Back to blog
Compliance

DPDP Rules 2025 Explained | Complete Guide for Startups

Understand the DPDP Rules 2025 with this practical guide for Indian startups and businesses. Learn key requirements, compliance steps, FAQs, and best practices.

Bilal Shaikh
July 23, 2026
11 min read

DPDP Rules 2025 Explained

The Digital Personal Data Protection (DPDP) Act, 2023 established India's legal framework for protecting digital personal data. The DPDP Rules, 2025notified on 13 November 2025 — provide operational detail on how organisations implement the Act's requirements in practice.

If you're a startup founder, product manager, compliance officer, HR leader, or business owner, understanding these Rules will help you prepare for responsible data governance before the 13 May 2027 full compliance deadline.

Act vs Rules: The Act defines what the law requires. The notified Rules explain how many of those requirements operate day to day — notices, consent mechanics, breach reporting timelines, and more. An earlier draft of the Rules circulated in January 2025; the notified Rules of 13 November 2025 are what you should implement against.

Related guides: What is the DPDP Act? · DPDP compliance checklist · Ultimate compliance guide (2026) · Free readiness check · DPDPKit


Table of contents


What Are the DPDP Rules?

The DPDP Act establishes the legal framework. The DPDP Rules, 2025 explain how certain provisions of the Act operate in practice — including implementation expectations, operational procedures, and compliance-related processes.

Think of it this way:

DPDP Act → Defines what the law requires.

DPDP Rules, 2025 → Explain how organisations implement those requirements.

The Rules cover areas such as:

  • Privacy and consent notices
  • Consent withdrawal mechanics
  • Security safeguards
  • Personal data breach intimation and reporting
  • Data retention and erasure
  • Grievance handling
  • Rights request processes
  • Significant Data Fiduciary obligations (where applicable)

Key Dates and Milestones

Milestone Date
DPDP Act passed August 2023
Draft Rules circulated January 2025
DPDP Rules, 2025 notified 13 November 2025
Data Protection Board operational From 13 November 2025
Full compliance mandatory 13 May 2027

Phase 1 provisions — including the Board and penalty framework — are already live. Complaints can be filed today. Full operational compliance must be in place by May 2027.


DPDP Act vs DPDP Rules

DPDP Act, 2023 DPDP Rules, 2025
Nature Primary legislation Subordinate rules under the Act
Passed / issued by Parliament Government notification
Scope Legal principles and obligations Operational implementation detail
Examples Data Fiduciary duties, penalties, Board powers Notice format, breach reporting steps, retention expectations
Status In force Notified 13 November 2025

Businesses should understand both together. Your policies and SOPs should reference the Act for legal basis and align operational steps to the notified Rules.


Who Should Pay Attention?

The Rules are relevant to organisations that process digital personal data, including:

  • SaaS startups
  • E-commerce companies
  • FinTech businesses
  • Healthcare and health-tech platforms
  • EdTech companies
  • AI startups
  • HR software providers
  • Marketing agencies
  • Mobile application developers
  • Enterprises and growing SMEs

If your organization collects personal information digitally — including B2B customer and employee data — you should understand how the notified Rules apply to you.


Key Provisions Under the DPDP Rules, 2025

The following sections summarise the practical areas founders most often need to operationalise. Rule numbers refer to the notified DPDP Rules, 2025.

1. Privacy and consent notices

Individuals should receive a clear notice before or at the time their personal data is collected. Under the Rules, notices must be itemised — not buried in Terms of Service.

A good notice typically explains:

  • What information is collected
  • Why it is collected (specific purposes)
  • How it will be used and shared
  • How individuals can exercise their rights
  • Grievance Officer contact details

Avoid legal jargon, hidden disclosures, and ambiguous wording. Notices should also be available in English and a scheduled Indian language where required.


2. Consent management

Where consent is the lawful basis, it should be:

  • Free, specific, informed, and unambiguous
  • Backed by the itemised notice
  • As easy to withdraw as it was to give

Good practices:

  • Separate consent checkboxes for different purposes
  • Plain language purpose descriptions
  • No pre-selected marketing checkboxes
  • No consent bundling ("agree to marketing to create an account")

Maintain versioned consent records — who consented, to what, and when.


