Skip to main content

The 3rd and main DPDP commencement date is computed as 13 May 2027, which is interpretation until officially confirmed.

Sources last verified on 23 September 2026. Methodology

Reference

The DPDP Rules 2025

The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 as G.S.R. 846(E) and operationalise the Act. Pick a rule or Schedule from the contents list to read its official Gazette text with corrigendum corrections applied and its commencement status explained.

23 of 23 rules and 7 of 7 Schedules currently publish with verified Gazette text. Where corrigenda G.S.R. 892(E) corrected the print, both the corrected and the original wording are shown.

Original document: the official Gazette PDF, English and Hindi ↗ Also on MeitY (byte identical) ↗ · all official documents with verification dates are on the documents page.

How the Rules commence

Rule 1 brings the Rules into force in three groups, counted from the printed publication date of Gazette issue No. 760, 13 November 2025. Computed future dates are presented as interpretation until officially confirmed. The Schedules are presented as commencing with the rules that give them effect; the Rules do not state this expressly.

  • 13 November 2025· official

    Rules 1, 2 and 17 to 21

  • 13 November 2026· computed date, interpretation until officially confirmed

    Rule 4

  • 13 May 2027· computed date, interpretation until officially confirmed

    Rules 3, 5 to 16, 22 and 23

A guide to the Rules, by theme

Consent and notice. Rule 3 fixes what the notice must contain, and Rule 4 with the First Schedule sets up Consent Manager registration and obligations.

Security and breaches. Rule 6 lists the reasonable security safeguards, and Rule 7 sets the breach intimation duties and the 72 hour Board clock.

Retention and contact. Rule 8 and the Third Schedule set timed erasure and retention floors, and Rule 9 requires publishing contact details for processing questions.

Children and guardians. Rule 10 and Rule 11 set verifiable consent mechanics, with the exemptions of Rule 12 and the Fourth Schedule.

Bigger fiduciaries, rights and transfers. Rule 13 adds Significant Data Fiduciary obligations, Rule 14 sets rights handling, including the 90 days it names for grievances, and Rule 15 governs transfers outside India.

The State and the Board. Rule 5 and Rule 16 cover State processing and the research exemption, and Rules 17 to 21 run the Board's appointments and digital functioning, with appeals and calling for information closing the set.

The corrigenda themselves are tracked on the corrections page. For the section that each rule is made under, see the Act to Rules map. To see which obligations apply to your organisation, run the applicability checker.