The Digital Personal Data Protection Act of 2023 ensures that the processing of digital personal data in India is lawful, transparent, and secure. The Act sets out who may process personal data, and on what basis, with penalties for non-compliance. The DPDP Rules 2025, released on 13th November 2025, on the other hand, aim to put the DPDP Act into effect by prescribing how data protection obligations, rights, and enforcement procedures must be employed. It outlines the procedures for obtaining consent, implementing security measures, reporting breaches, and exercising oversight.
Phased Commencement of the DPDP Rules
The DPDP Rules will be enforced in a phased manner to ensure organizations get time to plan their data protection strategy in line with the DPDP Act. The phases are as follows:
- Phase I: This phase is effective since 13 November 2025. It brings into force Rules 1 and 2, along with Rules 17 to 21. These rules establish the purpose, appointment, and functioning of the Data Protection Board.
- Phase II: This will take effect one year from the date of publication. This will activate Rule 4 and govern the registration of Consent managers, their eligibility, responsibilities, and regulatory oversight.
- Phase III: Applicable 18 months from the date of publication, this phase enforces Rules 3, 5 to 16, and Rules 22 and 23. Under this, core compliance obligations for data fiduciaries and processors will be enforced, including seeking consent, implementing security safeguards, reporting breaches, data retention, and erasing data, etc.
This allows institutions to build governance and infrastructure before substantive enforcement begins.

Image 1: DPDP Rules Phased Commencement
DPDP Rules 2025
Rule 1: Short Title and Commencement
Rule 1 establishes the DPDP Rules, 2025, and specifies their phased commencement, setting out when different provisions will come into action.
Rule 2: Definitions
DPDP Rule 2 clarifies that references to the ‘Act’ in these rules mean the Digital Data Protection Act 2023. It refers to techno-legal measures, defines ‘user account’ to include profiles, identifiers, email addresses, mobile numbers, and similar access mechanisms.
Further, it links verifiable consent for data processing to Rules 10 and 11. This linkage removes ambiguity in interpreting verifiable consent standards for children and persons with disabilities.
Rule 3: Notice to Data Principals
Rule 3 prescribes how notice must be provided by a Data Fiduciary to a Data Principal.
Under the DPDPA, a data fiduciary is any person who has the purpose and means of processing personal data. A data principal is the individual to whom the personal data relates.
The notice provided by the data fiduciary to the data principal must be clear, in simple language, easily understandable without any reference to other documents. It must describe the categories of personal data processed and the specific purposes for which processing occurs. Rule 3 also requires disclosure of mechanisms for consent withdrawal, exercise of rights, and grievance submission. Withdrawal must be as easy as giving consent.
Rule 4: Registration of Consent Manager & Obligations
DPDP Rule 4 establishes the framework for consent managers. The Act defines Consent Manager as “a person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform.”
Rule 4 sets out eligibility, application procedures, and registration criteria through the ‘First Schedule.’ The Schedule requires the entity seeking registration to be incorporated in India. It sets out requirements relating to financial thresholds, governance standards, management integrity, and technical and operational capacity.
Part B of the ‘First Schedule’ defines the obligations of consent managers:
- The consent manager must provide a functional platform through which data principals can grant, review, manage, and withdraw consent.
- The consent manager must ensure that consent signals are accurately transmitted to the relevant data fiduciaries.
- Consent managers are required to comply with data protection standards, technical frameworks, at all times, and other requirements that may be notified by the Data Protection Board.
Rule 5: Processing by the State and Its Instrumentalities
Rule 5 governs personal data processing by the State and its instrumentalities for the delivery of subsidies, benefits, services, certificates, licenses, and permits. Such processing must comply with standards specified in the ‘Second Schedule’, which are:
- Processing personal data only as is necessary and appropriate for providing the relevant subsidy, benefit, service, certificate, license, or permit.
- Implementing technical and organisational security measures to prevent unauthorised access, use, or disclosure of personal data.
- Controlling access and accountability mechanisms to ensure that public sector data processing is carried out for lawful and specified purposes only.
Rule 6: Reasonable Security Safeguards
Rule 6 imposes a detailed security obligation on Data Fiduciaries. Security is not framed as a general duty; it is broken into specific measures that can be demonstrated as and when required. These are:
- Encryption, masking or tokenisation, controlled access to systems, continuous logging and monitoring, and reliable backup and recovery mechanisms.
- Contractual data processors must maintain equivalent security safeguards.
