Technology and data
The DPDP Rules are notified, and almost nothing in them binds until 13 May 2027
The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 as G.S.R. 846(E). Rules 1, 2 and 17 to 21 came into force that day, and they are the machinery of the Data Protection Board rather than anything a company must do. Rule 4, on consent managers, starts on 13 November 2026. Everything a data fiduciary has to build, the notice, the security measures, breach reporting, erasure and the rights machinery, starts on 13 May 2027, and sections 3 to 17 of the Act start on the same day. The regulator exists now. The duties do not.
The numberEighteen months from 13 November 2025, so 13 May 2027, is the single date on which sections 3 to 17 of the Act and rules 3 and 5 to 16 of the Rules come into force together, while the Data Protection Board itself has been in existence since 13 November 2025 under G.S.R. 844(E).
The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 as G.S.R. 846(E). Rules 1, 2 and 17 to 21 came into force that day, and they are the machinery of the Data Protection Board rather than anything a company must do. Rule 4, on consent managers, starts on 13 November 2026. Everything a data fiduciary has to build, the notice, the security measures, breach reporting, erasure and the rights machinery, starts on 13 May 2027, and sections 3 to 17 of the Act start on the same day. The regulator exists now. The duties do not.
Three instruments on one day
The Ministry of Electronics and Information Technology issued all three on 13 November 2025, in the Gazette of India Extraordinary, Part II, Section 3, sub-section (i). G.S.R. 846(E) is the Rules. G.S.R. 843(E) appoints the dates on which the provisions of the Digital Personal Data Protection Act, 2023 come into force. G.S.R. 844(E) establishes the Data Protection Board of India and places it in the National Capital Region.
The order matters more than it looks. A commencement notification issued alongside the rules reads as deliberate: the two timetables were set against each other, and reading either one alone gives the wrong answer about what a company owes and from when.
Which parts of the Act are in force?
G.S.R. 843(E) appoints three dates.
On publication, 13 November 2025: section 2, sections 18 to 26, section 35, sections 38 to 43, and sub-sections (1) and (3) of section 44. That is the definitions, the Board and its composition, powers and procedure, the appeal route, and the power to make rules. It is the apparatus of enforcement and none of it is addressed to a data fiduciary.
One year on, 13 November 2026: sub-section (9) of section 6, and clause (d) of sub-section (1) of section 27.
Eighteen months on, 13 May 2027: sections 3, 4 and 5, sub-sections (1) to (8) and (10) of section 6, sections 7 to 17, section 27 other than clause (d) of sub-section (1), sections 28 to 34, sections 36 and 37, and sub-section (2) of section 44.
The third group is the substance of the Act. Section 4 is the ground any processing has to stand on. Section 5 is notice, section 6 is consent, section 8 is the data fiduciary's general obligations, section 9 is children, section 10 is the significant data fiduciary, and sections 11 to 14 are the data principal's rights. A company processing personal data in India on 1 May 2027 owes none of these things under this Act. On 13 May 2027 it owes all of them at once.
The Rules run on the same clock
Sub-rule (2) of rule 1 splits the Rules three ways, and the split lines up with the Act almost provision by provision.
Rules 1, 2 and 17 to 21 came into force on 13 November 2025. Rule 1 is the short title, rule 2 the definitions, and rules 17 to 21 cover the appointment of the Chairperson and Members, their salary and conditions of service, the procedure of the Board's meetings, the Board functioning as a digital office, and the appointment of its officers and employees. Again, machinery.
Rule 4 comes into force on 13 November 2026. It carries the registration and obligations of a consent manager, with the conditions set out in the First Schedule. It pairs with sub-section (9) of section 6, which is the consent manager provision in the Act, and both start on the same day. A consent manager therefore has a year of lead time on everyone else, which is the right way round: the register has to exist before a data fiduciary can point a data principal at anything on it.
Rules 3, 5 to 16, 22 and 23 come into force on 13 May 2027.
What does a data fiduciary have to have built by then?
Notice, under rule 3. The notice must be presented and be understandable independently of any other information the data fiduciary has made available or may make available. It must, in the words of the rule,
give, in clear and plain language, a fair account of the details necessary to enable the Data Principal to give specific and informed consent for the processing of her personal data
and that account must carry at a minimum an itemised description of the personal data and the specified purpose or purposes, with a specific description of the goods or services to be provided or the uses to be enabled. The notice must also give the communication link for the website or app and describe the means by which the data principal may withdraw consent, exercise rights under the Act and complain to the Board. Withdrawal has to be as easy as giving consent was. That last requirement is the one most likely to force a change to an existing product, because an account deletion flow buried four screens down does not satisfy it.
Security, under rule 6. The rule names the measures rather than gesturing at reasonableness. Encryption, obfuscation, masking or the use of virtual tokens. Control over access to computer resources. Logs and monitoring adequate to detect unauthorised access, with the logs and the personal data kept for a year. Continuity measures including backups. Terms in the contract with a data processor that oblige the processor to take these measures too. And the technical and organisational measures needed to make compliance real rather than stated. The one-year retention of logs is a floor, not a cap, and it runs alongside the erasure duty below rather than yielding to it.
