Digital Personal Data Protection Rules, 2025

Nov 14, 2025 | by TeamLease RegTech Legal Research Team

Free Legal updates for the week 00


Industry Specific ComplianceThe Ministry of Electronics and Information Technology (MeitY) on November 13, 2025, issued the Digital Personal Data Protection Rules, 2025.

The key rules are as follows:

• Notice to Data Principals (Rule 3)

Data Fiduciaries must give clear, stand-alone notices explaining what personal data is collected, for what purpose, and how users can withdraw consent, exercise rights, or file complaints.

• Consent Managers (Rule 4)

Entities meeting prescribed criteria may register as Consent Managers. The Board can approve, monitor, direct corrective measures, or suspend/cancel their registration based on compliance.

• State Processing for Subsidies/Services (Rule 5)

Processing of personal data for government subsidies, benefits, services, certificates, licences or permits must follow standards in the Second Schedule and applies when such services are provided under law, policy, or public funds.

• Security Safeguards (Rule 6)

Data Fiduciaries must ensure reasonable security measures such as encryption, access control, logging, backups, and contractual safeguards with processors. Logs and relevant personal data must be retained for at least one year.

• Personal Data Breach Notification (Rule 7)

On becoming aware of a breach, Data Fiduciaries must promptly inform:

o affected individuals with details and safety steps;

o the Board with reports, investigation details, impacts, and remediation (initially immediately, and detailed report within 72 hours).

• Erasure of Data After Purpose Ends (Rule 8)

For categories in the Third Schedule, data must be erased once it is no longer needed unless law requires retention. At least 48 hours’ prior notice must be given. Minimum one-year retention of logs/data applies for all processing.

• Contact Information (Rule 9)

Data Fiduciaries must publish contact details of their Data Protection Officer or responsible person for queries.

• Verifiable Consent for Children’s Data (Rule 10)

Parental consent must be verifiable using reliable identity/age details or virtual tokens, with adults confirmed through identity verification or Digital Locker.

• Consent for Persons with Disabilities (Rule 11)

Where a lawful guardian provides consent, Data Fiduciaries must verify court/designated-authority/local-level-committee appointment under applicable disability laws.

• Exemptions for Child Data Processing (Rule 12)

Certain Data Fiduciaries and certain purposes (as per Fourth Schedule) are exempt from Section 9(1) & (3) obligations, subject to conditions.

• Significant Data Fiduciaries (Rule 13)

They must conduct annual Data Protection Impact Assessments and audits, verify their technical systems for risk, comply with data-localisation restrictions for specified datasets, and report findings to the Board.

• Exercising Rights (Rule 14)

Data Fiduciaries/Consent Managers must publish means to exercise rights, grievance redressal timelines (max 90 days), and allow nomination for right-exercise.

• Cross-Border Data Transfer (Rule 15)

Personal data may be transferred outside India subject to conditions or restrictions specified by the Central Government.

• Research/Archiving/Statistics Exemption (Rule 16)

Processing for research, archiving or statistical purposes is exempt if done per Second Schedule standards.

• Appointment of Board Members (Rule 17)

Search-cum-Selection Committees will recommend Chairperson and Members; the Government will appoint them.

• Service Conditions (Rule 18)

Salaries, allowances, and service conditions of the Chairperson and Members are in the Fifth Schedule.

• Board Meetings & Procedures (Rule 19)

Rules for meetings, quorum, voting, conflict of interest, emergency actions, decisions by circulation, authentication of orders, and inquiry timelines (normally six months).

• Digital Functioning of the Board (Rule 20)

The Board will operate as a digital office and may conduct proceedings without physical presence.

• Officers & Staff (Rule 21)

Board may appoint officers/employees with prior Central Government approval; service conditions in Sixth Schedule.

• Appeals (Rule 22)

Aggrieved persons may digitally file appeals before the Appellate Tribunal, with applicable fees, and proceedings conducted digitally.

• Government’s Power to Call for Information (Rule 23)

For purposes listed in Seventh Schedule, Government may require Data Fiduciaries or intermediaries to furnish information. Disclosure of such requests may be restricted for security reasons.

Rules 1, 2 and 17 to 21 shall come into force on November 13, 2025.

Rule 4 shall come into force one year after the date of publication of this Gazette. 

Rules 3, 5 to 16, 22 and 23 shall come into force eighteen months after the date of publication of this Gazette.

[Notification No. G.S.R. 846(E)]


Bookmark

Related Updates



Alternate Text

Get updates on the go on RegUpdate Mobile App.

NEW  ·  AI ASSISTANT