

{"id":2807,"date":"2025-11-27T11:50:21","date_gmt":"2025-11-27T06:20:21","guid":{"rendered":"https:\/\/www.sgcms.com\/regulatory-updates\/?p=2807"},"modified":"2025-11-27T11:50:21","modified_gmt":"2025-11-27T06:20:21","slug":"digital-personal-data-protection-dpdpa-rules-2025","status":"publish","type":"post","link":"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/","title":{"rendered":"Digital Personal Data Protection (DPDPA) Rules, 2025"},"content":{"rendered":"<p>The Digital Personal Data Protection Rules, 2025 have now been officially notified, operationalising the Digital Personal Data Protection Act, 2023 and setting out detailed compliance requirements for organisations in India.\u200b<\/p>\n<p><strong>When the new rules kick in<\/strong><\/p>\n<ul>\n<li>The Rules are called the Digital Personal Data Protection Rules, 2025 and are issued under section 40 of the DPDPA, 2023.\u200b<\/li>\n<li>Different provisions start on different timelines from the date of publication in the Gazette:\n<ul>\n<li>Rules 1, 2 and 17\u201321<strong>: effective immediately<\/strong> on publication.\u200b<\/li>\n<li>Rule 4 (Consent Managers): <strong>after 1 year<\/strong>.\u200b<\/li>\n<li>Rules 3, 5\u201316, 22 and 23 (core operational obligations): <strong>after 18 months.\u200b<\/strong><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>This staggered approach gives businesses a limited but important transition window to build their privacy, consent and security frameworks.\u200b<\/p>\n<p><strong>Key concepts and definitions clarified<\/strong><\/p>\n<p>The Rules clarify several operational concepts introduced in the Act so that implementation is more uniform across sectors.\u200b<\/p>\n<ul>\n<li>\u201c<strong>Techno-legal measures<\/strong>\u201d are referenced for running the Data Protection Board as a digital office and for conducting proceedings without physical presence.\u200b<\/li>\n<li>\u201c<strong>User account<\/strong>\u201d covers not just classic logins but also profiles, pages, handles, email IDs, mobile numbers and similar presences through which a Data Principal accesses services.\u200b<\/li>\n<li>\u201c<strong>Verifiable consent<\/strong>\u201d is tied to specific standards under Rules 10 and 11 for children and persons with disabilities, including age and identity verification mechanisms.\u200b<\/li>\n<\/ul>\n<p>These clarifications mean that even platforms relying on phone-based or handle-based access must treat those as user accounts under the Rules.\u200b<\/p>\n<p><strong>Notice and consent: front door of compliance<\/strong><\/p>\n<p>The Rules tighten what an acceptable privacy notice and consent flow must look like.\u200b<\/p>\n<ul>\n<li>Data Fiduciaries must give notices that:\n<ul>\n<li>Are understandable on their own, not buried inside other documents.\u200b<\/li>\n<li>Use clear, plain language and give a fair account of the processing.\u200b<\/li>\n<li>At minimum, itemise the personal data being processed and specify purposes and the related goods\/services.\u200b<\/li>\n<\/ul>\n<\/li>\n<li>Notices must also clearly provide:\n<ul>\n<li>A link and description of how to withdraw consent, with ease comparable to giving consent.\u200b<\/li>\n<li>Ways to exercise Data Principal rights.\u200b<\/li>\n<li>A route to complain to the Board.\u200b<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>For children and certain persons with disabilities, \u201cverifiable consent\u201d from a parent or lawful guardian requires robust age\/identity checks, including use of identity details or tokens from authorised entities and Digital Locker service providers.\u200b<\/p>\n<p><strong>Consent Managers: a new regulated ecosystem<\/strong><\/p>\n<p>One of the most significant institutional changes is formalisation of Consent Managers, who will provide interoperable platforms to manage consent across multiple Data Fiduciaries.\u200b<\/p>\n<ul>\n<li>Only Indian companies can register as Consent Managers, and they must meet conditions such as:\n<ul>\n<li>Minimum net worth of \u20b92 crore and adequate technical, operational and financial capacity.\u200b<\/li>\n<li>Fit-and-proper management with sound financial condition and reputation.\u200b<\/li>\n<li>Governance documents aligned with conditions set out in the First Schedule.