What Are the DPDP Rules 2025?

The Digital Personal Data Protection Rules 2025 are subordinate legislation made under Section 40 of the DPDP Act 2023. While the Act established the rights of Data Principals and the obligations of Data Fiduciaries in broad terms, it explicitly delegated the operational specifics to Rules to be framed by the Central Government.

The Ministry of Electronics and Information Technology (MeitY) released a draft of the Rules for public consultation in January 2025. The consultation attracted significant interest — over 500 organisations submitted comments, ranging from major technology platforms and industry associations to civil society groups and individual privacy advocates.

As of mid-2026, the final DPDP Rules have not been notified. The government is expected to publish the final Rules in 2026, after which a separate commencement date will be set — likely 12 to 18 months later — to give businesses adequate time to implement the required changes.

The draft Rules cover six core areas:

  • Consent notice format and requirements — how notice must be given and what it must contain
  • Data Principal rights timelines — how quickly Data Fiduciaries must respond to rights requests
  • Breach notification timelines and content — what must be reported and when
  • Children's data protections — parental consent, age verification, and restrictions
  • Cross-border data transfer framework — approved countries and restricted categories
  • Data Protection Board of India procedure — composition, complaints process, adjudication

The consent notice requirements in the draft DPDP Rules are among the most operationally significant changes for businesses. The Act required that consent be free, specific, informed, and unambiguous — but it left the format and content requirements to the Rules. The draft Rules fill this gap with concrete requirements.

Plain language requirement

Consent notices must be written in plain, everyday language — not legal jargon. The draft Rules explicitly prohibit the use of technical or legal language that a reasonable person would not understand without specialist training. Privacy policies and terms of service that bury consent language in dense legalese will not satisfy this requirement.

Indian language availability

Consent notices must be made available in the Eighth Schedule Indian languages. This is a significant operational requirement for any platform serving Indian users across linguistic regions. A startup that currently provides only an English privacy policy will need to provide translated versions in the languages of its user base.

Per-purpose itemisation

Each processing purpose must be listed separately in the consent notice. Data Principals must be able to grant consent to some purposes and withhold it from others — bundled consent for all purposes together is not permitted. This means a platform that processes user data for (1) service delivery, (2) personalisation, (3) marketing, and (4) third-party sharing must present each as a separate consent item.

Additional required elements

  • The data retention period for each category of personal data
  • The names of all third parties with whom data will be shared
  • The contact details of the Data Fiduciary's grievance officer
  • A clear explanation of the Data Principal's right to withdraw consent
  • The consent notice must be a standalone document — separate from terms of service, end-user licence agreements, and other contractual documents

The consent notice requirements in the DPDP Rules are not a minor tweak to existing privacy policies. They represent a structural change: moving from one-size-fits-all consent to itemised, per-purpose consent with full transparency on sharing and retention. Most Indian businesses will need to rebuild their consent infrastructure from scratch to comply.

What Breach Notification Timeline Do the DPDP Rules Require?

The draft DPDP Rules propose a 72-hour breach notification timeline — matching the GDPR standard that has become the global benchmark for breach notification. This means that when a data breach affecting personal data occurs, a Data Fiduciary must notify both the Data Protection Board and affected Data Principals within 72 hours of becoming aware of the breach.

72 hrs
Breach notification deadline to Board and Data Principals
30 days
Expected rights response deadline for Data Fiduciaries
18
Minimum age for independent consent without parental approval
500+
Organisations that submitted comments on the draft Rules

The breach notification must include:

  • The nature of the breach — what happened, and how it occurred
  • The categories and approximate volume of personal data affected
  • The approximate number of Data Principals whose data was involved
  • The likely consequences of the breach for affected individuals
  • The remedial measures taken or planned by the Data Fiduciary

For "significant" breaches — a category the draft Rules indicate will be defined further — the notification requirements are expected to be more detailed and the process more rigorous. The definition of what constitutes a significant breach has not yet been finalised.

To meet a 72-hour timeline consistently, organisations need a functioning breach detection, triage, and escalation process — not just a documented policy. Breaches that are discovered but not escalated internally within the first 24 hours routinely miss the notification window even when the organisation acts quickly once aware. Investment in detection tooling and internal response procedures is a prerequisite for compliance with this obligation.

What Do the DPDP Rules Say About Children's Data?

The children's data provisions in the draft DPDP Rules establish India's highest age threshold among major data protection frameworks. The GDPR sets the age of consent at 16 (with member states permitted to lower it to 13). India's DPDP Act sets it at 18 years — anyone under 18 requires verifiable parental consent before their personal data can be processed.

Parental consent requirements

The consent of a parent or legal guardian must be obtained before any personal data of a child is processed. The draft Rules specify that this consent must be verifiable — a checkbox asking users to confirm they are over 18, or asking parents to check a box giving consent, does not satisfy the requirement. The verification mechanism must be reliable, though the specific technical standard for verification has not yet been finalised in the draft.

Restrictions on processing children's data

  • No targeted advertising directed at children — any advertising shown to users identified as under 18 must not be behaviorally targeted
  • No behavioural tracking or profiling of children for any purpose
  • No monitoring of children's online activity beyond what is strictly necessary for service delivery
  • Children's personal data must be stored within India — the draft Rules impose a localisation requirement specifically for this category

Platform implications

For platforms with significant numbers of users under 18 — gaming platforms, educational apps, social platforms — these requirements represent a material compliance challenge. Age verification at scale is technically and commercially complex. Platforms that currently use self-reported age data without verification will need to implement more robust systems before the Rules come into force.

What Do the DPDP Rules Say About Cross-Border Data Transfers?

