/The Rules · 2025
Rule 1: Short title and commencement
DPDP Rules, 2025, G.S.R. 846(E) dated 13 November 2025. In force since 13 November 2025.
- Provision
- Rule 1 of The Digital Personal Data Protection Rules, 2025
- Status
- In force since 13 November 2025 (phase 1)
- Made under
- s. 40 Power to make rules
- Source
- Ministry of Electronics and Information Technology · G.S.R. 846(E) · 13 November 2025 · Official PDF
- line 22, for “of this Gazette”, read “in the Official Gazette";
- line 24, for "of this Gazette", read "in the Official Gazette";
This rule establishes the official title of the regulations as the Digital Personal Data Protection Rules, 2025. It also provides a specific, staggered timeline for when the various rules actually become legally enforceable. Instead of starting all at once, the rules are divided into three different starting dates based on when they are published in the Official Gazette.\n\nThe first group of rules takes effect immediately on the date of publication. This immediate group includes Rules 1 and 2, along with Rules 17 through 21.\n\nThe remaining rules give affected parties more time to prepare before they come into force. Rule 4 will take effect exactly one year after the date the rules are published in the Gazette. Finally, the largest group of rules, which includes Rule 3, Rules 5 through 16, Rule 22, and Rule 23, will take effect eighteen months after the publication date.
Key points
- The official name of the rules is the Digital Personal Data Protection Rules, 2025 (1).
- Rules 1, 2, and 17 through 21 take effect immediately upon their publication in the Official Gazette (2).
- Rule 4 takes effect exactly one year after the publication date (3).
- Rules 3, 5 through 16, 22, and 23 take effect eighteen months after the publication date (4).
Common misreadings
- Readers might assume all rules take effect immediately upon publication, but the text clearly staggers the effective dates over an eighteen-month period.
Interpretation prepared from the official text only, 9 September 2026. The official text above prevails.
/MYND · DPDP practice
Putting this into practice?
MYND runs DPDP compliance programmes for the data that flows through HR, payroll, finance and vendor operations: readiness assessments, consent and notice design, processor contracts and breach playbooks. Tell us what you are working on and a compliance lead will reply within one working day.