DPDP Rules 2025: What Changed, What It Means, and Your 6-Month Compliance Checklist

OB
OpenBlockAI
Author
DPDP Rules 2025: What Changed, What It Means, and Your 6-Month Compliance Checklist

The DPDP Rules 2025 operationalise the Digital Personal Data Protection Act with specific requirements for consent managers, data localisation, and Significant Data Fiduciary classification — here is what changed and what to do.

What the DPDP Rules 2025 Add to the Act

The Digital Personal Data Protection Act 2023 is the framework. The DPDP Rules 2025, notified by the Ministry of Electronics and Information Technology, are the operational specification. The Act told you what obligations exist; the Rules tell you how to discharge them.

The Rules address several areas where the Act was deliberately silent — leaving the specifics to delegated legislation. The most consequential additions are:

  • The consent manager framework, including registration and operational requirements for this new regulated intermediary
  • The Significant Data Fiduciary classification process and the specific obligations that apply once classified
  • Data localisation requirements — which categories of data must be stored within Indian territory
  • The approved countries list for cross-border data transfers
  • Breach notification timelines and content requirements
  • The Data Protection Board's procedural rules for adjudication

Understanding the Rules is not optional for compliance — you cannot build a compliant programme from the Act alone. The Rules are where the enforceable specifics live.

Consent Manager Rules: A New Regulated Intermediary

One of DPDPA's most distinctive innovations is the Consent Manager — a regulated entity that can collect, manage, and facilitate withdrawal of consents on behalf of Data Principals, interoperable across multiple Data Fiduciaries. Think of it as a centralised consent wallet: a Data Principal registers with a Consent Manager, and all their consents across participating Fiduciaries flow through and are accessible from that single interface.

The Rules establish the registration requirements for Consent Managers (they must be registered with the Data Protection Board), the technical interoperability standards they must meet, and the obligations they owe to Data Principals. They cannot act as Data Processors themselves — their role is pure consent facilitation.

For Data Fiduciaries, the Consent Manager framework creates both an opportunity and an obligation. If a Data Principal exercises their rights via a Consent Manager, the Fiduciary must honour those rights as if the request came directly. This means your consent management infrastructure must be capable of receiving and processing API-based consent signals from registered Consent Managers — not just from your own application interfaces.

Significant Data Fiduciary Classification Criteria

The Rules specify the criteria the government uses to notify an organisation as a Significant Data Fiduciary. While the exact thresholds can be updated by notification, the classification framework looks at:

  • Volume of personal data processed: Organisations processing very large volumes of personal data — particularly sensitive personal data — are more likely to be classified as SDFs
  • Sensitivity of personal data: Processing financial data, health data, or data of children increases the risk profile
  • National security and public order implications: Organisations whose data processing has implications for national security are priority candidates
  • Risk of harm to Data Principals: If a breach or misuse of the data would cause significant harm to individuals, the risk profile is elevated
  • Impact on sovereignty and integrity of India: Cross-border data flows at scale increase SDF candidacy

If you are a large consumer internet platform, a major fintech, a healthcare network, or a telecom operator — you should be planning for SDF classification rather than hoping to avoid it. The DPO appointment, independent audit, and periodic DPIA requirements need to be in your compliance roadmap.

Data Localisation: Which Data Must Stay in India

The Rules introduce data localisation requirements for specific categories of personal data — mandating that certain data be stored and processed within Indian territory and not transferred outside India except to approved countries.

The categories subject to localisation requirements include sensitive personal data and data notified as subject to localisation for national security or sovereignty reasons. The government maintains the approved countries list — countries with adequate data protection frameworks where cross-border transfers are permitted — and updates it by notification.

Practical implications for multi-cloud organisations:

  • Review your cloud infrastructure — if Indian personal data is stored in AWS regions outside India, Azure regions, or GCP regions outside India, assess which data categories are affected
  • Ensure your data architecture can segregate localisation-required data from data that can be stored globally
  • Check your SaaS vendor contracts — if a vendor is processing Indian personal data on your behalf and storing it outside India, you may need contractual amendments or vendor changes
  • Document your localisation compliance — the Data Protection Board can request evidence that localisation requirements are being met

The Data Protection Board: Powers, Process, and Enforcement Timeline

The Rules establish the procedural framework for the Data Protection Board — the adjudicatory body that will hear complaints, investigate breaches, and impose penalties under DPDPA. Key procedural points:

The Board operates as a digital-first body. Complaints are filed electronically, proceedings are conducted online where possible, and the Board has the power to call for documents, take evidence, and conduct searches and seizures in relation to alleged violations.

Enforcement process:

  • A Data Principal who is unsatisfied with a Fiduciary's grievance response can file a complaint with the Board
  • The Board can also act on its own motion based on media reports or referrals from government agencies
  • On receiving a complaint, the Board sends a notice to the Data Fiduciary with a defined response period
  • The Board can impose penalties and issue directions — including directions to change processing practices, not just financial penalties

The key takeaway: enforcement is not solely initiated by the regulator. Every Data Principal is a potential complainant. A poorly handled grievance or an unanswered rights request is a direct pathway to Board proceedings.

Your 6-Month DPDPA Compliance Action Plan

With the Rules in force, here is a realistic 6-month action plan for organisations that are not yet fully compliant:

Month 1 — Audit and Gap Analysis: Map all personal data flows; identify processing purposes; document which legal basis applies to each; assess whether existing consent notices meet the mandatory elements checklist; identify all Data Processors and review DPAs for DPDPA compliance.

Month 2 — Consent Infrastructure: Remediate notice defects; implement purpose-specific consent collection; build withdrawal propagation to downstream processors; deploy the grievance mechanism with 30-day SLA tracking.

Month 3 — Rights Fulfilment: Build or configure the access request fulfilment workflow; implement correction and erasure propagation; deploy the nomination capture mechanism; establish the 30-day grievance response SLA.

Month 4 — Processor Accountability: Update vendor DPAs for DPDPA requirements; build the processor registry; implement audit rights into key vendor agreements; address sub-processor disclosure gaps.

Month 5 — Breach Response: Update the incident response plan with the 72-hour notification requirement; build the DPB notification workflow; prepare individual notification templates; run a tabletop exercise.

Month 6 — SDF Preparation and Documentation: Assess SDF classification likelihood; if applicable, begin DPO recruitment; document compliance posture for potential Board inquiry; establish ongoing compliance monitoring cadence.

Consentica by OpenBlockAI covers Months 2 and 3 of this plan as a turnkey deployment — purpose-specific consent collection, notice management, withdrawal propagation, rights fulfilment workflows, and 30-day grievance SLA tracking, deployable in days rather than months.

Run your DPDPA readiness assessment →

Frequently Asked Questions

They operationalise the Act with specific requirements around consent managers, data localisation, and how organisations get classified as Significant Data Fiduciaries.

3 months FREE.
Zero integration. Unlimited Consents. Live within 48 hours.

Start implementing DPDP-ready consent without long contracts, technical effort, or surprise billing. Launch fast, validate your consent flow, and scale when you’re ready.

What happens next:

1

A privacy specialist reaches out to understand your use case

2

We map your consent flow across app, web, offline and vendor access

3

We set up your consent workflow with zero integration required

4

Your consent system can go live within 48 hours