G.S.R. 846(E)

DIGITAL PERSONAL DATA PROTECTION RULES, 2025

The rules that put the Act into practice — notice wording, breach reporting, erasure timelines.

Notified
13 November 2025
Rules
11
Linkable clauses
47

The text below is the official text. Where it helps, a short plain-English note sits beside a provision — those notes are ours, and are marked as such. They are a starting point, not legal advice.

COMMENCEMENT SCHEDULE#

RulesCommencement
Rules 1, 2, 17–21Immediate (13 November 2025)
Rule 4 (Consent Manager registration)1 year after notification = 13 November 2026
Rules 3, 5–16, 22–2318 months after notification = 13 May 2027

NOTIFICATION PREAMBLE#

MINISTRY OF ELECTRONICS AND INFORMATION TECHNOLOGY NOTIFICATION New Delhi, the 13th November, 2025

G.S.R. 846(E).––– Whereas draft of the Digital Personal Data Protection Rules, 2025 were published, as required under sub-section (1) of section 40 of the Digital Personal Data Protection Act, 2023 (22 of 2023), vide notification of the Government of India in the Ministry of Electronics and Information Technology vide number G.S.R. 02 (E), dated the 3rd January, 2025, in the Gazette of India, Extraordinary, Part II, Section 3, Sub-section (i), dated the 3rd January, 2025, inviting objections and suggestions from all persons likely to be affected thereby, before the expiry of the period of forty-five days from the date on which copies of the Official Gazette containing the said notification were made available to public;

And whereas copies of the said Official Gazette were made available to the public on the 3rd January, 2025;

And whereas objections and suggestions were received from the public in respect of the said draft rules have been considered by the Central Government;

Now, therefore in exercise of powers conferred by sub-sections (1) and (2) of section 40 of the Digital Personal Data Protection Act, 2023 (22 of 2023), the Central Government hereby makes the following rules, namely: —

Rule 1SHORT TITLE AND COMMENCEMENT#

(1)

These rules may be called the Digital Personal Data Protection Rules, 2025.#

(2)

Rules 1, 2 and 17 to 21 shall come into force on the date of their publication in the Official Gazette.#

(3)

Rule 4 shall come into force one year after the date of publication of this Gazette.#

(4)

Rules 3, 5 to 16, 22 and 23 shall come into force eighteen months after the date of publication of this Gazette.#

Rule 2DEFINITIONS#

(1)

In these rules, unless the context otherwise requires, –#

(a)

"Act" means the Digital Personal Data Protection Act, 2023 (22 of 2023);

(b)

"techno-legal measures" means as referred to under rules 20 and 22;

(c)

"user account" means the online account registered by the Data Principal with the Data Fiduciary, and includes any profiles, pages, handles, email address, mobile number and other similar presences by means of which such Data Principal is able to access the services of such Data Fiduciary; and

(d)

"verifiable consent" means a consent as specified in rule 10 or 11.

(2)

The words and expressions used in these rules and not defined, but defined in the Act, shall have the same meanings respectively assigned to them in the Act.#

Rule 3NOTICE GIVEN BY DATA FIDUCIARY TO DATA PRINCIPAL#

*(In force: 13 May 2027)*

The notice given by the Data Fiduciary to the Data Principal shall—

(a)

be presented and be understandable independently of any other information that has been, is or may be made available by such Data Fiduciary;

(b)

give, in clear and plain language, a fair account of the details necessary to enable the Data Principal to give specific and informed consent for the processing of her personal data, which shall include, at the minimum, —

(i)

an itemised description of such personal data; and

(ii)

the specified purpose or purposes of, and specific description of the goods or services to be provided or uses to be enabled by, such processing; and

(c)

give, the particular communication link for accessing the website or app, or both, of such Data Fiduciary, and a description of other means, if any, using which such Data Principal may—

(i)

withdraw her consent, with the ease of doing so being comparable to that with which such consent was given;

(ii)

exercise her rights under the Act; and

(iii)

make a complaint to the Board.

Rule 4REGISTRATION AND OBLIGATIONS OF CONSENT MANAGER#

*(In force: 13 November 2026)*

(1)

A person who fulfils the conditions for registration of Consent Managers set out in Part A of First Schedule may apply to the Board for registration as a Consent Manager by furnishing such particulars and such other information and documents as the Board may publish in this behalf on its website.#

(2)

On receipt of such application, the Board may make such inquiry as it may deem fit to satisfy itself regarding fulfilment of the conditions set out in Part A of First Schedule, and if it—#

(a)

is satisfied, register the applicant as a Consent Manager, under intimation to the applicant, and publish on its website the particulars of such Consent Manager; or

(b)

is not satisfied, reject the application and communicate the reasons for the rejection to the applicant.

(a)

suspend or cancel the registration of such Consent Manager; and

(b)

give such directions as it may deem fit to that Consent Manager, to protect the interests of the Data Principals.

