Search this Act
Jump directly to a section by number or title.
Chapter 1
Digital Personal Data Protection Rules, 2025
23 rules (1–23)
- 1Short title and commencement
- 2Definitions
- 3Notice given by Data Fiduciary to Data Principal
- 4Registration and obligations of Consent Manager
- 5Processing of personal data for provision or issue of subsidy, benefit, service, certificate, licence or permit by State and its instrumentalities
- 6Reasonable security safeguards
- 7Intimation of personal data breach
- 8Time period for specified purpose to be deemed as no longer being served
- 9Contact information of person to answer questions about processing
- 10Verifiable consent for processing of personal data of child
- 11Verifiable consent for processing of personal data of person with disability who has lawful guardian
- 12Exemptions from certain obligations applicable to processing of personal data of child
- 13Additional obligations of Significant Data Fiduciary
- 14Rights of Data Principals
- 15Transfer of personal data outside the territory of India
- 16Exemption from Act for research, archiving or statistical purposes
- 17Appointment of Chairperson and other Members
- 18Salary, allowances and other terms and conditions of service of Chairperson and other Members
- 19Procedure for meetings of Board and authentication of its orders, directions and instruments
- 20Functioning of Board as digital office
- 21Terms and conditions of appointment and service of officers and employees of Board
- 22Appeal to Appellate Tribunal
- 23Calling for information from Data Fiduciary or intermediary