Breach reporting, under rule 7. Two duties, on two clocks. The data fiduciary must inform each affected data principal, to the best of its knowledge, in a brief, clear and explicit manner and without undue delay, through the user's account or a registered communication medium. Separately it must inform the Board: without undue delay, a description of the breach including its nature, scope, the time and location of the incident and the likely impact; and then the fuller particulars
within seventy-two hours of receipt of information of the breach, or within such extended period as may be given in writing by the Board in this regard
Seventy-two hours runs from receipt of information of the breach, not from the breach, and not from the completion of an investigation. An extension is possible but has to be given in writing by the Board, which means it has to be asked for.
Erasure, under rule 8 and the Third Schedule. Three classes of data fiduciary must erase personal data after three years of silence from the data principal: an e-commerce entity with at least two crore registered users in India, an online gaming intermediary with not less than fifty lakh registered users in India, and a social media intermediary with at least two crore registered users in India. The three years runs from the data principal's last approach to the fiduciary for the purpose, or her last exercise of a right, or the commencement of the Rules, whichever is later. Access to a user account, and access to virtual tokens usable for goods or services, are carved out of the duty. Retention required by any other law is preserved. Sub-rule (2) of rule 8 requires the fiduciary to tell the data principal that the personal data will be deleted at least forty-eight hours before the retention period expires, which gives her a last chance to keep it by logging in or exercising a right. Processing logs and associated traffic data are kept for at least a year regardless.
A drafting point worth noticing: the Third Schedule measures the three years from the later of the data principal's last contact and "the commencement of these rules", and the Rules commence in three tranches. Rule 8 itself is in the eighteen-month tranche. Which of the two dates the Schedule intends is not spelt out, and for a company with a long tail of dormant accounts the difference is eighteen months of retention.
A published point of contact, under rule 9. The contact details of the Data Protection Officer, or of the person able to answer a data principal's questions about the processing, must be displayed prominently on the website or the app, and be in any notice or communication sent to a data principal.
The significant data fiduciary carries four more
Rule 13 sits on top of section 10 of the Act. A data protection impact assessment and an audit, once in every period of twelve months from the date the fiduciary is notified into the category. A report of the significant findings of that assessment and audit, submitted to the Board by the person who conducted it. Due diligence to verify that its algorithmic software, including the technical measures it uses for hosting, processing, uploading, amending, publishing, transmitting, storing, updating or sharing personal data,
poses no threat to the rights of Data Principals
And a localisation duty: personal data specified on the recommendation of a committee constituted by the Central Government, comprising officers from the Ministry of Electronics and Information Technology and possibly other ministries, must be processed under the restriction that it and the traffic data relating to its flow are not transferred outside India. The category is conferred by notification, so no company is a significant data fiduciary until it is told it is one, and the twelve month audit clock starts from that date rather than from 13 May 2027.
Transfers out of India
Rule 15 permits transfer of personal data processed by a data fiduciary outside India, subject to the data fiduciary meeting the requirements the Central Government may specify by general or special order in respect of a foreign State, or a State controlled entity or organisation. It is a permission with a condition attached to it, and the condition is empty until an order specifies something. No such order is cited in the Rules themselves, so on the face of the notified text the transfer is permitted and the restriction is held in reserve. The one place a hard localisation duty does appear is rule 13, and it reaches only a significant data fiduciary and only the data a committee has specified.
What the eighteen months are actually for
Not a grace period, because there is nothing yet to be in breach of. Sections 3 to 17 do not apply before 13 May 2027, so a processing operation that would fail rule 6 today fails nothing. What it is instead is the only window in which the build can be done without the duty running alongside it, and three pieces of that build are slow: rewriting the notice and the consent flow so withdrawal is as easy as consent, getting processor contracts amended to carry rule 6 measures down the chain, and putting a seventy-two hour reporting path in place that a duty officer can actually run at two in the morning.
Two things are live now and worth watching in the meantime. The Board exists, and rules 17 to 21 mean it can be constituted and can sit as a digital office. And the consent manager register opens a year before the duties do, on 13 November 2026, which is when the shape of the consent manager market becomes visible rather than theoretical.
What a data fiduciary has to decide now is which of those three slow pieces it starts first, and who owns the seventy-two hour path, because none of the three can be done in the quarter before 13 May 2027.
Sources
- Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), 13 November 2025, Gazette of India Extraordinary, Part II, Section 3, Sub-section (i), Ministry of Electronics and Information Technology
- Notification appointing the dates on which provisions of the Digital Personal Data Protection Act, 2023 come into force, G.S.R. 843(E), 13 November 2025, Gazette of India Extraordinary, Part II, Section 3, Sub-section (i)
- Notification establishing the Data Protection Board of India under section 18 of the Digital Personal Data Protection Act, 2023, G.S.R. 844(E), 13 November 2025, Gazette of India Extraordinary, Part II, Section 3, Sub-section (i)
- The Digital Personal Data Protection Act, 2023 (No. 22 of 2023)
