Latest alerts
  1. Home
  2. Insights
  3. Compliance
// compliance · 7 min read

DPDP Rules, 2025: what changes, when, and what to do now

The Rules are notified and the 18-month clock is running. A practical, phase-by-phase plan for Indian businesses.

Published 18 September 2026 · Dravincon Security Team

India's Digital Personal Data Protection Act, 2023 became operational when the Ministry of Electronics and Information Technology notified the DPDP Rules, 2025 in November 2025. The Rules arrive in phases, and the longest runway — 18 months — covers most of the obligations businesses actually have to build. That window closes in 2027.

The three phases

  • Immediately: definitions and the provisions that set up the Data Protection Board.
  • After 12 months: registration and obligations of Consent Managers — the platforms that will let people give, manage and withdraw consent across services.
  • After 18 months: notices, security safeguards, breach intimation, retention and erasure, children's data, rights of Data Principals and Significant Data Fiduciary duties.

The obligations that take the longest

1. Knowing where personal data lives

You cannot write an honest notice, delete data on time or report a breach accurately if you do not know which systems hold personal data. Data discovery across apps, databases, shared drives, spreadsheets, vendors and backups is the foundation — and typically the slowest step.

2. Notices and consent

Notices must be stand-alone, clear and plain, list the personal data and the specific purpose, and give a direct way to withdraw consent and to complain to the Board. Withdrawing consent must be as easy as giving it. Pre-ticked boxes and bundled "I agree to everything" checkboxes do not survive this standard.

3. Reasonable security safeguards

The Rules expect, at minimum, measures such as encryption, obfuscation or masking, access control, visibility through logs and monitoring, backups for continuity, and contracts that bind your processors to the same standard. Logs relating to processing must be kept for at least one year. Failing to take reasonable safeguards carries the Act's highest penalty — up to ₹250 crore.

4. Breach intimation

On becoming aware of a personal-data breach, you must inform each affected Data Principal and the Data Protection Board without delay, and send the Board a detailed report — facts, cause, mitigation and notifications made — within 72 hours. If you already report cyber incidents to CERT-In within 6 hours, align both processes now so one investigation feeds both.

5. Rights and grievances

People can ask for a summary of their data, correction, completion, updating and erasure, and can nominate someone to act for them. Publish how to make a request and respond to grievances within the period the Rules set — no more than 90 days.

A 90-day starter plan

  1. Weeks 1–4: appoint an owner, map personal data and processors, list every place you collect it.
  2. Weeks 5–8: rewrite notices, fix consent capture and withdrawal, define retention periods.
  3. Weeks 9–12: close security gaps on the systems holding the most sensitive data, write and rehearse the breach playbook.

Not sure where you stand? Our free DPDP check takes about five minutes and runs entirely in your browser.

This article is general information, not legal advice. Refer to the official text of the Act and Rules for your specific obligations.

// ready when you are

Find out how an attacker sees you — before they do.

Book a free 30-minute scoping call with our security team. No sales script, just an honest view of your risk and what to do first.

Call Email Under attack? Free DPDP Check