\u200b<\/li>\n<\/ul>\n<\/li>\n<li>Registered Consent Managers must:\n<ul>\n<li>Act in a fiduciary capacity towards Data Principals and avoid conflicts of interest with Data Fiduciaries.\u200b<\/li>\n<li>Maintain an interoperable platform through which Data Principals can give, manage, review and withdraw consent, including routing consent between Data Fiduciaries.\u200b<\/li>\n<li>Keep records of consents, notices and data sharing for at least 7 years, and provide machine-readable copies on request.\u200b<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>For financial services, health, and large digital platforms, Consent Managers can become the backbone for consent-based data sharing between institutions.\u200b<\/p>\n<p><strong>Security, breach response and retention<\/strong><\/p>\n<p>The Rules provide detailed expectations for \u201creasonable security safeguards\u201d and breach management, moving from generic obligations to an operational checklist.\u200b<\/p>\n<ul>\n<li>Security safeguards must at minimum include:\n<ul>\n<li>Encryption, obfuscation, masking or tokenisation of personal data.\u200b<\/li>\n<li>Access control on computer resources and monitoring of who accesses personal data.\u200b<\/li>\n<li>Logging, monitoring and review for detecting unauthorised access, with retention of logs and related personal data for at least one year unless another law requires more.\u200b<\/li>\n<li>Backup and continuity arrangements so processing can continue if confidentiality, integrity or availability is affected.\u200b<\/li>\n<\/ul>\n<\/li>\n<li>On becoming aware of a personal data breach, Data Fiduciaries must promptly notify:\n<ul>\n<li>Each affected Data Principal with a description, likely consequences, mitigation measures, suggested safety steps, and a contact point.\u200b<\/li>\n<li>The Board without delay, and then share fuller details (scope, causes, measures, responsible persons, and intimation report) within 72 hours or a longer period allowed by the Board.\u200b<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Retention is also addressed through a mix of minimum logging requirements and sector\/class-based auto-erasure triggers.\u200b<\/p>\n<p><strong>Auto-erasure and minimum log retention<\/strong><\/p>\n<p>The Third Schedule introduces a structured approach to when purposes are deemed no longer served and when data must be erased.\u200b<\/p>\n<ul>\n<li>For specified classes of large digital entities (e-commerce, online gaming, and social media intermediaries above certain user thresholds) the Rules require erasure after 3 years from the last interaction, except for:\n<ul>\n<li>Access to the user account.<\/li>\n<li>Access to virtual tokens used to obtain money, goods or services.\u200b<\/li>\n<\/ul>\n<\/li>\n<li>Independently, all Data Fiduciaries must retain personal data, traffic data and other logs relating to processing for at least one year for purposes set out in the Seventh Schedule, after which they must erase it unless another law requires longer retention.\u200b<\/li>\n<li>Data Fiduciaries must inform Data Principals at least 48 hours before erasing data under the auto-erasure rule, giving them a chance to re-engage or exercise their rights.\u200b<\/li>\n<\/ul>\n<p>This combination pushes digital businesses towards formal data retention schedules instead of indefinite storage.\u200b<\/p>\n<p><strong>Special treatment of children\u2019s data<\/strong><\/p>\n<p>Children\u2019s data remains a focus area, but the Rules also create calibrated exemptions where strict consent requirements would harm welfare-centric processing.\u200b<\/p>\n<ul>\n<li>Verifiable parental consent is mandatory for processing personal data of a child, with strict checks to ensure:\n<ul>\n<li>The person claiming to be parent is an identifiable adult.<\/li>\n<li>Identity\/age is confirmed via records already with the Data Fiduciary or via authorised entities\/Digital Locker tokens.\u200b<\/li>\n<\/ul>\n<\/li>\n<li>Exemptions from certain obligations in section 9 for children\u2019s data apply to:\n<ul>\n<li>Healthcare providers and allied health professionals, limited to protecting the child\u2019s health.\u200b<\/li>\n<li>Educational institutions and transport providers, limited to educational activities and safety\/behavioural monitoring.