The Digital Personal Data Protection Act 2023 set out the principles. The DPDP Rules 2025, notified in November 2025, supply the operational detail — how notices must look, how breaches must be reported, how long logs must be kept — and fix the dates from which each obligation applies. This guide summarises what the Rules mean for a Data Fiduciary preparing for compliance.
Implementation timeline
The Rules come into force in phases rather than all at once:
| Phase | What applies | When |
|---|---|---|
| Immediate | Constitution and functioning of the Data Protection Board of India | November 2025 |
| 12 months | Registration and obligations of Consent Managers | November 2026 |
| 18 months | Core Data Fiduciary obligations — notice, consent, security safeguards, breach intimation, data retention and erasure, data principal rights, children's data | May 2027 |
Eighteen months sounds generous, but most organisations first need to find where personal data lives, re-paper consent flows, and change systems. That work typically takes longer than expected, so a gap assessment well ahead of May 2027 is the safer path.
Key obligations under the Rules
1. Notice to Data Principals
A notice must be clear and in plain language, understandable on its own, and give an itemised description of the personal data collected and the specific purpose for each item. It must also explain how the individual can withdraw consent, exercise their rights and complain to the Board.
2. Reasonable security safeguards
Data Fiduciaries must implement reasonable security safeguards, including:
- Encryption, obfuscation, masking or virtual tokens to protect personal data
- Access controls over the computer resources that process personal data
- Logs and monitoring so unauthorised access can be detected and investigated
- Backups and measures to keep processing going after a compromise
- Retention of logs and related personal data for at least one year, unless another law says otherwise
- Matching safeguard obligations written into contracts with Data Processors
3. Personal data breach intimation
On becoming aware of a personal data breach, a Data Fiduciary must inform each affected Data Principal without delay and intimate the Data Protection Board. A detailed report to the Board, covering facts, cause, mitigation and notifications made, is due within 72 hours of becoming aware (or a longer period if the Board allows).
4. Data retention and erasure
Personal data must be erased once the purpose is served and consent is withdrawn or retention is no longer needed. For certain large platforms (such as e-commerce, online gaming and social media intermediaries above specified user thresholds), the Rules prescribe erasure after a fixed period of user inactivity, with advance notice to the user before erasure.
5. Data Principal rights and grievance redressal
Data Fiduciaries must publish how individuals can request access, correction, completion or erasure of their data, and nominate another person. Grievances must be resolved within the period set by the Rules, and contact details of the person who can answer data protection questions (or the DPO, for a Significant Data Fiduciary) must be published.
6. Children's data
Processing personal data of a child (under 18) requires verifiable consent of a parent or lawful guardian. The Rules describe how that verification can be done and list limited exemptions, such as certain healthcare and educational institutions.
7. Significant Data Fiduciaries
Organisations notified as Significant Data Fiduciaries carry extra duties: appointing a Data Protection Officer based in India, appointing an independent data auditor, and carrying out a Data Protection Impact Assessment and audit periodically, with findings reported to the Board.
Penalties
Penalties under the Schedule to the Act go up to ₹250 crore for failing to take reasonable security safeguards, and up to ₹200 crore each for failing to notify a breach or to meet the obligations for children's data. The Board decides the amount after considering the nature, gravity and duration of the breach.
What to do now
- Map where personal data is collected, stored and shared — including vendors.
- Review every consent and notice touchpoint against the itemised-notice requirement.
- Test your breach response against the 72-hour reporting window.
- Check log retention and access controls against the one-year minimum.
- Commission an independent gap assessment so remediation can be planned and budgeted.
See the DPDP audit checklist for the controls an auditor will test.
