The wait is over and the clock starts ticking.The Government of India notified the Digital Personal Data Protection (DPDP) Rules, 2025 on 14 November 2025. This marks the full operationalisation of the Digital Personal Data Protection Act, 2023 (DPDP Act). The Act and the Rules provide a citizen-centred framework for the responsible use of digital personal data. At the same time, due considerations are given to lawful data processing.
The discussion and deliberations on the data protection and privacy in India took a steep turn with landmark decision on right to privacy in Justice K.S. Puttaswamy (Retd.) vs. Union of India case in the year 2017, a petition filed in 2012 where Aadhaar project and its implications on personal data was challenged by Justice K.S. Puttaswamy (Retd.), a former Karnataka High Court judge. In this case, the Supreme Court of India unanimously ruled that the Right to Privacy is a Fundamental Right under Article 21 (Right to Life and Personal Liberty).
Prior to this, there were numerous occasions where fundamental right to privacy were not recognised. These includes:
i) A K Gopalan vs State of Madras (1950), where the decision came stating that Article 21 requires “procedures established by law”, even if unfair.
ii) MP Sharma vs Satish Chandra (1954)with a decision that right to privacy was not explicitly intended to be a fundamental right under the Indian constitution etc.
Subsequent to thePuttaswamycase judgement, and to make the fundamental right to privacy meaningful, a committee of experts under the chairmanship of Justice B N Srikrishna, a former supreme court judge was constituted by the Government of India. The committee submitted its report titled “A Free and Fair Digital Economy: Protecting Privacy, Empowering Indians” in 2018 to Government.
Subsequently thePersonal Data Protection Bill (PDPB) was presented in the parliament in 2018 and were reproduced with amendments in 2019 and 2021. In subsequent studies by the joint parliamentary committee (JPC) and experts, the bill was modified to Digital Personal Data Protection Bill (DPDPB) and presented in 2022. The public feedback on the draft ‘Digital Personal Data Protection Bill, 2022’ was published by the Ministry of Electronics and Information Technology and invited public for submission of feedback on the draft bill in a chapter wise manner within the prescribed time. The Digital Personal Data Protection Act (DPDPA), 2023 is in continuation to the bill presented. Government also consolidated and considered the views before releasing the DPDP Rules on 13th November 2025.
The government has planned for a phased approach in implementation of the rules.
- The short title and commencement (Rule 1), Definitions (Rule 2) and Rules pertaining to the constitution of Data Protection Board (Rule 17 to 21) will be applicable from the date of publication, i.e. 13th November 2025
- The rules related to registration and obligations of Consent manager (Rule 4) will be applicable in a year, i.e. 13th November 2026.
- All other rules, Rule 3, 5 to 16, 22 and 23 will be applicable in 18 months of the notification, i.e.1 3th May 2027.
In other words, organisations will be more concerned on assessing their current posture with respect to consent management, digital personal data collection, processing and storing/retention and comply with the expectations of DPDP rules latest by 13th May 2027.
The DPDP Act,2023 and DPDP Rules,2025 shall be applicable to the processing of digital personal data within the territory of Indiawhere the personal data is collected:
- in digital form or
- in non-digital form and digitised subsequently.
This act will also apply to processing of digital personal data outside the territory ofIndia, if such processing is in connection with any activity related to offering ofgoods or services to Data Principals within the territory of India. However, Act is clear that this will not be applicable to a personal data processed by an individual for any personal or domestic purpose or personal data that is made or caused to be made publicly available by the Data principal.
Now before we get into the roles defined in the DPDP rules, the basic related concepts of security, privacy and protection with respect to data are listed below.
Data Security: Measures, technologies, and controls used to protect data from unauthorized access, breaches, misuse, or cyberattacks.
Data privacy:Ensuring how personal data is collected, used, shared, and stored aligns with laws, policies, and user expectations.
Data Protection:A governance framework that includes both security and privacy to safeguard personal data throughout its lifecycle.
The major roles as per DPDP Act/Rules includes:
- Data Principal is the individual to whom the personal data relates. Otherwise, the Data Principal is the person whose data is being collected, processed, stored, or shared.In case of a child or a person with disability who requires a guardian, the parent or lawful guardian is also termed as data principalin such cases.
- Data Fiduciaryis any entity (person, company, organization, state body, etc.) that determines the purpose and means of processing personal data.
- Data Processoris any person or entity that processes personal data on behalf of a Data Fiduciary.The processing of personal data will be only as instructed by the Data fiduciary and cannot repurpose or share this.
- Consent Manageris a registered intermediary that acts asa single point of contact to enable a Data Principal to give, manage, review andwithdraw consent through an accessible, transparent and interoperable platform.
- Data Protection Board of Indiais a body established by the Government through notification, for the purposes of this act with vested powers as defined in the DPDP Act, 2023.
As per DPDP Act, the rights and duties in various roles are clearly defined. A data Principal will have rights throughout on the data which includes access, correction, erasure, getting grievances redressed, escalation to the board if not redressed in time, withdraw or modify consent etc.
Meantime, the Data fiduciary shall process the personal digital data of a data principal only for the purpose for which consent is obtained. As per the act, the consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose.
Data fiduciary shall be accountable for the compliance even if the data is processed through a data processor. Also, fiduciary should erase the personal data on serving the specified purpose and also if consent is withdrawn, unless its retention is necessary for compliance with any law for the time being in force.In case of any personal data breaches, the Data Fiduciary shall intimate to the Board with description of the breach, its nature, extent, timing and location of occurrence. The likely impact also should be informed. The intimation should be given at the earliest not later than 72 hours of becoming aware of the breach, unless otherwise extension is allowed by the board in writing. The DPDP Act, 2023 also prescribes penalties on various breach of provisions of DPDP Rules or Act, which may extend to two hundred and fifty crore rupees.
Another class of Fiduciary named Significant Data Fiduciary (SDF) is defined in the Act/Rules which is notified by the Central Government based on the assessment, which includes volume and sensitivity of personal data processed, Risks to data principal, potential impact on the sovereignty and integrity of India, risks to electoral democracy, security of the state etc. Additional obligations such as appointment of a “Data protection officer”, Engaging an independent data auditor, carrying out periodic data protection impact assessment (DPIA), ensure technical measures for Algorithm/software, Data localisation etc.
Now it is time for all entities to assess themselves on the readiness with respect to data collection, consent mechanism, data processing, data security and retention requirements as per the legal or regulatory requirements.
-by Jyothish Jolisa
VP (Information Security) & CISO