DPDP Glossary

DPDP Rules

The Digital Personal Data Protection Rules, 2025 made under the Act, providing operational detail with phased commencement.

Rules under Section 40; G.S.R. 846(E)

What it means

The Digital Personal Data Protection Rules, 2025 are made under Section 40 of the Act. They elaborate notice, Consent Manager registration, children’s verifiable consent, security safeguards, breach intimation, retention and other operational machinery — with phased commencement. Always read a Rule together with its parent section in the Act.

Worked example

Rule 6 elaborates reasonable security safeguards under Section 8(5); Rule 7 elaborates breach intimation under Section 8(6). Designing “security” or “breach” programmes from vendor blogs without those anchors risks inventing requirements the Rules do not state.

In practice

Maintain a Rules commencement tracker for your programme. Map each live Rule to owners (security, legal, product, ops). Prefer official MeitY PDFs over secondary summaries when drafting controls.

Act & Rules on the DPDP hub →

Source

Rules under Section 40; G.S.R. 846(E) · Official text (PDF)

Educational summary based on the Digital Personal Data Protection Act, 2023 and Rules, 2025. Not legal advice.

Further reading

← Back to glossary