# dpdprules.org > An independent, free reference for India's Digital Personal Data Protection framework: the DPDP Act 2023 and the DPDP Rules 2025. Every legal claim on the site carries an exact official source reference (Gazette of India, India Code, MeitY), a claim type label (official requirement, explanation, interpretation or recommendation), and a last verified date. Computed commencement dates are always labelled interpretation until officially confirmed. The site provides legal information, not legal advice. The statuses below were read against the Gazette prints between 16 August 2026 and 24 August 2026. That is when this site last read the instruments; it is not a statement that nothing has been notified since. Status last checked 28 September 2026 against the MeitY library and India Code. That second date is a weekly check for a new filing in either collection, not a re reading of the Gazette prints. Key facts, each carrying its own source and date on the page it comes from: the DPDP Act 2023 (Act No. 22 of 2023, assent 11 August 2023) commences in 3 phases under notification G.S.R. 843(E); the DPDP Rules 2025 were notified as G.S.R. 846(E) on 13 November 2025 and commence in 3 groups under Rule 1. The Data Protection Board of India was established on 13 November 2025 by G.S.R. 844(E), and the sections constituting the Board are in force. No appointment of a Chairperson or of a Member has been located in the primary record as at 28 August 2026, the most recent official document on file being MeitY's circular of 6 May 2026 inviting applications, and that is a statement about what a search of official channels found rather than a certified negative; the article "Is the Data Protection Board operational? 2 separate reasons it is not" below sets out the channels searched and their limits. ## Primary reference - [The DPDP Act 2023, all 44 sections verbatim](https://dpdprules.org/act): official Gazette text of every section with commencement status - [The DPDP Rules 2025, all 23 rules and 7 Schedules verbatim](https://dpdprules.org/rules): official Gazette text with corrigendum corrections applied - [Official documents](https://dpdprules.org/documents): the DPDP Act PDF, DPDP Rules PDF, corrigenda and commencement notifications - DPDP Rules 2025 PDF: G.S.R. 846(E), Gazette dated 13 November 2025, 41 pages, Hindi and English, https://egazette.gov.in/WriteReadData/2025/267650.pdf, also on MeitY (byte identical, checked 23 September 2026): https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf - DPDP Act 2023 PDF: Act No. 22 of 2023, Gazette dated 11 August 2023, 21 pages, English, https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf - Corrigendum to the DPDP Rules PDF: G.S.R. 892(E), Gazette dated 11 December 2025, 1 page, English, https://egazette.gov.in/WriteReadData/2025/268455.pdf, also on MeitY (byte identical, checked 23 September 2026): https://www.meity.gov.in/static/uploads/2025/12/3c7ebbae0e5456f493f486e6845df86b.pdf - Commencement notification PDF: G.S.R. 843(E), Gazette dated 13 November 2025, 2 pages, Hindi and English, https://egazette.gov.in/WriteReadData/2025/267647.pdf, also on MeitY (byte identical, checked 23 September 2026): https://www.meity.gov.in/static/uploads/2025/11/c56ceae6c383460ca69577428d36828b.pdf - [Act to Rules map](https://dpdprules.org/act-rules-map): which DPDP Rule 2025 operationalises which Act section, traced through the section 40(2) rule making clauses - [Timeline](https://dpdprules.org/timeline): verified milestones from 2017 to the computed 2027 dates, each with a primary source - [FAQs](https://dpdprules.org/questions): direct answers to common DPDP questions, each backed by a sourced article - [For individuals](https://dpdprules.org/individuals): what the Act gives a Data Principal, the 4 Chapter III rights and the right to withdraw consent, with the commencement basis on each ## The DPDP Act 2023 section by section, with the commencement status of each Each line states whether that provision is in force, then gives a plain English explanation of what it says, scoped to that status; the explanation is not the verbatim text. The 3 groups are set by paragraphs (a), (b) and (c) of notification G.S.R. 843(E): paragraph (a) is in force from publication on 13 November 2025, paragraph (b) runs 1 year from that date and paragraph (c) 18 months. A date computed from one of those periods, rather than fixed by the date of publication, always carries the label "interpretation until officially confirmed". G.S.R. 843(E) names sections, sub sections and clauses, and never names the Schedule at all; it also names section 1(2) without naming section 1(1). Where the status of a provision is itself a reading of that instrument, the line says so. - [Section 1, Short title and commencement](https://dpdprules.org/act/1): Partly in force since 13 November 2025. That status is a reading of notification G.S.R. 843(E), which does not name this provision in those words. What it says, only part of which is in force today: This section names the law as the Digital Personal Data Protection Act, 2023 and lets the Central Government bring it into effect through Gazette notification, with different dates allowed for different provisions. A reference to commencement in any provision then means the date that particular provision takes effect. - [Section 2, Definitions](https://dpdprules.org/act/2): In force since 13 November 2025. What it says: Here the Act defines its key terms, including Data Fiduciary (whoever decides why and how personal data is processed), Data Principal (the individual the data is about), Data Processor, personal data, processing, personal data breach, child, Consent Manager, Significant Data Fiduciary and the Board, along with supporting expressions used throughout the law. - [Section 3, Application of Act](https://dpdprules.org/act/3): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: The Act covers digital personal data processed within India, whether collected digitally or digitised later, and processing outside India connected with offering goods or services to Data Principals in India. It does not cover personal or domestic use by an individual, or data the Data Principal or someone legally required has made publicly available. - [Section 4, Grounds for processing personal data](https://dpdprules.org/act/4): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: Personal data may be processed only under this Act and for a lawful purpose, and only on one of two grounds: the Data Principal has given consent, or the processing falls within the certain legitimate uses the Act lists. A lawful purpose means any purpose not expressly forbidden by law. - [Section 5, Notice](https://dpdprules.org/act/5): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: Every consent request must be accompanied or preceded by a notice from the Data Fiduciary describing the personal data, the purpose, how to exercise her rights and how to complain to the Board. Notice is also due where consent predates commencement of the Act, and the Data Principal is the one given the option to access the notice in English or any Eighth Schedule language. - [Section 6, Consent](https://dpdprules.org/act/6): Phased commencement; it commences in 2 parts, on the computed date 13 November 2026, which is interpretation until officially confirmed, then the computed date 13 May 2027, which is interpretation until officially confirmed. No part of it is in force yet. What it says, none of which is in force today: Consent must be free, specific, informed, unconditional and unambiguous, given by clear affirmative action and limited to data necessary for the specified purpose. The Data Principal may withdraw consent at any time with ease comparable to giving it, may act through a Consent Manager, and the Data Fiduciary must prove notice and consent