Digital Personal Data Protection Rules, 2025 - Final Rules
AI / PRIVACY / CYBER RELEVANCE
Critical for AI/cloud/LLM systems because it turns the Act into operational security, consent and data-lifecycle controls.
AI: HighPrivacy: Very HighCybersecurity: Very High
READ FIRST
- Rule 6 - security safeguards
- Rule 7 - personal-data breach
- Rule 8 - retention/erasure
- Rule 10 - children
- commencement in Rule 1
PURVIEW
Provides the practical rules needed to implement the DPDP Act. It translates statutory requirements into detailed mechanisms dealing with notice, consent managers, security safeguards, personal-data breach response, retention and erasure, children’s data, rights requests, processing records and other compliance procedures. The Rules are therefore especially important for turning abstract privacy duties into implementable requirements for AI platforms, cloud environments, data pipelines and automated systems, while their own staggered commencement dates must be checked before treating a particular obligation as presently operative.
Classification and legal status. Binding subordinate legislation, but phased. Rules 1, 2 and 17 - 21 commenced on 13 Nov 2025; Rule 4 on 13 Nov 2026; Rules 3, 5 - 16, 22 - 23 on 13 May 2027.