Home/DPDP Rules 2025
Notified 13 November 2025 · Phased to May 2027

The Rules Are Final. The Start Dates Are Phased.

The Digital Personal Data Protection Rules, 2025 turn the Act's framework into operational requirements for notices, security safeguards, breach reporting, children's data, rights and Consent Managers. Not every provision started on publication.

Final rules notifiedCurrent as of 2 August 2026
Commencement timeline

Three dates to plan around

In force
01 · 13 November 2025

Institutional framework begins

Rules 1, 2 and 17–21 commenced on publication. The linked Act provisions include the Board, rule-making, interpretation and related institutional machinery.

Rules 1, 2, 17–21 · Act §§ 1(2), 2, 18–26, 35, 38–44 in part
Scheduled
02 · 13 November 2026

Consent Manager framework

Rule 4 is scheduled to commence one year after Gazette publication, alongside section 6(9) and the connected appellate provision.

Rule 4 · Act § 6(9) · § 27(1)(d)
Scheduled
03 · 13 May 2027

Core operational duties

Most notice, consent, fiduciary obligation, rights, breach, penalty and implementation provisions are scheduled eighteen months after publication.

Rules 3, 5–16, 22–23 · most of Act §§ 3–17 and §§ 27–37
Implementation

What the Rules add to the Act

Notices become operational

Rule 3 specifies a standalone, clear and plain-language notice that itemises the personal data and purpose, and explains how to withdraw consent, exercise rights and complain to the Board.

Rule 3 · Act § 5

Safeguards are specified

Rule 6 describes minimum reasonable security safeguards, including controls such as encryption or masking, access controls, logs, backups, detection and processor contract measures.

Rule 6 · Act § 8(5)

Breach notices have two stages

Affected Data Principals must be informed without delay. The Board receives an initial intimation without delay and fuller prescribed information within seventy-two hours unless more time is allowed.

Rule 7 · Act § 8(6)

Rights need published channels

Data Fiduciaries and Consent Managers must publish how Data Principals can exercise rights and provide identifiers needed to locate the relevant account or relationship.

Rule 14 · Act §§ 11–14

Start with an evidence-backed readiness review

Turn the statutory requirements into owned actions across legal, product, security, engineering, HR and procurement.

Open the checklist

This page is an educational summary, not legal advice. Dates follow Gazette notifications available on the official MeitY website; always check for later amendments or notifications.

Current questions

DPDP Rules and commencement, answered

Are the DPDP Rules, 2025 final?

Yes. The Central Government notified the Digital Personal Data Protection Rules, 2025 in the Gazette on 13 November 2025. Their commencement is phased rather than simultaneous.

Is the entire DPDP Act currently in force?

No. Institutional and rule-making provisions commenced in November 2025, while other provisions are scheduled one year or eighteen months after Gazette publication.

When do the main operational obligations commence?

Most operational provisions are scheduled for 13 May 2027, eighteen months after publication. Rule 4 and the Consent Manager-related Act provision are scheduled for 13 November 2026.

What should organisations do before May 2027?

Organisations should map data and purposes, repair notices and consent journeys, document safeguards, prepare breach workflows, implement rights handling, set retention rules and review processor contracts.

Read the Act beside the Rules.

The Academy reader keeps all 44 sections and the Schedule searchable in one place.

Open the Act reader

DPDP Academy Editorial: Legal education and implementation guidance. DPDP Academy Source Review: Primary-source verification against Gazette and MeitY publications; last checked 2 August 2026 against the notified DPDP Rules, 2025 and commencement notifications. Educational information, not legal advice.

Review standards and attribution →