DPDPAcademyKnow the law. Prove it.
Home/DPDP Rules 2025
Notified 13 November 2025 · Phased to May 2027

The Rules Are Final. The Start Dates Are Phased.

The Digital Personal Data Protection Rules, 2025 turn the Act's framework into operational requirements for notices, security safeguards, breach reporting, children's data, rights and Consent Managers. Not every provision started on publication.

Final rules notifiedCurrent as of 13 August 2026
Commencement timeline

Three dates to plan around

DPDP commencement timelineThree tranches. On 13 November 2025 the Data Protection Board, rule-making powers and the amendments to the TRAI and Right to Information Acts came into force. Twelve months later, on 13 November 2026, Consent Manager registration under section 6(9) and Rule 4 begins. Eighteen months after publication, in mid-May 2027, sections 3 to 17 and 28 to 34 commence, along with section 44(2), which omits section 43A of the Information Technology Act and ends the SPDI Rules, 2011.today13 Nov 2025On publicationBoard established (§§ 18–26)Rule-making, interpretation§ 44(1) TRAI · § 44(3) RTI13 Nov 2026+ 12 monthsConsent Manager registration§ 6(9) · Rule 4§ 27(1)(d) Board power13 May 2027+ 18 months§§ 3–17 · §§ 28–34 · § 37§ 44(2): IT Act § 43A omittedSPDI Rules, 2011 fall awayRules published 13 November 2025. Tranches run one year and eighteen months from that date.
Commencement of the DPDP Act, 2023 and the DPDP Rules, 2025. Position of the “today” marker reflects the content review date, 2026-08-13.
In force
01 · 13 November 2025

Institutional framework begins

Rules 1, 2 and 17–21 commenced on publication. The linked Act provisions include the Board, rule-making, interpretation and related institutional machinery.

Rules 1, 2, 17–21 · Act §§ 1(2), 2, 18–26, 35, 38–44 in part
Scheduled
02 · 13 November 2026

Consent Manager framework

Rule 4 is scheduled to commence one year after Gazette publication, alongside section 6(9) and the connected appellate provision.

Rule 4 · Act § 6(9) · § 27(1)(d)
Scheduled
03 · 13 May 2027

Core operational duties

Most notice, consent, fiduciary obligation, rights, breach, penalty and implementation provisions are scheduled eighteen months after publication.

Rules 3, 5–16, 22–23 · most of Act §§ 3–17 and §§ 27–37
Implementation

What the Rules add to the Act

Notices become operational

Rule 3 specifies a standalone, clear and plain-language notice that itemises the personal data and purpose, and explains how to withdraw consent, exercise rights and complain to the Board.

Rule 3 · Act § 5

Safeguards are specified

Rule 6 describes minimum reasonable security safeguards, including controls such as encryption or masking, access controls, logs, backups, detection and processor contract measures.

Rule 6 · Act § 8(5)

Breach notices have two stages

Affected Data Principals must be informed without delay. The Board receives an initial intimation without delay and fuller prescribed information within seventy-two hours unless more time is allowed.

Rule 7 · Act § 8(6)

Rights need published channels

Data Fiduciaries and Consent Managers must publish how Data Principals can exercise rights and provide identifiers needed to locate the relevant account or relationship.

Rule 14 · Act §§ 11–14

Start with an evidence-backed readiness review

Turn the statutory requirements into owned actions across legal, product, security, engineering, HR and procurement.

Open the checklist

Need the dates without the full Rules commentary?

Use the dedicated commencement page to map each implementation workstream to its scheduled phase.

Open the deadline timeline

This page is an educational summary, not legal advice. Dates follow Gazette notifications available on the official MeitY website; always check for later amendments or notifications.

Current questions

DPDP Rules and commencement, answered

Are the DPDP Rules, 2025 final?

Yes. The Central Government notified the Digital Personal Data Protection Rules, 2025 in the Gazette on 13 November 2025. Their commencement is phased rather than simultaneous.

Is the entire DPDP Act currently in force?

No. Institutional and rule-making provisions commenced in November 2025, while other provisions are scheduled one year or eighteen months after Gazette publication.

