Three specific changes from the Rules are worth knowing before anything else, because they affect nearly every organisation processing personal data in India.
THREE CONCRETE CHANGES
RETENTION
A one-year floor
A minimum retention period applies before certain data can be treated as no longer needed — three years for some categories.
ERASURE NOTICE
48 hours' warning
Before data is erased for inactivity, the person has to be given advance notice, not a silent deletion.
CROSS-BORDER
Allowed unless restricted
Data can move outside India freely, unless the government specifically names a restricted country — the opposite of a localisation regime.
That last point surprises a lot of people who expected India to follow stricter data-localisation models used elsewhere. Instead, the Rules take a permissive, “negative list” approach: transfers are allowed everywhere by default, and as of this writing, the government hasn’t named a single restricted country. That could change with a future notification, so it’s worth monitoring rather than assuming it’s settled permanently.
Common misconception — That the DPDP Rules require data to stay inside India, similar to some other countries’ localisation laws. They don’t — cross-border transfer is allowed unless a country is specifically restricted, and none currently are.
Three quiet but concrete shifts — retention floors, erasure notice, and permissive cross-border transfer — do more to change daily practice than any single headline provision.
SOURCES The DPDP Rules, 2025 — official text, MeitY — https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf