The DPDP Act 2023 established the framework. The DPDP Rules 2025, notified on November 13, 2025 (G.S.R. 846(E)), fill in the operational details — the specific procedures, timelines, and mechanisms that businesses must follow. They commence in phases: some rules applied at once, the Consent Manager rule (Rule 4) on a 12-month track, and the core business-facing obligations from May 13, 2027. Here's what they actually say.
Structure and Commencement
The Rules are phased rather than switched on all at once:
- Immediate: the rules establishing the Data Protection Board's constitution and functioning (Rules 17–21) took effect on notification
- ~12 months (from Nov 13, 2026): Rule 4, which sets up the Consent Manager regime
- ~18 months (from May 13, 2027): the core operational obligations — notice, consent, security, breach reporting, children's data, Data Principal rights and cross-border rules (Rules 3, 5–16 and 22–23)
Below we walk through the rules that matter most for a typical business, by their correct rule numbers in the notified Rules.
Rule 3 — Notice to Data Principals
Rule 3 operationalises Section 5 of the Act, the basis for your privacy notice. Key requirements:
- Notice must be given before or at the time of collection — not after
- Must be in clear, plain language — not legal text, and presented independently of other information
- Must specifically identify the personal data being collected, the purpose, and a description of the goods/services enabled
- Must tell the Data Principal how to withdraw consent and how to exercise their rights and complain to the Board
- Under Section 5(3), the notice must be available in English or any Eighth Schedule language at the individual's option
Rule 4 — Consent Managers
Rule 4 establishes the framework for Consent Managers — registered, Data-Principal-facing intermediaries that give an individual a single point of contact to give, review, manage and withdraw consent across multiple Fiduciaries. Importantly, a Consent Manager is accountable to the Data Principal and must act neutrally — it is not a vendor a business hires to collect consent for itself.
- Consent Managers register with the Data Protection Board, which maintains the register of approved entities
- A Consent Manager must meet operational requirements including a minimum net worth of ₹2 crore (First Schedule)
- The same entity cannot be both the Consent Manager and the Data Fiduciary/Processor for the same individual
EasyDP is designed to operate as a compliant consent management interface for businesses, not as a regulated Consent Manager (which serves individuals across multiple Fiduciaries).
Rule 6 — Reasonable Security Safeguards
Rule 6 operationalises the "reasonable security safeguards" requirement. It sets out a baseline that Data Fiduciaries must implement — including measures such as encryption or masking, access controls, logging and monitoring to detect unauthorised access, and the ability to reconstruct data in the event of an incident — appropriate to the data held.
Rule 7 — Breach Intimation
This is one of the most important rules for operational compliance — see our dedicated guide to the 72-hour breach notification rule:
- On becoming aware of a breach, intimate the affected Data Principals without delay, in clear and plain language, via their account or a registered mode of communication
- Give the Data Protection Board an initial intimation "without delay," then detailed particulars within 72 hours of becoming aware (or a longer period the Board allows)
- Particulars include the nature and extent of the breach, the events leading to it, mitigation measures, and remedial steps taken
Rule 10 — Children's Data
Rule 10 is the most operationally demanding rule for many businesses:
- Verifiable parental consent before processing data of anyone under 18 (the under-18 definition comes from Section 2(f) of the Act)
- Verification must establish that the parent/guardian is an identifiable adult
- Verified via reliable details the Fiduciary already holds, details the parent voluntarily provides, or a virtual age token from an authorised entity or a Digital Locker service provider (such as DigiLocker) — the Rules permit these options rather than mandating one product
Separately, the Act itself prohibits tracking or behavioural monitoring of children and targeted advertising directed at them, and processing likely to cause a detrimental effect on a child's well-being.
Rule 13 — Significant Data Fiduciaries
Rule 13 covers the additional obligations for entities the government designates as Significant Data Fiduciaries (SDFs) — such as appointing an India-based Data Protection Officer, an independent data auditor, and periodic Data Protection Impact Assessments. Most SMBs will not be designated as SDFs initially, but businesses should monitor the government's notifications.
Rule 14 — Data Principal Rights
Rule 14 sets out how a Data Principal exercises their rights — how they make a request to access, correct, or erase their data, and how the Fiduciary must publish the means of doing so and respond within its stated timelines. The correction/erasure right carries the obligation to have the Fiduciary's Data Processors erase the data too (Section 8(7)).
Rule 15 — Cross-Border Transfers
Rule 15 addresses transfers of personal data outside India — the government may restrict transfers to particular countries or territories by order. Until such an order is issued, transfers are permitted subject to any conditions, but this is an area to watch.
Rules 17–21 — The Data Protection Board
These rules establish the operational procedures of the Data Protection Board — how it is constituted, receives complaints, conducts inquiries, and functions largely as a digital office. For businesses, the key takeaway is that the Board has real investigatory teeth and can impose penalties under the Schedule to the Act.
What to Focus On Before May 2027
For most businesses, the most operationally significant rules are 3 (notice), 6 (security), 7 (breach intimation), 10 (children), and 14 (Data Principal rights). Building compliant systems for these will address the vast majority of your compliance risk. Start now — 18 months is not as long as it sounds when you're building from scratch.
References & Sources
- The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)) — Rules 3, 4, 6, 7, 10, 13, 14, 15 and 17–21, with phased commencement.
- Ministry of Electronics & IT, Government of India — The Digital Personal Data Protection Act, 2023 and Rules framework.
- India Code — Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), official consolidated text.
This article is general information about the DPDP Rules 2025 (G.S.R. 846(E)) and DPDP Act 2023, not legal advice. Rule numbers and commencement dates are cited from the notified text; verify against the current official version for your specific situation.