The Ministry of Electronics and Information Technology (MeitY) notified the Digital Personal Data Protection Rules, 2025 in November 2025, giving operational effect to the Digital Personal Data Protection Act, 2023. Commencement is phased rather than immediate. The provisions constituting the Data Protection Board of India took effect on notification, and the Board has since been constituted. Registration and obligations of Consent Managers apply 12 months after notification. The core obligations of Data Fiduciaries — notice, consent, security safeguards, breach intimation, Data Principal rights, retention limits and the additional duties of Significant Data Fiduciaries — apply 18 months after notification, which places them in May 2027 under the Rules as notified.
The phasing is a window, not a deferral. The obligations are now fixed in the text of the Rules, and the build work — data mapping, consent redesign, vendor contracts, breach playbooks — takes most organisations the better part of that window.
What the Rules Introduce
The Rules establish the operational architecture for three core obligations. First, consent. Consent must be free, specific, informed, unconditional and unambiguous, and it must be preceded by a standalone notice that itemises the personal data collected and the specific purpose for each item. Data Principals may withdraw consent at any time, and withdrawal must be as easy as giving it — consent flows that bury withdrawal in multi-step menus will not comply. Consent may also be given, managed and withdrawn through Consent Managers registered with the Board.
Second, Significant Data Fiduciaries (SDFs) — entities notified by the Central Government having regard to the volume and sensitivity of the data processed, the risk to Data Principals, and the potential impact on the sovereignty and integrity of India, electoral democracy, security of the State and public order — face an elevated tier. An SDF must appoint a Data Protection Officer based in India, appoint an independent data auditor, and carry out a Data Protection Impact Assessment and an audit every year. Entities processing personal data at scale, or sensitive categories of data, should prepare for designation rather than wait for it.
Third, cross-border transfers. The Act takes a negative-list approach: section 16 permits transfer of personal data outside India except to countries or territories the Central Government restricts by notification. The Rules make transfers subject to such requirements as the Central Government may specify by order, and SDFs may be required to keep specified categories of personal data within India. Businesses routing Indian customer data through global infrastructure should map those flows now.
Notice and Transparency Requirements
Rule 3 prescribes the notice a Data Fiduciary must give when seeking consent. It must be understandable on its own, independent of any other information, and must set out in clear and plain language an itemised description of the personal data and the specified purpose of processing, together with the means to withdraw consent, exercise rights and complain to the Board. Where personal data is held on the basis of consent given before the Act commenced, notice must be given as soon as reasonably practicable. Companies should review privacy notices, cookie banners, app permission screens and employee data collection forms.
Rights of Data Principals
The Act confers rights to access information about personal data processed, to correction, completion, updating and erasure, to grievance redressal, and to nominate another individual to exercise rights on death or incapacity; section 6 separately preserves the right to withdraw consent. Data Fiduciaries must publish how these rights can be exercised and must respond to grievances within the period the Rules prescribe, which cannot exceed ninety days. Delhi NCR businesses should assign ownership of this workflow to a named senior compliance or legal officer.
Personal Data Breach Intimation
Rule 7 requires a Data Fiduciary that becomes aware of a personal data breach to inform each affected Data Principal without delay, and to inform the Board without delay, followed by a detailed report to the Board within seventy-two hours (or such longer period as the Board allows). This runs alongside, not instead of, the CERT-In requirement to report cybersecurity incidents within six hours.
Penalties Under the Parent Act
The Schedule to the DPDP Act 2023 prescribes penalties of up to Rs 250 crore for failure to take reasonable security safeguards to prevent a personal data breach, and up to Rs 200 crore for failure to notify the Board and affected Data Principals of a breach. The caps apply per instance; the Act does not set an aggregate annual cap.
Sectoral Overlap and Existing Frameworks
Entities regulated by SEBI, RBI, IRDAI or TRAI must reconcile the DPDP framework with sectoral data protection requirements. Section 38 of the Act makes its provisions additional to other laws and gives the Act overriding effect where there is a conflict. Healthcare entities processing health data should map DPDP obligations against the Ayushman Bharat Digital Mission framework, and financial institutions against the RBI's IT governance and outsourcing directions, to identify gaps.
Action Items for Delhi NCR Businesses
- Complete a personal data inventory and data flow map across all business units well ahead of the 18-month deadline.
- Appoint the person or function accountable for Data Principal requests and grievances, and publish their contact details.
- Audit and redraft privacy notices, consent forms and cookie banners against Rule 3.
- Map cross-border data transfers and monitor Central Government notifications restricting transfers.
- Assess the likelihood of SDF designation and prepare the DPIA and audit programme.
- Review vendor and processor contracts for security safeguards, breach notification support and data return or deletion.
- Build a breach response protocol that meets both the CERT-In six-hour rule and the Rule 7 intimation timelines.