DPDP Act and Rules 2025: what every Indian business must do now
· 9 min read
Reviewed by Adv. Mahir Gupta, Advocate, Delhi High Court ·

India's Digital Personal Data Protection Act, 2023 has been law for some time, but it could not be enforced until rules were made under it. The Digital Personal Data Protection Rules, 2025 were notified by the Ministry of Electronics and Information Technology by G.S.R. 846(E), published in the Gazette on 13 November 2025 (the official press release followed on 14 November 2025). Since then the question for a business is no longer whether the law applies. It is whether your systems, contracts and staff will be ready on the day the main duties begin. This guide is written for founders, CFOs, and school and clinic owners. It is general information, not legal advice.
The dates first. The Rules commence in three phases. On 13 November 2025 the institutional provisions came into force: Rules 1, 2 and 17 to 21, covering the short title, definitions and the constitution and working of the Data Protection Board of India. On 13 November 2026, twelve months after publication, Rule 4, the registration framework for Consent Managers, takes effect. On 13 May 2027, eighteen months after publication, Rules 3 and 5 to 16 (and Rules 22 and 23) take effect, and with them the substantive duties: notice, consent, children's data, Significant Data Fiduciary duties, Data Principal rights, security safeguards, breach reporting, appeals and penalties. Some commentary rounds this last date to 14 May 2027. The Gazette date and the eighteen-month count point to 13 May 2027, and we use that date here. Please confirm it against the notification text before you set an internal deadline.
Who is who. A Data Fiduciary is the person or organisation that decides why and how personal data is processed. If you run a school, a clinic, an online shop or a payroll, you are almost certainly a Data Fiduciary. A Data Processor handles data on your behalf, such as a cloud host, a payment gateway, an SMS vendor or an outsourced accounting firm. The responsibility stays with you: the Act expects the Fiduciary to bind its processors by contract. The Data Principal is the individual the data is about, and for a child it includes the parent or lawful guardian.
Significant Data Fiduciaries are a smaller group, notified by the Central Government on factors such as the volume and sensitivity of data and the risk to individuals. If you are notified, you must appoint a Data Protection Officer based in India who reports to your board, engage an independent Data Auditor, and carry out an annual Data Protection Impact Assessment and audit. Most small businesses will not be in this class, but a large school group, a hospital chain or a lending app could be. Watch for the notifications.
Lawful grounds and consent. You may process personal data only for a lawful purpose, and in practice that means either consent or one of the limited 'legitimate uses' listed in the Act. Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and it must be as easy to withdraw as to give. Pre-ticked boxes and consent bundled into a take-it-or-leave-it form will not meet the standard. Collect only what you need for the stated purpose. A clinic that asks for a patient's Aadhaar copy to book a routine appointment should ask itself what purpose that serves.
The notice. Rule 3 requires the notice to be presented on its own, separate from other terms, in clear and plain language, and under S. 5(3) of the Act the person must be able to read it in English or any language listed in the Eighth Schedule to the Constitution. It must give an itemised description of the personal data, the specific purpose for which each item is used, and how the person can withdraw consent, exercise their rights and complain to the Board. For existing customers whose consent was obtained before the duties begin, S. 5(2) of the Act expects you to give the notice as soon as reasonably practicable, and you may keep processing until the person withdraws consent. Plan that notice, and plan fresh consent for any new purpose. Start with a data map, because you cannot write an itemised notice for data you have not listed.
Data Principal rights. Individuals can ask for a summary of the data you hold and the parties it has been shared with, ask for correction and erasure, withdraw consent, nominate someone to exercise rights on their behalf if they die or become incapacitated, and use a grievance process. You need a named contact point, a published way to raise a request, and an internal owner who answers within the time the Rules allow. A shared inbox that nobody reads is not a grievance process.
Security safeguards. The Act requires reasonable security safeguards to prevent a personal data breach, and this is where the highest penalty sits. In practice the Rules look for measures such as encryption or masking, access control, logging and monitoring, backups, and contracts that bind processors to the same standard. They also require you to retain the relevant logs and personal data for at least one year so that a breach can be investigated, unless another law asks for more. The Rules do not name specific products. As a practical baseline for a small business, we suggest multi-factor authentication on email and admin panels, patched systems, restricted staff access and a tested backup.
Breach intimation. If a personal data breach occurs, you must tell each affected individual without delay, in clear language: what happened, what data is involved, the likely consequences, what you have done, and what they can do to protect themselves. You must also intimate the Data Protection Board without delay, followed by a detailed report within 72 hours. This sits alongside the six-hour incident reporting direction issued by CERT-In under the IT Act, so one incident can trigger two clocks. Decide now who calls whom, and keep the evidence.
