DPDP Wiki Talk to us

/Guides · Compliance leads

The DPDP Rules, 2025 explained: what each rule does

A rule-by-rule walkthrough of the DPDP Rules, 2025, with the parent section of the Act for each rule and a summary of all seven schedules.

Interpretation · not legal adviceUpdated 9 September 20268 min read
Interpretation, not legal advice. This is a plain-English interpretation of the official text, prepared by the DPDP Wiki editorial team. It is not the law and not legal advice, and it may be incomplete or wrong. Always rely on the official text of the Act, the Rules and the notifications, and take advice from a qualified professional for your situation. Every statement links to the official provision it rests on.

The Digital Personal Data Protection Rules, 2025 were made under section 40 of the Act and published as G.S.R. 846(E) on 13 November 2025, after a January 2025 draft and public objections on it. This guide takes the 23 rules and seven schedules in order, with the part of the Act each hangs off.

Rules 1 and 2: the basics#

Rule 1 names the Rules and sets commencement in three tranches: rules 1, 2 and 17 to 21 from the date of publication, rule 4 one year later, and rules 3, 5 to 16, 22 and 23 eighteen months later. Rule 2 defines four expressions, including "user account", the online account a Data Principal registers with a Data Fiduciary, with its profiles and handles, and "verifiable consent", meaning consent as specified in rule 10 or 11.

Rule 3, under section 5, says a notice must stand on its own and give "in clear and plain language, a fair account of the details necessary to enable the Data Principal to give specific and informed consent", including at minimum an itemised description of the personal data and the specified purposes. It must also carry the means for withdrawing consent as easily as it was given, exercising rights and complaining to the Board.

Rule 4, under sections 6(8) and 6(9), governs Consent Managers: a person meeting the conditions in Part A of the First Schedule may apply to the Board for registration, and carries the Part B obligations once registered. The Board may direct corrective measures, and suspend or cancel a registration after a hearing.

State processing, security and breaches#

Rule 5, under section 7(b), requires State processing to provide a subsidy, benefit, service, certificate, licence or permit to follow the Second Schedule standards, and defines "under law", "under policy" and "using public funds".

Rule 6, under section 8(5), lists the minimum security safeguards: encryption, obfuscation, masking or virtual tokens; access control; logs, monitoring and review; backups; keeping those logs and data for one year unless another law requires otherwise; contract terms where a Data Processor is used; and technical and organisational measures for effective observance.

Rule 7, under section 8(6), splits breach reporting into two tracks. Affected Data Principals get, without delay and in plain language, its nature, extent and timing, the consequences for them, the mitigation under way, what they can do, and a contact. The Board gets the nature, extent, timing, location and likely impact without delay, then a fuller account within seventy-two hours.

Retention, contact and children#

Rule 8, under sections 8(7) and 8(8), fixes when a specified purpose is deemed no longer served: for the classes in the Third Schedule, data must be erased after the stated period of inactivity, on forty-eight hours' warning, unless a law requires retention. Sub-rule (3) separately requires every Data Fiduciary to keep personal data, traffic data and logs for at least one year for the Seventh Schedule purposes.

Rule 9, under section 8(9), requires every Data Fiduciary to publish prominently, and repeat in every response about rights, the business contact information of its Data Protection Officer if it has one, or of a person who can answer questions about the processing.

Rule 10, under section 9(1), sets out verifiable consent for a child's personal data. The Data Fiduciary must obtain the parent's consent first and observe due diligence that she is an identifiable adult, from reliable identity and age details it holds or from details voluntarily provided, including a virtual token from an authorised entity.

Rule 11, also under section 9(1), does the same for a person with disability who has a lawful guardian, requiring due diligence that the guardian was appointed by a court, by a designated authority under the Rights of Persons with Disabilities Act, 2016, or by a local level committee under the National Trust Act, 1999.

Rule 12, under section 9(4), switches off sections 9(1) and 9(3), verifiable consent and the ban on tracking, behavioural monitoring and targeted advertising, for the classes and purposes in the Fourth Schedule.