\u200b<\/li>\n<li>Certain public-interest purposes such as welfare schemes, statutory functions, and safety-related processing like location tracking.\u200b<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>These carve-outs are tied to tight purpose limitation and necessity conditions, ensuring processing remains proportionate.\u200b<\/p>\n<p><strong>Significant Data Fiduciaries: enhanced obligations<\/strong><\/p>\n<p>For Significant Data Fiduciaries (SDFs), the Rules convert many high-level duties from the Act into specific recurring compliance tasks.\u200b<\/p>\n<ul>\n<li>SDFs must, every 12 months:\n<ul>\n<li>Conduct a Data Protection Impact Assessment and a data protection audit.\u200b<\/li>\n<li>Submit a report with significant observations from both to the Board.\u200b<\/li>\n<\/ul>\n<\/li>\n<li>SDFs must ensure that their technical measures, including algorithmic software used for hosting, storing, updating and sharing personal data, do not pose risks to Data Principals\u2019 rights.\u200b<\/li>\n<li>For certain categories of personal data designated by the Central Government, SDFs must ensure that both the data and traffic data related to its flow are not transferred outside India.\u200b<\/li>\n<\/ul>\n<p>These requirements effectively mandate continuous privacy risk management and localised processing for notified datasets.\u200b<\/p>\n<p><strong>Rights of Data Principals and grievance redressal<\/strong><\/p>\n<p>The Rules strengthen practical enforceability of Data Principal rights by focusing on discoverability and timelines.\u200b<\/p>\n<ul>\n<li>Every Data Fiduciary must:\n<ul>\n<li>Prominently publish, on its website\/app, the contact details of the Data Protection Officer (if applicable) or another responsible contact person.\u200b<\/li>\n<li>Clearly explain the modes and identifiers (e.g., customer ID, email, mobile, licence number) Data Principals should use to exercise rights.\u200b<\/li>\n<\/ul>\n<\/li>\n<li>Grievance redressal systems must:\n<ul>\n<li>Be clearly disclosed on websites\/apps.\u200b<\/li>\n<li>Be structured to respond within a reasonable period not exceeding 90 days.\u200b<\/li>\n<\/ul>\n<\/li>\n<li>Data Principals can also nominate individuals to act on their behalf to exercise rights, in line with terms of service and applicable law.\u200b<\/li>\n<\/ul>\n<p>These safeguards make it harder for organisations to hide behind complex processes or unclear contact points.\u200b<\/p>\n<p><strong>Cross-border transfers, research and State use<\/strong><\/p>\n<p>The Rules also address some of the most debated topics under the DPDPA: international transfers, research exemptions, and State use of data.\u200b<\/p>\n<ul>\n<li>Personal data can be transferred outside India by Data Fiduciaries, but if data is being made available to a foreign State or its agencies, they must meet conditions specified by the Central Government through general or special orders.\u200b<\/li>\n<li>The Act does not apply to processing necessary for research, archiving or statistical purposes, so long as it complies with standards in the Second Schedule, which emphasise lawfulness, necessity, accuracy, security and accountability.\u200b<\/li>\n<li>When the State or its instrumentalities process personal data under clause b of section 7 or clause b of section 17(2), they must follow standards in the Second Schedule and can only use authorised officers listed in the Seventh Schedule for tasks such as using data for sovereignty\/security or calling for information from Data Fiduciaries.\u200b<\/li>\n<\/ul>\n<p>This tries to balance operational flexibility for the State and researchers with baseline privacy safeguards.\u200b<\/p>\n<p><strong>Board, appeals and digital-by-design enforcement<\/strong><\/p>\n<p>The enforcement architecture is explicitly designed as digital-first to match the nature of data processing being regulated.\u200b<\/p>\n<ul>\n<li>The Data Protection Board will function as a digital office and may use techno-legal measures so proceedings do not require physical presence, though it retains powers like summoning and examining persons on oath.\u200b<\/li>\n<li>The Board should ordinarily complete inquiries within 6 months of receiving a complaint\/intimation\/reference, with limited scope for written extensions of up to 3 months at a time.