if questioned in a proceeding. - [Section 7, Certain legitimate uses](https://dpdprules.org/act/7): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: 9 grounds let a Data Fiduciary process personal data without a fresh consent request: data the Data Principal volunteered without objection, prescribed State subsidies, benefits and services, State functions and security, legal disclosure obligations, court orders, medical emergencies, epidemics and public health threats, disasters or public order breakdowns, and employment related purposes. - [Section 8, General obligations of Data Fiduciary](https://dpdprules.org/act/8): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: A Data Fiduciary answers for compliance even when a Data Processor handles the work and may engage processors only under a valid contract. It must keep certain data accurate, apply security safeguards, report personal data breaches to the Board and affected Data Principals, erase data no longer needed, publish a contact point and provide grievance redressal. - [Section 9, Processing of personal data of children](https://dpdprules.org/act/9): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: For a child, or a person with disability who has a lawful guardian, the Data Fiduciary must first obtain verifiable parental or guardian consent. Processing likely to harm a child, tracking, behavioural monitoring and targeted advertising directed at children are barred; exemptions from the consent, tracking and advertising rules may be prescribed, with age relaxations for verifiably safe processing. - [Section 10, Additional obligations of Significant Data Fiduciary](https://dpdprules.org/act/10): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: Once the Central Government notifies a Data Fiduciary as a Significant Data Fiduciary, based on factors such as data volume and sensitivity, risk to Data Principals and national interests, it must appoint an India based Data Protection Officer answerable to its governing body, engage an independent data auditor, and carry out periodic Data Protection Impact Assessments and audits. - [Section 11, Right to access information about personal data](https://dpdprules.org/act/11): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: A Data Principal who gave consent, or volunteered data under certain legitimate uses, can ask the Data Fiduciary for a summary of her personal data and processing activities, the identities of Data Fiduciaries and Data Processors the data was shared with, and other prescribed information. An exception covers sharing authorised by law for offence or cyber incident purposes. - [Section 12, Right to correction and erasure of personal data](https://dpdprules.org/act/12): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: Correction, completion, updating and erasure of her personal data are rights of the Data Principal where she previously gave consent, including data volunteered under certain legitimate uses. The Data Fiduciary must fix inaccurate or misleading data, complete and update it, and erase it on request unless retention is needed for the specified purpose or legal compliance. - [Section 13, Right of grievance redressal](https://dpdprules.org/act/13): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: Every Data Principal is entitled to readily available grievance redressal from a Data Fiduciary or Consent Manager for acts or omissions concerning her personal data or her rights. Responses are due within a prescribed period, and she must exhaust this route before taking her grievance to the Board. - [Section 14, Right to nominate](https://dpdprules.org/act/14): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: The right to nominate lets a Data Principal name another individual who will exercise her rights under the Act if she dies or becomes incapacitated. Incapacity here means inability to exercise those rights due to unsoundness of mind or infirmity of body, and the manner of nomination will be prescribed. - [Section 15, Duties of Data Principal](https://dpdprules.org/act/15): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: Data Principals themselves carry duties: comply with applicable laws when exercising rights under the Act, not impersonate anyone when providing personal data, not suppress material information when providing data for State issued documents or identifiers, not file false or frivolous grievances with a Data Fiduciary or the Board, and give only verifiably authentic information when seeking correction or erasure. - [Section 16, Processing of personal data outside India](https://dpdprules.org/act/16): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: The Central Government may issue a notification restricting a Data Fiduciary from transferring personal data for processing to any country or territory it names. Any other Indian law that imposes stronger protection or tighter restrictions on such transfers outside India continues to apply and is not limited by this section. - [Section 17, Exemptions](https://dpdprules.org/act/17): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: Parts of the Act do not apply in listed situations, including enforcing legal rights or claims, judicial and regulatory functions, offence prevention, certain contracts concerning Data Principals outside India, approved company arrangements, and loan default assessment. Separate provisions cover notified state agencies, research, archiving and statistical purposes, and government power to relieve notified Data Fiduciaries, including startups, from some duties. - [Section 18, Establishment of Board](https://dpdprules.org/act/18): In force since 13 November 2025. What it says: This provision establishes the Data Protection Board of India, effective from a date the Central Government notifies. The Board is a body corporate with perpetual succession and a common seal; it can acquire, hold and dispose of property, enter contracts, and sue or be sued, with its headquarters at a notified place. - [Section 19, Composition and qualifications for appointment of Chairperson and Members](https://dpdprules.org/act/19): In force since 13 November 2025. What it says: The Board consists of a Chairperson and the number of Members the Central Government notifies, appointed in a prescribed manner. Appointees must have ability, integrity and standing, plus knowledge or experience in fields like data governance, dispute resolution, technology, the digital economy or law, and at least one Member must be a legal expert. - [Section 20, Salary, allowances payable to and term of office](https://dpdprules.org/act/20): In force since 13 November 2025. What it says: Salaries, allowances and other service conditions of the Chairperson and Members are set by prescribed rules and cannot be changed to their disadvantage after appointment. Each holds office for a term of two years and remains eligible for appointment to a further term. - [Section 21, Disqualifications for appointment and continuation as Chairperson and Members of Board](https://dpdprules.org/act/21): In force since 13 November 2025. What it says: A person cannot be appointed or continue as Chairperson or Member if adjudged insolvent, convicted of an offence that in the Central Government's opinion involves moral turpitude, physically or mentally incapable of acting, holding interests likely to prejudice their functions, or having abused the position against the public interest. Removal by the Central Government requires an opportunity to be heard. - [Section 22, Resignation by Members and filling of vacancy](https://dpdprules.org/act/22): In force since 13 November 2025. What it says: Resignation of the Chairperson or a Member takes effect on the earliest of government permission, three months after notice, a successor assuming office, or term expiry. Vacancies are