLocker credential. The Fourth Schedule then exempts several sectors from it entirely.
4
Notice has a third link in it
Rule 3 requires a standalone, itemised notice in plain language — and a link not only to withdraw consent and exercise rights, but to complain to the Data Protection Board. That third link is the one almost every existing privacy policy is missing.
Rule by rule
Every rule that changes what you do
The provision, what it actually requires, and the maximum the Act’s Schedule sets for getting it wrong.
Rule 3 · §5₹50 Cr
Give a standalone notice, in plain language, itemising the data you take and the purpose for each — with links to withdraw, to exercise rights, and to complain to the Board.
Notice
Rule 4 · First ScheduleRegistration
A “Consent Manager” is a Board-registered, India-incorporated entity acting for Data Principals. The title is defined, not descriptive — you cannot call yourself one without registering.
Definitions
Rule 6 · §8(5)₹250 Cr
Keep personal data secure with safeguards reasonable for what it is — encryption, access control, logging, and the ability to detect and investigate.
Security
Rule 7 · §8(6)₹200 Cr
On any breach: tell affected people without delay, tell the Board without delay, and file full particulars within 72 hours. No severity threshold.
Breach
Rule 8 · §8(7)₹50 Cr
Erase when the purpose ends. Give 48 hours’ notice first. Keep logs a minimum of one year. Erase after three years’ inactivity where the Third Schedule applies.
Retention
Rule 10 · §9₹200 Cr
Verify parental consent properly: reliable identity and age details already held, a virtual token from an authorised entity, or DigiLocker. Not a self-declared checkbox.
Children
Rule 12 · Fourth ScheduleExemption
Clinical establishments, healthcare professionals, educational institutions, crèches and school transport are exempt from verifiable parental consent and the tracking ban — for those purposes only.
Children
Rule 13 · §10₹150 Cr
If you are named a Significant Data Fiduciary: a data protection impact assessment and an audit every twelve months, algorithmic due diligence, and localisation of data the government specifies.
SDF
Rule 14 · §11–14₹50 Cr
Publish how to make a request, and redress a grievance within 90 days. People can access, correct, erase and nominate — and you must be reachable to hear it.
Rights
Rule 15 · §16₹50 Cr
Transfer outside India is permitted except to countries the government restricts — a blacklist, not a whitelist. Disclose it in the notice.
Cross-border
Penalties are the maximums in the Act’s Schedule (§33). They are assessed per contravention and stack across them — there is no single aggregate cap.
The numbers
Six figures worth committing to memory
Every one of these is a deadline or a threshold somebody will ask you about in a board meeting.
72h
Breach particulars to the Board
Initial intimation without delay; the full particulars inside 72 hours (Rule 7). The clock starts when you become aware, not when you finish investigating.
48h
Notice before you erase
Rule 8(2) requires you to tell the person 48 hours before erasing their data, so they can object or re-engage first.
90d
Grievance redressal
Rule 14(3) sets 90 days to redress a grievance. Note this attaches to grievances — a rights request is a different duty with its own response period.
1yr
Minimum log retention
Rule 8(3) and the Seventh Schedule set a one-year floor for logs. This one cuts against erasure — you cannot delete a record younger than the floor.
3yr
Inactivity erasure
The Third Schedule forces erasure after three years of inactivity for e-commerce and social media above 2 crore users, and online gaming above 50 lakh.
18
The age of a child
Under 18 is a child under §9 — higher than most jurisdictions. Consent must come from a parent, verifiably, unless the Fourth Schedule exempts you.
What it costs
The Schedule, in one table
DPDP penalties are set against the obligation you missed, not against your turnover. The largest is reserved for one failure in particular.
₹250 CrSecurity safeguards §8(5) — failing to keep personal data secure. The single largest item in the Schedule.
₹200 CrBreach notification §8(6) — failing to notify the Board or the affected people, on the Rule 7 timings.
₹200 CrChildren’s data §9 — processing a child’s data without verifiable parental consent, or tracking them.
₹150 CrSignificant Data Fiduciary duties §10 — the additional obligations that attach once you are named an SDF.
₹50 CrEverything else Notice, consent, retention, rights, grievance, vendors, cross-border — each ₹50 Cr.
₹10,000Data Principal duties §15 — the only penalty in the Act that falls on the individual, for frivolous complaints.
A common misreading: ₹250 crore is not a cap. It is the maximum for one category of failure. Penalties are assessed per contravention and stack across them, and the Board weighs what you did about it — §33(2)(e) makes mitigation an express factor.
Reading the Rules is the easy part. Knowing where you fall short is not.
The free Scorecard asks how your organisation actually works and returns a score, your exposure in rupees against these exact sections, and the three gaps that cost the most.
Children
The exemption almost every summary leaves out
§9 is read as an absolute bar on processing a child’s data without a parent. Rule 12 and the Fourth Schedule say otherwise, for named purposes.
Exempt, for that purpose
- Clinical establishments and healthcare professionals, where the processing protects the child’s health
- Educational institutions, for educational activity and for the child’s safety
- Crèches and childcare providers
- School transport, where location is processed for the child’s safety
- Real-time location processing purely for child safety
- Creating a user account limited to an email address
The exemption is purpose-bound. A hospital treating a child is exempt for treatment — not for marketing to their parents.
Still requires verified parental consent
- Any commercial or marketing purpose involving a child
- Behavioural tracking or targeted advertising directed at children (§9(3))
- General consumer services outside the Fourth Schedule list
- Anything a school or hospital does beyond the exempt purpose
Where consent is required, Rule 10 sets the standard: identity and age details you reliably hold, a virtual token from an authorised entity, or DigiLocker.
A definition worth getting right
“Consent Manager” does not mean consent software
Rule 4 and the First Schedule define it as a registered entity. Most tools described as consent managers are not one, including ours.
