LEGAL UPDATE

Digital Personal Data Protection Rules, 2025

November 19, 2025 2 mins read

The Ministry of Electronics and Information Technology (“MeitY”) notified the Digital Personal Data Protection Rules, 2025 on November 13, 2025. These rules implement the compliance framework under the Digital Personal Data Protection Act, 2023 (the “Act”), including consent, notices, security safeguards, breach notifications, children’s data, significant data fiduciaries, and cross border data transfer.

Key Compliance Requirements

  • Clear and simple notices explaining data use and rights.
  • Consent managers must register and enable users to give, manage and withdraw consent.
  • Mandatory security safeguards including encryption, access control and audit logs.
  • Mandatory breach notifications to affected individuals and the Board.
  • Data must be deleted after purpose completion; users must be notified 48 hours before deletion.
  • Parental consent required for processing children’s data.
  • Significant Data Fiduciaries must conduct annual data protection impact assessments, audits, ensure no harmful algorithmic impact, and appoint Data Protection Officers.
  • The contact information of the Data Protection Officers must be prominently provided on websites and mobile applications.
  • Personal data may be transferred outside India unless restricted by Government and subject to requirements to be met if the data is being shared with a foreign state government or an entity under its control.

What the Rules Broadly Permit

  • Consent based processing.
  • Cross border transfers unless restricted and subject to conditions as may be imposed.
  • Exemptions for research, archiving and statistical purposes subject to specified conditions.

What the Rules Broadly Do Not Permit

  • Processing children’s data without parental consent.
  • Retaining data after purpose completion.
  • Failing to notify data breaches.
  • Cross border transfers to restricted jurisdictions.

Companies Most Impacted

  • Digital platforms, e-commerce, fintech, OTT and social media companies.
  • Banks, NBFCs and insurers.
  • EdTech companies and platforms handling children’s data.
  • Companies classified as Significant Data Fiduciaries.
  • Government vendors handling public-facing data systems.

Timelines

  • The governance and administrative machinery of the Board become operational immediately.
  • Consent Managers get one year before registration requirements and their obligations become enforceable.
  • Entire operational compliance framework becomes applicable to companies—consent, notices, security, breach reporting, children’s data rules, etc., only post 18 months from the notification.

Impact

Organizations should now review consent flows, retention practices, data sharing policies and third-party arrangements to ensure compliance.

OTHER G&A INSIGHTS

Stay Ahead of Legal Developments