filled by fresh appointment. For 1 year after ceasing office they cannot accept employment without government approval, and must disclose subsequent employment with Data Fiduciaries against whom they initiated or heard proceedings. - [Section 23, Proceedings of Board](https://dpdprules.org/act/23): In force since 13 November 2025. What it says: Meetings of the Board, including by digital means, and the authentication of its orders follow prescribed procedure. Its acts remain valid despite vacancies, defects in constitution or appointments, or procedural irregularities not affecting the merits, and when the Chairperson cannot act, the most senior Member performs those functions until the Chairperson returns. - [Section 24, Officers and employees of Board](https://dpdprules.org/act/24): In force since 13 November 2025. What it says: With prior approval of the Central Government, the Board may appoint the officers and employees it considers necessary for efficient discharge of its functions under the Act. Their terms and conditions of appointment and service are those set out in prescribed rules. - [Section 25, Members and officers to be public servants](https://dpdprules.org/act/25): In force since 13 November 2025. What it says: When acting or claiming to act under this Act, the Chairperson, Members, officers and employees of the Board are treated as public servants within the meaning of section 21 of the Indian Penal Code. This deemed status applies to conduct in pursuance of the provisions of the Act. - [Section 26, Powers of Chairperson](https://dpdprules.org/act/26): In force since 13 November 2025. What it says: Three powers rest with the Chairperson: general superintendence and direction over the administrative matters of the Board, authorising any Board officer to scrutinise intimations, complaints, references or correspondence addressed to it, and authorising individual Members or groups of Members to perform Board functions or conduct proceedings, including allocating proceedings among them. - [Section 27, Powers and functions of Board](https://dpdprules.org/act/27): Phased commencement; it commences in 2 parts, on the computed date 13 November 2026, which is interpretation until officially confirmed, then the computed date 13 May 2027, which is interpretation until officially confirmed. No part of it is in force yet. What it says, none of which is in force today: On breach intimations, Data Principal complaints, government references or court directions, the Board inquires into personal data breaches and failures by Data Fiduciaries, Consent Managers or intermediaries, directs urgent remedial measures, and imposes penalties under the Act. It may issue binding directions after a hearing, and later modify, suspend, withdraw or cancel them. - [Section 28, Procedure to be followed by Board](https://dpdprules.org/act/28): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: The Board functions as an independent body and, as far as practicable, a digital office, deciding whether grounds exist to inquire, closing proceedings or inquiring with recorded reasons, and following natural justice. It has civil court powers over summons and evidence, may pass interim orders after hearing the person concerned, and can impose costs for false or frivolous complaints. - [Section 29, Appeal to Appellate Tribunal](https://dpdprules.org/act/29): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: Anyone aggrieved by a Board order or direction may appeal to the Appellate Tribunal within sixty days, with late appeals allowed for sufficient cause. After hearing the parties the Tribunal may confirm, modify or set aside the order, aims to decide appeals within six months, and operates as far as practicable as a digital office. - [Section 30, Orders passed by Appellate Tribunal to be executable as decree](https://dpdprules.org/act/30): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: Orders of the Appellate Tribunal under this Act are executable by the Tribunal as a decree of a civil court, and the Tribunal has all the powers of a civil court for that purpose. It may also send an order to a civil court with local jurisdiction, which must execute it as its own decree. - [Section 31, Alternate dispute resolution](https://dpdprules.org/act/31): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: When the Board considers that a complaint could be settled through mediation, it may direct the parties to attempt resolution that way. The mediator can be someone the parties mutually agree upon, or one provided for under any law currently in force in India. - [Section 32, Voluntary undertaking](https://dpdprules.org/act/32): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: At any stage of a section 28 proceeding, the Board may accept a voluntary undertaking from a person about observing the Act and may vary its terms with that person's consent. Acceptance bars proceedings on the matters it covers, but breaking it is deemed a breach of the Act, letting the Board proceed under section 33 after offering a hearing. - [Section 33, Penalties](https://dpdprules.org/act/33): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: Once an inquiry concludes and the Board finds a significant breach, it may, after offering the person a hearing, impose a monetary penalty specified in the Schedule. When setting the amount, it weighs factors such as the nature, gravity and duration of the breach, the data affected, repetition, gains made, mitigation efforts, proportionality and the likely impact on the person. - [Section 34, Crediting sums realised by way of penalties to Consolidated Fund of India](https://dpdprules.org/act/34): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: Penalty money collected under this Act flows to one destination. All sums realised through penalties imposed by the Board are credited to the Consolidated Fund of India. The rule covers every penalty amount, with no exceptions stated in the provision itself. - [Section 35, Protection of action taken in good faith](https://dpdprules.org/act/35): In force since 13 November 2025. What it says: Legal proceedings cannot be brought against the Central Government, the Board, or the Board's Chairperson, Members, officers or employees for anything done, or intended to be done, in good faith under this Act or its rules. This shield covers suits, prosecutions and other legal proceedings alike. - [Section 36, Power to call for information](https://dpdprules.org/act/36): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: The Central Government may require the Board, any Data Fiduciary or any intermediary to furnish whatever information it calls for, so long as it is for the purposes of this Act. The provision itself sets no format, deadline or procedure for such information requests. - [Section 37, Power of Central Government to issue directions](https://dpdprules.org/act/37): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: Blocking orders become possible once the Board refers, in writing, a Data Fiduciary penalised in two or more instances and advises blocking in the general public's interest. After offering that Data Fiduciary a hearing and recording reasons, the Central Government may direct its agencies or any intermediary to block public access to the relevant information; intermediaries so directed must comply. - [Section 38, Consistency with other laws](https://dpdprules.org/act/38): In force since 13 November 2025. What it says: This Act adds to existing law rather than replacing it. Its provisions operate in addition to, and not in derogation of, any other law in force. If a provision of this Act conflicts with a provision of another law, this Act prevails, but only to the extent of that conflict. - [Section 39, Bar of jurisdiction](https://dpdprules.org/act/39): In force since 13 November 2025. What