The Indian government today notifies the Digital Personal Data Protection Rules 2025, starting phased implementation of the DPDP Act 2023.
Key points
- Most operational obligations apply from 13 May 2027.
- Notice and consent requirements, including consent managers.
- Reasonable security safeguards, including encryption, access control and logging.
- Breach notification to the Data Protection Board and affected individuals.
- Rules on cross-border transfers and significant data fiduciaries.
UK organisations with Indian customers or data processing in India should use the transition period to update notices, consent and incident response.
Source: Digital Personal Data Protection Rules, 2025 (MeitY)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.