\u200b<\/li>\n<li>Appeals against Board orders go to the Appellate Tribunal in digital form, with fees aligned to those under the Telecom Regulatory Authority of India Act and payable through UPI or other authorised digital payment systems.\u200b<\/li>\n<\/ul>\n<p>This model is intended to make enforcement faster and more accessible, especially for digital-first businesses and Data Principals.\u200b<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone  wp-image-2162\" src=\"https:\/\/www.sgcms.com\/regulatory-updates\/wp-content\/uploads\/2024\/09\/pdf-icon-210x300.png\" alt=\"pdf icon\" width=\"31\" height=\"44\" srcset=\"https:\/\/www.sgcms.com\/regulatory-updates\/wp-content\/uploads\/2024\/09\/pdf-icon-210x300.png 210w, https:\/\/www.sgcms.com\/regulatory-updates\/wp-content\/uploads\/2024\/09\/pdf-icon-105x150.png 105w, https:\/\/www.sgcms.com\/regulatory-updates\/wp-content\/uploads\/2024\/09\/pdf-icon.png 512w\" sizes=\"auto, (max-width: 31px) 100vw, 31px\" \/> <strong><a href=\"https:\/\/www.sgcms.com\/regulatory-updates\/wp-content\/uploads\/2025\/11\/Digital_Personal_Data_Protection_DPDPA_Rules_2025_have_been_officially.pdf\">Digital_Personal_Data_Protection_DPDPA_Rules<\/a><\/strong><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Digital Personal Data Protection Rules, 2025 have now been officially notified, operationalising the Digital Personal Data Protection Act, 2023 and setting out detailed compliance requirements for organisations in India.\u200b When the new rules kick in The Rules are called the Digital Personal Data Protection Rules, 2025 and are issued under section 40 of the&hellip; <a class=\"more-link\" href=\"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/\">Continue reading <span class=\"screen-reader-text\">Digital Personal Data Protection (DPDPA) Rules, 2025<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":2120,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[57],"tags":[107,108],"class_list":["post-2807","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-compliance","tag-dpda","tag-it-security","statesofindia-central","entry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Digital Personal Data Protection (DPDPA) Rules, 2025 - Regulatory Updates by SGCMS<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Digital Personal Data Protection (DPDPA) Rules, 2025 - Regulatory Updates by SGCMS\" \/>\n<meta property=\"og:description\" content=\"The Digital Personal Data Protection Rules, 2025 have now been officially notified, operationalising the Digital Personal Data Protection Act, 2023 and setting out detailed compliance requirements for organisations in India.\u200b When the new rules kick in The Rules are called the Digital Personal Data Protection Rules, 2025 and are issued under section 40 of the&hellip; Continue reading Digital Personal Data Protection (DPDPA) Rules, 2025\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/\" \/>\n<meta property=\"og:site_name\" content=\"Regulatory Updates by SGCMS\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-27T06:20:21+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.sgcms.com\/regulatory-updates\/wp-content\/uploads\/2024\/09\/Apprentices-Act.png\" \/>\n\t<meta property=\"og:image:width\" content=\"300\" \/>\n\t<meta property=\"og:image:height\" content=\"210\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"SGCMS\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"SGCMS\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/\"},\"author\":{\"name\":\"SGCMS\",\"@id\":\"https:\/\/www.sgcms.com\/regulatory-updates\/#\/schema\/person\/b8d5729c6deafb37d0db7013fec9766a\"},\"headline\":\"Digital Personal Data Protection (DPDPA) Rules, 2025\",\"datePublished\":\"2025-11-27T06:20:21+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/\"},\"wordCount\":1529,\"publisher\":{\"@id\":\"https:\/\/www.sgcms.com\/regulatory-updates\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.sgcms.com\/regulatory-updates\/wp-content\/uploads\/2024\/09\/Apprentices-Act.png\",\"keywords\":[\"DPDA\",\"IT Security\"],\"articleSection\":[\"Compliance\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/\",\"url\":\"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/\",\"name\":\"Digital Personal Data Protection (DPDPA) Rules, 2025 - Regulatory Updates by SGCMS\",\"isPartOf\":{\"@id\":\"https:\/\/www.sgcms.com\/regulatory-updates\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.sgcms.com\/regulatory-updates\/wp-content\/uploads\/2024\/09\/Apprentices-Act.png\",\"datePublished\":\"2025-11-27T06:20:21+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/#primaryimage\",\"url\":\"https:\/\/www.sgcms.com\/regulatory-updates\/wp-content\/uploads\/2024\/09\/Apprentices-Act.png\",\"contentUrl\":\"https:\/\/www.sgcms.com\/regulatory-updates\/wp-content\/uploads\/2024\/09\/Apprentices-Act.png\",\"width\":300,\"height\":210},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.sgcms.com\/regulatory-updates\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Digital Personal Data Protection (DPDPA) Rules, 2025\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.sgcms.com\/regulatory-updates\/#website\",\"url\":\"https:\/\/www.sgcms.com\/regulatory-updates\/\",\"name\":\"Regulatory Updates by SGCMS\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.sgcms.com\/regulatory-updates\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.sgcms.com\/regulatory-updates\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.sgcms.com\/regulatory-updates\/#organization\",\"name\":\"Regulatory Updates by SGCMS\",\"url\":\"https:\/\/www.sgcms.com\/regulatory-updates\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.sgcms.com\/regulatory-updates\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.sgcms.com\/regulatory-updates\/wp-content\/uploads\/2023\/11\/sgc-and-pionhr-logo1.png\",\"contentUrl\":\"https:\/\/www.sgcms.com\/regulatory-updates\/wp-content\/uploads\/2023\/11\/sgc-and-pionhr-logo1.png\",\"width\":753,\"height\":331,\"caption\":\"Regulatory Updates by SGCMS\"},\"image\":{\"@id\":\"https:\/\/www.sgcms.com\/regulatory-updates\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.sgcms.com\/regulatory-updates\/#\/schema\/person\/b8d5729c6deafb37d0db7013fec9766a\",\"name\":\"SGCMS\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.sgcms.com\/regulatory-updates\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/7932b2e116b076a54f452848eaabd5857f61bd957fe8a218faf216f24c9885bb?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/7932b2e116b076a54f452848eaabd5857f61bd957fe8a218faf216f24c9885bb?s=96&d=mm&r=g\",\"caption\":\"SGCMS\"},\"sameAs\":[\"https:\/\/www.sgcms.com\/regulatory-updates\"],\"url\":\"https:\/\/www.sgcms.com\/regulatory-updates\/author\/admin\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Digital Personal Data Protection (DPDPA) Rules, 2025 - Regulatory Updates by SGCMS","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/","og_locale":"en_US","og_type":"article","og_title":"Digital Personal Data Protection (DPDPA) Rules, 2025 - Regulatory Updates by SGCMS","og_description":"The Digital Personal Data Protection Rules, 2025 have now been officially notified, operationalising the Digital Personal Data Protection Act, 2023 and setting out detailed compliance requirements for organisations in India.\u200b When the new rules kick in The Rules are called the Digital Personal Data Protection Rules, 2025 and are issued under section 40 of the&hellip; Continue reading Digital Personal Data Protection (DPDPA) Rules, 2025","og_url":"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/","og_site_name":"Regulatory Updates by SGCMS","article_published_time":"2025-11-27T06:20:21+00:00","og_image":[{"width":300,"height":210,"url":"https:\/\/www.sgcms.com\/regulatory-updates\/wp-content\/uploads\/2024\/09\/Apprentices-Act.png","type":"image\/png"}],"author":"SGCMS","twitter_card":"summary_large_image","twitter_misc":{"Written by":"SGCMS","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/#article","isPartOf":{"@id":"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/"},"author":{"name":"SGCMS","@id":"https:\/\/www.sgcms.com\/regulatory-updates\/#\/schema\/person\/b8d5729c6deafb37d0db7013fec9766a"},"headline":"Digital Personal Data Protection (DPDPA) Rules, 2025","datePublished":"2025-11-27T06:20:21+00:00","mainEntityOfPage":{"@id":"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/"},"wordCount":1529,"publisher":{"@id":"https:\/\/www.sgcms.com\/regulatory-updates\/#organization"},"image":{"@id":"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/#primaryimage"},"thumbnailUrl":"https:\/\/www.sgcms.com\/regulatory-updates\/wp-content\/uploads\/2024\/09\/Apprentices-Act.png","keywords":["DPDA","IT Security"],"articleSection":["Compliance"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/","url":"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/","name":"Digital Personal Data Protection (DPDPA) Rules, 2025 - Regulatory Updates by SGCMS","isPartOf":{"@id":"https:\/\/www.sgcms.com\/regulatory-updates\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/#primaryimage"},"image":{"@id":"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/#primaryimage"},"thumbnailUrl":"https:\/\/www.sgcms.com\/regulatory-updates\/wp-content\/uploads\/2024\/09\/Apprentices-Act.png","datePublished":"2025-11-27T06:20:21+00:00","breadcrumb":{"@id":"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/#primaryimage","url":"https:\/\/www.sgcms.com\/regulatory-updates\/wp-content\/uploads\/2024\/09\/Apprentices-Act.png","contentUrl":"https:\/\/www.sgcms.com\/regulatory-updates\/wp-content\/uploads\/2024\/09\/Apprentices-Act.png","width":300,"height":210},{"@type":"BreadcrumbList","@id":"https:\/\/www.sgcms.com\/regulatory-updates\/digital-personal-data-protection-dpdpa-rules-2025\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.sgcms.com\/regulatory-updates\/"},{"@type":"ListItem","position":2,"name":"Digital Personal Data Protection (DPDPA) Rules, 2025"}]},{"@type":"WebSite","@id":"https:\/\/www.sgcms.com\/regulatory-updates\/#website","url":"https:\/\/www.sgcms.com\/regulatory-updates\/","name":"Regulatory Updates by SGCMS","description":"","publisher":{"@id":"https:\/\/www.sgcms.com\/regulatory-updates\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.sgcms.com\/regulatory-updates\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.sgcms.com\/regulatory-updates\/#organization","name":"Regulatory Updates by SGCMS","url":"https:\/\/www.sgcms.com\/regulatory-updates\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.sgcms.com\/regulatory-updates\/#\/schema\/logo\/image\/","url":"https:\/\/www.sgcms.com\/regulatory-updates\/wp-content\/uploads\/2023\/11\/sgc-and-pionhr-logo1.png","contentUrl":"https:\/\/www.sgcms.com\/regulatory-updates\/wp-content\/uploads\/2023\/11\/sgc-and-pionhr-logo1.png","width":753,"height":331,"caption":"Regulatory Updates by SGCMS"},"image":{"@id":"https:\/\/www.sgcms.com\/regulatory-updates\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.sgcms.com\/regulatory-updates\/#\/schema\/person\/b8d5729c6deafb37d0db7013fec9766a","name":"SGCMS","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.sgcms.com\/regulatory-updates\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/7932b2e116b076a54f452848eaabd5857f61bd957fe8a218faf216f24c9885bb?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7932b2e116b076a54f452848eaabd5857f61bd957fe8a218faf216f24c9885bb?s=96&d=mm&r=g","caption":"SGCMS"},"sameAs":["https:\/\/www.sgcms.com\/regulatory-updates"],"url":"https:\/\/www.sgcms.com\/regulatory-updates\/author\/admin\/"}]}},"_links":{"self":[{"href":"https:\/\/www.sgcms.com\/regulatory-updates\/wp-json\/wp\/v2\/posts\/2807","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.sgcms.com\/regulatory-updates\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.sgcms.com\/regulatory-updates\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.sgcms.com\/regulatory-updates\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.sgcms.com\/regulatory-updates\/wp-json\/wp\/v2\/comments?post=2807"}],"version-history":[{"count":2,"href":"https:\/\/www.sgcms.com\/regulatory-updates\/wp-json\/wp\/v2\/posts\/2807\/revisions"}],"predecessor-version":[{"id":2810,"href":"https:\/\/www.sgcms.com\/regulatory-updates\/wp-json\/wp\/v2\/posts\/2807\/revisions\/2810"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.sgcms.com\/regulatory-updates\/wp-json\/wp\/v2\/media\/2120"}],"wp:attachment":[{"href":"https:\/\/www.sgcms.com\/regulatory-updates\/wp-json\/wp\/v2\/media?parent=2807"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.sgcms.com\/regulatory-updates\/wp-json\/wp\/v2\/categories?post=2807"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.sgcms.com\/regulatory-updates\/wp-json\/wp\/v2\/tags?post=2807"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}