it says: Civil courts cannot entertain any suit or proceeding over matters for which the Board is empowered under this Act. Nor may any court or other authority grant an injunction in respect of action taken, or to be taken, under any power the Act confers. - [Section 40, Power to make rules](https://dpdprules.org/act/40): In force since 13 November 2025. What it says: Rulemaking power sits with the Central Government, which may, by notification and after previous publication, make rules consistent with this Act to carry out its purposes. A long list of specific matters follows, from notices, Consent Managers and breach intimation to Board appointments and appeals, ending with a residual clause covering anything else the Act leaves to rules. - [Section 41, Laying of rules and certain notifications](https://dpdprules.org/act/41): In force since 13 November 2025. What it says: Parliament gets oversight of rules made under this Act. Every rule, and every notification issued under section 16 or section 42, must be laid before each House while in session for a total of thirty days. Both Houses may modify or annul it, without affecting the validity of anything already done under it. - [Section 42, Power to amend Schedule](https://dpdprules.org/act/42): In force since 13 November 2025. What it says: Amendments to the Schedule can be made by the Central Government through notification, with one hard limit: no penalty may be raised to more than twice the amount specified when the Act was originally enacted. Any such amendment takes effect as if enacted in the Act, from the date of the notification. - [Section 43, Power to remove difficulties](https://dpdprules.org/act/43): In force since 13 November 2025. What it says: If difficulties arise in giving effect to this Act, the Central Government may issue an order in the Official Gazette making provisions, consistent with the Act, to remove them. This power lapses 3 years after the Act commences, and every such order must be laid before each House of Parliament. - [Section 44, Amendments to certain Acts](https://dpdprules.org/act/44): Partly in force since 13 November 2025. What it says, of which only sub sections (1) and (3) are in force today; sub section (2), the Information Technology Act amendments including the omission of section 43A, is not yet in force: Three older statutes are amended here. The provision updates the appellate tribunal listing in the Telecom Regulatory Authority of India Act, 1997; omits section 43A and clause (ob) of section 87(2) of the Information Technology Act, 2000 and amends its section 81 proviso; and replaces clause (j) in section 8(1) of the Right to Information Act, 2005. - [The Schedule: monetary penalties](https://dpdprules.org/act/schedule): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. That status is a reading of notification G.S.R. 843(E), which does not name this Schedule at all. What it says, not what is in force today: The Schedule caps penalties: 250 crore rupees for not taking reasonable security safeguards, 200 crore each for breach notification failures and children's provisions, 150 crore for Significant Data Fiduciary obligations, ten thousand rupees for Data Principal duties, 50 crore otherwise, and up to the underlying breach amount for breaching a voluntary undertaking. ## The DPDP Rules 2025 rule by rule, with the commencement status of each Each line states whether that rule or Schedule is in force, then gives a plain English explanation of what it says, scoped to that status; the explanation is not the verbatim text. The 3 groups are set by Rule 1 of the Rules themselves: Rule 1(2) names the rules in force from publication on 13 November 2025, Rule 1(3) the group 1 year later and Rule 1(4) the group 18 months later. Computed dates carry the same interpretation label as above. None of the 3 sub rules names a Schedule at all, so a Schedule's group is read off the rule it serves, and every line whose status rests on that reading says so. - [Rule 1, Short title and commencement](https://dpdprules.org/rules/1): In force since 13 November 2025. What it says: This opening rule gives the rules their official name, the Digital Personal Data Protection Rules, 2025, and sets a phased schedule: Rules 1, 2 and 17 to 21 take effect on Gazette publication, Rule 4 1 year later, and Rules 3, 5 to 16, 22 and 23 after 18 months. - [Rule 2, Definitions](https://dpdprules.org/rules/2): In force since 13 November 2025. What it says: Definitions live here: the Act means the Digital Personal Data Protection Act, 2023; a user account covers profiles, handles, email addresses and similar presences registered with a Data Fiduciary; and verifiable consent means consent under rule 10 or 11. Terms not defined carry their meanings from the Act. - [Rule 3, Notice given by Data Fiduciary to Data Principal](https://dpdprules.org/rules/3): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: Every notice from a Data Fiduciary must be understandable on its own and give, in clear and plain language, a fair account enabling specific and informed consent, including at minimum an itemised description of the personal data and the specified purpose or purposes with a specific description of the goods or services to be provided or uses to be enabled. It must also give the particular communication link to the website or app, and describe any other means, through which the Data Principal may withdraw consent with ease comparable to that with which it was given, exercise her rights under the Act, and complain to the Board. - [Rule 4, Registration and obligations of Consent Manager](https://dpdprules.org/rules/4): Not yet in force; the computed date is 13 November 2026, which is interpretation until officially confirmed. What it says, not what is in force today: Anyone meeting the First Schedule conditions may apply to the Board for registration as a Consent Manager, and the Board may register or reject the application with reasons. Registered Consent Managers must follow the Schedule's obligations, and the Board can direct compliance measures, demand information, or suspend or cancel a registration after a hearing. - [Rule 5, Processing of personal data for provision or issue of subsidy, benefit, service, certificate, licence or permit by State and its instrumentalities](https://dpdprules.org/rules/5): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: When the State or its instrumentalities process personal data to provide or issue a subsidy, benefit, service, certificate, licence or permit, they must follow the standards in the Second Schedule. The rule also explains what provision under law, under policy, or using public funds means for this purpose. - [Rule 6, Reasonable security safeguards](https://dpdprules.org/rules/6): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: Reasonable security safeguards are required from every Data Fiduciary to prevent a personal data breach, covering encryption or masking, access controls, logs and monitoring to detect unauthorised access, backups for continuity, retention of relevant logs and data for 1 year unless law requires otherwise, contractual safeguards with any Data Processor, and technical and organisational measures. - [Rule 7, Intimation of personal data breach](https://dpdprules.org/rules/7): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: After becoming aware of a personal data breach, a Data Fiduciary must promptly tell each affected Data Principal, in clear and plain terms, what happened, the likely consequences, mitigation steps, safety measures and a contact person. It must also notify the Board without delay and send detailed information within 72 hours, or longer if the Board allows. - [Rule 8, Time period for specified purpose to be deemed as no longer being served](https://dpdprules.org/rules/8): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: Personal data held by specified classes of Data Fiduciary must be erased after the periods in the Third Schedule if the Data Principal stays inactive, unless law requires retention. The Data Fiduciary must warn the Data Principal at least 48 hours before erasure, and must keep the data and processing logs for at least 1 year for Seventh Schedule purposes. - [Rule 9, Contact information of person to answer questions about processing](https://dpdprules.org/rules/9): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: Business contact information of the Data Protection Officer, where applicable, or of someone able to answer questions about processing must be prominently published by the Data Fiduciary on its website or app and included in every response to a Data Principal exercising her rights under the Act. - [Rule 10, Verifiable consent for processing of personal data of child](https://dpdprules.org/rules/10): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: Before processing a child's personal data, a Data Fiduciary must obtain verifiable consent from the parent and take care to confirm that the person claiming to be the parent is an identifiable adult, using identity and age details it already holds, details voluntarily provided, or a virtual token issued by an authorised entity. - [Rule 11, Verifiable consent for processing of personal data of person with disability who has lawful guardian](https://dpdprules.org/rules/11): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: For a person with disability who has a lawful guardian, verifiable consent comes from that guardian, and the Data Fiduciary must exercise due diligence to verify that the guardian was appointed by a court, a designated authority, or a local level committee under the law applicable to guardianship. It also defines who qualifies as a person with disability. - [Rule 12, Exemptions from certain obligations applicable to processing of personal data of child](https://dpdprules.org/rules/12): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: Exemptions for child data appear here: the obligations in parts (1) and (3) of section 9 of the Act do not apply to processing of a child's personal data by the classes of Data Fiduciary listed in Part A of the Fourth Schedule, or for the purposes listed in Part B, subject to the conditions specified there. - [Rule 13, Additional obligations of Significant Data Fiduciary](https://dpdprules.org/rules/13): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: A Significant Data Fiduciary must undertake a Data Protection Impact Assessment and an audit once every 12 months, with significant observations reported to the Board. It must verify that technical measures, including algorithmic software, are not likely to pose risks to Data Principals' rights, and keep government specified personal data and its traffic data within India. - [Rule 14, Rights of Data Principals](https://dpdprules.org/rules/14): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: For Data Principals to exercise their rights, a Data Fiduciary and, where applicable, a Consent Manager must publish on its website or app the means for making requests and identifying particulars required. Sub rule (3) requires every Data Fiduciary and Consent Manager to prominently publish on its website or app, and to implement technical and organisational measures for responding effectively under its grievance redressal system, and it names 90 days, in a sentence printed with no object for the word publish, so what the 90 days caps is not stated on its face. A Data Principal may nominate one or more individuals under applicable terms of service and law. - [Rule 15, Transfer of personal data outside the territory of India](https://dpdprules.org/rules/15): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: Personal data may be sent outside India, provided the Data Fiduciary meets any requirements the Central Government sets by general or special order. Those requirements concern making such personal data available to a foreign State, or to any person, entity or agency under that State's control. - [Rule 16, Exemption from Act for research, archiving or statistical purposes](https://dpdprules.org/rules/16): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: None of the Act's provisions apply to processing of personal data that is necessary for research, archiving or statistical purposes, so long as that processing is carried out in accordance with the standards specified in the Second Schedule. Both conditions, necessity and adherence to those standards, must be met. - [Rule 17, Appointment of Chairperson and other Members](https://dpdprules.org/rules/17): In force since 13 November 2025. What it says: The Central Government sets up committees to recommend candidates for the Board: one chaired by the Cabinet Secretary for the Chairperson post, another chaired by the Electronics and Information Technology Secretary for other Members. After considering the recommendations, the Government makes the appointments, and a vacancy or defect in a committee does not invalidate its proceedings. - [Rule 18, Salary, allowances and other terms and conditions of service of Chairperson and other Members](https://dpdprules.org/rules/18): In force since 13 November 2025. What it says: Pay and service conditions for the leadership of the Board come from one place: the Fifth Schedule. The Chairperson and every other Member receive the salary and allowances set out there, and their remaining terms and conditions of service are likewise whatever that Schedule specifies for them. - [Rule 19, Procedure for meetings of Board and authentication of its orders, directions and instruments](https://dpdprules.org/rules/19): In force since 13 November 2025. What it says: How the Board conducts business is set out here: the Chairperson convenes meetings, one third of Members make a quorum, decisions pass by majority with a casting vote for the chair, conflicted Members abstain, and authorised signatories authenticate its orders. Inquiries must finish within six months, extendable for recorded reasons by three months at a time. - [Rule 20, Functioning of Board as digital office](https://dpdprules.org/rules/20): In force since 13 November 2025. What it says: The Board is to function as a digital office and may use technology backed legal measures to conduct proceedings without requiring anyone's physical presence. This does not take away its power to summon any person, enforce attendance and examine that person on oath. - [Rule 21, Terms and conditions of appointment and service of officers and employees of Board](https://dpdprules.org/rules/21): In force since 13 November 2025. What it says: With the prior approval of the Central Government, the Board may appoint whatever officers and employees it considers necessary to discharge its functions under the Act efficiently. The terms and conditions of service for those officers and employees are the ones specified in the Sixth Schedule. - [Rule 22, Appeal to Appellate Tribunal](https://dpdprules.org/rules/22): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: Anyone aggrieved by an order or direction of the Board can appeal to the Appellate Tribunal, filing digitally and paying the same fee as appeals under the Telecom Regulatory Authority of India Act, 1997, unless the Tribunal's Chairperson reduces or waives it. The Tribunal follows natural justice rather than civil court procedure and operates as a digital office. - [Rule 23, Calling for information from Data Fiduciary or intermediary](https://dpdprules.org/rules/23): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. What it says, not what is in force today: For the purposes specified in the Seventh Schedule, the Central Government, acting through the authorised person named there, may