What Changes for Organisations Under the DPDP Rules

Three specific changes from the Rules are worth knowing before anything else, because they affect nearly every organisation processing personal data in India.

THREE CONCRETE CHANGES

RETENTION

A one-year floor

A minimum retention period applies before certain data can be treated as no longer needed — three years for some categories.

ERASURE NOTICE

48 hours' warning

Before data is erased for inactivity, the person has to be given advance notice, not a silent deletion.

CROSS-BORDER

Allowed unless restricted

Data can move outside India freely, unless the government specifically names a restricted country — the opposite of a localisation regime.
That last point surprises a lot of people who expected India to follow stricter data-localisation models used elsewhere. Instead, the Rules take a permissive, “negative list” approach: transfers are allowed everywhere by default, and as of this writing, the government hasn’t named a single restricted country. That could change with a future notification, so it’s worth monitoring rather than assuming it’s settled permanently.
Common misconception — That the DPDP Rules require data to stay inside India, similar to some other countries’ localisation laws. They don’t — cross-border transfer is allowed unless a country is specifically restricted, and none currently are.

Three quiet but concrete shifts — retention floors, erasure notice, and permissive cross-border transfer — do more to change daily practice than any single headline provision.

SOURCES  The DPDP Rules, 2025 — official text, MeitYhttps://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf   

Ready to get compliant?

Talk to our team or register your organisation to get started with ConveyGrid.