When do the main operational obligations commence?

Most operational provisions are scheduled for 13 May 2027, eighteen months after publication. Rule 4 and the Consent Manager-related Act provision are scheduled for 13 November 2026.

What should organisations do before May 2027?

Organisations should map data and purposes, repair notices and consent journeys, document safeguards, prepare breach workflows, implement rights handling, set retention rules and review processor contracts.

Read the Act beside the Rules.

The Academy reader keeps all 44 sections and the Schedule searchable in one place.

Open the Act reader
23 rules · 7 schedules

The Schedules are where the numbers live

The rules state obligations; the Schedules carry the figures that decide whether one applies to you. Read from the Gazette text rather than from summaries - two of these seven are barely covered anywhere.

FirstConditions for registering as a Consent ManagerSee rule 4. Part A sets eligibility: a company incorporated in India, sufficient technical, operational and financial capacity, sound financial condition and general character of management, and a net worth of not less than two crore rupees. Part B sets the operating obligations.Covered in depth on the Consent Managers page.
SecondStandards for processing by the StateSee rules 5(1) and 16. Technical and organisational standards for the State and its instrumentalities processing under section 7(b), and for processing necessary for the purposes in section 17(2)(b) - lawfulness, and the rest of the listed observances.The least-discussed Schedule of the seven. It is the only place the Rules set standards specifically for State processing.
ThirdRetention periods, by class and user countSee rule 8(1). Named classes of Data Fiduciary must erase personal data three years after the Data Principal last approached them or exercised a right - or after the Rules commenced, whichever is latest - unless retention is required by law.Thresholds and carve-outs are set out below. This is the Schedule most organisations need to check against themselves.
FourthWhere the children's provisions do not applySee rule 12. Part A lists classes of Data Fiduciary exempt from section 9(1) and 9(3) - beginning with clinical establishments, mental health establishments and healthcare professionals, where processing is restricted to providing health services to the child. Part B lists exempt purposes.This is the mechanism section 9(4) anticipated. Without it, verifiable parental consent would gate a child's emergency care.
FifthWhat the Board is paidSee rule 18. The Chairperson receives a consolidated salary of ₹4,50,000 per month and every other Member ₹4,00,000, in both cases without house or car.Dry, but it tells you the seniority the Government intends for the Board - and it is public, fixed and consolidated rather than negotiated.
SixthThe Board's officers and employeesSee rule 21(2). Terms of appointment and service, including appointment on deputation from central or state government or from an autonomous body, under the Fundamental Rules and DoPT guidelines.
SeventhWho may demand data from you, and for whatSee rules 23(1) and 8(3). Pairs each purpose with the authorised person who may act on it - beginning with use by the State in the interest of the sovereignty and integrity of India or the security of the State, exercised by an officer designated under section 17(2)(a).It also fixes the one-year floor for retaining processing logs, since rule 8(3) points here.
Third Schedule · rule 8(1)

Does the three-year erasure clock apply to you?

Only three classes of Data Fiduciary are named, and each carries a registered-user threshold. Below the threshold, or outside the class, this Schedule does not reach you - the general erasure duty in section 8(7) still does.

E-commerce entity≥ 2 crore registered users in India
Online gaming intermediary≥ 50 lakh registered users in India
Social media intermediary≥ 2 crore registered users in India
What the clock actually measures

Three years from the date the Data Principal last approached you for the specified purpose or exercised a right - or from the commencement of the Rules, whichever is latest. That last limb matters: it means the clock does not start expired for a user who went quiet in 2023.

Two things are carved out and must survive the erasure: what is needed to let her access her user account, and what is needed to let her access a virtual token issued by or for you, held on your platform, that can be exchanged for money, goods or services.

And at least forty-eight hours before the period completes, you must tell her the data is about to be erased unless she logs in or otherwise makes contact.

DPDP Academy Editorial: Legal education and implementation guidance. DPDP Academy Source Review: Primary-source verification against Gazette and MeitY publications; last checked 9 August 2026 against the notified DPDP Rules, 2025 and commencement notifications. Educational information, not legal advice.

Review standards and attribution →