Rules

The Digital Personal Data Protection Rules 2025 (DPDP Rules 2025) were notified by India’s Ministry of Electronics and
Information Technology (MeitY) on 13 November 2025. These Rules operationalise the DPDPA 2023 and come into force in a
phased manner — certain provisions are effective immediately, others after 12 months, and the remaining after 18 months.
This page contains the full text of all 10 Rules with compliance guidance, published by Secure Privacy.

Ministry of Electronics and Information

RuleDescriptionEffective Date
RULE 1 – Short title and CommencementEstablishes the official title of the Digital Personal Data Protection Rules and defines their commencement timeline.
RULE 2 – DefinitionsDefines key terms and concepts used throughout the Digital Personal Data Protection Rules, including roles, systems, and consent mechanisms.
RULE 3 – Notice to seek consent of Data PrincipalSpecifies how notice must be given before obtaining user consent.
RULE 4 – Notice to inform of processing done where data principal has given consent before commencement of ActRequires informing users about data processing done based on prior consent.
RULE 5 – Registration, Accountability and Obligations of a Consent ManagerSets rules for registration and responsibilities of consent managers.
RULE 6 – Processing of Personal data for provision of subsidy, benefit, service, certificate, license or permitAllows processing of personal data for government services, benefits, and permits.
RULE 7 – Intimation of personal data breachRequires reporting personal data breaches to the authority within a specified time.
RULE 8 – Time period for specified purpose to be deemed as no longer being servedDefines when personal data must be deleted after purpose is fulfilled.
RULE 9 – Publishing of contact information of person who is able to answer questions about processingRequires publishing contact details for handling data-related queries.
RULE 10 – Verifiable Consent for processing personal data of child or person with disability who has lawful guardianRequires verifiable consent for processing data of children or persons with disabilities.
RULE 11 – Exemptions from processing of personal data of childProvides exemptions for processing personal data of children in specific cases.
RULE 12 – Measures to be undertaken by the Significant Data Fiduciary.Defines additional compliance measures for significant data fiduciaries.
RULE 13 – Rights of Data PrincipalOutlines the rights of data principals and how they can exercise them.
RULE 14 – Exemption from Act for Research, Archiving and Statistical purposeProvides exemptions for data processing in research, archiving, and statistical purposes.
RULE 15 – Appointment of Chairperson and other MembersDefines the process for appointing the Chairperson and members of the Board.
RULE 16 – Salary, allowances and other terms and conditions of service of Chairperson and other membersSpecifies salary, allowances, and service terms of the Chairperson and members.
RULE 17 – Proceedings of Board and authentication of its orders, directions and instrumentsCovers procedures for Board meetings and authentication of its decisions.
RULE 18 – Terms and conditions of appointment and service of officers and employees of BoardDefines terms of appointment and service conditions for Board officers and employees.
RULE 19 – Techno Legal measures to be adopted by BoardRequires adoption of techno-legal measures by the Board.
RULE 20 – AppealDefines the process for filing appeals against Board decisions.
SCHEDULE-I – Model NoticeProvides a model notice format for collecting user consent.
SCHEDULE-II – Standards for Processing by State and its InstrumentatlitiesDefines standards for data processing by the State and its authorities.
SCHEDULE-III – Table of time periodDefines data retention time periods for different purposes and entities.
SCHEDULE-IV – Exemptions from processing per personal data of Child u/s 9(4)Provides exemptions for processing personal data of children under specific conditions.
SCHEDULE-V – Standards of processing for research, archiving and statistical purposes u/s 17(2)(b)Provides standards and exemptions for processing data for research, archiving, and statistical purposes.
SCHEDULE-VI – Terms and Conditions of Service of the Chairperson and Other MembersSpecifies detailed service conditions, salary, and benefits of the Chairperson and members.
SCHEDULE-VII – Terms and Conditions of of appointment and service of officers and employees of BoardSpecifies terms and conditions of service for Board officers and employees.

Notification

New Delhi, the …………., 2024

GSR……..(E) : Draft of rules proposed to be made by the Central Government in exercise of the powers conferred by the
sub sections (1) and 92) of Section 40 of the Digital Personal Data Protection Act, 2023 (22 of 2023), on or after the
date of coming into force of the Act, are hereby published for the information of all persons likely to be affected
thereby; and notice is hereby given that the said draft rules shall be taken into consideration
after……………..2024.

Objections and Suggestions, if any, may be submitted on the website of MyGov (………….) by the said date.

The objections and suggestions which may be received from any person with respect to the said draft rules before the
expiry of the period specified above, shall not be attributd to the persons submitting publicly and shall be held in
fiduciary capacity to enable them to provide the same freely and shall be considered by the Central Government.

Scroll to Top