How the DPDP Rules Turn the Act into Day-to-Day Practice

On 13 November 2025, MeitY notified the DPDP Rules — the moment the Act stopped being a set of principles and started becoming something organisations could actually build against.

WHAT THE RULES ACTUALLY COVER

NOTICES

Format and content

What a compliant notice has to say, and how it has to be presented to count.

CONSENT MANAGERS

Registration and standards

The qualifications and conduct required of a registered Consent Manager.

BREACHES & TRANSFERS

Timelines and mechanics

How fast breaches must be reported, and how cross-border data transfers work.
Before November 2025, businesses were essentially designing compliance programmes around an outline, filling gaps with their best guess at what “reasonable” might mean. The Rules replaced a lot of that guesswork with actual specifics — which is also why a compliance approach built entirely on the Act’s text alone is now out of date.

Common misconception — That India just copied Europe’s GDPR. It didn’t. This law grew out of an Indian court case about an Indian identity scheme, not an imported European framework, even though global developments did shape parts of India’s thinking along the way.

The Rules are where DPDP compliance stopped being a judgement call and started being a checklist.

SOURCES  The DPDP Rules, 2025 — official text, MeitYhttps://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf   ·   MeitY notifies the DPDP Rules, 2025 — PIB press release — https://www.pib.gov.in/PressReleasePage.aspx?PRID=2090048 

Ready to get compliant?

Talk to our team or register your organisation to get started with ConveyGrid.