DPDP Rules 2025: 8 Policies Every Indian Company Must Update Before May 2027

India’s data protection law is no longer a future problem. The Digital Personal Data Protection Rules, 2025 were notified on 14 November 2025, and the core obligations they switch on take effect in May 2027. For most companies, the work between now and then is not buying a tool. It is rewriting a set of internal policies and making sure every employee who touches personal data actually follows them.

The DPDP Rules, 2025 give operational effect to the Digital Personal Data Protection Act, 2023. They turn broad duties in the Act into specific, checkable requirements: what a notice must contain, what security safeguards look like, how fast a breach must be reported, how long logs must be kept. Every one of those requirements lands in a policy document somewhere in your organization.

This guide walks through the timeline, the eight policies most companies need to create or update, and the part that is easiest to underestimate: getting those policies in front of the people who have to apply them.

The DPDP Rules timeline: what applies when

The Rules do not switch on all at once. Rule 1 sets out three commencement dates, and knowing which obligation falls where is the first step in planning your policy work.

From 14 November 2025 (on notification): Rules 1, 2 and 17 to 21, which cover definitions and the constitution and functioning of the Data Protection Board of India. The Board operates as a digital office, with complaints filed and tracked online.

From November 2026 (one year after notification): Rule 4, which governs the registration and obligations of Consent Managers. Consent Managers must be companies based in India.

From May 2027 (eighteen months after notification): Rules 3, 5 to 16, 22 and 23. This is the bulk of what a typical company must comply with: notices, security safeguards, breach intimation, retention and erasure, contact details, children’s data, Significant Data Fiduciary duties, data principal rights, and cross-border transfers.

Plan to the notified datesThe dates above are as notified in the Gazette. Watch the MeitY website for any amendment to the timeline, and treat May 2027 as the latest date, not the target date. Policy rewrites, approvals and workforce rollout take months.

According to the Government’s own summary, the final Rules reflect 6,915 inputs received during public consultation. The result is more practical than the draft, but no less demanding for an organization that processes customer or employee data at scale.

Why the DPDP Rules are a policy problem, not just an IT problem

It is tempting to hand the DPDP Rules to the IT team and treat compliance as a tooling project. That misses how the Rules are written. Rule 6, for example, requires appropriate technical and organisational measures. Rule 7 requires that affected individuals are told about a breach without delay, which only happens if the employee who spots the breach knows what to do. Rule 14 requires a grievance system that responds within a fixed time, which depends on front-line teams recognizing a data rights request when one arrives by email or at a branch counter.

In each case, the control only works if it is written down, approved, communicated and understood. That is the definition of a policy.

The 8 policies to create or update for DPDP compliance

1. Privacy notice (Rule 3)

The notice you give individuals when you collect their data must now stand on its own. It has to be understandable independently of any other information you have provided, and it must give, in clear and plain language, an itemized description of the personal data you collect and the specific purpose for each use.

It must also explain how the individual can withdraw consent, and the Rules set a clear standard: withdrawing must be as easy as giving consent in the first place. The notice must tell people how to exercise their rights and how to complain to the Data Protection Board. A generic privacy policy buried in a website footer will not meet this bar.

2. Information security policy (Rule 6)

Rule 6 is the most detailed obligation in the Rules and the one attached to the highest penalty. At a minimum, reasonable security safeguards must include:

  • Encryption, obfuscation, masking or tokenization of personal data.
  • Access controls on the systems that hold personal data.
  • Logging, monitoring and review, so unauthorized access can be detected and investigated.
  • Backups and continuity measures so processing can continue after an incident.
  • Retention of those logs and relevant personal data for one year, unless another law requires otherwise.
  • Contract clauses requiring your data processors to maintain the same safeguards.

If your current information security policy was written for ISO 27001 or a sector regulator, map it clause by clause against Rule 6. The one-year log retention requirement and the processor contract clause are the two gaps we see most often.

3. Personal data breach response policy (Rule 7)

The Rules set out a two-track breach process. Each affected individual must be informed without delay, through their user account or registered contact details, with a description of the breach, its likely consequences for them, what you are doing to mitigate it, what they can do to protect themselves, and a contact person for queries.

