MeitY · Rules

Digital Personal Data Protection Rules, 2025

G.S.R. 846(E)

In short
G.S.R. 846(E) is the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 and commenced in three tranches by Rule 1. The definitions and the machinery of the Data Protection Board took effect on publication; Consent Manager registration follows one year later; and everything a Data Fiduciary actually has to do — notice, security safeguards, breach intimation, retention limits and Data Principal rights — commences eighteen months after publication, on 13 May 2027.

The record

ReferenceG.S.R. 846(E)
Issued byMinistry of Electronics and Information Technology (MeitY)
Instrument typeRules
Date of issue13 November 2025
StatusPartly in force
BindsData Fiduciaries processing digital personal data. Phased, with full compliance required by 13 May 2027.
Dates it sets
  • 13 May 2027Full compliance with the Rules.
DPDP Rules, 2025 as the register holds it, read from the issuing regulator's own notification.

What it says

  • Rule 1(2) commenced rules 1, 2 and 17 to 21 on publication: the definitions, and the appointment, terms and functioning of the Data Protection Board.
  • Rule 1(3) commences rule 4 one year after publication, on 13 November 2026: the registration and obligations of Consent Managers, and nothing else.
  • Rule 1(4) commences rules 3, 5 to 16, 22 and 23 eighteen months after publication, on 13 May 2027 — every substantive Data Fiduciary obligation.
  • Rule 6 asks for encryption or tokenisation, access control, monitoring able to detect unauthorised access, backups, a year of retained logs, contractual terms binding every processor, and evidence that all of it is observed.
  • States commencement as intervals from publication rather than as printed dates, which is why the notification date is load-bearing.

What accounts of this instrument get wrong

Read the instrument

The link below goes to the issuing regulator’s own copy. Where a regulator serves its text through a PDF viewer or a query-string URL, it points at the document rather than at a landing page that may not render it.

Not a reading list. Each of these alters the obligation on this page — the amendment that moved a date, the sibling that binds the entity class this one excludes, or the separate track it is routinely merged with.

  • CERT-In Directions, 2022 No. 20(3)/2022-CERT-InVery nearly every organisation in India, with a six-hour incident report to CERT-In.
  • IRDAI Guidelines, 2026 IRDAI/GA&HR/CIR/MISC/51/4/2026All insurers, insurance intermediaries and the Insurance Information Bureau of India.

This record is one entry in the Indian cyber regulation register, which publishes the same fields for every instrument as an open dataset. Indicative, and not legal advice: whether an instrument reaches your organisation turns on your licences and registrations, and is a determination for your legal team.

Every instrument cited here was verified against the issuing regulator's own notification on .

Knowing the instrument is not knowing where you stand.

Every instrument on this page asks an organisation to know its own exposure. Your organisation already has a security rating, calculated from signals anyone outside it can see — including whoever supervises you. Request the complimentary Cyber Risk Rating Report and read what those signals say.

Request my rating What Rule 6 asks you to build