Complied AIComplied AIBack to law libraryReading nowDigital Personal Data Protection Rules, 20251 chapter · 30 rules · 7 schedules
Divisions8
    • ¶Chapter 1 overview
    • 1Short title and commencement
    • 2Definitions
    • 3Notice given by Data Fiduciary to Data Principal
    • 4Registration and obligations of Consent Manager
    • 5Processing of personal data for provision or issue of subsidy, benefit, service, certificate, licence or permit by State and its instrumentalities
    • 6Reasonable security safeguards
    • 7Intimation of personal data breach
    • 8Time period for specified purpose to be deemed as no longer being served
    • 9Contact information of person to answer questions about processing
    • 10Verifiable consent for processing of personal data of child
    • 11Verifiable consent for processing of personal data of person with disability who has lawful guardian
    • 12Exemptions from certain obligations applicable to processing of personal data of child
    • 13Additional obligations of Significant Data Fiduciary
    • 14Rights of Data Principals
    • 15Transfer of personal data outside the territory of India
    • 16Exemption from Act for research, archiving or statistical purposes
    • 17Appointment of Chairperson and other Members
    • 18Salary, allowances and other terms and conditions of service of Chairperson and other Members
    • 19Procedure for meetings of Board and authentication of its orders, directions and instruments
    • 20Functioning of Board as digital office
    • 21Terms and conditions of appointment and service of officers and employees of Board
    • 22Appeal to Appellate Tribunal
    • 23Calling for information from Data Fiduciary or intermediary
Reading nowDigital Personal Data Protection RulesAct contents
Law libraryUpdates

Search this Act

Jump directly to a section by number or title.

  1. Chapter 1

Chapter 1

Digital Personal Data Protection Rules, 2025

23 rules (1–23)

  • 1Short title and commencement
  • 2Definitions
  • 3Notice given by Data Fiduciary to Data Principal
  • 4Registration and obligations of Consent Manager
  • 5Processing of personal data for provision or issue of subsidy, benefit, service, certificate, licence or permit by State and its instrumentalities
  • 6Reasonable security safeguards
  • 7Intimation of personal data breach
  • 8Time period for specified purpose to be deemed as no longer being served
  • 9Contact information of person to answer questions about processing
  • 10Verifiable consent for processing of personal data of child
  • 11Verifiable consent for processing of personal data of person with disability who has lawful guardian
  • 12Exemptions from certain obligations applicable to processing of personal data of child
  • 13Additional obligations of Significant Data Fiduciary
  • 14Rights of Data Principals
  • 15Transfer of personal data outside the territory of India
  • 16Exemption from Act for research, archiving or statistical purposes
  • 17Appointment of Chairperson and other Members
  • 18Salary, allowances and other terms and conditions of service of Chairperson and other Members
  • 19Procedure for meetings of Board and authentication of its orders, directions and instruments
  • 20Functioning of Board as digital office
  • 21Terms and conditions of appointment and service of officers and employees of Board
  • 22Appeal to Appellate Tribunal
  • 23Calling for information from Data Fiduciary or intermediary
Start of act
ScheduleConditions For Registration and Obligations of Consent Manager