The DPDP Rules 2025 are the operating rules notified under India's Digital Personal Data Protection Act 2023, published in the Gazette in November 2025. The Act set the obligations in 2023; the Rules set the mechanics: how a consent notice must read, how a Consent Manager gets registered, how fast a breach must be reported, and what counts as verifiable consent for a child's data.
Most search traffic on this topic is chasing a deadline. That's the wrong frame. The Act already applies to any company processing personal data of individuals in India: the Rules don't create that scope, they schedule when the Data Protection Board can act on it.
The Rules notified in November 2025 phase in on two dates: Consent Manager registration on November 13, 2026, and hard enforcement of processor and Significant Data Fiduciary obligations on May 13, 2027.
What do the DPDP Rules 2025 actually cover?
The Rules translate the Act's principles into checkable mechanics across five areas: consent notice content, Consent Manager registration and interoperability, breach notification timelines, children's data verification, and additional duties for entities designated as Significant Data Fiduciaries. Each area has its own rule number and its own compliance surface, so a company can be behind on one and current on another.
- Consent notice content: what a notice must state in clear language before data is collected, separate from any existing terms-of-service or privacy-policy boilerplate.
- Consent Manager registration (Rule 4): the mechanics of the interoperable, Board-registered intermediary described in the Act's §6.
- Breach notification timelines: how quickly a Data Fiduciary must inform affected Data Principals and the Board once a personal data breach is identified.
- Children's data: the verification standard for parental or guardian consent, and restrictions on tracking or targeted advertising to minors.
- Significant Data Fiduciary duties: added obligations (data protection officer, periodic audit, algorithmic-impact assessment for some categories) that apply once MEITY designates an entity.
When do the DPDP Rules 2025 take effect?
The notification set a phased timeline, not a single go-live date. Phase I, the Data Protection Board's formation, is already complete. Phase II is the one most engineering teams are missing: it makes Consent Manager registration mandatory from November 13, 2026. Phase III brings the remaining rules, including processor obligations and the full Significant Data Fiduciary regime, into hard enforcement on May 13, 2027.
That gap matters operationally. A company that waits for the May 2027 date to start work will have missed the November 2026 Consent Manager deadline by six months, and will be building consent infrastructure and processor terms on the same timeline instead of sequencing them.
What's actually new for a consent flow?
Rule 4 defines a Consent Manager as a Board-registered, interoperable intermediary with a verifiable audit trail of every consent given and withdrawn. A cookie banner does not meet that bar on its own: it has to connect to a registered Consent Manager, or the processing has to rely on a documented §7 legitimate-use assessment instead. The full engineering breakdown of what that connection requires is in the Phase II consent manager post.
What do the Rules change for processors and vendors?
The Rules give the Act's processor obligations (documented instructions only, reasonable security safeguards, prompt breach notification to the Data Fiduciary, no unauthorised sub-processing) a concrete terminology and audit standard. A privacy policy or processor agreement drafted before the November 2025 notification is very likely using pre-Rules language, which is exactly what a BFSI or enterprise procurement review checks for. The processor-specific breakdown, including breach notification pathways, is in the DPDP processor obligations post.
What does breach notification actually require under the Rules?
The Act's §8(6) obligation to notify the Data Protection Board and affected Data Principals "as soon as possible" gets a concrete standard under the Rules: a Data Fiduciary must notify affected Data Principals without delay once a breach is identified, and must notify the Board within a fixed window that is materially shorter than most India SaaS companies' current incident-response runbooks assume. A processor handling data on a Fiduciary's behalf carries a parallel, faster obligation to notify the Fiduciary itself, since the Fiduciary cannot start its own clock until it knows a breach occurred. Most breach-response documentation predates this standard entirely: it was written against a generic "reasonable time" assumption, not a fixed window with two separate notification chains.
What should a company actually do before either enforcement date?
The two dates require different work, and starting them in the wrong order is the most common mistake. November 13, 2026 is the nearer deadline and the one most engineering teams underestimate, because it looks like a legal filing rather than a data-architecture project.
- Before November 13, 2026: map every processing activity currently running on consent as its legal basis, decide the Consent Manager route or a documented §7 legitimate-use assessment for each, and build or integrate the audit-trail infrastructure a registered Consent Manager requires.
- Before May 13, 2027: update every privacy policy and processor agreement to DPDP Rules 2025 terminology, add documented processor terms to enterprise contracts covering deletion and breach timelines, and confirm whether MEITY's Significant Data Fiduciary criteria apply to your scale and data categories.
- Ongoing, starting now: the Act's own obligations already apply regardless of enforcement phase, so a public-facing privacy notice with pre-Rules language or a missing consent mechanism is a live gap today, not a future one.
Teams that treat May 2027 as the only real deadline tend to discover the November 2026 Consent Manager requirement in Q4 2026, with six months of data-architecture work compressed into a much shorter runway. Sequencing the two dates correctly, rather than treating "DPDP Rules 2025" as a single monolithic deadline, is the actual takeaway of this explainer.
Frequently asked questions
What are the DPDP Rules 2025?
The DPDP Rules 2025 are the operating rules notified under India's Digital Personal Data Protection Act 2023. They were notified in the Gazette in November 2025 and specify how the Act's obligations actually work in practice: consent notice content, Consent Manager registration, breach notification timelines, children's data verification, and additional duties for Significant Data Fiduciaries. The Act set the obligations; the Rules set the mechanics.
When do the DPDP Rules 2025 take effect?
The Rules came into force in phases from their November 2025 notification date. Phase I, the Data Protection Board's formation, is already complete. Phase II activates the Consent Manager registration framework on November 13, 2026. Phase III brings the bulk of operational obligations, including processor duties and Significant Data Fiduciary requirements, into hard enforcement on May 13, 2027.
Do the DPDP Rules 2025 apply to a company before enforcement begins?
Yes. The DPDP Act 2023 defines who is a Data Fiduciary and what personal data processing is covered independently of the Rules' phased enforcement timeline. Any company processing the personal data of individuals in India is in scope from the Act's own commencement, regardless of when the Data Protection Board begins active adjudication. The enforcement dates change when the Board can act, not whether the obligation exists.
What do the DPDP Rules 2025 require of a Consent Manager?
Under Rule 4 of the DPDP Rules 2025, a Consent Manager must be registered with the Data Protection Board, be interoperable so a Data Principal can manage consent across multiple Data Fiduciaries through one interface, and maintain a verifiable audit trail of every consent given and withdrawn. A cookie banner or an internal preference toggle does not meet this definition.
What do the DPDP Rules 2025 say about children's data?
The Rules require verifiable parental or guardian consent before processing a child's personal data, using a method that can confirm the identity and age of the consenting adult rather than a simple self-declared checkbox. Processing that involves tracking, behavioural monitoring, or targeted advertising directed at children is restricted regardless of consent obtained.
Instant DPDP Rules 2025 posture scan, no account required
Juro scans your public-facing privacy notice and consent flow for DPDP Rules 2025 markers: pre-Rules terminology, missing consent-notice elements, and gaps in what your site discloses. It won't tell you that you're compliant, no scanner can, but it will show you what your public surface signals before a client or the Board looks at it.
Scan your site →