The Act sets obligations at the level of principle. The Rules tell you what compliance actually looks like — how long you keep logs, how much notice you give before erasing, what a breach report contains, what a Consent Manager must be worth.
If you are building systems rather than writing policy, the Rules are where your requirements come from.
Notification and correction. The Rules were published as G.S.R. 846(E), dated 13 November 2025, in the Gazette of India Extraordinary, Part II, Section 3, Sub-section (i). Corrigenda were issued by G.S.R. 892(E) dated 10 December 2025, correcting a set of typographical and cross-reference errors. Any reading of the Rules should account for the corrigenda.
The Rules follow the same phased structure as the Act.
| Date | Rules in force |
|---|---|
| 13 November 2025 | Rules 1, 2, and 17–21 — title, definitions, Board procedure, techno-legal measures and appeals |
| 13 November 2026 | Rule 4 — registration of Consent Managers |
| 13 May 2027 | Rules 3, 5–16, 22 and 23 — notice, safeguards, breach intimation, erasure, children's consent, SDF obligations, rights procedure |
Not all 23 rules carry equal engineering weight. These are the ones that do.
Notice must be presented independently of any other information, in clear and plain language, and must give a fair account of what is necessary to enable informed consent. It requires an itemised description of the personal data, the specified purpose with an itemised description of the goods, services or uses enabled, and the communication link for the Data Principal to withdraw consent, exercise rights and make a complaint to the Board.
"Independently of any other information" is the operative constraint. A notice folded into terms and conditions does not satisfy this.
This is the most operationally demanding rule in the instrument, and it works in three layers.
Rule 8(1) — a Data Fiduciary of a class specified in the Third Schedule, processing for the corresponding purposes, must erase personal data after the specified time period if the Data Principal neither approaches it for the specified purpose nor exercises her rights — unless retention is necessary for compliance with any law.
Rule 8(2) — at least forty-eight hours before that period completes, the Fiduciary must inform the Data Principal that the data will be erased, unless she logs in or otherwise initiates contact or exercises her rights.
Rule 8(3) — separately and without prejudice to the above, a Fiduciary must retain personal data, associated traffic data and other processing logs for a minimum of one year from the date of processing, for the purposes in the Seventh Schedule, before erasing — unless a longer period is required by other law.
Read those together and the picture is not "delete on request." It is a floor and a ceiling operating at once. The Rules include illustrations making it explicit: an e-book platform must retain order, payment and delivery records for at least a year even if the customer deletes her account, and a company using a cloud provider must ensure the provider also retains data and logs for the minimum period. → Retention and Erasure
Every Data Fiduciary must prominently publish on its website or app, and mention in every response to a communication exercising Data Principal rights, the business contact information of its Data Protection Officer if applicable, or of a person able to answer questions about processing on its behalf.
The second limb is a template requirement in your outbound correspondence, not a website task. It is easy to satisfy the first and fail the second for years.
Before processing a child's personal data, a Data Fiduciary must observe due diligence to verify that the individual identifying herself as the parent is an identifiable adult, using reliable identity and age details already available with the Fiduciary, or details or a virtual token voluntarily provided and mapped by an entitled authority or a permitted Consent Manager.
For education and consumer platforms, this is the single hardest control to build, because age assurance and identity verification interact with the very data minimisation the Act requires.
Rule 12, with the Fourth Schedule, disapplies s. 9(1) and s. 9(3) for specified classes, subject to purpose conditions. Part A begins with clinical establishments, mental health establishments, healthcare professionals and allied healthcare professionals, in each case restricted to the provision of health services or supporting a treatment and referral plan to the extent necessary for the child's health.
The policy logic is sound and worth stating: parental consent must not become a gate that delays a child's medical treatment.
The Central Government may, for purposes specified in the Seventh Schedule and acting through the corresponding authorised person, require a Data Fiduciary or intermediary to furnish information within a specified period. Where disclosure would prejudicially affect the sovereignty and integrity of India or the security of the State, the Fiduciary may be required not to disclose the request to the affected Data Principal or anyone else without prior written permission.
| Schedule | Referenced by | What it sets out |
|---|---|---|
| First | Rule 4 | Conditions for registration of a Consent Manager, and its obligations. Includes Indian incorporation, net worth of not less than ₹2 crore, and independent certification of the interoperable platform |
| Second | Rule 5 | Standards for State processing for a subsidy, benefit, service, certificate, licence or permit |
| Third | Rule 8(1) | Classes of Data Fiduciary with time-bound erasure duties, and the corresponding purposes and periods |
| Fourth | Rule 12 | Classes for whom s. 9(1) and s. 9(3) do not apply, with conditions |
| Fifth | — | Board-related provisions |
| Sixth | Rule 21(2) | Terms and conditions of appointment and service of Board officers and employees |
| Seventh | Rules 8(3), 23 | Purposes for which the minimum retention applies, and for which the Government may call for information, with the authorised persons |
| Class of Data Fiduciary | Threshold | Period |
|---|---|---|
| E-commerce entity | Not less than two crore registered users in India | Three years from the Data Principal's last approach for the specified purpose or exercise of rights, or the commencement of the Rules, whichever is later |
| Online gaming intermediary | Not less than fifty lakh registered users in India | Same |
| Social media intermediary | Not less than two crore registered users in India | Same |
In each case the erasure duty covers all purposes except enabling the Data Principal to access her user account, and enabling her to access a virtual token issued by or on behalf of the Fiduciary that is stored on its platform and may be used to obtain money, goods or services.
The Schedule's note defines "e-commerce entity" by reference to the Consumer Protection Act, 2019, and excludes a seller offering goods or services on a marketplace e-commerce entity. That exclusion materially changes who is in scope. → Retention and Erasure
On 13 November 2025, by G.S.R. 846(E), published in the Gazette of India Extraordinary. Corrigenda were issued by G.S.R. 892(E) on 10 December 2025.
Twenty-three rules and seven Schedules.
Three things: time-bound erasure for Third Schedule classes after a period of Data Principal inactivity; at least forty-eight hours' advance notice to the individual before that erasure; and a separate minimum one-year retention of personal data, traffic data and processing logs for Seventh Schedule purposes.
Third Schedule classes: e-commerce entities and social media intermediaries with not less than two crore registered users in India, and online gaming intermediaries with not less than fifty lakh — subject to the account-access and virtual-token carve-outs.
The obligations are framed on the Data Fiduciary, but several reach through to processors. Rule 8(3) requires retention in respect of processing undertaken by a Processor on the Fiduciary's behalf, and the Rules illustrate this with a cloud service provider.
Not yet. Rule 4, governing Consent Manager registration, commences on 13 November 2026.
Consiva.ai maps every obligation above to a workflow, dashboard, or automated job — so your team focuses on decisions, not tracking.
Start Free — No Credit Card →Verified against the Gazette of India on 17 August 2026. Sources: Digital Personal Data Protection Rules, 2025, G.S.R. 846(E) dated 13 November 2025, as corrected by G.S.R. 892(E) dated 10 December 2025; Rules 3, 4, 8, 9, 10, 12, 23 and First to Seventh Schedules. Reference material about the law, not legal advice — see /disclaimer.