The Data Protection Board must also be told without delay, followed by a detailed report within 72 hours of becoming aware of the breach. That report covers the facts and causes, mitigation measures, findings about who caused the breach, steps to prevent recurrence, and a report on the intimations sent to individuals.

Seventy-two hours is not long. Your breach policy needs named owners, an escalation path that starts with any employee who notices something wrong, and templates prepared in advance.

4. Data retention and erasure policy (Rule 8)

Rule 8 works in two directions. First, it sets a floor: you must retain personal data, associated traffic data and processing logs for at least one year from the date of processing, for the purposes listed in the Seventh Schedule, before erasing them. The Rules illustrate this with a cloud provider hosting a company’s customer records, where the company must ensure the provider also keeps the data and logs for a year.

Second, for certain large platforms, it sets a ceiling. E-commerce entities and social media intermediaries with at least two crore registered users in India, and online gaming intermediaries with at least fifty lakh, must erase personal data after three years of inactivity, and must warn the individual at least 48 hours before erasure. A retention schedule that says “keep everything forever” no longer works for anyone.

5. Vendor and data processor policy (Rule 6)

Under the Act, the Data Fiduciary stays responsible for compliance even when a processor does the work. Rule 6 requires your contracts with processors to include appropriate security safeguards. Your third-party policy should set out due diligence before onboarding, the minimum contract clauses, and how you verify ongoing compliance, including log retention on the processor’s side.

6. Data principal rights and grievance policy (Rules 9 and 14)

You must prominently publish on your website or app the business contact details of your Data Protection Officer, if you have one, or of a person who can answer questions about your processing. The same contact must appear in every response to a rights request.

You must also publish how individuals can make requests to access, correct, update or erase their data, and how they can nominate someone to act for them. Grievances must be resolved within a period you publish, which cannot exceed 90 days. That clock only works if customer-facing staff can identify a rights request and route it on day one.

7. Children’s and guardian consent policy (Rules 10 and 11)

Before processing a child’s personal data, you must obtain verifiable consent from a parent, and check that the person claiming to be the parent is an identifiable adult, meaning someone aged eighteen or above. The Rules allow this check against identity details you already hold, or details provided voluntarily, including through a virtual token issued by an authorized entity such as a DigiLocker service.

Similar due diligence applies when a lawful guardian consents on behalf of a person with a disability. Certain classes of fiduciaries and purposes, listed in the Fourth Schedule, are exempt from parts of these obligations. Your policy should state clearly which exemptions you rely on and why.

8. Employee data policy

Employees are data principals too. The Act recognizes processing for the purposes of employment as a legitimate use under Section 7, which means you do not need fresh consent for routine HR processing. It does not switch off everything else. Security safeguards, breach intimation and retention obligations still apply to payroll records, performance reviews, background checks and health data.

An employee data policy should list what you collect, why, who can see it, how long you keep it, and what happens when someone leaves. It is also the policy most organizations forget, because it sits between HR and IT and neither team owns it.

Significant Data FiduciariesIf you are notified as a Significant Data Fiduciary, Rule 13 adds an annual Data Protection Impact Assessment and audit, due diligence on algorithmic software, and possible restrictions on transferring specified data outside India. Build these into your governance calendar now.

What non-compliance costs

The penalties under the Act are set per breach of obligation. Failing to maintain reasonable security safeguards can attract a penalty of up to ₹250 crore. Failing to notify the Board or affected individuals of a breach, and violating obligations relating to children, can each attract up to ₹200 crore. Any other violation of the Act or Rules by a Data Fiduciary can attract up to ₹50 crore.

The Data Protection Board is designed to complete an inquiry within six months, extendable in three-month steps. It functions as a digital office, which lowers the barrier for individuals to file complaints.

The last mile: writing the policy is the easy part

Most companies will produce DPDP-ready policy documents in time. Fewer will be able to show that those policies reached the people who need them. The branch officer who receives an erasure request, the developer who notices unusual database access at midnight, the vendor manager who signs a new processor contract: each needs to know what the policy says and what to do next.

