Rules 1-2 explained: this guide covers what it means, who it applies to, the step-by-step process, documents required, fees, due dates and penalties in India — so you can stay compliant with confidence and avoid costly mistakes.
Rule 1 gives the Rules their name and says that they start in three stages, not all at once. Rule 2 defines four terms and tells you that any other word takes its meaning from the Digital Personal Data Protection Act, 2023. Both rules are in the first group, which starts on publication.
The Rules are called the Digital Personal Data Protection Rules, 2025. Rules 1, 2 and 17 to 21 came with publication in the Official Gazette; rule 4 follows one year after the date of publication of the Gazette; rules 3, 5 to 16, 22 and 23 follow eighteen months after it. Rule 2 defines "Act", "techno-legal measures", "user account" and "verifiable consent", and sends every other undefined word back to the Act. Rules 1 and 2 are in the group that starts on publication.
Where the Rules come from
The Rules were notified by the Ministry of Electronics and Information Technology as G.S.R. 846(E) on 13 November 2025. The recital says the draft Rules were published on 3 January 2025, that objections and suggestions were received and considered, and that the Central Government makes the Rules under sub-sections (1) and (2) of section 40 of the Act. That is the rule-making power the site covers in Section 40 of the DPDP Act. So what you read here is the notified text, not the earlier draft.
Printing slip: the recital reads "of the of the Digital Personal Data Protection Act". It is a repeated word in the Gazette and changes nothing.
Rule 1(1): the short title
"These rules may be called the Digital Personal Data Protection Rules, 2025." Everything else in rule 1 is about when each part starts.
Rule 1(2) to (4): three groups
Rule 1 does not bring all 23 rules into force on one day. It prints three sub-rules, and they are the answer to any question about the commencement date of the Rules:
- Sub-rule (2): "Rules 1, 2 and 17 to 21 shall come into force on the date of their publication in the Official Gazette."
- Sub-rule (3): "Rule 4 shall come into force one year after the date of publication of this Gazette."
- Sub-rule (4): "Rules 3, 5 to 16, 22 and 23 shall come into force eighteen months after the date of publication of this Gazette."
The Gazette is dated Thursday, 13 November 2025. Counting from the Gazette date of 13 November 2025, one year ends in mid-November 2026 and eighteen months end in mid-May 2027; confirm the exact date of publication before relying on a date. For legal advice on how the stages affect your timetable, talk to a legal consultant before you fix a compliance calendar.
| Group | Rules | What the rule says | What those rules cover |
|---|---|---|---|
| On publication | 1, 2, 17 to 21 | Rule 1(2) | Short title, definitions, the Board's search-cum-selection committee and appointments, service terms of Board Members and staff, procedure of the Board |
| One year after the date of publication of the Gazette | 4 | Rule 1(3) | Registration and obligations of Consent Managers |
| Eighteen months after the date of publication of the Gazette | 3, 5 to 16, 22, 23 | Rule 1(4) | Notice, State processing, security safeguards, breach intimation, erasure, contact details, children's data, Significant Data Fiduciaries, Data Principals' rights, transfer outside India, appeal, calling for information |
The Schedules have no commencement line of their own. Each Schedule follows the rule that refers to it: the First Schedule with rule 4, the Second with rules 5 and 16, the Third with rule 8, the Fourth with rule 12, the Fifth with rule 18, the Sixth with rule 21 and the Seventh with rules 23 and 8(3).
What the staging means for a business
Rule 1 says nothing beyond the three stages. It does not say which sections of the Act are in force, and the Rules as notified are silent on that. Section 1(2) of the Act brings the Act into force by notification; see Section 1 of the DPDP Act. Check the Gazette for any notification before you rely on a date.
A practical way to use the table: if you run an app that collects personal data, the notice rule (rule 3), the security rule (rule 6) and the breach rule (rule 7) all sit in the eighteen-month group, so that is the group that touches day-to-day operations. If you plan to act as a Consent Manager, rule 4 and the First Schedule come first, one year after the date of publication of the Gazette.