Significant Data Fiduciaries, rights and transfers#

Rule 13, under section 10, adds three duties for a Significant Data Fiduciary: a Data Protection Impact Assessment and audit every twelve months, with significant observations reported to the Board; due diligence that its technical measures, "including algorithmic software", are not likely to risk the rights of Data Principals; and no transfer outside India of personal data specified by the Central Government on a committee's recommendation, or of the traffic data about its flow.

Rule 14, under sections 11 to 14, covers how rights are exercised. The Data Fiduciary and, where relevant, the Consent Manager must publish prominently how a request is made, what identifiers are needed, and a grievance redressal system for responding "within a reasonable period not exceeding ninety days". A Data Principal may nominate one or more individuals under the terms of service and applicable law.

Rule 15, under section 16, allows transfer of personal data outside India, subject to any requirements the Central Government specifies by general or special order for making that data available to a foreign State or a person under its control.

Rule 16, under section 17(2)(b), disapplies the Act for research, archiving or statistical processing carried on in accordance with the Second Schedule.

The Board and appeals#

Rule 17, under section 19(2), creates two Search-cum-Selection Committees, each with two experts of repute: one chaired by the Cabinet Secretary to recommend the Chairperson, the other by the Secretary of the Ministry of Electronics and Information Technology. Rule 18, under section 20(1), points to the Fifth Schedule for pay and service terms.

Rule 19, under section 23(1), sets meeting procedure: the Chairperson fixes meetings and agenda, one third of the membership is the quorum, and decisions go by majority with a casting vote. Sub-rule (9) requires an inquiry to be completed within six months, extendable, for reasons recorded in writing, by up to three months at a time.

Rule 20, under section 28(1), says the Board shall function as a digital office, using techno-legal measures so proceedings need no physical presence. Rule 21, under section 24, lets the Board appoint officers and employees with the Central Government's approval, on the Sixth Schedule terms.

Rule 22, under section 29, requires appeals to be filed digitally with the Appellate Tribunal, with the same fee as an appeal under the Telecom Regulatory Authority of India Act, 1997 unless reduced or waived, paid through the Unified Payments Interface or another system authorised by the Reserve Bank of India. The Tribunal is guided by natural justice rather than the Code of Civil Procedure, 1908, and also functions as a digital office.

Rule 23, under section 36, lets the Central Government require a Data Fiduciary or intermediary to furnish information for the Seventh Schedule purposes, through the authorised person named there. Where disclosure would prejudicially affect India's sovereignty and integrity or the security of the State, it may direct that the request not be disclosed.

The seven schedules#

ScheduleRead withContents
Firstrule 4Part A, nine registration conditions for a Consent Manager, among them incorporation in India, net worth of at least two crore rupees and independent certification of the platform. Part B, thirteen obligations, including a fiduciary capacity towards the Data Principal, no conflicts of interest, no sub-contracting, and Board approval for any transfer of control.
Secondrules 5(1) and 16Standards for State processing under section 7(b) and for research, archiving and statistics under section 17(2)(b): lawfulness, purpose limitation, minimisation, accuracy, limited retention, safeguards and accountability.
Thirdrule 8(1)Erasure three years from the Data Principal's last contact or these Rules' commencement, whichever is latest, for e-commerce entities with two crore or more registered users in India, online gaming intermediaries with fifty lakh or more and social media intermediaries with two crore or more, except data needed to access her user account or a stored virtual token.
Fourthrule 12Part A, five classes exempt from sections 9(1) and 9(3) on conditions: healthcare, allied healthcare, educational institutions, creches and day care, and transport engaged by them. Part B, six purposes, among them a legal function in a child's interests, a subsidy, an email account, location for safety, and age confirmation.
Fifthrule 18Service terms for the Chairperson and Members, including a consolidated monthly salary of four lakh fifty thousand rupees for the Chairperson and four lakh for other Members.
Sixthrule 21(2)Appointment and service terms for the Board's officers and employees: deputation, gratuity, travel, medical assistance and leave.
Seventhrules 23(1) and 8(3)Three purposes for which the Central Government may call for information, each with its authorised person: State use of personal data for sovereignty, integrity or security; State use for a legal function or required disclosure; and assessment for notifying a Significant Data Fiduciary.

Key provisions#

/MYND · DPDP practice

Want help applying this?

MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.

How we use these details: only to respond to you. Withdraw any time by writing to sales@myndsol.com. This form is protected against automated submissions.