DPDP Rules 2025: what they require and when

Updated 19 Sep 2026 · 6min read · Reviewed by ConsentLo's DPDP audit team

The Digital Personal Data Protection Rules, 2025 turn the DPDP Act into day-to-day requirements. They were notified in November 2025 and apply in phases. Here is what they ask of a Data Fiduciary.

A phased start

The provisions setting up the Data Protection Board took effect first. Registration of Consent Managers follows after about 12 months, and most obligations on businesses, including notices, consent, rights, breach reporting and retention, apply after about 18 months. That gives organisations a defined window to prepare.

Notices

A notice must be clear and stand on its own. It should itemise the personal data and the specific purpose, and explain how to withdraw consent, exercise rights and complain to the Board. It must be available in English and, on request, in the Eighth Schedule languages.

Breach reporting

On becoming aware of a personal data breach, you must inform each affected Data Principal without delay, in plain language, including what happened, the likely consequences, what you are doing about it and what they can do. You must also send the Board an initial intimation without delay and a detailed report within 72 hours.

Retention and erasure

Data must be erased once the purpose is served. For some large platforms, such as e-commerce, online gaming and social media intermediaries above set user thresholds, data is treated as no longer needed after a defined period of inactivity. You must give the person notice at least 48 hours before erasure so they can log in and keep their account.

Children's data

Verifiable parental consent can be established using reliable details already held about an identifiable adult, or through a virtual token issued by an authorised entity such as DigiLocker. Certain classes, such as healthcare and educational institutions, get limited exemptions for specific purposes.

Security, logs and grievances

Reasonable security safeguards include encryption or masking, access control, logging and monitoring. Logs should be kept for at least a year. Grievances must be answered within a reasonable period, not exceeding 90 days.

Frequently asked questions

When were the DPDP Rules notified?

The Digital Personal Data Protection Rules, 2025 were notified in November 2025, with most business obligations applying after an 18-month transition.

How fast must a data breach be reported under the DPDP Rules?

Affected people must be told without delay, and the Data Protection Board must receive a detailed report within 72 hours of becoming aware of the breach.

Do the DPDP Rules require notices in Indian languages?

Yes. Notices must be available in English and in any of the 22 languages listed in the Eighth Schedule of the Constitution.

This guide is general information about the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, not legal advice.