3. Withdrawal of consent

Individuals must have a straightforward way to withdraw consent. Businesses should establish documented workflows so withdrawal requests are handled consistently, logged, and result in cessation of the relevant processing (subject to lawful exceptions).


4. Grievance Officer

The Act and Rules require Data Fiduciaries to appoint a Grievance Officer — a named internal contact for Data Principal complaints. Contact details must be published in your privacy policy. This is one of the most commonly missed requirements in readiness checks.


5. Data security

Organisations must implement reasonable security safeguards appropriate to the nature of personal data processed.

Examples include:

  • Multi-factor authentication
  • Encryption in transit (TLS 1.2+)
  • Role-based access controls
  • Secure backups and restore testing
  • Regular software updates and dependency scanning
  • Monitoring and logging

Security is an ongoing process, not a one-time project.


6. Personal data breach reporting

The Rules operationalise the Act's breach obligations. In summary:

  • Notify affected Data Principals without undue delay where required
  • Intimate the Data Protection Board without delay
  • File a detailed report within 72 hours

Maintain a Breach Register — log every incident including near-misses. Run a tabletop drill before you need the plan for real.


7. Data retention and erasure

Organisations should avoid keeping personal information indefinitely. Create documented retention schedules defining:

  • What data is stored
  • Why it is retained
  • How long it is retained
  • When and how it is deleted

Regular reviews reduce unnecessary data accumulation and simplify rights requests.


8. Responding to individual requests

Prepare internal processes for access, correction, erasure, and consent withdrawal requests.

Practical preparation includes:

  • Request intake process (email, form, or in-app)
  • Identity verification
  • Internal owner assigned
  • Rights Request Register
  • Documented response workflow and timelines

9. Vendor oversight

Many businesses rely on external providers for cloud hosting, email, payments, analytics, CRM, and customer support. The Rules expect Data Fiduciaries to govern processors through DPAs and due diligence.

Maintain a Vendor Register and review cross-border storage locations.


10. Employee awareness and governance

Employees play a critical role in protecting personal data. Training should cover password security, phishing awareness, incident reporting, data handling practices, and privacy responsibilities.

Good compliance depends on internal governance — policies, registers, and a workbook that tracks gap assessment progress.


Practical Compliance Checklist

Use this quick assessment. For the full 13-section version, see our DPDP compliance checklist.

Governance

  • Data inventory completed
  • Privacy Policy updated against notified Rules
  • Processing purposes documented
  • Grievance Officer appointed and published
  • Vendor Register created

Website and product

  • Privacy Policy published
  • Itemised consent notices reviewed
  • Consent withdrawal mechanism available
  • Contact and Grievance Officer details visible

Security and breach

  • MFA enabled on critical systems
  • Backups configured and tested
  • Access controls reviewed
  • Breach Response Plan prepared (72-hour Board reporting)
  • Breach Register set up

Documentation

  • Employee Privacy Notice
  • Consent records with version tracking
  • Data Retention Schedule
  • Rights Request Register
  • Compliance Workbook with gap assessment

30-Day Action Plan

A focused starting point aligned to the notified Rules. For a fuller plan, see the 90-day roadmap in DPDPKit.

Week 1 — Discover

  • Identify personal data across all systems
  • Build data inventory
  • Review website forms and signup flows
  • Audit Privacy Policy against notified Rules

Week 2 — Document

  • Review vendors and send DPAs
  • Prepare or update consent notices
  • Define retention periods
  • Appoint Grievance Officer

Week 3 — Operationalise

  • Set up registers (consent, DSR, vendor, breach)
  • Test rights request and deletion workflows
  • Finalise breach response plan
  • Train employees on basics

Week 4 — Review

  • Re-run gap assessment — target 80%+ complete
  • Address high-priority gaps
  • Schedule quarterly reviews through May 2027

Common Mistakes

Many organizations:

  • Treat the January 2025 draft Rules as current — instead of the November 2025 notified Rules
  • Assume privacy is only a legal team's responsibility
  • Never review third-party vendors or sign DPAs
  • Keep data indefinitely without a retention schedule
  • Ignore employee records
  • Use copied GDPR Privacy Policies
  • Forget to appoint a Grievance Officer
  • Lack a breach response process with 72-hour Board reporting
  • Have no documented governance or registers

A structured implementation plan reduces these risks. Take the free readiness check to see which gaps apply to you.


