DPDP Rules 2025 Are Out — What Your Business Must Do Before May 2027

Last Updated: June 9, 2026 · Author: Saurabh Gupta, CISM, CIPP/E · Founder, MYITMANAGER

India’s Digital Personal Data Protection Rules 2025 were notified on April 8, 2025, following the DPDP Act 2023. The Rules set the operational framework — deadlines, procedures, and technical requirements — that every Data Fiduciary must implement before enforcement begins in May 2027. If you’ve been waiting for the Rules before acting on DPDP compliance, the clock is now running.

This guide covers the most important changes introduced by the DPDP Rules 2025, what they mean for your business, and the specific actions you need to take before the May 2027 deadline.

What the DPDP Rules 2025 Add to the DPDP Act 2023

The DPDP Act 2023 established the legal framework — definitions, rights, obligations, and penalty structure. The Rules 2025 fill in the operational detail that businesses actually need to implement compliance:

  • Consent Manager framework: Consent Managers must register with the Data Protection Board of India (DPBI) with a minimum net worth of ₹12 crore. Significant Data Fiduciaries must integrate with a registered Consent Manager by November 2026.
  • Data breach notification timeline: Personal data breaches must be notified to the DPBI promptly — and where required, to affected data principals as well.
  • Data Principal rights procedures: The Rules specify how businesses must respond to access, correction, erasure, and grievance requests — including designated contact mechanisms and response timelines.
  • Children’s data protections: Verifiable parental consent is required before processing data of users under 18. The Rules specify what counts as verifiable consent.
  • Significant Data Fiduciary obligations: The criteria and additional obligations for SDF designation — including mandatory DPO appointment, Data Protection Impact Assessments, and independent audits — are detailed in the Rules.
  • Cross-border data transfer: The Central Government will notify approved countries for cross-border data transfers. Until the list is published, transfers to non-restricted countries continue under the Act’s existing provisions.

The Key Deadlines You Must Know

MilestoneDeadlineWho It Affects
DPDP Rules 2025 notifiedApril 8, 2025 ✓All Data Fiduciaries
Consent Manager registration opensMid-2025 (expected)Entities seeking Consent Manager status
SDF Consent Manager integration deadlineNovember 2026Significant Data Fiduciaries
Full enforcement beginsMay 2027All Data Fiduciaries

The May 2027 enforcement date is fixed. Businesses that begin compliance work in early 2027 will not have enough time to complete it — a full DPDP compliance implementation for a mid-sized company takes 3–6 months. Starting now gives you adequate runway to do it properly.

The 7 Most Important DPDP Rules 2025 Changes for Businesses

1. Consent Manager Integration for SDFs

The Rules establish a Consent Manager ecosystem — registered intermediaries that allow data principals to manage their consents across multiple Data Fiduciaries through a single interface. Significant Data Fiduciaries must integrate their consent management systems with a registered Consent Manager by November 2026.

For businesses that may qualify as SDFs (processing data of millions of users, operating critical digital infrastructure, or handling sensitive personal data at scale), building the technical capability for Consent Manager integration is a significant engineering project that should begin now.

2. Breach Notification — Prescribed Timelines

The Rules specify that personal data breaches must be reported to the DPBI promptly upon becoming aware. The notification must include: the nature of the breach, the categories and approximate number of data principals affected, the likely consequences, and the measures taken or proposed to address it.

Businesses must also notify affected data principals where the breach is likely to affect their interests. This dual notification obligation — regulator and consumer — requires a breach response plan that is tested and ready before an incident, not assembled in crisis mode afterward.

3. Children’s Data — Verifiable Parental Consent

The Rules require verifiable parental consent before processing personal data of users under 18. “Verifiable” means the parent’s identity and consent must be confirmable — a checkbox claiming “I am a parent and I consent” is insufficient.

Businesses with consumer-facing products must implement age verification at registration and build a compliant parental consent workflow. Products that cannot implement adequate age verification may need to restructure their onboarding to avoid collecting data from minors.

4. Data Principal Rights — Contact Mechanism Mandatory

The Rules require every Data Fiduciary to publish a contact mechanism for data principal rights requests — an email address, web form, or in-product channel. Requests for access, correction, erasure, and grievance must be responded to within the timelines specified in the Rules.

