Government notifies Digital Personal Data Protection Rules, 2025
The Government notified the Digital Personal Data Protection (DPDP) Rules, 2025 on 14 November 2025, fully operationalising the DPDP Act, 2023 that Parliament enacted on 11 August 2023.
Summary
The DPDP Rules give organisations (Data Fiduciaries) an 18-month phased compliance timeline and require standalone, plain-language consent notices explaining the purpose of data collection. Consent Managers must be Indian companies, data breaches must be reported promptly to affected individuals, and verifiable consent is needed before processing children's data, with limited exemptions for healthcare, education and real-time safety. The Data Protection Board will work as a fully digital body, with appeals going to the Appellate Tribunal (TDSAT). The framework follows the SARAL design â Simple, Accessible, Rational and Actionable.
Key facts
- Rules
- DPDP Rules, 2025 â notified 14 Nov 2025
- Parent Act
- DPDP Act, 2023 (enacted 11 Aug 2023)
- Compliance timeline
- 18 months, phased
- Consent Managers
- Must be Indian companies
- Appeals
- Against Data Protection Board to TDSAT
- Design
- SARAL â Simple, Accessible, Rational, Actionable
Practice MCQs 3 questions
What compliance timeline do the DPDP Rules, 2025 give organisations?
Show answer
Correct answer: C â 18 months
The Rules provide an 18-month phased compliance timeline.
Under the DPDP framework, appeals against decisions of the Data Protection Board lie with:
Show answer
Correct answer: D â TDSAT
Appeals against the Board's decisions lie with the Appellate Tribunal, TDSAT.
Consider the following statements about the DPDP Act, 2023 and the DPDP Rules, 2025: 1. Consent Managers must be Indian companies. 2. The framework follows the SARAL design â Simple, Accessible, Rational and Actionable. Which of the statements given above is/are correct?
Show answer
Correct answer: C â Both 1 and 2
Both statements are correct as per MeitY's release on the notification of the Rules.