Children's data. Under the Act a child is anyone under 18. Before processing a child's data you must obtain verifiable consent from the parent or lawful guardian, and you must not track or monitor a child's behaviour or direct targeted advertising at children. The Rules allow the parent's identity to be verified through existing records or a government-authorised service such as DigiLocker. Limited exemptions exist for educational institutions and healthcare providers, but only for what the activity requires, for example a school using data for education and safety. Marketing to pupils or parents is not covered by that exemption.
Retention and erasure. Keep personal data only as long as the purpose lasts, then erase it, unless a law requires you to keep it. For large e-commerce, online gaming and social media platforms above the user thresholds in the Third Schedule, the Rules require erasure once the user has been inactive for three years, with at least 48 hours' prior notice to the user. Other businesses are not bound by that three-year rule. Smaller businesses should still set a written retention schedule: for example, applicant data deleted after a hiring cycle, and enquiry data deleted when the enquiry closes. Ask your processors to delete on the same schedule.
Cross-border transfers. India has not chosen blanket data localisation for ordinary businesses, although the Rules allow the Central Government to specify certain data that Significant Data Fiduciaries must not transfer abroad. Under S. 16 of the Act, you may transfer personal data outside India unless the Central Government has restricted the transfer to a particular country or territory by notification. That means a foreign cloud or software vendor is usually permitted today, but you should record where your data sits and be ready to move it if a restriction is notified. Sector regulators such as the RBI may impose stricter requirements, and those continue to apply.
The Data Protection Board and penalties. The Board is the enforcement body. It receives complaints and breach reports, inquires into them and can impose penalties after a hearing. The maximum penalties in the Schedule to the Act are: up to ₹250 crore for failure to take reasonable security safeguards; up to ₹200 crore for failure to notify a breach; up to ₹200 crore for breach of the duties relating to children; up to ₹150 crore for breach of Significant Data Fiduciary duties; and up to ₹50 crore for other breaches. These are ceilings, not fixed fines, and the Board weighs the nature, gravity and duration of the breach and what you did to limit harm. Under S. 37, if penalties have been imposed on a Data Fiduciary in two or more instances, the Central Government may, on the Board's reference, direct the blocking of public access to its service.
Readiness checklist, part one. 1. Appoint one accountable person, even if you are a five-person company, and write down who decides about data. 2. Build a data map that lists every kind of personal data you hold, where it sits, who can see it and which vendors touch it. 3. For each item, write the purpose and the lawful ground, and delete data that has no purpose. 4. Rewrite your notice as a separate, plain-language document in English and, where your customers need it, their main language, with the itemised data and purposes.
Readiness checklist, part two. 5. Rebuild consent so that it is an affirmative action, can be withdrawn as easily as it was given, and is recorded with a date and the notice version. 6. Set up a way for people to ask for access, correction and erasure, name the person who answers, and test it once. 7. Put written data-protection terms into the contract of every processor, including the cloud host, payment gateway, messaging tool and accountant. 8. Apply the basic security controls: multi-factor authentication, encryption of stored personal data, restricted access, patching, tested backups and one year of logs.
Readiness checklist, part three. 9. Write a breach playbook that names who tells the individuals, who tells the Board within the timelines in the Act and the Rules, who tells CERT-In within six hours, and who preserves the evidence, then rehearse it. 10. If you handle children's data, introduce verifiable parental consent and switch off tracking and targeted advertising aimed at children. 11. Fix a retention schedule and an erasure routine, and record where data is stored outside India. 12. Brief your staff, review the plan every quarter until 13 May 2027, and check whether you may be notified as a Significant Data Fiduciary.
Why start early. Most of the work in this list is slow: mapping data, renegotiating vendor contracts and rebuilding consent screens. A business that begins in 2027 will be doing this in the weeks before enforcement. Penalties for security failures are also the highest in the schedule, so the technical work matters as much as the paperwork. Codesnag's security assessments can help you test the safeguards in point 8, and our response team supports organisations during a breach. For questions on how the law applies to your own facts, please consult a qualified advocate.
Sources
- Legal 500: India's DPDP Act and the DPDP Rules 2025: Phased Commencement, Core Obligations and a Board-Ready Compliance Strategy
- TCSA: DPDP Rules 2025: The Complete Implementation Roadmap for Indian Companies
- Privy by IDfy: DPDP Compliance Guide 2026: What Indian Enterprises Must Do Before May 2027
- PIB: DPDP Rules, 2025 Notified
First published on codesnag.ai