- Retention of logs and related processing records for a minimum period of 1-year, unless a longer retention period is required under applicable law.
Rule 7: Notify Personal Data Breach
Rule 7 establishes a two-tier breach notification obligation. Affected Data Principals must be informed promptly through registered communication channels. The notice must describe the nature of the breach, its consequences, mitigation steps taken, and contact details for follow-up. The Data Protection Board must also be notified without delay. A detailed report must follow within 72 hours, unless extended by the Board. The Rule specifies the exact contents of this report, including root cause analysis and preventive actions.
Rule 8: Data Retention and Erasure
Rule 8 requires data fiduciaries to perform Data Erasure after the period prescribed in the ‘Third Schedule’ or if the data principal remains inactive and no legal data retention obligation applies.
The DPDP Rules 2025 require advance notice to be given to the data principal at least 48 hours before erasing data. This rule mandates a minimum 1-year retention of processing logs and related records, as detailed in the ‘Seventh Schedule.’
Rule 9: Contact Details
Rule 9 requires the data fiduciaries to publish contact details of the acting Data Protection Officer (DPO) on their website or app for addressing queries related to personal data processing.
Rules 10 to 12: Children and Persons with Disabilities
Rule 10 sets out requirements for verifiable parental consent for processing children’s personal data. Identity and age verification may rely on reliable records or authorised digital token systems, including Digital Locker Services.
Rule 11 extends similar safeguards to persons with disabilities who have lawful guardians. Verification must confirm the legal authority of the guardian.
Rule 12 provides limited exemptions for specified classes of Data Fiduciaries and purposes, subject to conditions set out in the ‘Fourth Schedule.’ The Schedule identifies defined classes of Data Fiduciaries, such as educational and healthcare entities, and specific purposes, including child safety, welfare, healthcare, education, and legal compliance, where strict consent requirements may be relaxed.
Rule 13: Significant Data Fiduciaries
Rule 13 imposes additional obligations on entities notified as ‘Significant Data Fiduciaries.’ These entities are required to conduct annual Data Protection Impact Assessments (DPIA) and maintain audit reports, which should be submitted to the Board.
The DPDP Rules 2025 also require assurance that algorithmic systems used for processing do not endanger data principal rights. Certain cross-border data transfer restrictions may apply based on committee recommendations.
Rule 14: Rights of Data Principals
Rule 14 prescribes the manner, form, and process through which data principals can exercise their rights granted under the DPDP Act. By standardising the manner in which data principal requests are submitted and handled, the framework ensures consistency, transparency, accessibility, and timely redressal.
Procedures for exercising rights, such as obtaining data, correcting it, or filing complaints, should be described on the website or the app. An effective grievance redressal mechanism must be in place, and complaints must be resolved within a period not exceeding 90 days.
Rules 15 & 16: Cross-Border Transfers and Research Exemptions
Rule 15 permits cross-border transfer of personal data subject to conditions and restrictions as notified by the Central Government.
Rule 16 provides exemptions for processing data necessary for research, archiving, or statistical purposes, provided standards in the Second Schedule are met.
Rules 17 to 21: Data Protection Board, Its Constitution & Procedure
Rules 17 and 18 govern the appointment of the Data Protection Board, its members, their remuneration, and service conditions of the Chairperson and Members, supported by the ‘Fifth Schedule.’
Rules 19 to 21 regulate Board procedure, allowing the Board to operate as a digital office. Proceedings, hearings, and certifications may occur without physical presence. Emergency actions and quorum requirements are clearly defined.
Rules 22 & 23: Appeals and Government Information Requests
Rule 22 sets out the appeal mechanism before the Appellate Tribunal. Appeals are filed by aggrieved data principals digitally.
Rule 23 empowers the Government to seek information from data fiduciaries or intermediaries for the purposes specified in the Seventh Schedule; however, disclosures remain subject to prescribed safeguards, and information may be withheld where sharing it could impact national security.

Image 2: Seventh Schedule of DPDPA
Source: https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf
How Data Erasure Supports Compliance with the DPDP Rules, 2025
Under the Digital Personal Data Protection Rules, 2025, organisations must demonstrate secure handling of personal information across their lifecycle. BitRaser plays an important role in complying with DPDP Rules by enabling permanent data erasure in line with DPDPA requirements, as required in Rule 8, and reasonable security safeguard Rule 6. The tamper-proof erasure reports help organisations demonstrate proof of data wiping during audits. Likewise, performing secure sanitization before asset reuse or redeployment supports responsible data governance.