THE RULES

Rule 1 - Short title and commencement

Official text

(1)These rules may be called the Digital Personal Data Protection Rules, 2025.

(2)Rules 1, 2 and 17 to 21 shall come into force on the date of their publication in the Official Gazette.

(3)Rule 4 shall come into force one year after the date of publication of this Gazette.

(4)Rules 3, 5 to 16, 22 and 23 shall come into force eighteen months after the date of publication of this Gazette.

Cross-references

Rule 1

Commentary

Rule 1, Short Title and Commencement: The Three-Phase Commencement of the DPDP Framework

Rule 1 appears, at first sight, to be a purely procedural provision. It gives the Rules their short title and specifies when different provisions will come into force. In the context of the Digital Personal Data Protection Act, 2023 (“DPDP Act”), however, Rule 1 performs a much more consequential function. It establishes the temporal architecture of India’s data-protection regime.

The DPDP framework does not become enforceable on a single date. The Central Government has deliberately divided implementation into three phases, with the principal operational obligations being deferred to allow Data Fiduciaries, Data Processors, Consent Managers and other participants in the ecosystem time to build the necessary legal, technical and organisational infrastructure.

The Rules were notified on 13 November 2025. The commencement notification for the Act was issued on the same date. The Gazette notification expressly divides the Act into three commencement dates:13 November 2025,13 November 2026, and13 May 2027. ([eGazette][1])

The most important point, therefore, is this:

“The DPDP Act, 2023” is not, by itself, a sufficient answer to the question whether a particular obligation is presently enforceable. One must identify the provision, identify the corresponding Rule, and then identify its applicable commencement phase.

This becomes particularly important because the commencement of the Rules does not mirror the commencement of the Act provision-by-provision in a simple one-to-one fashion. Some Rules become operative before the substantive statutory obligations which they help implement. Others commence simultaneously with the relevant statutory regime.

The entire framework can therefore be understood through the following three dates.


I. The Master Timeline: What Comes Into Force, and When?

PhaseExact dateDPDP Act, provisions coming into forceDPDP Rules, provisions coming into forceWhat this means in practice
Phase I13 November 2025Section 1(2); Section 2; Sections 18, 26; Section 35; Sections 38, 43; Section 44(1) and 44(3)Rules 1, 2 and 17, 21Institutional and regulatory framework begins. Definitions and Data Protection Board framework become operative.
Phase II13 November 2026Section 6(9); Section 27(1)(d)Rule 4Consent Manager registration regime and the Central Government’s rule-making power concerning specified matters under Section 27(1)(d) become operative.
Phase III13 May 2027Sections 3, 5; Sections 6(1), (8) and 6(10); Sections 7, 17; Section 27 except clause (d) of sub-section (1); Sections 28, 34; Sections 36, 37; Section 44(2)Rules 3, 5, 16 and 22, 23The substantive data-protection regime becomes operational: notice, consent, fiduciary obligations, children's data, rights, breach response, retention, SDF obligations, Board proceedings, appeals and government information powers.

The dates above follow directly from the two Gazette notifications. The Act's commencement notification was G.S.R. 843(E), dated 13 November 2025, while the Rules were notified as G.S.R. 846(E), also dated13 November 2025. ([eGazette][1])

Thus, as of 11 September 2026, Phase I has commenced, Phase II is approaching, and Phase III has not yet commenced.


II. The Three Dates Should Not Be Confused

There are three legally distinct concepts that are easy to conflate:

1. The Act was enacted

The DPDP Act received Presidential assent on 11 August 2023.

That does not mean that all its substantive provisions became operational on that date.

2. The Rules were notified

The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025.

That again does not mean that all 23 Rules became enforceable on that date.

3. Particular provisions commenced

The commencement notifications determine when each provision actually becomes operative.

Accordingly, the correct legal chronology is:

  1. 2023, Act enacted
  2. 13 November 2025, commencement notification + Rules notified
  3. 13 November 2025, Phase I
  4. 13 November 2026, Phase II
  5. 13 May 2027, Phase III

This distinction is particularly important when advising an organisation today. A lawyer should not simply say that “the DPDP Act is in force” or “the DPDP Rules have been notified.” The more precise question is:

Which provision has commenced, and what obligation does that provision create?


III. Phase I, 13 November 2025

Phase I is the institutional and foundational phase.

The Act provisions commencing on this date are predominantly concerned with the preliminary framework, the Data Protection Board and certain miscellaneous provisions rather than the principal compliance obligations imposed upon Data Fiduciaries.

