DPDP Rules 2025: Business Compliance Guide for India
India’s data-protection regime has moved from legislation to implementation. With the Digital Personal Data Protection Rules, 2025 notified and the principal business obligations scheduled to take effect in May 2027, organisations should use the transition period to redesign their consent, security, breach-response and vendor-management systems.
India’s DPDP Rules, 2025: What Businesses Must Do Before the Compliance Deadline
India’s digital privacy framework has entered the implementation stage. On 13 November 2025, the Ministry of Electronics and Information Technology notified the final Digital Personal Data Protection Rules, 2025, under the Digital Personal Data Protection Act, 2023.
The framework follows a phased commencement. Rules 1, 2 and 17 to 21 came into force upon publication. Rule 4, dealing with the registration and obligations of Consent Managers, is scheduled to come into force one year after publication, while Rules 3, 5 to 16, 22 and 23 are scheduled to come into force eighteen months after publication. A corresponding notification under the Act follows a similar staggered timeline. Consequently, Rule 4 is scheduled to take effect on 13 November 2026, while most operational rules and substantive business obligations are scheduled to take effect on 13 May 2027.
MeitY also stated in a May 2026 recruitment notice that the Data Protection Board of India had been established as a body corporate and invited applications for its Chairperson and Members. The Board is intended to inquire into personal-data breaches and non-compliance, issue remedial directions and impose monetary penalties under the Act.
Who Will Be Covered by the DPDP Framework?
The Act applies to digital personal data processed within India where the information was collected digitally or was collected in a non-digital form and subsequently digitised.
It can also apply to processing undertaken outside India when that processing relates to offering goods or services to individuals situated in India. Therefore, overseas businesses serving Indian customers may also need to examine their compliance position. Personal or domestic processing and certain personal data made publicly available by the individual or under a legal obligation are excluded from the Act’s scope.
1. Privacy Notices Must Become Clear and Specific
Businesses will need to move away from broad, generic privacy policies that attempt to cover every possible use of data.
Under the Rules, a notice must be understandable independently of other information. It must describe, in clear and plain language, the categories of personal data being processed and the specific purposes for which that data will be used. It must also provide an accessible method through which the individual can withdraw consent, exercise statutory rights and make a complaint to the Data Protection Board.
Consent under the Act must be free, specific, informed, unconditional and unambiguous. It must involve clear affirmative action and must be limited to personal data necessary for the stated purpose. Withdrawing consent must be as easy as giving it.
In practical terms, businesses should review:
- Website and mobile-app consent screens.
- Cookie and marketing preferences.
- Customer registration forms.
- Employee privacy notices.
- Existing databases collected before the law becomes operational.
- Methods for recording and proving consent.
2. Minimum Security Safeguards Are Now More Clearly Defined
The Rules require Data Fiduciaries to adopt reasonable security safeguards for personal data processed directly by them or on their behalf by a Data Processor.
The minimum measures include encryption, masking, obfuscation or tokenisation where appropriate; access controls; monitoring and review of access logs; measures to detect and investigate unauthorised access; backups and business-continuity arrangements; suitable security provisions in contracts with Data Processors; and appropriate technical and organisational controls. Relevant security logs and personal data connected with an incident may need to be retained for at least one year, unless another law requires a different period.
A business will remain responsible for processing carried out on its behalf. Merely outsourcing data storage, payroll, customer support, analytics or cloud services will not transfer the Data Fiduciary’s statutory responsibility to the service provider. The Act expressly requires the engagement of a Data Processor to be governed by a valid contract.
Businesses should therefore update vendor agreements to include security standards, access restrictions, audit rights, breach-reporting timelines, assistance with individual-rights requests, data-return obligations and secure deletion requirements.
3. Personal-Data Breaches Will Require Rapid Notification
A Data Fiduciary that becomes aware of a personal-data breach must notify each affected Data Principal without delay. The notification should explain the nature and extent of the breach, its likely consequences, the measures being taken to mitigate the risk, steps the affected person may take to protect themselves and the contact details of a responsible representative.
The Data Protection Board must also be informed without delay. Updated and detailed information must ordinarily be provided within 72 hours of becoming aware of the breach, unless the Board allows additional time following a written request.
This makes it essential for businesses to establish an incident-response plan before the law becomes fully operational. The plan should identify who will investigate the incident, who will decide whether notification is required, who will communicate with customers and regulators, and how the organisation will document its response.
4. Retention and Deletion Practices Must Be Defensible
Personal data should not be retained indefinitely merely because storage is inexpensive.
The Act requires data to be erased when consent is withdrawn or when it is reasonable to assume that the stated purpose is no longer being served, unless retention is required by another law. The Data Fiduciary must also cause its Data Processor to erase data made available for processing.
The Rules prescribe inactivity-based retention periods for specified categories of large e-commerce entities, online-gaming intermediaries and social-media intermediaries. They also require advance intimation, ordinarily at least 48 hours before scheduled erasure, in the circumstances covered by Rule 8.
Every organisation should consequently prepare a data-retention schedule that identifies:
- What information is held.
- Why it is being retained.
- The law or business purpose supporting retention.
- The applicable retention period.
- The method used for secure deletion.
- Whether copies remain with vendors, cloud providers or group companies.
5. Individuals Must Have Usable Rights and Grievance Channels
The Act recognises rights relating to access, correction, completion, updating, erasure, grievance redressal and nomination.
Businesses will need to publish an accessible method through which individuals can make rights requests. The Rules require the organisation’s grievance-redressal period to be prominently published and provide that it cannot exceed 90 days.
A general customer-service email address may not be sufficient unless the organisation has a documented process for authenticating the requester, locating relevant data, coordinating with processors, applying legal-retention exceptions and responding within the published timeline.
6. Children’s Data Requires Additional Safeguards
Under the Act, a person below the age of 18 is treated as a child. Before processing a child’s personal data, the Data Fiduciary must ordinarily obtain verifiable consent from the parent or lawful guardian.
The Act also restricts processing likely to have a detrimental effect on a child’s well-being and prohibits tracking, behavioural monitoring and targeted advertising directed at children, subject to prescribed exemptions. The Rules specify mechanisms for verifying the identity and age of the parent or guardian and recognise authorised entities and Digital Locker services for certain verification purposes.
Businesses offering education, gaming, social-media, entertainment, health, retail or financial services to young users should examine whether they can reliably identify child users and obtain legally valid parental consent.
7. Significant Data Fiduciaries Will Face Enhanced Duties
The Central Government may designate particular organisations or classes of organisations as Significant Data Fiduciaries after considering factors such as the volume and sensitivity of data processed, risks to individuals, national security, public order and electoral democracy.
Such entities will have to appoint a Data Protection Officer based in India, appoint an independent data auditor and conduct periodic data-protection impact assessments and audits.
Penalty Exposure
The statutory penalty for failure to take reasonable security safeguards may extend to ₹250 crore. Failure to comply with breach-notification obligations and specified obligations relating to children may attract penalties extending to ₹200 crore, subject to an inquiry and determination by the Data Protection Board.
A Practical DPDP Readiness Plan
Businesses should use the remaining implementation period to complete the following work:
- Prepare an organisation-wide personal-data inventory.
- Record the purpose and legal basis for every processing activity.
- Rewrite customer, employee and vendor privacy notices.
- Redesign consent and consent-withdrawal processes.
- Establish procedures for access, correction and erasure requests.
- Update Data Processor and technology-vendor contracts.
- Test a 72-hour breach-investigation and reporting workflow.
- Create retention and secure-deletion schedules.
- Review children’s-data and age-verification processes.
- Train employees who handle personal data.
Conclusion
The DPDP framework should not be treated as a privacy-policy drafting exercise. It will require coordinated changes across technology, information security, customer service, marketing, human resources, procurement and legal functions.
Organisations that begin early will be better placed to identify unnecessary data collection, renegotiate vendor contracts, improve cyber resilience and avoid hurried compliance work immediately before the operative deadline.
Avyaksham Legal LLP can assist businesses with DPDP compliance audits, privacy notices, consent frameworks, vendor contracts, data-retention policies and personal-data breach response protocols.
Disclaimer: This article is intended for general informational purposes and does not constitute legal advice. The applicability of the DPDP Act and Rules will depend on the nature of the organisation, the data processed and the specific processing activities undertaken.