require any Data Fiduciary or intermediary to furnish information within a specified period. Where disclosure could prejudice India's sovereignty, integrity or state security, it may direct that the request not be revealed to anyone without the authorised person's prior written permission. - [First Schedule: registration and obligations of Consent Manager](https://dpdprules.org/rules/first-schedule): Not yet in force; the computed date is 13 November 2026, which is interpretation until officially confirmed. That status is a reading of Rule 1 of the DPDP Rules 2025, which does not name this Schedule at all. What it says, not what is in force today: Registration conditions for Consent Managers appear in Part A: an Indian company with net worth of at least 2 crore rupees, sound finances, fit management and a certified interoperable platform. Part B lists ongoing obligations, including keeping consent records seven years or more, being unable to read the data shared, avoiding conflicts of interest and reporting audits to the Board. - [Second Schedule: standards for State processing and for research, archiving or statistical purposes](https://dpdprules.org/rules/second-schedule): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. That status is a reading of Rule 1 of the DPDP Rules 2025, which does not name this Schedule at all. What it says, not what is in force today: Standards in this Schedule govern two situations: processing by the State and its instrumentalities under section 7(b) of the Act, and processing for research, archiving or statistical purposes under section 17(2)(b). They require lawful, purpose limited and necessary processing, accuracy efforts, limited retention, security safeguards, intimation to Data Principals where applicable, and accountability for observance. - [Third Schedule: time periods for retention under rule 8](https://dpdprules.org/rules/third-schedule): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. That status is a reading of Rule 1 of the DPDP Rules 2025, which does not name this Schedule at all. What it says, not what is in force today: Retention periods under rule 8 apply to online shopping entities and social media intermediaries with at least 2 crore registered users in India and online gaming intermediaries with at least 50 lakh. The period runs 3 years from the Data Principal's last approach or these Rules' commencement, whichever is latest, excluding user account and virtual token access. - [Fourth Schedule: exemptions for processing of children's personal data](https://dpdprules.org/rules/fourth-schedule): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. That status is a reading of Rule 1 of the DPDP Rules 2025, which does not name this Schedule at all. What it says, not what is in force today: Exemptions from section 9(1) and 9(3) of the Act for processing children's data come in two parts: Part A names classes of Data Fiduciaries, including healthcare providers, schools, crèches and child transport services, and Part B names purposes, including legal duties, benefits, email account creation, safety tracking, shielding children from harmful content and age confirmation, each under set conditions. - [Fifth Schedule: terms and conditions of service of Chairperson and Members](https://dpdprules.org/rules/fifth-schedule): In force since 13 November 2025. That status is a reading of Rule 1 of the DPDP Rules 2025, which does not name this Schedule at all. What it says: The Fifth Schedule sets service terms for the Board's leadership: a consolidated monthly salary of rupees four lakh fifty thousand for the Chairperson and rupees four lakh for other Members, with no house or car facility and no pension or gratuity. Travel and leave entitlements follow Central Government rules, and medical assistance comes through a Board group health insurance scheme. - [Sixth Schedule: terms of appointment and service of Board officers and employees](https://dpdprules.org/rules/sixth-schedule): In force since 13 November 2025. That status is a reading of Rule 1 of the DPDP Rules 2025, which does not name this Schedule at all. What it says: The Board may take staff on deputation, capped at five years, from the Central Government, State Governments, autonomous or statutory bodies or public sector enterprises, or the National Institute for Smart Government on market guided pay. Gratuity follows the Payment of Gratuity Act, allowances, leave and conduct track Central Government rules, and medical assistance uses a Board group insurance scheme. - [Seventh Schedule: purposes and authorised persons for calling for information](https://dpdprules.org/rules/seventh-schedule): Not yet in force; the computed date is 13 May 2027, which is interpretation until officially confirmed. That status is a reading of Rule 1 of the DPDP Rules 2025, which does not name this Schedule at all. What it says, not what is in force today: Linked to rules 23 and 8(3), this table pairs each purpose for calling information with the person authorised to act: state use for sovereignty or security, state functions or disclosure duties under law, and assessments for notifying Significant Data Fiduciaries, handled respectively by designated officers, legally authorised persons and a designated officer in the Electronics and Information Technology Ministry. ## Tools (deterministic, no signup, nothing leaves the browser) - [Applicability Checker](https://dpdprules.org/tools/does-dpdp-apply): Find out whether the DPDP framework likely applies to your organisation and processing - [Role and Actor Checker](https://dpdprules.org/tools/what-is-my-dpdp-role): Work out your likely role for a processing activity, such as Data Fiduciary or Data Processor - [Compliance Plan](https://dpdprules.org/tools/compliance-checklist): Generate 1 company level action plan and see the work for your role first - [Data Breach Response Playbook](https://dpdprules.org/tools/data-breach-response): Rule 7 is not in force yet, so plan its breach steps now, including the 72 hour submission to the Board, against the exact requirements - [Privacy Notice Checker](https://dpdprules.org/tools/privacy-notice-checker): Check whether your notice covers the elements the DPDP sources require - [Privacy Notice Generator](https://dpdprules.org/tools/privacy-notice-generator): Assemble a starting template for your privacy notice from the Rule 3 minimums, which are not in force yet - [Retention and Erasure Planner](https://dpdprules.org/tools/retention-erasure): Identify DPDP retention and erasure triggers and the action steps for your context - [Children's Data Checker](https://dpdprules.org/tools/childrens-data): See whether child data obligations or exemptions are triggered and what they require - [Vendor and Processor Checklist](https://dpdprules.org/tools/vendor-processor-checklist): Identify DPDP relevant actions for your vendors and Data Processors - [DPDP vs GDPR Gap Checker](https://dpdprules.org/tools/dpdp-vs-gdpr): If you have a GDPR program, find the DPDP specific areas that need separate review - [Individual Rights Assistant](https://dpdprules.org/tools/my-dpdp-rights): Understand your rights as an individual and the channels a Data Fiduciary must offer - [All 11 tools](https://dpdprules.org/tools) ## Guides and articles (56 in total, newest first within each section) ### Applicability - [DPDP and AI: the Act never names it, and public data is not a free pass](https://dpdprules.org/blog/does-dpdp-apply-to-ai): Artificial intelligence, machine learning and profiling appear 0 times in the DPDP Act and Rules - [Section 17 of the DPDP Act: what the exemptions actually switch off](https://dpdprules.org/blog/dpdp-section-17-exemptions): Section 17(1) is not in force: from a computed 13 May 2027 it disapplies Chapter II except sections 8(1) and 8(5), Chapter III and section 16 - [Does DPDP apply to