Law note · India
Digital Personal Data Protection Rules, 2025
cite G.S.R. 846(E), Digital Personal Data Protection Rules, 2025, notified 13 November 2025
stage RECENT in force 10 months
effective 2025-11-13
kind Comprehensive regime
binds public and private bodies
reviewed 2026-08-29
What it requires
- The Digital Personal Data Protection Rules, 2025 are only partly in force: today, only the Data Protection Board's own administrative machinery rules apply. Once fully in force (Rule 4 on 13 November 2026, and the remaining app-facing rules, including consent-notice form, breach notification, and Significant Data Fiduciary duties, on 13 May 2027), an app processing Indian personal data, including a biometric identifier, must follow the notified consent-notice, security-safeguard, and breach-notification detail these Rules set.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
What we found
The Rules implement the DPDPA's app-facing detail: consent-notice form, security safeguards, breach notification (Rule 7), children's-data verification, and Significant Data Fiduciary duties including an annual Data Protection Impact Assessment and algorithmic-fairness assessment (Rule 13).
As notified, only Rules 1, 2, and 17 to 21, the Data Protection Board's own administrative machinery (member recruitment, meeting procedure, digital-office functioning, staff appointment), are currently in force. Rule 4 (Consent Manager registration) commences 13 November 2026; the app-facing bulk (Rules 3, 5 to 16, 22, and 23) commences 13 May 2027.