Loading…
Loading…
The 2025 Rules are the long-awaited subordinate legislation that operationalises the Digital Personal Data Protection Act, 2023 — which itself sat dormant for over two years awaiting the Rules to give it practical effect. MeitY notified the package on 13 Nov 2025 via four companion gazette notifications (G.S.R. 843(E)–846(E)), with G.S.R. 846(E) carrying the substantive Rules text.
Phased commencement (per the staged notifications):
and the constitution and operations of the Data Protection Board of India (DPBI).
obligations of Consent Managers.
substantive obligations: notice and consent, processing of children's data, data-breach notification, retention/erasure, Significant Data Fiduciary (SDF) duties, and Rule 14 cross-border data transfer restrictions (Central Government may by notification specify countries or classes of recipients to which personal data may not be transferred — the "negative list" approach, in contrast to the EU's adequacy-list approach).
Penalty structure: tiered monetary penalties under Schedule 1 of the DPDP Act, up to INR 250 crore (~USD 30m) per breach for failure to take reasonable security safeguards, plus INR 200 crore for breach notification failures and INR 150 crore for processing children's data in violation of obligations.
Extraterritorial reach: per the parent Act §3, the Rules apply to processing of digital personal data outside India where such processing is in connection with offering goods or services to data principals in India — capturing every multinational SaaS, cloud, payments, ad-tech, HR-tech, and AI-training platform serving Indian users.
data flows shape SaaS/cloud/payments/HR/AI training cost structures across global tech.
to restrict transfers to specific jurisdictions on geopolitical grounds — an instrument adjacent to (but not yet used as) a digital-sovereignty trade tool, comparable to China's PIPL Article 38 outbound-transfer regime and EU GDPR Chapter V.
Central Government — will impose DPIA, audit, and Indian-resident Data Protection Officer requirements on large platforms (Big Tech, large fintechs, telcos, e-commerce marketplaces).
consent flows, notice-and-choice UX, breach-detection telemetry, and data-localisation-adjacent architectures for Indian users — adds India to the growing patchwork of country-level privacy regimes (EU GDPR, UK DPA, Brazil LGPD, China PIPL, Vietnam Decree 13, Indonesia PDP Law).
power in reserve as a geopolitical lever?
volume, sector, or strategic-importance designation?
for payments, IRDAI for insurance, SEBI for capital-markets data) whose stricter localisation rules will likely continue to apply.