Frequently Asked
Questions

DPDP Rules & DPDP Implementation

The DPDP Rules 2025 represent a significant milestone in India's data protection landscape, designed to create a robust framework that prioritizes both individual privacy rights and organizational responsibilities. These rules aim to establish a balanced approach where transparency and accountability are paramount in handling practices. While entities can use data for legitimate purposes, they must do so within clear guidelines that protect individual privacy rights. The rules demonstrate India's commitment to modernizing its data protection regime and aligning with global privacy standards.

The Rules emphasize the importance of transparent privacy policies that clearly communicate an organization’s data handling practices to individuals. Organizations must maintain detailed privacy policies that explain how personal data is collected, processed, and protected. These policies must be easily accessible and written in clear language that helps individuals understand their privacy rights and how their data is being used. The Rules require regular updates to privacy policies to reflect any changes in data processing practices or regulatory requirements.

The final DPDP rules introduced several clarifications and operational changes compared to the draft, across notice requirements, security, data retention, breach reporting, and child data handling:

  • Notice Requirements (Rule 3): The draft required an itemized list of collected data and goods/services. The final rules relax this, mandating only a specific description of goods/services. While slightly easier, organisations must still ensure clarity in notices.
  • Security Safeguards (Rule 6): Draft rules prescribed baseline measures with “should include” language. Final rules adopt a flexible, risk-based approach with “such as” and “where applicable,” requiring organisations to exercise judgement in implementing safeguards.
  • Data Retention (Rule 8(3)): Draft rules had no specific retention for government-authorized purposes. Final rules mandate retaining certain data for 1 year as per the Seventh Schedule, while keeping storage limitation principles for inactive data. Organisations must align retention practices with sectoral and cyber regulations.
  • Child Data & Data Principal Rights (Rules 10 & 14(3)):
    • Child Data (Rule 10): Final rules require verification that the parent is an identifiable adult, with the child declaring the person as their parent, making parent-verification workflows mandatory.
    • Grievance Redressal (Rule 14(3)): Final rules introduce a 90-day cap for resolving grievances, providing operational clarity.

Overall, the final rules require organisations to exercise judgement in security, implement reliable verification and retention mechanisms, simplify reporting, and ensure clear documentation. The changes ease some compliance burdens but demand stronger internal governance and clarity across processes.

  • First 30 Days: Build Visibility and Purpose Clarity Begin by identifying personal data elements across the organisation. Work closely with business units to understand what data exists, where it resides, who accesses it, and how it is used. This information must be consolidated to create a clear, enterprise-level view of privacy and data risk. In parallel, map end-to-end data flows and clearly define the purpose behind every collection and processing activity. The DPDP Act is purpose-driven; when purposes are well defined and consistently applied, both legal interpretation and technical implementation become far more manageable. This phase should also include mapping the extended business ecosystem, vendors, partners, group entities, and processors involved in handling personal data.
  • Next 30 Days: Operationalise Policies and Governance Translate visibility into action by formalising policies and governance structures. Establish a cross-functional privacy committee to guide decisions and steer the compliance roadmap. Documentation becomes critical at this stage, including Records of Processing Activities (ROPA), data flow traces, and detailed processing inventories. These artefacts help visualise how data moves, highlight compliance gaps, and surface risk. Internal awareness and training should begin alongside this work, ensuring teams understand how everyday data practices connect to obligations under the DPDP Act.
  • Final 30 Days: Enable Technology and Execution Consolidate insights from the earlier phases into a single, actionable view. Evaluate technology partners and define how to operationalise a techno-legal approach to compliance. A clear roadmap should be defined for consent management, log retention (significantly stricter under the DPDP Act), rights management, and integrations across internal and third-party systems.

By the end of 90 days, organisations should have clarity on governance models, technology architecture, and integration priorities, allowing them to move from documentation to sustained, operational compliance.

Significant data fiduciaries face a more comprehensive set of obligations under the Rules. They must conduct regular Data Protection Impact Assessments to identify and mitigate privacy risks, undergo annual audits, keep detailed compliance documentation, and maintain high standards of algorithmic fairness in their data processing activities. Additionally, they must update and publish privacy policies whenever changes occur. These enhanced responsibilities reflect their larger role in data processing and the potential impact of their activities on data principals’ privacy rights.

Consent Management

Under the DPDP Act, a Consent Manager is a registered third-party entity that enables data principals to give, review, manage, or withdraw consent through a transparent and interoperable platform. Registered with the Data Protection Board, Consent Managers operate independently as data fiduciaries and provide consent status to organisations before personal data is processed.

Within an organisation, a Consent Management System (CMS) handles consent end to end across internal workflows. It records consent, links it to specific purposes, and ensures that downstream processing stops automatically if consent is denied or withdrawn.

In simple terms, the Consent Manager provides the consent signal, while the organisation’s CMS operationalises that consent across its systems. Much like CKYC allows institutions to rely on a shared KYC record, Consent Managers let individuals manage consent centrally, while businesses enforce it internally.

The Rules place particular emphasis on protecting children’s data through enhanced safeguards and stringent requirements. At the core of these protections is the mandatory requirement for verifiable parental consent before processing any child’s personal data. This reflects an understanding of the heightened risks children face and places additional responsibility on organizations to protect their privacy rights. The framework recognizes that children require additional safeguards and places the onus on organizations to implement appropriate measures to very strictly protect children’s data.

Breach Management

Under the DPDP Rules, organizations face strict requirements for breach reporting, with a mandatory 72-hour window to notify the Data Protection Board of India about such incidents. This timeframe ensures rapid response to potential privacy violations and requires organizations to provide comprehensive reports detailing the nature of the breach, its impact, and the measures taken to contain its effects. This heightened vigilance is designed to protect data principals by enabling swift action and mitigation of potential damages from data breaches.

Third-party Risk Management

Third-party risk management under the Rules requires a comprehensive approach that combines contractual obligations with practical oversight. Organizations must ensure that their third-party partners implement appropriate technical and organizational measures through detailed contractual requirements. This includes establishing strong governance practices, regularly monitoring compliance, and maintaining documentation of third-party data processing. Organizations must also conduct regular assessments of their third-party partners to ensure ongoing compliance with data protection requirements and maintain the security of personal data throughout the data processing chain.

Consent Manager

A consent manager is a professional officially recognized by the Board who serves as the primary point of contact for data principals (individuals whose data is being handled). Their main function is to provide a platform where individuals can grant, oversee, modify, and revoke their consent for data usage through a system that prioritizes accessibility and transparency.

Consent managers assist individuals by providing them with an efficient platform to manage their data privacy preferences. They offer a user-friendly interface where people can easily grant, monitor, adjust, or withdraw their consent for data usage. Think of them as privacy advocates who help individuals maintain control over their personal information.

Consent managers assist organizations (data fiduciaries) by streamlining their compliance with data protection regulations. They function similarly to how banks manage money - but instead of handling finances, they protect consent. Through their technological platforms, consent managers help organizations maintain proper consent records, process consent changes, and handle consent-related inquiries. This makes it easier for organizations to maintain compliance while respecting individual privacy rights.