Law / India

Digital Personal Data Protection Rules, 2025

G.S.R. 846(E), Digital Personal Data Protection Rules, 2025, notified 13 November 2025

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force 10 months, effective 13 November 2025.

A comprehensive regime rule binding public and private bodies.

As of 29 August 2026.

What it requires

  • The Digital Personal Data Protection Rules, 2025 are only partly in force: today, only the Data Protection Board's own administrative machinery rules apply. Once fully in force (Rule 4 on 13 November 2026, and the remaining app-facing rules, including consent-notice form, breach notification, and Significant Data Fiduciary duties, on 13 May 2027), an app processing Indian personal data, including a biometric identifier, must follow the notified consent-notice, security-safeguard, and breach-notification detail these Rules set.

Who checks it

Audit expectation

periodic

Who audits it

Independent third party

Where the report goes

Filed with regulator

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The Rules implement the DPDPA's app-facing detail: consent-notice form, security safeguards, breach notification (Rule 7), children's-data verification, and Significant Data Fiduciary duties including an annual Data Protection Impact Assessment and algorithmic-fairness assessment (Rule 13).

As notified, only Rules 1, 2, and 17 to 21, the Data Protection Board's own administrative machinery (member recruitment, meeting procedure, digital-office functioning, staff appointment), are currently in force. Rule 4 (Consent Manager registration) commences 13 November 2026; the app-facing bulk (Rules 3, 5 to 16, 22, and 23) commences 13 May 2027.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

Read the law

official Rules text, Gazette of India Extraordinary, Ministry of Electronics and Information Technology

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app