The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025. They do not all start together. Here is where things stand as at 20 September 2026.
What has changed
The Rules give effect to the Digital Personal Data Protection Act, 2023. They set out how notice, consent, security, breach reporting and the Data Protection Board must work.
Key dates
- 13 November 2025: the Rules on the Data Protection Board and their working came into force at once.
- About 13 November 2026: Rule 4, on the registration of consent managers, begins.
- About 13 May 2027: the main duties begin. These include notice, consent, security, breach reporting, children’s data and the exercise of rights.
Some sources count a day later, so confirm the exact dates before you plan around them.
Possible earlier start
In January 2026 MeitY floated a proposal to cut the 18-month period to 12 months. Feedback closed on 4 February 2026. We have found no amending notification so far. Watch the Gazette and MeitY announcements.
The Data Protection Board
The Board exists in law. As at September 2026, no Chairperson or Members had been reported as appointed. MeitY invited applications on 6 May 2026.
Duties to prepare for
- Notice (Rule 3). Give a standalone notice in plain language. It must be available in the languages of the Eighth Schedule on request.
- Security (Rule 6). Use measures such as encryption, masking or tokenisation, access control, activity logs and backups. Include security terms in contracts with processors.
- Breach (Rule 7). Tell each affected person promptly, in plain language. Tell the Board without delay, and give full details within 72 hours or a longer period the Board allows.
- Retention (Rules 6 and 8). Keep logs and certain data for at least one year. Erase inactive users’ data as the Third Schedule requires, after 48 hours’ prior warning.
- Children (Rules 10 and 11). Obtain verifiable consent from a parent or guardian, subject to listed exceptions.
Penalty ceilings
The Schedule to the Act sets ceilings of ₹250 crore for security failures and ₹200 crore for breach reporting or children’s data failures. Significant data fiduciaries face up to ₹150 crore for breaching their extra duties.
What to do now
- Map personal data: what you hold, where, and why.
- Draft notices and consent flows, and test them.
- Set retention and deletion schedules.
- Write a breach plan with a 72-hour reporting drill.
- Review contracts with processors.
Key takeaway
Plan to the May 2027 date, but prepare as if it could move earlier. Breach reporting and data mapping are the sensible places to start.