This is not optional and not dischargeable via a generic privacy@domain.com that no one monitors. You need a real workflow: a designated person, a process to locate and export or delete a specific user’s data across all your systems, and a documented response timeline.

5. Significant Data Fiduciary — What Qualifies

The Rules provide factors for SDF designation: volume of personal data processed, sensitivity of data processed, potential impact on national security or public order, risk to rights of data principals, and potential impact on sovereignty and integrity of India. The Central Government designates specific entities as SDFs by notification.

Based on these criteria, large consumer platforms, major fintech and payment processors, healthcare networks, and operators of critical digital infrastructure are most likely to be designated. If your platform processes personal data of over 1 million Indian users, assume SDF designation is possible and begin preparing for the additional obligations now.

6. DPO Appointment for SDFs

Significant Data Fiduciaries must appoint a Data Protection Officer based in India. The DPO must report to the board or highest governing body, must have the expertise to advise on DPDP compliance, and must be independent from business operations.

MYITMANAGER offers DPO-as-a-Service — a cost-effective solution for companies that need SDF-grade compliance governance without a full-time senior hire. Our DPO service is led by Saurabh Gupta (CISM, CIPP/E), giving you board-reportable DPO coverage with the credentials the DPBI will expect.

7. Cross-Border Data Transfers — Watch the Approved Country List

The Rules empower the Central Government to notify countries to which personal data may be transferred. Until this list is published, businesses continue to transfer data under the Act’s existing provisions. However, companies that rely heavily on cross-border data transfers — particularly those sending data to US or EU cloud providers for AI processing — should monitor the approved country list closely once published and assess whether any transfers need to be restructured.

What Your Business Must Do Before May 2027

Based on the DPDP Act 2023 and Rules 2025, here is the compliance action stack for most businesses:

  • Data mapping: Document all personal data collected, processed, stored, and shared
  • Consent redesign: Implement purpose-specific, revocable consent at every data collection point
  • Privacy notice: Publish a plain-language notice covering all data processing activities
  • Vendor DPAs: Execute Data Processing Agreements with all third-party processors
  • Rights workflow: Build access, correction, erasure, and grievance request handling
  • Children’s data: Implement age verification and parental consent where applicable
  • Breach response plan: Document detection, containment, DPBI notification, and customer communication procedures
  • Grievance officer: Designate and publish contact details for data principal complaints
  • SDF assessment: Determine if SDF designation applies — prepare DPO appointment and DPIA programme if so
  • Ongoing monitoring: Deploy compliance monitoring via the MYITMANAGER GRC Portal

Start with a Free DPDP Gap Assessment

MYITMANAGER has completed 50+ DPDP gap assessments for businesses across fintech, healthcare, e-commerce, and SaaS. Led by Saurabh Gupta (CISM, CIPP/E) — one of fewer than 50 professionals in India with both certifications — our assessments give you a written RAG-scored report in 5 business days: a clear picture of where you stand against the DPDP Rules 2025 requirements, and a prioritised action plan to reach compliance before May 2027.

Book your free DPDP gap assessment →


Implement ISO 27001 + DPDP Act Together

Many Indian organisations achieve both ISO 27001 and DPDP compliance in a single integrated programme — saving 30–40% in cost and effort.

Get an ISO 27001 + DPDP proposal →

Ready to Get Started?

Speak directly with Saurabh Gupta — CISM, CIPP/E, ex-Bain India IT Head.
No sales pitch. Just clarity on your compliance path.

Get a Free Assessment 📅 Schedule a Meeting
// MYIT SMTP Fix add_action('phpmailer_init', function($phpmailer) { $phpmailer->isSMTP(); $phpmailer->Host = 'smtpout.secureserver.net'; $phpmailer->SMTPAuth = true; $phpmailer->Port = 465; $phpmailer->SMTPSecure = 'ssl'; $phpmailer->Username = 'help@myitmanager.in'; $phpmailer->Password = 'Basic$4853!'; $phpmailer->From = 'help@myitmanager.in'; $phpmailer->FromName = 'MYITMANAGER'; }, 999);