The Act's commencement notification provides that, from 13 November 2025, the following provisions came into force:

  • Section 1(2);
  • Section 2;
  • Sections 18 to 26;
  • Section 35;
  • Sections 38 to 43; and
  • Sections 44(1) and 44(3). ([eGazette][1])

The Rules similarly bring Rules 1, 2 and 17 to 21 into force immediately upon publication. ([MeitY][2])

Phase I mapping

DPDP Act provisionSubjectRuleSubjectStatus from 13 Nov 2025
Section 1(2)Commencement provisionRule 1Short title and commencementIn force
Section 2DefinitionsRule 2DefinitionsIn force
Sections 18, 26Data Protection Board of India and related institutional provisionsRules 17, 21Board constitution, service conditions, meetings, digital functioning and officers/employeesIn force
Section 35Exemption concerning legal proceedings etc.,,In force
Sections 38, 43Miscellaneous provisions,,In force
Section 44(1), (3)Amendments/repeals and related provisions,,In force

The most significant practical development in Phase I is therefore the Data Protection Board architecture.

Rules 17, 21 provide the operational framework concerning matters such as appointment and service conditions of the Chairperson and Members, Board meetings and authentication, functioning as a digital office, and appointment and service of officers and employees. ([EY][3])

But is Phase I “the DPDP compliance regime”?

Not in the conventional sense.

A Data Fiduciary does not, merely because 13 November 2025 has passed, suddenly become subject to all the principal operational obligations contained in Sections 5, 17.

For example, the detailed statutory obligations concerning:

  • notice;
  • consent;
  • legitimate uses;
  • security safeguards;
  • breach notification;
  • retention and erasure;
  • DPO/contact requirements;
  • children's data;
  • Significant Data Fiduciaries; and
  • Data Principal rights

belong predominantly to Phase III.

That distinction is crucial.


IV. Phase II, 13 November 2026

The second phase is considerably narrower.

It commences exactly one year after 13 November 2025, i.e. on:

13 November 2026.

The Act's commencement notification brings into force:

  • Section 6(9); and
  • Section 27(1)(d). ([eGazette][1])

Rule 1(3) simultaneously provides that:

Rule 4 shall come into force one year after the date of publication of the Gazette.

Accordingly:

DateActRulePrincipal significance
13 November 2026Section 6(9)Rule 4Consent Manager registration and associated regulatory framework
13 November 2026Section 27(1)(d),Central Government rule-making power under the specified provision

The importance of Section 6(9) lies in the fact that it concerns the registration of Consent Managers.

The Act envisages Consent Managers as regulated entities that enable Data Principals to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform.

Rule 4 then supplies the operational registration and obligation framework.

The delayed commencement therefore makes structural sense.

There is little utility in requiring the substantive consent-management ecosystem to be fully operational before the statutory registration mechanism itself has commenced.

The important distinction

Phase II is not the date on which general consent requirements under Section 6 commence.

That occurs in Phase III.

This distinction can be represented as:

ProvisionDate
Section 6(9), Consent Manager registration13 Nov 2026
Rule 4, Consent Manager registration/obligations13 Nov 2026
Section 6(1), (8), (10), substantive consent regime13 May 2027

Thus, the regulatory infrastructure concerning Consent Managers becomes operative six months before the broader substantive consent regime.

This gives the ecosystem time to establish registered Consent Managers before the principal consent provisions become enforceable.


V. Phase III, 13 May 2027

Phase III is the substantive compliance phase.

It is by far the most important date for Data Fiduciaries.

The Act's commencement notification places the principal operational provisions into force eighteen months from 13 November 2025, namely:

13 May 2027. ([eGazette][1])

The Rules correspondingly bring Rules 3, 5, 16 and 22, 23 into force under Rule 1(4). ([MeitY][2])

This is the date on which the bulk of the DPDP compliance architecture becomes legally operative.


VI. Phase III: Complete Act-to-Rules Mapping

This is the table that is most useful for compliance planning.

