DPDP Audits

DPDP Rules 2025 Explained: Timeline and Key Obligations

What the DPDP Rules 2025 require, when each obligation applies, and what Data Fiduciaries should prepare before the May 2027 compliance date.

By Ram Krishan Dudeja, CISA CAIIB · Last reviewed 25 September 2026

The Digital Personal Data Protection Act 2023 set out the principles. The DPDP Rules 2025, notified in November 2025, supply the operational detail — how notices must look, how breaches must be reported, how long logs must be kept — and fix the dates from which each obligation applies. This guide summarises what the Rules mean for a Data Fiduciary preparing for compliance.

Implementation timeline

The Rules come into force in phases rather than all at once:

PhaseWhat appliesWhen
ImmediateConstitution and functioning of the Data Protection Board of IndiaNovember 2025
12 monthsRegistration and obligations of Consent ManagersNovember 2026
18 monthsCore Data Fiduciary obligations — notice, consent, security safeguards, breach intimation, data retention and erasure, data principal rights, children's dataMay 2027

Eighteen months sounds generous, but most organisations first need to find where personal data lives, re-paper consent flows, and change systems. That work typically takes longer than expected, so a gap assessment well ahead of May 2027 is the safer path.

Key obligations under the Rules

1. Notice to Data Principals

A notice must be clear and in plain language, understandable on its own, and give an itemised description of the personal data collected and the specific purpose for each item. It must also explain how the individual can withdraw consent, exercise their rights and complain to the Board.

2. Reasonable security safeguards

Data Fiduciaries must implement reasonable security safeguards, including:

3. Personal data breach intimation

On becoming aware of a personal data breach, a Data Fiduciary must inform each affected Data Principal without delay and intimate the Data Protection Board. A detailed report to the Board, covering facts, cause, mitigation and notifications made, is due within 72 hours of becoming aware (or a longer period if the Board allows).

4. Data retention and erasure

Personal data must be erased once the purpose is served and consent is withdrawn or retention is no longer needed. For certain large platforms (such as e-commerce, online gaming and social media intermediaries above specified user thresholds), the Rules prescribe erasure after a fixed period of user inactivity, with advance notice to the user before erasure.

5. Data Principal rights and grievance redressal

Data Fiduciaries must publish how individuals can request access, correction, completion or erasure of their data, and nominate another person. Grievances must be resolved within the period set by the Rules, and contact details of the person who can answer data protection questions (or the DPO, for a Significant Data Fiduciary) must be published.

6. Children's data

Processing personal data of a child (under 18) requires verifiable consent of a parent or lawful guardian. The Rules describe how that verification can be done and list limited exemptions, such as certain healthcare and educational institutions.

7. Significant Data Fiduciaries

Organisations notified as Significant Data Fiduciaries carry extra duties: appointing a Data Protection Officer based in India, appointing an independent data auditor, and carrying out a Data Protection Impact Assessment and audit periodically, with findings reported to the Board.

Penalties

Penalties under the Schedule to the Act go up to ₹250 crore for failing to take reasonable security safeguards, and up to ₹200 crore each for failing to notify a breach or to meet the obligations for children's data. The Board decides the amount after considering the nature, gravity and duration of the breach.

What to do now

  1. Map where personal data is collected, stored and shared — including vendors.
  2. Review every consent and notice touchpoint against the itemised-notice requirement.
  3. Test your breach response against the 72-hour reporting window.
  4. Check log retention and access controls against the one-year minimum.
  5. Commission an independent gap assessment so remediation can be planned and budgeted.

See the DPDP audit checklist for the controls an auditor will test.

Need an independent DPDP audit?

67 controls, auditor-signed findings, and a remediation roadmap you can act on.

Book a Free Consultation

Related guides

This guide is general information, not legal advice. Refer to the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 as notified for the authoritative text.