Frequently Asked Questions

Are the DPDP Rules different from the DPDP Act?

Yes. The Act establishes the legal framework; the notified Rules provide operational guidance for implementing various provisions.

Are the DPDP Rules 2025 still in draft?

No. They were formally notified on 13 November 2025. Implement against the notified Rules, not the earlier January 2025 draft.

Do startups need to follow the Rules?

Organizations that process digital personal data should understand how the Rules apply to their activities — regardless of company size.

Can I wait until my company grows?

Building good privacy practices early is easier than retrofitting them later. The Board is already accepting complaints, and the 13 May 2027 deadline is fixed.

What documents should a startup prepare?

Common documents include a Privacy Policy, consent notices, data inventory, vendor register, rights request register, retention schedule, breach SOP, and Grievance Officer appointment. See the full document list in our pillar guide.

Are spreadsheets enough?

Many early-stage startups begin with structured spreadsheets. DPDPKit's 8-tab workbook is built for this stage and aligned to the notified Rules.


Free DPDP Readiness Check

Not sure how prepared your business is?

Take our free DPDP readiness check — 50 questions, about 2 minutes, instant score with your top three gaps. No signup required.

Start your free assessment →


Get DPDPKit

Instead of creating every document from scratch, DPDPKit includes templates and a workbook drafted against the DPDP Rules notified 13 November 2025 — not the January 2025 draft:

  • Privacy Policy template (DPDP-aligned)
  • Itemised Consent Notice
  • Cookie and Tracking Consent Notice
  • Data Principal Rights Request SOP
  • Grievance Officer Appointment and Charter
  • Data Breach Notification SOP (72-hour Board reporting)
  • Data Processing Agreement (DPA) Template
  • Employee and HR Data Privacy Notice
  • Vendor and Third-Party Processor Checklist
  • Children's Data Processing Policy
  • Data Retention and Deletion Schedule
  • 8-tab Compliance Workbook with gap assessment and 90-day roadmap

₹4,999 — instant download after payment.

Get DPDPKit →


Final thoughts

The DPDP Rules, 2025 translate the principles of the DPDP Act into practical, day-to-day operations. Rather than treating compliance as a one-time legal project, view it as ongoing governance that evolves with your products and services.

Start with the basics: understand what personal data you process, align your documents to the notified Rules, establish clear internal procedures, and review them regularly. For startups, embedding privacy early improves customer trust, strengthens security, and reduces future compliance effort.

Next steps:

  1. Take the free readiness check to score yourself against 50 requirements
  2. Work through the DPDP compliance checklist
  3. Read the Ultimate DPDP Compliance Guide (2026) for the full implementation walkthrough
  4. Get DPDPKit if you want templates aligned to the November 2025 Rules

This guide is for informational purposes only and does not constitute legal advice. Have your counsel or CA review your customised documents before you rely on them.

Written by

Bilal Shaikh

Founder, UXLaunch Lab

11+ years across fintech, Web3, and SaaS. Shipped RoleGrowth — an AI-powered career platform — end-to-end in 8 weeks.

Frequently asked questions

Quick answers.

Are the DPDP Rules different from the DPDP Act?
Yes. The Act establishes the legal framework and principles. The DPDP Rules, 2025 — notified on 13 November 2025 — provide operational detail on how many provisions are implemented in practice.
Are the DPDP Rules 2025 still in draft?
No. The DPDP Rules, 2025 were formally notified on 13 November 2025. An earlier draft circulated in January 2025, but the notified Rules are what organisations should implement against.
Do startups need to follow the DPDP Rules?
Organisations that process digital personal data should understand how the notified Rules apply to their activities — including notices, consent, breach reporting, and Grievance Officer requirements.
When is full DPDP compliance mandatory?
Full compliance under the DPDP Act, 2023 and the DPDP Rules, 2025 is mandatory by 13 May 2027. The Data Protection Board has been operational since 13 November 2025.
What documents should a startup prepare under the Rules?
Common documents include a privacy policy, itemised consent notices, data inventory, vendor register, rights request register, retention schedule, breach SOP, and Grievance Officer appointment. Exact requirements depend on your processing activities.
Are spreadsheets enough for DPDP Rules compliance?
Many early-stage startups begin with structured spreadsheets and documented processes. DPDPKit includes an 8-tab workbook aligned to the notified Rules.

Related articles