Next due
11 OCTGSTR-1 · Outward supplies · Sep 2026in 2 days 15 OCTPF & ESI · Contributions · Sep 2026in 6 days 20 OCTGSTR-3B · Summary return · Sep 2026in 11 days 21 OCTTax Audit Report · Form 3CA/3CB · AY 2026-27 · extended from 30 Sepin 12 days 30 OCTAOC-4 · Financial statements · FY 2025-26in 21 days 7 NOVTDS / TCS deposit · Deducted in Oct 2026in 29 days 21 NOVITR filing · Audit cases · AY 2026-27 · extended from 31 Octin 43 days 29 NOVMGT-7 / 7A · Annual return · FY 2025-26in 51 days
All due dates

Rules 1-2 of the Digital Personal Data Protection Rules, 2025: short title, staged commencement and definitions

The Rules are called the Digital Personal Data Protection Rules, 2025. Rules 1, 2 and 17 to 21 came with publication in the Official Gazette; rule 4 follows one year after the...

Published
Updated
Reading time
8 min
Views
12
Questions
7 answered
  • Expert Reviewed
  • Medium Complexity
  • In-Depth Guide
Topic
Data Protection
Published
October 2, 2026
Last updated
Oct 9, 2026
Reading time
8 min
0:00
Last updated: October 2026Verified against: Government sources

Rule 1 gives the Rules their name and says that they start in three stages, not all at once. Rule 2 defines four terms and tells you that any other word takes its meaning from the Digital Personal Data Protection Act, 2023. Both rules are in the first group, which starts on publication.

Where the Rules come from

The Rules were notified by the Ministry of Electronics and Information Technology as G.S.R. 846(E) on 13 November 2025. The recital says the draft Rules were published on 3 January 2025, that objections and suggestions were received and considered, and that the Central Government makes the Rules under sub-sections (1) and (2) of section 40 of the Act. That is the rule-making power the site covers in Section 40 of the DPDP Act. So what you read here is the notified text, not the earlier draft.

Printing slip: the recital reads "of the of the Digital Personal Data Protection Act". It is a repeated word in the Gazette and changes nothing.

Rule 1(1): the short title

"These rules may be called the Digital Personal Data Protection Rules, 2025." Everything else in rule 1 is about when each part starts.

Rule 1(2) to (4): three groups

Rule 1 does not bring all 23 rules into force on one day. It prints three sub-rules, and they are the answer to any question about the commencement date of the Rules:

  • Sub-rule (2): "Rules 1, 2 and 17 to 21 shall come into force on the date of their publication in the Official Gazette."
  • Sub-rule (3): "Rule 4 shall come into force one year after the date of publication of this Gazette."
  • Sub-rule (4): "Rules 3, 5 to 16, 22 and 23 shall come into force eighteen months after the date of publication of this Gazette."

The Gazette is dated Thursday, 13 November 2025. Counting from the Gazette date of 13 November 2025, one year ends in mid-November 2026 and eighteen months end in mid-May 2027; confirm the exact date of publication before relying on a date. For legal advice on how the stages affect your timetable, talk to a legal consultant before you fix a compliance calendar.

GroupRulesWhat the rule saysWhat those rules cover
On publication1, 2, 17 to 21Rule 1(2)Short title, definitions, the Board's search-cum-selection committee and appointments, service terms of Board Members and staff, procedure of the Board
One year after the date of publication of the Gazette4Rule 1(3)Registration and obligations of Consent Managers
Eighteen months after the date of publication of the Gazette3, 5 to 16, 22, 23Rule 1(4)Notice, State processing, security safeguards, breach intimation, erasure, contact details, children's data, Significant Data Fiduciaries, Data Principals' rights, transfer outside India, appeal, calling for information

The Schedules have no commencement line of their own. Each Schedule follows the rule that refers to it: the First Schedule with rule 4, the Second with rules 5 and 16, the Third with rule 8, the Fourth with rule 12, the Fifth with rule 18, the Sixth with rule 21 and the Seventh with rules 23 and 8(3).

What the staging means for a business

Rule 1 says nothing beyond the three stages. It does not say which sections of the Act are in force, and the Rules as notified are silent on that. Section 1(2) of the Act brings the Act into force by notification; see Section 1 of the DPDP Act. Check the Gazette for any notification before you rely on a date.

A practical way to use the table: if you run an app that collects personal data, the notice rule (rule 3), the security rule (rule 6) and the breach rule (rule 7) all sit in the eighteen-month group, so that is the group that touches day-to-day operations. If you plan to act as a Consent Manager, rule 4 and the First Schedule come first, one year after the date of publication of the Gazette.

Rule 2(1): four definitions

Rule 2(1) begins "In these rules, unless the context otherwise requires". Then it defines four terms.

(a) "Act" means the Digital Personal Data Protection Act, 2023 (22 of 2023).

(b) "techno-legal measures" means "as referred to under rules 20 and 22". That is the whole definition. Rule 20 (the Board as a digital office) and rule 22 (appeal) use the expression but neither defines it. Printing slip: the definition points to rules that use the term without explaining it, so the Rules give no meaning of their own. Read rule 20 in our article on the Board as a digital office; nothing there supplies a meaning either.

(c) "user account" means "the online account registered by the Data Principal with the Data Fiduciary". It also "includes any profiles, pages, handles, email address, mobile number and other similar presences by means of which such Data Principal is able to access the services of such Data Fiduciary". The breach rule (rule 7) tells a Data Fiduciary to inform an affected Data Principal through her user account or any registered mode of communication, and the erasure rule (rule 8) refers to her logging into her user account. So this definition is wider than a login: an email address or mobile number through which she reaches the service counts.

(d) "verifiable consent" means "a consent as specified in rule 10 or 11". Rule 10 deals with a child and rule 11 with a person with disability who has a lawful guardian. Read them in our articles on rule 10 and rule 11.

Rule 2(2): the Act fills the gaps

"The words and expressions used in these rules and not defined, but defined in the Act, shall have the same meanings respectively assigned to them in the Act." So "Data Fiduciary", "Data Principal", "Data Processor", "Consent Manager", "Significant Data Fiduciary", "Board", "personal data", "processing" and "specified purpose" are not redefined in the Rules. They carry the Act's meaning. The site explains those in three articles on section 2: data and processing, Data Principal, Data Fiduciary and Data Processor, and Board, gain, loss and specified purpose.

Rule 2(2) does not help where a word is defined in neither place. Other laws are named at several points in the Rules (for instance "computer resource" in rule 6(2) is tied to the Information Technology Act, 2000), and each of those references is explained where it appears.

A short example

Anaya Foods runs a delivery app. A customer registers with her mobile number and an email address. Under rule 2(1)(c) both of those, together with her profile page, are part of her "user account". When Anaya Foods later informs her about a data breach, it can use those registered means; the Rules do not require a separate channel. The example is ours; it is not an Illustration in the Rules.

Need help with the DPDP timetable?

If your business must map its processes to the three stages, a short consultation can turn the table above into a plan of what to do and when. You can speak to our legal team for a review that sets the notice, security and breach steps against the stage each rule belongs to.

Key takeaways

  • Rule 1(2): rules 1, 2 and 17 to 21 start on the date of their publication in the Official Gazette.
  • Rule 1(3): rule 4 starts one year after the date of publication of the Gazette.
  • Rule 1(4): rules 3, 5 to 16, 22 and 23 start eighteen months after the date of publication of the Gazette.
  • Rule 2 defines "Act", "techno-legal measures", "user account" and "verifiable consent"; the Act's meanings apply to every other term.
  • "Techno-legal measures" is defined only by pointing to rules 20 and 22, which do not define it.
  • Check later amendments and notifications before relying on any date.

Read next

Disclaimer: Based on the Digital Personal Data Protection Rules, 2025 as notified in the Gazette of India on 13 November 2025 (G.S.R. 846(E)), as consulted on 2 October 2026. The Rules come into force in three stages under rule 1; later amendments, notifications and anything published by the Data Protection Board of India should be checked. This article is general information, not legal advice; check the official text before acting.

Quick recapKey facts & short answers

Key Facts About Rules 1-2

  • Applies in: All states across India, under the relevant central law.
  • Mode: Mostly online via the official government portal.
  • Typical timeline: Ranges from a few days to a few weeks depending on the case.
  • Non-compliance: May attract penalties, interest or late fees.
  • Expert help: TaxClue completes the entire process end to end for you.

When do the DPDP Rules, 2025 come into force?

In three stages under rule 1: rules 1, 2 and 17 to 21 on publication, rule 4 one year after the date of publication of the Gazette, and rules 3, 5 to 16, 22 and 23 eighteen months after it. Counting from the Gazette date of 13 November 2025, one year ends in mid-November 2026 and eighteen months end in mid-May 2027; confirm the exact date of publication before relying on a date.

Which rules start on publication?

Rules 1, 2 and 17 to 21. They cover the title, definitions, the appointment of the Board's Chairperson and Members, their service terms, procedure of the Board and its officers.

A breach is handled well or badly in the first few hours — have the plan before the incident.

— TaxClue Data Protection Desk

Rules 1-2: a key compliance topic in Indian tax and corporate law that businesses and individuals must understand to remain compliant.

Related Services & Guides

Was this article helpful?
About the author
13,350 articles
Vikas Sharma Verified expert Tax & Compliance Expert

Experienced in company registration, GST, trademark, and compliance. Helping Indian businesses stay compliant.

Last reviewed: Live

Disclaimer: This article is for general informational purposes only and does not constitute professional tax, legal or financial advice. Laws, rates and due dates change and can vary by individual case — always verify with the relevant government source (e.g. mca.gov.in, incometax.gov.in) or consult a qualified professional before acting. TaxClue accepts no liability for decisions taken based on this content.

People also ask

Questions, answered

Short, direct answers to the 7 questions readers ask most on this topic.

In three stages under rule 1: rules 1, 2 and 17 to 21 on publication, rule 4 one year after the date of publication of the Gazette, and rules 3, 5 to 16, 22 and 23 eighteen months after it. Counting from the Gazette date of 13 November 2025, one year ends in mid-November 2026 and eighteen months end in mid-May 2027; confirm the exact date of publication before relying on a date.

Rules 1, 2 and 17 to 21. They cover the title, definitions, the appointment of the Board's Chairperson and Members, their service terms, procedure of the Board and its officers.

No. Rule 1 deals only with the Rules. The Act comes into force by notification under its own section 1(2), and that notification is not part of the Rules.

Rule 2(1)(b) says "as referred to under rules 20 and 22". Those rules use the expression without defining it, so the Rules give no separate meaning.

The online account the Data Principal registered with the Data Fiduciary, including profiles, pages, handles, email address, mobile number and similar presences through which she can access the services.

Consent as specified in rule 10 (child) or rule 11 (person with disability and lawful guardian).

Under rule 2(2) it takes the meaning given in the Act, if the Act defines it.