Rule 2(1): four definitions
Rule 2(1) begins "In these rules, unless the context otherwise requires". Then it defines four terms.
(a) "Act" means the Digital Personal Data Protection Act, 2023 (22 of 2023).
(b) "techno-legal measures" means "as referred to under rules 20 and 22". That is the whole definition. Rule 20 (the Board as a digital office) and rule 22 (appeal) use the expression but neither defines it. Printing slip: the definition points to rules that use the term without explaining it, so the Rules give no meaning of their own. Read rule 20 in our article on the Board as a digital office; nothing there supplies a meaning either.
(c) "user account" means "the online account registered by the Data Principal with the Data Fiduciary". It also "includes any profiles, pages, handles, email address, mobile number and other similar presences by means of which such Data Principal is able to access the services of such Data Fiduciary". The breach rule (rule 7) tells a Data Fiduciary to inform an affected Data Principal through her user account or any registered mode of communication, and the erasure rule (rule 8) refers to her logging into her user account. So this definition is wider than a login: an email address or mobile number through which she reaches the service counts.
(d) "verifiable consent" means "a consent as specified in rule 10 or 11". Rule 10 deals with a child and rule 11 with a person with disability who has a lawful guardian. Read them in our articles on rule 10 and rule 11.
Rule 2(2): the Act fills the gaps
"The words and expressions used in these rules and not defined, but defined in the Act, shall have the same meanings respectively assigned to them in the Act." So "Data Fiduciary", "Data Principal", "Data Processor", "Consent Manager", "Significant Data Fiduciary", "Board", "personal data", "processing" and "specified purpose" are not redefined in the Rules. They carry the Act's meaning. The site explains those in three articles on section 2: data and processing, Data Principal, Data Fiduciary and Data Processor, and Board, gain, loss and specified purpose.
Rule 2(2) does not help where a word is defined in neither place. Other laws are named at several points in the Rules (for instance "computer resource" in rule 6(2) is tied to the Information Technology Act, 2000), and each of those references is explained where it appears.
A short example
Anaya Foods runs a delivery app. A customer registers with her mobile number and an email address. Under rule 2(1)(c) both of those, together with her profile page, are part of her "user account". When Anaya Foods later informs her about a data breach, it can use those registered means; the Rules do not require a separate channel. The example is ours; it is not an Illustration in the Rules.
Need help with the DPDP timetable?
If your business must map its processes to the three stages, a short consultation can turn the table above into a plan of what to do and when. You can speak to our legal team for a review that sets the notice, security and breach steps against the stage each rule belongs to.
Key takeaways
- Rule 1(2): rules 1, 2 and 17 to 21 start on the date of their publication in the Official Gazette.
- Rule 1(3): rule 4 starts one year after the date of publication of the Gazette.
- Rule 1(4): rules 3, 5 to 16, 22 and 23 start eighteen months after the date of publication of the Gazette.
- Rule 2 defines "Act", "techno-legal measures", "user account" and "verifiable consent"; the Act's meanings apply to every other term.
- "Techno-legal measures" is defined only by pointing to rules 20 and 22, which do not define it.
- Check later amendments and notifications before relying on any date.
Read next
- Rule 3: notice by a Data Fiduciary to a Data Principal
- Rule 4: registration of a Consent Manager and powers of the Board
- Section 40 of the DPDP Act: power to make rules
- DPDP compliance checklist for businesses
Disclaimer: Based on the Digital Personal Data Protection Rules, 2025 as notified in the Gazette of India on 13 November 2025 (G.S.R. 846(E)), as consulted on 2 October 2026. The Rules come into force in three stages under rule 1; later amendments, notifications and anything published by the Data Protection Board of India should be checked. This article is general information, not legal advice; check the official text before acting.