DPDP ActWhat becomes operative on 13 May 2027Corresponding Rule(s)Practical consequence
Section 3Application of the Act,Determines territorial/material applicability
Section 4Grounds for processing personal data,Processing must have a lawful basis under the Act
Section 5NoticeRule 3Notice must satisfy detailed content, presentation and accessibility requirements
Section 6(1), (8)Consent frameworkRules 3, 4 and related provisionsValid consent, withdrawal and Consent Manager architecture
Section 6(10)Consent-related provisionRule 4 / related consent architectureBecomes operative with substantive consent regime
Section 7Certain legitimate usesRule 5Specified State/public-benefit processing framework
Section 8General obligations of Data FiduciaryRules 6, 9Security, breach response, retention/erasure and contact information
Section 9Processing of children's personal dataRules 10, 12Verifiable parental consent, due diligence and exemptions
Section 10Significant Data FiduciaryRule 13Additional SDF obligations
Section 11Right to access informationRule 14Operational rights-request mechanism
Section 12Right to correction and erasureRule 14Operational rights-request mechanism
Section 13Grievance redressalRule 14Grievance mechanism
Section 14NominationRule 14Nomination mechanism
Section 15Duties of Data Principal,Data Principal obligations become operative
Section 16Processing outside IndiaRule 15Government-prescribed restrictions/conditions
Section 17ExemptionsRule 16Research, archiving and statistical processing framework
Section 27, except 27(1)(d)Residual rule-making provisions,Remaining specified Central Government rule-making power
Sections 28, 34Board powers/procedure and appeals-related frameworkRules 17, 23Board enforcement architecture operates alongside substantive obligations
Sections 36, 37Government powers / related provisionsRule 23Information requests and associated mechanisms
Section 44(2)Amendment/repeal provision,Statutory amendments take effect

The mapping above should be read alongside the actual commencement notification, because not every Act provision has a dedicated implementing Rule. The absence of a corresponding Rule does not mean that the statutory provision is unimportant or inoperative. It simply means that the Act provision itself supplies the substantive rule, or that no further procedural prescription is required for commencement. ([eGazette][1])


VII. The Three-Phase DPDP Compliance Calendar

For practical purposes, the entire framework can be reduced to the following compliance calendar.

DATELEGAL STATUSKEY ACT PROVISIONSKEY RULESWHAT AN ORGANISATION SHOULD UNDERSTAND
11 Aug 2023Act receives Presidential assentDPDP Act enacted,Statutory framework created, but substantive provisions await commencement notifications
13 Nov 2025PHASE I, IN FORCE§1(2), §2, §§18, 26, §35, §§38, 43, §44(1), §44(3)Rules 1, 2, 17, 21Foundational definitions + Board/institutional architecture
13 Nov 2026PHASE II, COMES INTO FORCE§6(9), §27(1)(d)Rule 4Consent Manager registration regime begins
13 May 2027PHASE III, MAJOR SUBSTANTIVE REGIME§§3, 5; §6(1), (8),(10); §§7, 17; §27 except 27(1)(d); §§28, 34; §§36, 37; §44(2)Rules 3, 5, 16, 22, 23Core Data Fiduciary, Data Principal, children's-data, SDF, rights, breach, retention and enforcement obligations become operative

VIII. The Most Important Point: Rules 3, 16 Are Not Enforceable Today

As of 11 September 2026, the position is therefore:

Already in force

Rules 1, 2 and 17, 21.

Coming into force in approximately two months

Rule 4, 13 November 2026.

Coming into force on 13 May 2027

Rules 3, 5, 16 and 22, 23.

This means that the detailed requirements concerning:

  • notices under Rule 3;
  • State/public-benefit processing under Rule 5;
  • security safeguards under Rule 6;
  • breach notification under Rule 7;
  • retention and erasure under Rule 8;
  • DPO/contact details under Rule 9;
  • children's verifiable consent under Rule 10;
  • lawful guardian consent under Rule 11;
  • Fourth Schedule exemptions under Rule 12;
  • Significant Data Fiduciary obligations under Rule 13;
  • Data Principal rights under Rule 14;
  • transfers outside India under Rule 15;
  • research/archiving/statistical processing under Rule 16;
  • appeals under Rule 22; and
  • government information requests under Rule 23

belong to the 13 May 2027 compliance date.

That is a critical distinction between preparation andenforcement.

An organisation can, and realistically should, prepare for these requirements before May 2027. But preparation should not be confused with the legal commencement of the provisions.


IX. One Particularly Important Cross-Reference: Section 9 and the Fourth Schedule

The commencement structure becomes especially interesting when children's data are considered.

The Fourth Schedule is connected with Rule 12.

Rule 12 itself implements the exemption mechanism contemplated by Section 9(4).

But:

ProvisionCommencement
Section 913 May 2027
Rule 10, verifiable parental consent13 May 2027
Rule 11, lawful guardian consent13 May 2027
Rule 12, exemptions13 May 2027
Fourth Schedule13 May 2027

This means the child-data regime arrives as a coordinated package.

It would be incorrect to say that the Fourth Schedule itself creates a presently available exemption from child-data obligations merely because the Rules have been notified.

Rule 12 has not yet commenced.

Its operative date is 13 May 2027.

The same principle applies to Rule 10: although the Rule has been notified, its substantive operation is deferred until Phase III.


X. Another Important Cross-Reference: Section 5 and Rule 3

The same approach applies to notices.

Section 5 is scheduled to commence on:

13 May 2027.

Rule 3 is also scheduled to commence on:

13 May 2027.

Therefore:

Section 5 = statutory notice obligation

Rule 3 = detailed operational requirements for that notice

13 May 2027 = both become operative

This is why Rule 3 should be read together with Section 5 rather than as an isolated rule.

Section 5 creates the obligation to give notice.

Rule 3 specifies the manner and content of that notice.

The result is a complete notice regime from 13 May 2027.


XI. The DPDP Regime Is Therefore Best Viewed as Three Regulatory Layers

The three phases are not arbitrary dates. They broadly reflect three different regulatory functions.

Phase I, Build the regulator

13 November 2025

The Board and foundational statutory architecture begin.

13 November 2026

Consent Manager registration becomes operative.

Phase III, Regulate the actual processing ecosystem

13 May 2027

The principal obligations imposed upon Data Fiduciaries and rights granted to Data Principals become operative.

This can be represented more simply:

PHASEDATEREGULATORY FUNCTION
I13 Nov 2025Institutionalisation, definitions + Board
II13 Nov 2026Consent infrastructure, Consent Managers
III13 May 2027Substantive regulation, processing + rights + obligations + enforcement

The significance of this architecture is that the Central Government has not attempted to activate the entire data-protection ecosystem simultaneously.


XII. What Should a Data Fiduciary Do on Each Date?

A useful compliance-oriented reading of Rule 1 is therefore:

DateLegal questionCompliance question
13 Nov 2025What is already legally operative?Understand applicable Phase I provisions and Board architecture
13 Nov 2026What changes?If operating as/through a Consent Manager, assess Rule 4 and §6(9) requirements
13 May 2027What becomes fully operational?Core DPDP compliance programme must be operational
After 13 May 2027Is the organisation actually compliant?Test processing against the Act + Rules + applicable Schedules

The most significant compliance preparation should therefore occur before 13 May 2027, rather than beginning on that date.

A serious DPDP implementation exercise should by then have mapped:

data inventory → purposes → lawful basis → notices → consent → withdrawal → rights → retention → security → breach → children → processors → SDF obligations, if applicable → cross-border transfers → grievance handling → Board interface.


XIII. Final Rule 1 Map, The Table to Remember

The clearest master table for Rule 1 is:

Commencement datePhaseDPDP Act, provisionsDPDP Rules, provisionsCore subject matter becoming operativePractical significance
13 November 2025Phase I§1(2), §2, §§18, 26, §35, §§38, 43, §44(1), §44(3)Rules 1, 2, 17, 21Preliminary provisions, definitions, Data Protection Board and institutional machineryRegulatory foundation is operational
13 November 2026Phase II§6(9), §27(1)(d)Rule 4Consent Manager registration and related statutory frameworkConsent-management infrastructure becomes operational
13 May 2027Phase III§§3, 5; §6(1), (8),(10); §§7, 17; §27 (except §27(1)(d)); §§28, 34; §§36, 37; §44(2)Rules 3, 5, 16, 22, 23Application, lawful processing, notice, consent, legitimate uses, fiduciary obligations, security, breaches, retention, children, SDFs, rights, exemptions, appeals and government powersThe substantive DPDP compliance regime becomes operational

The single most important takeaway from Rule 1 is therefore not merely that implementation is “phased.” It is that the DPDP framework hasthree legally identifiable commencement dates, and the applicable date must be determined by tracing the obligation through theAct → commencement notification → corresponding Rule → Schedule, where applicable.

The proposition can be framed this way:

Rule 1 is effectively the temporal index to the DPDP framework. It determines not when the DPDP regime was enacted or when the Rules were notified, but when each component of that regime becomes legally operative. The distinction is fundamental because the substantive obligations imposed on Data Fiduciaries largely do not commence with the notification of the Rules on 13 November 2025; they are concentrated in the third phase commencing on 13 May 2027.

One final qualification is important: 13 November 2025 is the date printed in the Gazette notifications, although some secondary webpages describe the Rules as published on 14 November 2025 because the Ministry webpage displays the document on that date. For commencement calculations, the operative statutory notification identifies13 November 2025 as the date of publication in the Official Gazette. (eGazette)

MeitY, Digital Personal Data Protection Rules, 2025

Reproduced from official sources for reference. Not legal advice. In case of any discrepancy, the text published in the Gazette of India prevails.