The Digital Personal Data Protection Rules, 2025 come into force in three phases. Here is what applies on each date, rule by rule, and a practical plan for startups working back from the main deadline.
By Amar Gite and Santosh Sangle, Legismith Partners LLP · Reviewed 30 September 2026
Rules 1 and 2 (title and definitions) and rules 17 to 21 on the Data Protection Board: how members are selected, their terms of service, how the Board meets and how it works as a digital office.
Rule 4 and the First Schedule: the conditions a Consent Manager must meet to register with the Board, and its obligations once registered.
Rules 3, 5 to 16, 22 and 23: notice, security safeguards, breach intimation, retention and erasure, privacy contact, children's data, Significant Data Fiduciaries, rights, cross-border transfers, appeals and calls for information.
| Rule | Subject | In force from |
|---|---|---|
| 1 and 2 | Short title, commencement and definitions | 13 Nov 2025 |
| 3 | Notice given by a Data Fiduciary to a Data Principal | 13 May 2027 |
| 4 | Registration and obligations of Consent Managers | 13 Nov 2026 |
| 5 | Processing by the State for subsidies, benefits, services, certificates, licences and permits | 13 May 2027 |
| 6 | Reasonable security safeguards | 13 May 2027 |
| 7 | Intimation of a personal data breach (72-hour detailed report to the Board) | 13 May 2027 |
| 8 | When a purpose is treated as served, erasure, and one-year log retention | 13 May 2027 |
| 9 | Contact information of the person who answers questions about processing | 13 May 2027 |
| 10 and 11 | Verifiable consent for children and for persons with disability who have a lawful guardian | 13 May 2027 |
| 12 | Exemptions from certain obligations for children's data | 13 May 2027 |
| 13 | Additional obligations of Significant Data Fiduciaries (annual DPIA and audit) | 13 May 2027 |
| 14 | Rights of Data Principals and grievance redressal within 90 days | 13 May 2027 |
| 15 | Transfer of personal data outside India | 13 May 2027 |
| 16 | Exemption for research, archiving and statistical purposes | 13 May 2027 |
| 17 to 21 | The Data Protection Board: appointments, service conditions, meetings, digital office, staff | 13 Nov 2025 |
| 22 | Appeal to the Appellate Tribunal | 13 May 2027 |
| 23 | Calling for information from a Data Fiduciary or intermediary | 13 May 2027 |
Source: Digital Personal Data Protection Rules, 2025, rule 1(2) to 1(4), Gazette notification G.S.R. 846(E) dated 13 November 2025, published by the Ministry of Electronics and Information Technology.
Most of the work is not legal drafting but product and vendor changes, which take longer than expected. This is the order we recommend.
List the personal data you hold, where it comes from and which vendors receive it. Run a gap assessment and put the fixes in next year's budget.
Write the notices, consent wording, policies and vendor terms. Change sign-up, consent and settings screens, and set up the rights request route.
Run a breach drill on paper against the 72-hour clock, test erasure and log retention, and train everyone who handles customer data.
Publish the notices and the privacy contact, switch on the new consent flows, and keep a record of what you did and when.
Review every new feature, vendor and market for its privacy impact, and handle requests and grievances within the time limits.
The Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025 by Gazette notification G.S.R. 846(E) dated 13 November 2025.
13 May 2027. That is when rules 3, 5 to 16, 22 and 23 come into force, eighteen months after notification, covering notice, security, breach reporting, retention, children's data and the rights of Data Principals.
Rules 1 and 2 and rules 17 to 21, which deal with the Data Protection Board, came into force on 13 November 2025, the date of publication.
Rule 4, on the registration and obligations of Consent Managers, comes into force one year after publication, on 13 November 2026.
You can, but it is risky. Changing consent flows, vendor contracts and data retention takes months of product and engineering time, so most startups need to start their gap assessment in 2026 to be ready by 13 May 2027.
Tell us what your product does and roughly how many users you have. We will reply within 24 hours with a fixed-fee quote for a readiness check.
Prefer chat? WhatsApp us.
General information on the DPDP Act, 2023 and the DPDP Rules, 2025, current to 30 September 2026. Not legal advice for your specific situation.
We use essential cookies to run this website and keep our enquiry forms secure. With your permission we would also like to use analytics cookies, to see how the site is used, and advertising cookies, to measure our Google Ads. These collect your IP address, device and browser details and the pages you visit, and share them with Google and Cloudflare. You can change or withdraw your choice at any time using Cookie settings at the bottom of every page, or write to [email protected].
Disclaimer: Under the Bar Council of India rules, advocates may not advertise or solicit work. This website only shares general information on intellectual property. It is not an advertisement, a solicitation or legal advice, and using it does not create a lawyer–client relationship.