Don’t do SECURITY. Do business SECURELY.

India notifies the DPDP Rules 2025

India notifies its Digital Personal Data Protection Rules, starting a phased implementation with most obligations applying from May 2027.

The Indian government today notifies the Digital Personal Data Protection Rules 2025, starting phased implementation of the DPDP Act 2023.

Key points

  • Most operational obligations apply from 13 May 2027.
  • Notice and consent requirements, including consent managers.
  • Reasonable security safeguards, including encryption, access control and logging.
  • Breach notification to the Data Protection Board and affected individuals.
  • Rules on cross-border transfers and significant data fiduciaries.

UK organisations with Indian customers or data processing in India should use the transition period to update notices, consent and incident response.

Source: Digital Personal Data Protection Rules, 2025 (MeitY)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights