The Act was passed in August 2023. The Rules that actually explain how to follow it didn’t arrive until November 2025 — a gap of more than two years. Here’s why that gap exists.
The Act
- Sets out principles — consent must be free, specific, informed
- Creates the Data Protection Board
- States that reasonable security safeguards are required
The Rules
- Sets out mechanics — exactly what a notice must contain, how it should look
- Explains how the Board operates and how to approach it
- Gets closer to what “reasonable” actually requires in practice
This two-tier structure isn’t unusual — most Indian legislation works this way, with Parliament setting principles in an Act and the relevant Ministry filling in operational detail through Rules. It does mean, though, that reading the Act alone only tells you half the story.
Common misconception — That the Rules are optional guidance, softer than the Act itself. They’re not — they’re legally binding, just operating at a more detailed, practical level than the Act does.
The Act says what must happen. The Rules say how.
SOURCES The DPDP Act, 2023 — official text, MeitY — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf · The DPDP Rules, 2025 — official text, MeitY — https://www.meity.gov.in/static/uploads/2025/11/53450e6e5dc0bfa85ebd78686cadad39.pdf