B2B SaaS companies?](https://dpdprules.org/blog/does-dpdp-apply-to-b2b-saas): Usually yes, in 2 roles at once - [Does DPDP apply to foreign companies?](https://dpdprules.org/blog/does-dpdp-apply-to-foreign-companies): Section 3(b), not in force yet, reaches processing outside India in connection with any activity related to offering goods or services to people in India - [Does the DPDP Act apply to startups? No size test, and 3 places size counts](https://dpdprules.org/blog/does-dpdp-apply-to-startups): Section 3 carries no turnover, headcount or user threshold, so a 2 person company is inside the Act once section 3 commences on a computed 13 May 2027 ### Breach response - [डेटा ब्रीच हो जाए तो क्या करें? DPDP नियम 7 और 2 समयसीमाएँ](https://dpdprules.org/blog/dpdp-data-breach-kya-karein): डेटा ब्रीच के बाद भारत में 2 समयसीमाएँ हैं: CERT In को 6 घंटे, जो आज लागू है, और DPDP नियम 7, जो अभी लागू नहीं है - [A data breach just hit your organisation: the hour by hour response under DPDP](https://dpdprules.org/blog/data-breach-at-your-organisation-what-to-do): Rule 7 of the DPDP Rules 2025 is not in force, and when it commences 2 clocks start the moment your organisation becomes aware of a personal data breach - [DPDP breach notification: 72 hours to the Board, 6 hours to CERT In](https://dpdprules.org/blog/dpdp-breach-72-hours-cert-in-6-hours): India runs 2 breach clocks and only 1 is in force today: CERT In, 6 hours - [DPDP data breach reporting: what Rule 7 actually requires](https://dpdprules.org/blog/dpdp-breach-reporting-rule-7): DPDP Rule 7, not in force yet, starts 2 clocks on awareness of a breach: intimation without delay, then detailed information to the Board within 72 hours ### Children - [DPDP for schools and edtech: what the Fourth Schedule exemption really covers](https://dpdprules.org/blog/dpdp-for-schools-and-edtech): The DPDP education carve out covers tracking and behavioural monitoring only - [Children's data under the DPDP Act: consent, bans and exemptions](https://dpdprules.org/blog/dpdp-childrens-data-rules): The child definition is in force and the section 9 duties are not: they commence on a computed 13 May 2027, interpretation until officially confirmed - [What is verifiable consent under DPDP?](https://dpdprules.org/blog/what-is-verifiable-consent-dpdp): Rule 10 is not in force yet: it commences on a computed 13 May 2027, interpretation until officially confirmed ### Compliance - [Data Protection Officer under the DPDP Act: who must appoint one](https://dpdprules.org/blog/data-protection-officer-under-dpdp): Nobody owes a DPO yet: section 10(2)(a) commences on a computed 13 May 2027, interpretation until officially confirmed - [DPDP compliance requirements for businesses: the obligations map (2026)](https://dpdprules.org/blog/dpdp-compliance-requirements-for-businesses): The DPDP duties on a business in 6 groups, none of them in force yet: the 2 grounds, notice, consent, section 8, rights, children, SDF and transfers - [Data protection audit under the DPDP Act: who must be audited and what the text requires](https://dpdprules.org/blog/dpdp-data-protection-audit-requirements): Only notified Significant Data Fiduciaries need a DPDP audit, and the duty has not started: section 10(2)(b) and Rule 13 commence on a computed 13 May 2027 - [Additional obligations of a Significant Data Fiduciary: DPO, auditor, DPIA](https://dpdprules.org/blog/dpdp-significant-data-fiduciary-obligations): Section 10 adds an India based DPO, an independent auditor and a 12 month Rule 13 DPIA and audit cycle once notified: all 3 commence on a computed 13 May 2027 - [DPIA under the DPDP Act: who must do one, what it contains, when it starts](https://dpdprules.org/blog/dpia-under-dpdp-act): Only a notified Significant Data Fiduciary will owe a DPIA, and section 10 and Rule 13 both commence on a computed 13 May 2027 - [DPDP Act for HR teams: employee data, section 7 and what needs consent](https://dpdprules.org/blog/dpdp-act-for-hr-teams-employee-data): Section 7(i), not in force yet, lets employers process employee personal data for the purposes of employment without consent; the ground is purpose based - [DPDP compliance checklist for small businesses: 10 steps (2026)](https://dpdprules.org/blog/dpdp-compliance-checklist-small-business): There is no small business exemption in the DPDP Act's application section, so a small Indian business works the same 10 steps - [DPDP compliance checklist for CTOs](https://dpdprules.org/blog/dpdp-compliance-checklist-for-ctos): The DPDP obligations belong to your organisation and not to the CTO, and none of these rules is in force yet: all are computed to commence 13 May 2027 - [DPDP compliance checklist for startups](https://dpdprules.org/blog/dpdp-compliance-checklist-for-startups): A small team's path through the DPDP framework: settle applicability, map your data, and build the 5 duty clusters in dependency order while the runway lasts - [Significant Data Fiduciary: what changes if you are notified](https://dpdprules.org/blog/significant-data-fiduciary-explained): No Significant Data Fiduciary duty is in force yet: section 10 commences on a computed 13 May 2027, interpretation until officially confirmed ### Consent - [DPDP and cookies: the Act never mentions them](https://dpdprules.org/blog/dpdp-cookie-consent-what-the-law-says): The word cookie appears 0 times in the DPDP Act 2023 and 0 times in the DPDP Rules 2025 - [DPDP and marketing consent: 2 regimes, and the one in force is not DPDP](https://dpdprules.org/blog/dpdp-marketing-consent-whatsapp-sms): Marketing to Indian customers sits under 2 separate regimes - [Deemed consent does not exist under the DPDP Act](https://dpdprules.org/blog/dpdp-deemed-consent-does-not-exist): The DPDP Act 2023 contains no deemed consent and no legitimate interest ground: what replaced them is section 7, not in force until a computed 13 May 2027 - [What is a Consent Manager under the DPDP Act? Definition, registration and obligations](https://dpdprules.org/blog/dpdp-consent-managers-explained): A Consent Manager is a person registered with the Data Protection Board who acts as a single point of contact for consent, not software - [Do you need to register as a Consent Manager? Rule 4 and who it applies to](https://dpdprules.org/blog/consent-managers-under-dpdp): Most ordinary businesses do not need to register as a Consent Manager, and Rule 4 is not in force yet - [DPDP consent requirements: what section 6 actually demands](https://dpdprules.org/blog/dpdp-consent-requirements): Section 6 sets 5 qualities, a clear affirmative action, a necessity limit and a proof burden that lands on you ### Current status - [SPDI Rules 2011: still in force, and what the DPDP Act does to them](https://dpdprules.org/blog/spdi-rules-2011-and-the-dpdp-act): On the Gazette prints on file, read as at 6 September 2026, the Information Technology SPDI Rules 2011 still bind a body corporate - [DPDP deadline: is the 18 month window being cut to 12 months?](https://dpdprules.org/blog/dpdp-18-months-to-12-months-proposal): MeitY was reported in January 2026 to have proposed cutting the DPDP compliance window from 18 months to 12 - [Is the DPDP deadline 13 or 14 May 2027? Why sources disagree by 1 day](https://dpdprules.org/blog/dpdp-commencement-date-13-or-14-november): Gazette issue No. 760 is printed 13 November 2025; the eGazette file code on that same issue records 14 November - [Supreme Court challenge to the DPDP Act: what stands today](https://dpdprules.org/blog/dpdp-act-supreme-court-challenge): Writ petitions in the Supreme Court challenge the DPDP Act's RTI amendment, exemptions and Board design - [DPDP Act 2023 and Rules 2025: what is in force in 2026?](https://dpdprules.org/blog/dpdp-act-rules-what-is-in-force-2026): A source backed status check: which parts of India's DPDP framework operate today, which dates are official, and which dates are computed ### Definitions - [Does the DPDP Act have a sensitive personal data category? No](https://dpdprules.org/blog/dpdp-sensitive-personal-data): The word sensitive appears nowhere in the DPDP Act, there is no section 3(d), and the duties that bite harder are not in force until a computed 13 May 2027 - [DPDP Act क्या है? फुल फॉर्म, नियम और तारीखें (2026)](https://dpdprules.org/blog/dpdp-act-kya-hai): DPDP का फुल फॉर्म है Digital Personal Data Protection - [What is DPDP? India's data protection law, explained from the official text](https://dpdprules.org/blog/what-is-dpdp): DPDP stands for Digital Personal Data Protection - [Is a name and email address personal data under DPDP?](https://dpdprules.org/blog/is-name-email-personal-data-dpdp): Usually yes in ordinary business records ### Enforcement - [Is the Data Protection Board operational? 2 separate reasons it is not](https://dpdprules.org/blog/is-the-data-protection-board-operational): The Data Protection Board of India exists in law and has no appointed members ### Notice - [Does the DPDP notice have to be in 22 languages? What section 5(3) actually says](https://dpdprules.org/blog/dpdp-notice-language-requirements): The section 5(3) language option is not in force yet: it commences on a computed 13 May 2027, interpretation until officially confirmed - [What must a DPDP privacy notice contain? Section 5 and Rule 3](https://dpdprules.org/blog/what-must-a-dpdp-privacy-notice-contain): Section 5 names 3 things the notice must inform and Rule 3 sets its shape and 2 minimums, but neither is in force yet ### Official documents - [DPDP Rules 2025 corrigendum G.S.R. 892(E): all 8 corrections](https://dpdprules.org/blog/dpdp-rules-corrigendum-gsr-892e): Corrigenda G.S.R. 892(E) of 10 December 2025 made 8 corrections to the DPDP Rules 2025 ### Penalties - [Jan Vishwas Act 2023: what it changed in the IT Act, and what it left alone](https://dpdprules.org/blog/jan-vishwas-act-and-the-it-act-penalties): On the Gazette prints on file, read as at 6 September 2026 - [From complaint to penalty: how the Data Protection Board process works](https://dpdprules.org/blog/dpdp-board-complaint-inquiry-appeal): The Board complaint route is not open yet: sections 28 to 34 commence on a computed 13 May 2027, interpretation until officially confirmed - [DPDP Act penalties: fines up to Rs 250 crore explained (2026)](https://dpdprules.org/blog/dpdp-penalties-schedule-explained): No penalty under the DPDP Act can be imposed yet: section 33, the route to the Schedule caps of up to 250 crore rupees, commences on a computed 13 May 2027 - [Voluntary undertakings under section 32: the DPDP settlement track](https://dpdprules.org/blog/dpdp-voluntary-undertakings-section-32): Section 32 is not in force: the voluntary undertaking settlement track starts on a computed 13 May 2027, interpretation until officially confirmed ### Retention - [DPDP data retention and erasure: Rule 8 and the 2 minimum floors](https://dpdprules.org/blog/dpdp-retention-rule-8-explained): The DPDP framework sets no retention period ### Rights - [Can I sue under the DPDP Act? The Act has no compensation route](https://dpdprules.org/blog/can-i-sue-under-dpdp-act): The DPDP Act 2023 gives a Data Principal no right to sue and no compensation - [DPDP grievance redressal: what Rule 14(3) says about 90 days](https://dpdprules.org/blog/dpdp-grievance-redressal-90-days): Rule 14(3), not in force yet, names 90 days in a sentence printed with no object for "publish", so what the 90 days caps is not stated on its face - [Data Principal rights under the DPDP Act: sections 11 to 14](https://dpdprules.org/blog/dpdp-individual-rights-explained): The 4 Chapter III rights, plus section 6(4) withdrawal ### Roles - [Data Processor obligations under DPDP: what you actually have to do](https://dpdprules.org/blog/dpdp-data-processor-obligations): The DPDP framework never addresses a Data Processor by name - [Data Fiduciary vs Data Processor: which role are you?](https://dpdprules.org/blog/data-fiduciary-vs-data-processor): One test decides it: who determines the purpose and means of the processing ### Security - [DPDP Rule 6 security safeguards, explained control by control](https://dpdprules.org/blog/dpdp-rule-6-security-safeguards): Rule 6 names 7 security minimums and not 1 is in force yet: the Rule commences on a computed 13 May 2027, interpretation until officially confirmed ### Transfers - [DPDP vs GDPR: key differences for Indian businesses (2026)](https://dpdprules.org/blog/dpdp-vs-gdpr-key-differences): DPDP and GDPR differ in machinery, and the DPDP duties compared here are not in force yet: computed commencement 13 November 2026 and 13 May 2027 - [Does DPDP require data localisation? Cross border transfers, and the 1 rule that does](https://dpdprules.org/blog/dpdp-cross-border-transfers): Transfers out of India are permitted by default under Rule 15, which is not in force yet ### Vendors - [DPA clauses under the DPDP Act: what the law requires versus good drafting](https://dpdprules.org/blog/dpdp-data-processing-agreement-clauses): The DPDP Act prescribes little about a DPA, and none of that little is in force: a contract, Rule 6(1)(f) safeguards, erasure, from a computed 13 May 2027 - [Do you need a contract with your Data Processor under DPDP?](https://dpdprules.org/blog/dpdp-processor-contracts): Once section 8(2) and Rule 6 are in force, a Data Processor may be engaged only under a valid contract, and that contract must carry safeguard provisions - [All articles](https://dpdprules.org/blog) - [Templates and policies](https://dpdprules.org/templates) ## Concepts, the defined terms with their verbatim statutory definitions - [Personal data](https://dpdprules.org/concepts/personal-data) - [Digital personal data](https://dpdprules.org/concepts/digital-personal-data) - [Data Fiduciary](https://dpdprules.org/concepts/data-fiduciary) - [Data Processor](https://dpdprules.org/concepts/data-processor) - [Data Principal](https://dpdprules.org/concepts/data-principal) - [Consent Manager](https://dpdprules.org/concepts/consent-manager) - [Significant Data Fiduciary](https://dpdprules.org/concepts/significant-data-fiduciary) - [Data Protection Officer](https://dpdprules.org/concepts/data-protection-officer) - [Personal data breach](https://dpdprules.org/concepts/personal-data-breach) - [Processing](https://dpdprules.org/concepts/processing) - [Child](https://dpdprules.org/concepts/child) - [Data Protection Board of India](https://dpdprules.org/concepts/data-protection-board) - [Specified purpose](https://dpdprules.org/concepts/specified-purpose) - [All concepts](https://dpdprules.org/concepts) ## Guides by role The obligations belong to the organisation. These pages change only the presentation, never the legal duty. - [CTO and engineering leaders](https://dpdprules.org/roles/cto) - [Legal and privacy counsel](https://dpdprules.org/roles/legal) - [Compliance and data protection officers](https://dpdprules.org/roles/compliance) - [Security teams](https://dpdprules.org/roles/security) - [HR and people teams](https://dpdprules.org/roles/hr) - [Founders and small teams](https://dpdprules.org/roles/founder) - [All role guides](https://dpdprules.org/roles) ## Guides by industry - [Startups](https://dpdprules.org/industries/startups) - [SaaS](https://dpdprules.org/industries/saas) - [Ecommerce](https://dpdprules.org/industries/ecommerce) - [Healthcare](https://dpdprules.org/industries/healthcare) - [Fintech](https://dpdprules.org/industries/fintech) - [Education and edtech](https://dpdprules.org/industries/education) - [All industry guides](https://dpdprules.org/industries) ## Method - [How content is verified](https://dpdprules.org/methodology) - [Corrections](https://dpdprules.org/corrections) - [About and editorial identity](https://dpdprules.org/about)