Law note · India

Digital Personal Data Protection Rules, 2025

cite G.S.R. 846(E), Digital Personal Data Protection Rules, 2025, notified 13 November 2025 stage RECENT in force 10 months effective 2025-11-13 kind Comprehensive regime binds public and private bodies reviewed 2026-08-29

What it requires

  • The Digital Personal Data Protection Rules, 2025 are only partly in force: today, only the Data Protection Board's own administrative machinery rules apply. Once fully in force (Rule 4 on 13 November 2026, and the remaining app-facing rules, including consent-notice form, breach notification, and Significant Data Fiduciary duties, on 13 May 2027), an app processing Indian personal data, including a biometric identifier, must follow the notified consent-notice, security-safeguard, and breach-notification detail these Rules set.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics

What we found

The Rules implement the DPDPA's app-facing detail: consent-notice form, security safeguards, breach notification (Rule 7), children's-data verification, and Significant Data Fiduciary duties including an annual Data Protection Impact Assessment and algorithmic-fairness assessment (Rule 13).

As notified, only Rules 1, 2, and 17 to 21, the Data Protection Board's own administrative machinery (member recruitment, meeting procedure, digital-office functioning, staff appointment), are currently in force. Rule 4 (Consent Manager registration) commences 13 November 2026; the app-facing bulk (Rules 3, 5 to 16, 22, and 23) commences 13 May 2027.

← Back to the example  ·  Lint your app →