DPDP Rules 2025 · Explainer

The final DPDP Rules are here. Here's your actual deadline — and your plan.

Published July 2026 · ~8 min read · by Ronin Works
Short answer

MeitY notified the final DPDP Rules in November 2025, starting a phased 18-month clock. The Data Protection Board is already operating; Consent Manager provisions switch on around November 2026; and everything else — consent, notice, rights requests, grievance redressal — must be fully working by 13 May 2027. The Rules also added teeth: retain logs for at least a year, answer grievances within 90 days, and report breaches to the Board within 72 hours.

For two years, "DPDP compliance" was something Indian businesses could postpone because the detailed rules weren't final. That excuse ended in November 2025. The law of the land now has dates, procedures and a functioning regulator — and if your business handles personal data of people in India, the 18-month runway is already burning.

What actually happened

The DPDP Act passed in 2023 but left the operating detail — how consent notices must look, how breaches are reported, how the Data Protection Board works — to Rules. A draft was published in January 2025, industry feedback followed, and the final Rules were notified in the Gazette in November 2025. Notification means this is no longer a proposal: it is enforceable law rolling out on a fixed schedule.

The timeline that matters

WhenWhat takes effect
Nov 2025Immediately on notification: the Data Protection Board of India framework — the Board has been constituted and can act.
~Nov 202612 months in: Consent Manager provisions — the registration framework for the new class of consent-management intermediaries. (What a Consent Manager actually is — most MSMEs don't need to become one.)
13 May 202718 months in — full compliance: consent and notice requirements, data-principal rights (access, correction, erasure), grievance redressal, children's-data safeguards, and the rest of the Act and Rules.

Read that last row carefully: 13 May 2027 is not the day to start. Consent flows, a data inventory, request-handling processes and vendor agreements realistically take months to build — the deadline is when they must already be running.

The three new obligations that surprise people

1. Keep your logs for a year

The Rules require businesses to retain personal data, traffic logs and related records for at least one year (subject to narrow exceptions). Many businesses delete logs after 30 or 90 days to save storage — that default is now non-compliant. Review your log retention settings and set a 12-month hold.

2. Answer grievances within 90 days

Data-principal grievances now carry a hard 90-day response cap. If you don't have a tracked process — a mailbox someone owns, a log of what came in and when it was closed — you can't prove you met it. This is exactly the machinery a grievance officer runs.

3. Report breaches fast

On a personal data breach, affected individuals must be informed promptly with what happened and what you're doing about it — and the Data Protection Board must receive a detailed notification within 72 hours. Nobody drafts a breach notice well at 2 a.m. during an incident; write the playbook now.

What didn't change

The fundamentals of the Act stand: consent must be free, specific, informed and as easy to withdraw as to give (what valid consent looks like); people keep their rights to access, correction and erasure; children's data needs verifiable parental consent; and the penalty schedule still tops out at ₹250 crore per instance for failing security safeguards. Sectoral regulators (RBI, SEBI, IRDAI) still sit on top — where they demand longer retention, the longer rule wins.

Your next-90-days plan

Where do you stand today?

Take the free, 2-minute DPDP Readiness Scorecard — 12 questions, a per-area gap report, and exactly what to fix first before 13 May 2027.

How Ronin Works helps

We run the whole readiness programme — data discovery, cleansing, consent and grievance processes, breach playbooks, records — and we're building Ronin Consent, a simple consent-collection tool for MSMEs, so the consent log the Rules demand exists from day one rather than being reconstructed for an audit.

Keep reading

Not a business — just you?

The DPDP Act gives individuals rights too. Saaph.in — a Ronin Works product — finds where your personal data is exposed across the open web and gets it removed under the Act, then keeps watch.

Scan your exposure at Saaph.in →
Enquiry

Need help with the 18-month runway?

Send us a note — we reply within one working day.

✓ Thank you — we'll be in touch.

This article is general information, not legal advice. Dates and obligations summarise the DPDP Act, 2023 and the DPDP Rules as notified in November 2025; consult the Gazette notifications or a qualified professional for the authoritative text, or talk to Ronin Works.