On 13 November 2025, MeitY notified the DPDP Rules — the moment the Act stopped being a set of principles and started becoming something organisations could actually build against.
WHAT THE RULES ACTUALLY COVER
NOTICES
Format and content
What a compliant notice has to say, and how it has to be presented to count.
CONSENT MANAGERS
Registration and standards
The qualifications and conduct required of a registered Consent Manager.
BREACHES & TRANSFERS
Timelines and mechanics
How fast breaches must be reported, and how cross-border data transfers work.
Before November 2025, businesses were essentially designing compliance programmes around an outline, filling gaps with their best guess at what “reasonable” might mean. The Rules replaced a lot of that guesswork with actual specifics — which is also why a compliance approach built entirely on the Act’s text alone is now out of date.
Common misconception — That India just copied Europe’s GDPR. It didn’t. This law grew out of an Indian court case about an Indian identity scheme, not an imported European framework, even though global developments did shape parts of India’s thinking along the way.
The Rules are where DPDP compliance stopped being a judgement call and started being a checklist.
SOURCES The DPDP Rules, 2025 — official text, MeitY — https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf · MeitY notifies the DPDP Rules, 2025 — PIB press release — https://www.pib.gov.in/PressReleasePage.aspx?PRID=2090048