(3)

The Consent Manager shall have obligations as specified in Part B of First Schedule.#

(4)

If the Board is of the opinion that a Consent Manager is not adhering to the conditions and obligations under this rule, it may, after giving an opportunity of being heard, inform the Consent Manager of such non-adherence and direct the Consent Manager to take measures to ensure adherence.#

(5)

The Board may, if it is satisfied that it is necessary so to do in the interests of Data Principals, after giving the Consent Manager an opportunity of being heard, by order, for reasons to be recorded in writing, —#

(6)

The Board may, for the purposes of this rule, require the Consent Manager to furnish such information as the Board may call for.#

Rule 5PROCESSING FOR STATE SUBSIDY/BENEFIT/SERVICE#

*(In force: 13 May 2027)*

(1)

Processing the personal data of a Data Principal under this rule shall be done following the standards specified in Second Schedule.#

*(Full text continues in official PDF — see link at top)*

KEY OPERATIVE RULES — SUMMARY#

Summary, not the rule itself. This is a condensed description. Read the notified text in the official PDF.

*(In force: 13 May 2027, except where noted. Rule titles per the notified text; consult the official gazette PDF linked above for the full text of every rule and schedule.)*

Rule 6Reasonable Security Safeguards#

Summary, not the rule itself. This is a condensed description. Read the notified text in the official PDF.

Data Fiduciaries must protect personal data in their possession or control by adopting reasonable security safeguards — at minimum including measures such as encryption/obfuscation, access control, logging and monitoring, backups, and retention of logs for one year — and must ensure equivalent protection by their Data Processors under contract.

Rule 7Intimation of Personal Data Breach#

Summary, not the rule itself. This is a condensed description. Read the notified text in the official PDF.

On becoming aware of a personal data breach, the Data Fiduciary must, without delay, intimate each affected Data Principal (nature of the breach, likely consequences, mitigation measures, safety steps they can take, contact for queries) and intimate the Board; and must provide the Board the detailed breach information within 72 hours of becoming aware (or a longer period the Board allows on written request).

Rule 8Erasure of Personal Data#

Summary, not the rule itself. This is a condensed description. Read the notified text in the official PDF.

Personal data must be erased when consent is withdrawn or the specified purpose is no longer being served. For the classes of Data Fiduciaries listed in the Third Schedule (large e-commerce entities, online gaming intermediaries, and social media intermediaries above user thresholds), the purpose is deemed no longer served three years after the Data Principal last engaged, and the Fiduciary must give at least 48 hours' notice before erasing.

Rule 10Verifiable Consent (Children and Persons with Disabilities)#

Summary, not the rule itself. This is a condensed description. Read the notified text in the official PDF.

Prescribes how a Data Fiduciary must obtain verifiable consent of a parent or lawful guardian before processing personal data of a child or of a person with disability who has a lawful guardian, including verifying the identity and age of the person claiming to be the parent/guardian.

Rule 13Additional Obligations of Significant Data Fiduciaries#

Summary, not the rule itself. This is a condensed description. Read the notified text in the official PDF.

Entities notified as Significant Data Fiduciaries must, among other obligations, undertake a Data Protection Impact Assessment and audit once every twelve months and observe restrictions on transferring specified personal data and related traffic data outside India.

Rule 14Rights of Data Principals#

Summary, not the rule itself. This is a condensed description. Read the notified text in the official PDF.

Data Fiduciaries and Consent Managers must publish how Data Principals can exercise their rights (access, correction, erasure, nomination) and the time periods within which grievances will be responded to, and must implement measures to meet those published timelines.

SCHEDULES#

Summary, not the rule itself. This is a condensed description. Read the notified text in the official PDF.

First Schedule — Consent Managers#

Summary, not the rule itself. This is a condensed description. Read the notified text in the official PDF.

Part A: Conditions for registration of Consent Managers. Part B: Ongoing obligations of registered Consent Managers.

Second Schedule — Standards for State Processing#

Summary, not the rule itself. This is a condensed description. Read the notified text in the official PDF.

Standards for processing personal data for subsidies, benefits, services, certificates, licences and permits provided by the State.

Third Schedule — Classes of Data Fiduciaries and Time Periods for Erasure#

Summary, not the rule itself. This is a condensed description. Read the notified text in the official PDF.

The classes of Data Fiduciaries (e-commerce entities, online gaming intermediaries, social media intermediaries above specified user thresholds) and the time periods after which personal data must be erased under Rule 8.

*(The remaining schedules cover Board-related and procedural matters — see the official gazette PDF.)*

*Note: Rules 1–4 above are extracted from the official notification text. The summaries of the operative rules and schedules cover the provisions most relevant to businesses; for the complete and authoritative text of all 23 rules and schedules, use the official gazette PDF at the link at the top of this document.*