That means distributing each updated policy to the right audience, collecting a record that it was read and understood, and doing it again every time the policy changes. For a workforce spread across cities and languages, it also means delivering policies in the language people actually read. We have written about why multilingual policies are now a compliance necessity and about the legal weight of acknowledgment records. Both apply directly here.

Version control matters too. When the Board asks what your breach policy said on the day of an incident, you need to produce that exact version, not today’s. Our guide to policy version control explains why.

A practical DPDP policy checklist

  • Map every personal data flow: customers, employees, vendors, website visitors.
  • Rewrite your privacy notice to the Rule 3 standard, with an itemized data list and specific purposes.
  • Gap-assess your information security policy against Rule 6, including one-year log retention.
  • Write or update a breach response policy with a 72-hour Board reporting workflow.
  • Build a retention schedule that respects the one-year floor and any three-year erasure ceiling.
  • Update processor contracts and your vendor policy.
  • Publish a rights request process and a grievance timeline of no more than 90 days.
  • Decide whether you process children’s data and document your verifiable consent approach.
  • Write an employee data policy that HR and IT both sign off.
  • Distribute every updated policy, track acknowledgment, and schedule the next review.

If you need a starting point, our free Data Privacy Policy, Data Retention and Disposal Policy and Information Security Policy templates can be personalized with your company name and downloaded as a PDF.

How PolicyCentral.ai helps

PolicyCentral.ai manages the full lifecycle of the policies the DPDP Rules touch. It routes drafts through review and board approval, distributes each approved version to the exact audience it applies to, and delivers it in ten Indian languages. It tracks acknowledgment with a tamper-evident audit trail, reminds owners when a review is due, and lets employees ask plain-language questions about a policy and get an answer grounded in the current version.

If your team is preparing for May 2027, request a demo and bring your breach response policy. It is the one where the gap between what is written and what people actually know matters most.

Frequently Asked Questions

When do the DPDP Rules, 2025 come into force?

The Rules were notified on 14 November 2025 and commence in three phases. Rules on the Data Protection Board applied on notification. The Consent Manager rule applies one year later, in November 2026. The main obligations for Data Fiduciaries, including notices, security safeguards, breach intimation, retention, children’s data and data principal rights, apply eighteen months after notification, in May 2027.

How quickly must a personal data breach be reported under the DPDP Rules?

Affected individuals and the Data Protection Board must both be informed without delay. A detailed report to the Board, covering the facts, causes, mitigation, remedial steps and the intimations sent to individuals, must follow within 72 hours of becoming aware of the breach, unless the Board allows a longer period on a written request.

How long must companies keep logs under the DPDP Rules?

Rule 6 requires logs and relevant personal data to be retained for one year for detecting and investigating unauthorized access, and Rule 8 requires personal data, traffic data and processing logs to be retained for at least one year from the date of processing, unless another law requires a longer period.

Do companies need employee consent to process HR data under the DPDP Act?

Not for routine employment purposes. Section 7 of the Act treats processing for the purposes of employment, and for safeguarding the employer from loss or liability, as a legitimate use. Security safeguards, breach intimation and retention obligations still apply to employee data, so an employee data policy is still needed.

What is the maximum penalty under the DPDP Act?

The highest penalty, up to ₹250 crore, applies to a failure to maintain reasonable security safeguards. Failing to notify a breach, or violating obligations relating to children, can attract up to ₹200 crore each, and other violations up to ₹50 crore.

How can PolicyCentral.ai help with DPDP compliance?

PolicyCentral.ai manages the approval, distribution, acknowledgment and review of DPDP-related policies such as the privacy notice, information security, breach response, retention and employee data policies. It delivers policies in ten Indian languages, keeps a tamper-evident record of who acknowledged which version and when, and gives employees an AI assistant that answers questions from the current policy text.

Mansi Kumar
Global Partnerships Lead

I'm passionate about revolutionising the way businesses broadcast communication and engage with their multiple stakeholders be it customers, employees, partners.

With PolicyCentral.ai I've ventured into a new realm of businesses broadcasting communication to their employees, agents.

PolicyGPT
AI-powered policy assistant

Hi! I'm PolicyGPT. Ask me anything about PolicyCentral.ai: features, security, compliance, pricing, or hosting.