DPDP Rules 2025 Explained: Timeline and Key Rules
DPDP Rules 2025, rule by rule: notice, security safeguards, 72-hour breach reports, 90-day rights requests, children's data and the dates to May 2027.
By the GRC-Flow team · Published · 8 min read
Key takeaways
- The Digital Personal Data Protection Rules, 2025 were notified on 14 November 2025 and put the DPDP Act 2023 into practice.
- They apply in three phases: the Data Protection Board at once, Consent Managers from 13 November 2026, and most business obligations from 13 May 2027.
- Every personal data breach must be reported to affected people without delay, and a detailed report must reach the Board within 72 hours.
- Requests from people to access, correct or erase their data must be answered within 90 days.
- Personal data and processing logs must be kept for at least one year for the purposes the Rules list, then erased unless another law requires them.
What are the DPDP Rules 2025?
The DPDP Act 2023 sets the principles; the Digital Personal Data Protection Rules, 2025 set the mechanics. They say what a privacy notice must contain, which security measures count as reasonable, how fast to report a breach, how long to keep logs, and how the Data Protection Board works.
The timeline: three phases
| When | What comes into force |
|---|---|
| 14 November 2025 | Data Protection Board: set-up, functioning, digital office |
| 13 November 2026 | Consent Managers: registration with the Board and their obligations |
| 13 May 2027 | Notice, security safeguards, breach intimation, retention and erasure, contact details, children's data, Significant Data Fiduciaries, rights of Data Principals, transfers, and calling for information |
That last date is the one that matters for most businesses. Eighteen months sounds long, but mapping data, rewriting notices, changing consent flows and fixing vendor contracts usually takes six to twelve months.
The rules businesses need to know
Rule 3: Notice
The notice must stand on its own, be clear and plain, and give an itemised description of the personal data and the specific purpose for each item. It must explain how to withdraw consent (as easily as it was given), how to exercise rights, and how to complain to the Board.
Rule 4: Consent Managers
Consent Managers are platforms registered with the Board that let people give, review and withdraw consent across services. They must be companies incorporated in India and meet the conditions in the First Schedule. Most businesses will not become one; they may integrate with one.
Rule 6: Reasonable security safeguards
The minimum measures include:
- encryption, obfuscation, masking or virtual tokens for personal data;
- access controls on the systems that hold it;
- logs and monitoring to detect unauthorised access, kept so a breach can be investigated;
- backups and measures to keep processing going after an incident;
- these same safeguards written into contracts with Data Processors.
Rule 7: Personal data breach
Every breach is reportable, whatever its size:
- To affected people, without delay: what happened, the likely consequences, what you are doing, and what they can do.
- To the Board, without delay: a first intimation.
- To the Board, within 72 hours: a detailed report with the facts, the cause, the people affected, the mitigation and the notices sent.
Rule 8: Retention and erasure
Personal data, traffic data and processing logs must be retained for at least one year for the purposes set out in the Rules, then erased unless another law requires otherwise. Large e-commerce, online gaming and social media platforms (above the user thresholds in the Third Schedule) must erase the data of users inactive for three years, with 48 hours' notice before erasure.
Rule 9: Contact details
Publish, prominently on your website or app, the business contact of the person who answers questions about personal data (the Data Protection Officer, for a Significant Data Fiduciary).
Rules 10 and 11: Children and persons with disabilities
Before processing a child's data, obtain verifiable consent of a parent, checking the parent is an identifiable adult. For a person with a disability who cannot decide for themselves, consent comes from their lawful guardian.
Rule 13: Significant Data Fiduciaries
A Significant Data Fiduciary must carry out a Data Protection Impact Assessment and an audit every 12 months, report the significant findings to the Board, check that its algorithmic software does not put rights at risk, and keep specified categories of data in India.
Rule 14: Rights of Data Principals
Publish how people can make requests (access, correction, erasure, nomination) and the identifiers you need, and respond within 90 days.
How to act on the Rules
Turn each rule into an owner, a deadline and evidence. Our DPDP compliance checklist lists the steps in order. If you advise clients, GRC Flow maps intake answers to each obligation in the Act and Rules, tracks the 72-hour breach and 90-day request clocks, and keeps the evidence for each control.
Frequently asked questions
When were the DPDP Rules 2025 notified?
The Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025 on 14 November 2025.
When do the DPDP Rules come into force?
In phases. Rules on the Data Protection Board applied on notification. Consent Manager rules apply from 13 November 2026. Rules on notice, security, breach reporting, retention, children's data, rights and Significant Data Fiduciaries apply 18 months after notification, from 13 May 2027.
What is the breach reporting timeline under the DPDP Rules?
Rule 7: inform each affected Data Principal without delay, inform the Board without delay, and send the Board a detailed report within 72 hours of becoming aware of the breach (or longer if the Board allows).
How long do businesses have to answer a data rights request?
Rule 14(3) sets a maximum of 90 days to respond to requests from Data Principals.
Sources
- PIB: Digital Personal Data Protection Rules, 2025
- KPMG India: DPDP Rules 2025 guidance
- Bar & Bench: MeitY notifies final DPDP Rules 2025
- K&S Partners: DPDP data breach notification timeline
This guide explains the law in general terms and is not legal advice. Check specific situations with a qualified lawyer.
Related guides
- DPDP Act 2023 Explained: Full Form and Who Must Comply
DPDP Act 2023 in plain English: full form, who must comply, Data Fiduciary vs Data Principal, consent, rights, penalties and the 13 May 2027 deadline.
- DPDP Compliance Checklist: 12 Steps Before May 2027
A practical DPDP compliance checklist: data mapping, notices, consent, security, a 72-hour breach plan, rights requests, vendors, children's data and evidence.
- DPDP Act Penalties: Up to ₹250 Crore, Explained
DPDP Act penalties in one table: ₹250 crore for weak security, ₹200 crore for unreported breaches or children's data, ₹150 crore for SDFs, and how fines are set.