The draft DPDP Rules do not impose blanket data localisation. Instead, they establish a government-approved country list mechanism: cross-border transfers of personal data are permitted to countries that the Central Government has approved by notification. Transfers to countries not on the approved list are prohibited.

Approved country list — not yet published

The approved country list is one of the most significant pending elements of the DPDP Rules. As of mid-2026, the list has not been published. Businesses cannot yet know with certainty which countries will be approved for data transfer. Based on India's existing data-sharing relationships and the pattern of other jurisdictions' adequacy decisions, major western democracies, ASEAN partners, and countries with established data protection regimes are likely to be included — but this cannot be confirmed until the list is published.

No adequacy assessment by businesses

Unlike GDPR's adequacy mechanism — which allows businesses to assess third-country protections themselves and use contractual safeguards — the DPDP Rules take a simpler approach: the government decides which countries are approved, and businesses either transfer to approved countries or do not. There is no DPDP equivalent of Standard Contractual Clauses for transferring data to non-approved countries.

Sector-specific localisation still applies

Even where the DPDP Rules permit cross-border transfers, sector-specific regulations from RBI, SEBI, IRDAI, and other regulators impose their own localisation requirements on specific data categories. Financial transaction data, health records, and insurance data face localisation requirements under sector regulations that operate independently of the DPDP framework. Organisations in regulated sectors must comply with both sets of rules.

How Do the DPDP Rules Affect Grievance Redressal?

The draft Rules establish a two-tier grievance redressal system: first to the Data Fiduciary's internal grievance mechanism, then escalation to the Data Protection Board if the Data Principal is unsatisfied with the response.

Data Fiduciary obligations

Every Data Fiduciary must publish the name and contact details of a designated grievance officer. The draft Rules propose a 30-day response deadline for grievances raised with the Data Fiduciary. The grievance officer must be a person — not just a helpdesk email — and must have the authority to resolve complaints, not merely acknowledge them.

Data Protection Board procedure

The Data Protection Board of India will operate as a digital-first body. The draft Rules specify:

  • All complaints must be filed through a digital portal — no paper filings
  • Hearings may be conducted virtually
  • The Board must acknowledge complaints within 7 days of receipt
  • The Board may refer complaints to mediation before formal adjudication — this is expected to be the primary route for most complaints
  • Where mediation fails, the Board proceeds to adjudication and may impose penalties up to ₹250 crore per violation under the DPDP Act

What Hasn't Been Finalised in the DPDP Rules 2025?

The draft Rules leave several important details to be specified separately, either through additional notifications or through the final version of the Rules. Organisations planning their compliance programmes need to plan for this uncertainty:

  • Approved country list for cross-border transfers — the most commercially significant gap; businesses with international data flows cannot fully plan transfer compliance until this is published
  • Technical standards for age verification — the requirement for verifiable parental consent is clear, but the specific technical mechanism is still to be specified
  • Accreditation criteria for independent data auditors — SDFs must appoint accredited data auditors, but the accreditation framework is not yet established
  • Significant Data Fiduciary designation criteria — the factors are set out in Section 10, but numeric thresholds or additional criteria have not been specified
  • Definition of "significant data breach" requiring enhanced reporting beyond the standard 72-hour notification
  • Commencement date — the Rules have not been notified, and the commencement date will be set separately after notification
Planning note

The gaps in the draft Rules are not a reason to delay compliance preparation. The core requirements — consent notices, breach notification, rights fulfilment, grievance mechanisms — are unlikely to change materially. Build your compliance programme on the draft now, and plan to close the gaps as the remaining pieces are published.

What Should Businesses Do Now While the Rules Are Pending?

The fact that the final DPDP Rules have not been notified does not mean businesses can defer their compliance programmes. The 12-to-18-month implementation window after notification is shorter than most organisations expect when they calculate the time required to build compliant consent management platforms, breach notification workflows, and rights fulfilment infrastructure.

Start now on the requirements that are settled

Build your consent management platform on the principles in the draft — plain language, per-purpose granularity, separate consent document, Indian language availability. These requirements are substantively unlikely to change between the draft and the final notification. Starting now means you are not rebuilding from scratch under time pressure after the Rules are notified.

Implement 72-hour breach detection and response

The 72-hour breach notification timeline requires a functioning detection-to-notification pipeline. Work backwards from the notification deadline: how long does it take your organisation to detect a breach? To triage and confirm it? To draft a notification? To obtain internal approvals? Most organisations that have not done this exercise find they cannot consistently meet 72 hours without significant process changes.

Assess your children's data exposure

Review your data inventory for children's data. If your platform processes data of users who may be under 18 — even if you do not explicitly target children — the parental consent requirements apply. The question is not whether you intend to serve children but whether children use your service. For most consumer platforms, the answer is yes.

Map your cross-border data flows

The approved country list uncertainty is real risk for organisations with significant international data flows. Map every cross-border transfer now: what data is transferred, to which countries, for what purpose, under what legal basis. When the approved country list is published, you will need to assess each flow against it quickly — you cannot do that assessment without first knowing what flows exist.

Identify your DPO if you may be a Significant Data Fiduciary

If your organisation processes data at a scale, or with a sensitivity, that could trigger Significant Data Fiduciary designation, begin identifying your Data Protection Officer now. The DPO must be India-based and must hold a senior enough position to have genuine authority over compliance decisions. Recruiting or designating a qualified DPO takes time — do not leave this until after you receive a designation notification.

DPDP compliance guide & assessment

For the complete picture of DPDP Act obligations — all Data Fiduciary requirements, the penalty structure, the full compliance timeline, and our free DPDP compliance checklist — see our comprehensive guides. Or book a free 30-minute assessment session to map your DPDP Rules readiness against your current posture.