Under the Act and Rule 4, a Consent Manager is a specific thing: an entity incorporated in India, registered with the Data Protection Board, meeting the net-worth and interoperability conditions in the First Schedule, and acting on behalf of the Data Principal — a neutral intermediary through which a person can give, review and withdraw consent across many fiduciaries from one place.
A tool that a company uses to collect and evidence consent from its own customers is a Data Fiduciary’s tool. It serves the organisation, not the individual, and it does not require registration. Both are legitimate; they are simply different roles under the same statute.
RuleExpert’s consent module is the second kind. We are not a Board-registered Consent Manager, we do not claim to be, and any vendor telling you their software makes you one has misread Rule 4.
Where to start
Three moves that unblock the rest
Nothing else in the Rules can be satisfied until you know what personal data you hold and where it lives.
01 — FIND IT
Map what you hold
Every system, what personal data is in it, whose it is, and who owns the system. You cannot erase, disclose or secure what you have not located — which is why a weak map caps a DPDP compliance score however good everything else looks.
02 — FIX THE NOTICE
Rewrite the notice to Rule 3
Standalone, itemised, plain language, and three links: withdraw, exercise rights, complain to the Board. This is the cheapest item on the list and the most visible to a regulator.
03 — START THE CLOCKS
Put the deadlines somewhere real
72 hours, 48 hours, 90 days and the one-year floor are only met by a process that runs. A calendar reminder is not a control; an owner and an audit trail is.
Questions
About the DPDP Rules 2025
When were the DPDP Rules 2025 notified, and when do they apply?
The Digital Personal Data Protection Rules, 2025 were notified on 14 November 2025. They are final rules, not a draft. The obligations that affect most organisations phase in over eighteen months from notification, putting the working deadline at 14 May 2027. The phase-in is staged rather than a single switch — provisions constituting the Data Protection Board took effect earlier, because the Board must exist before it can administer the rest.
What is the difference between the DPDP Act and the DPDP Rules?
The Act creates the duties; the Rules make them operable. The Digital Personal Data Protection Act, 2023 says you must give notice, take consent, secure data, report breaches and honour rights. The Rules, 2025 say what a notice must contain, how parental consent is verified, how many hours you have to report a breach, how long logs must be kept, and what a Significant Data Fiduciary must audit. Penalties live in the Act’s Schedule; deadlines and formats live in the Rules.
How long do I have to report a data breach under the DPDP Rules?
Rule 7 requires three things. Tell the affected Data Principals without delay. Tell the Data Protection Board without delay. Then give the Board the full particulars — what happened, the extent, the likely consequences and what you have done — within 72 hours. There is no severity threshold: the duty attaches to any personal data breach, so an organisation cannot decide a breach was too small to report.
Do the DPDP Rules 2025 say anything about cookies?
No — there is no cookie-specific provision anywhere in the Act or the Rules. Cookies matter only where they process personal data, and then the ordinary rules apply: a §5 notice that itemises what you collect and why, and §6 consent that is free, specific, informed and as easy to withdraw as it was to give. In practice that means a cookie banner which pre-ticks non-essential categories fails §6, but it fails it as consent, not as a cookie rule.
What is the maximum penalty under the DPDP Act?
₹250 crore, for failing to take reasonable security safeguards under §8(5). Breach notification and children’s data failures carry ₹200 crore each, Significant Data Fiduciary duties ₹150 crore, and most other contraventions ₹50 crore. A common misreading is that ₹250 crore caps total exposure — it does not. Penalties are assessed per contravention and stack across them, and §33(2) directs the Board to weigh the nature of the breach and what you did to mitigate it.
Does the DPDP Act apply to my company if we are small?
Yes. There is no revenue threshold, no headcount threshold and no exemption for startups. If you determine the purpose and means of processing personal data of people in India, you are a Data Fiduciary and the whole Act applies. What scale changes is whether you are additionally named a Significant Data Fiduciary under §10, which adds impact assessments, annual audits and localisation on top — and whether the Third Schedule’s inactivity-erasure thresholds catch you.
Does DPDP compliance mean I am GDPR compliant, or the reverse?
Neither, though the overlap is real. GDPR work gives you a head start on mapping, security and rights handling. What it does not give you is the DPDP-specific machinery: notice in the languages the Act requires, verifiable parental consent under Rule 10 with 18 as the age of a child rather than 13–16, the 72-hour Board filing with no severity threshold, the blacklist model for cross-border transfer under Rule 15, and penalties calculated from India’s Schedule rather than a percentage of global turnover.
Who enforces the DPDP Act, and how does a complaint start?
The Data Protection Board of India. A Data Principal must generally come to you first — which is why Rule 3 requires your notice to carry a link to your grievance channel — and Rule 14(3) gives you 90 days to redress it. If you do not, or they are unsatisfied, they can complain to the Board directly, and your notice has to tell them that too. The Board can inquire, direct remedial measures and impose the Schedule penalties.
What compliance teams tell us
Real client quotes, attributed by role and sector — we never name a client.
DPDP, explained properly
DPDP in India: The Complete Guide to Data Protection Compliance, DPDP Guidelines and Automated Compliance Management (2026)
3 September 2026 · 35 min read DPDP ActHealthcare Vendor Governance Under India’s DPDP Act: The Complete 2026–27 Compliance Framework
27 August 2026 · 32 min read DPDP ActDPDP vs GDPR Compliance Tool: What’s Actually Different, and What a Tool Needs to Handle Both
26 August 2026 · 34 min readWorking across
Know where you fall short.
Five minutes, no login, no card. A score against these exact sections, your exposure in rupees, and the three gaps that cost the most.
Check your DPDP score — free Book a demo Get a free consultation


