India explainer

The DPDP Rules: What Changes Now That India's Data Law Has Teeth

A law without rules is a statement of intent. With the operating rules notified, India's data-protection regime becomes something companies must actually do — which is when you find out what it really protects, and from whom.

The DPDP Rules are where India’s data protection law stops being an idea and starts being a set of instructions someone in a compliance team has to follow on a Tuesday morning. The Digital Personal Data Protection Act gave us the architecture — data principals, data fiduciaries, consent, penalties. The Rules, notified in November 2025 and phasing in across roughly eighteen months, supply the operating detail: how consent must be worded and logged, who may run a consent-management platform, what a breach report must contain and how fast it must be filed, when data has to be deleted. That detail is the difference between a right you can name and a right you can use. It is also where the exemptions live.

The Act set the frame; the Rules make it run

I’ve written separately about India’s data protection Act — what it says, who it covers, and where its drafting is weakest. So I won’t re-litigate the statute here. One line will do: the Act established that organisations holding your personal data are fiduciaries, that they generally need your consent, that you have rights against them, and that a Data Protection Board can fine them heavily for failures. What it did not do was explain how any of that works in practice. Almost every operative question — what a valid notice looks like, how a breach gets reported, how long a company may keep data it no longer needs — was left to subordinate legislation.

That subordinate legislation is now here. And it is worth saying plainly: on the compliance mechanics, the Rules are more serious than many expected. This is not a token framework. It imposes real cost, real record-keeping and real deadlines on Indian businesses, and it gives individuals procedures they can actually invoke. The problem is not that the Rules are toothless. The problem is who the teeth are pointed at.

The clock: what applies when

Compliance arrives in stages rather than all at once, which is unusual for Indian tech regulation and, on balance, sensible. As reported, the structure runs roughly like this:

  • Immediately on notification (November 2025). The machinery provisions — definitions, and the constitution of the Data Protection Board of India itself. The referee had to exist before the game could start.
  • At about twelve months (November 2026). The consent-manager framework goes live, meaning entities can register with the Board to operate as consent intermediaries. As I write this in September 2026, that date is weeks away.
  • At about eighteen months (May 2027). The substantive obligations most people care about — notice and consent in their full form, breach reporting, retention and erasure duties, the machinery for exercising rights, the extra burdens on large platforms.

So the honest status today is: the law exists, the Board exists, the deadline is visible, and most organisations are somewhere between a gap analysis and a panic. The reported ceiling on penalties — up to ₹250 crore for the most serious failures, particularly security breaches — is high enough that the panic is rational.

Consent you can prove

The single biggest practical shift is that consent becomes an auditable artefact rather than a vibe. Under the Rules, the notice presented to a person must stand on its own — plain language, an itemised description of what data is being collected, the specific purposes it will be used for, and a clear route to withdraw consent and to complain. It cannot be buried in a forty-page terms document, and it cannot bundle unrelated purposes into one tick box.

More importantly, a company has to be able to show, later, what it asked and what you agreed to. That means versioned notices, timestamped consent records, and a withdrawal mechanism that is as easy to use as the agreement mechanism was. Anyone who has tried to unsubscribe from an Indian service will recognise how far that is from current practice.

The consent manager: a new kind of middleman

The most genuinely novel invention in the Rules is the consent manager — a registered intermediary that sits between you and the companies holding your data, giving you one dashboard to grant, review and withdraw consents across services. In principle it is a fine idea and the closest thing in Indian law to a practical answer to consent fatigue.

The Rules set a real bar for who may be one. As reported, a consent manager must be an Indian-incorporated company meeting a minimum net worth threshold of ₹2 crore, must register with the Board, must operate neutrally without favouring particular fiduciaries, must not monetise the consent data flowing through it, and must retain consent audit logs for years. It also cannot wear two hats and act as a fiduciary for the same person whose consents it manages.

I like the design and I’m sceptical of the outcome, for one reason: a capital threshold and a registration regime mean consent managers will be companies, funded by someone, needing revenue from somewhere. Neutrality is easy to write into a rule and hard to sustain in a business model. Whether these become genuine user agents or a compliance utility sold to enterprises is the thing to watch after the framework opens.

Consent stops being a vibe and becomes an artefact — versioned, timestamped, provable. That is real progress. It also means the strongest new rights in Indian data law run against companies, and the weakest run against the state.

Breaches: what must be told, and how fast

Breach notification is the provision with the sharpest edge, because it converts a private embarrassment into a public obligation. The reported structure is two-tier. Affected individuals must be told without delay, in a communication that describes the nature and extent of the breach, the likely consequences for them, what the company is doing about it, and what they should do to protect themselves. The Board must receive an initial intimation quickly and a fuller report — facts, circumstances, mitigation, remedial measures, findings about who caused it — within 72 hours of the company becoming aware, with extensions at the Board’s discretion.

Seventy-two hours is not a technical detail. It forces detection capability, an escalation chain and a pre-written playbook, because no organisation drafts a defensible breach report from scratch in three days. It also ends the Indian norm of discovering your data was leaked months later from a journalist rather than from the company that lost it.

Data that expires

The Rules also give personal data something it has never really had in India: an expiry date. The general principle is that data must be erased once the purpose it was collected for has been served, or once consent is withdrawn. On top of that, specified large platforms — as reported, e-commerce and social media services above a two-crore user threshold and online gaming services above fifty lakh — must delete a user’s data after three years of inactivity, measured from the last login or transaction, unless the user comes back or the law requires retention. And the company must warn you, reportedly at least 48 hours in advance, so you can log in and stop the clock if you want to.

This is a quietly significant change. Indefinite retention is the default posture of almost every consumer platform, and the reason old data keeps surfacing in breaches long after the relationship ended.

What you actually get

Set against the compliance burden, here is the practical yield for an individual once the substantive provisions bite:

  • Notice — a readable, standalone account of what is being collected and why, before you agree.
  • Purpose limitation — data collected for one stated purpose may not quietly become fuel for another.
  • Access — the right to a summary of the personal data a company holds about you and who it has been shared with.
  • Correction, completion and updating — the right to fix what is wrong about you in someone else’s database.
  • Erasure — the right to have data deleted when consent is withdrawn or the purpose is done, with a defined window for the company to respond.
  • Nomination — the right to name someone to exercise your rights if you die or become incapacitated, which is a thoughtful and unusual inclusion.
  • Grievance redress — a named contact and a published route to complain, with the Board available if the company stonewalls.

For businesses, the mirror image: publish a compliant notice, keep consent records, name a grievance officer, build erasure and access workflows, secure the data with logging and access control, and — for the largest players designated as significant data fiduciaries — appoint an India-based data protection officer, run periodic impact assessments and independent audits, and carry out due diligence on algorithms that process personal data.

The exemption at the centre

Now the part that determines what all of the above is worth.

The obligations I have just described bind companies. They bind the state far more loosely. The Act allows the government to exempt its own instrumentalities from the law’s requirements on grounds like the sovereignty and integrity of India, security of the state, public order and friendly relations with foreign states — categories broad enough to cover a great deal, and assessed by the executive itself rather than by a court. The Rules build the plumbing for state demands for personal data, and, as reported, restrict fiduciaries from disclosing that such a demand was made.

Read that arrangement as a whole. The entity that collects the most data about Indians — through identity, welfare, taxation, policing, transport and the payment rails that run underneath daily life — is the entity with the widest ability to exempt itself, on grounds it defines, without a public necessity test, and with the recipients of its demands gagged. I’ve made the same argument about Aadhaar, UPI and privacy: the systems are extraordinary infrastructure, and the accountability attached to them has never matched their reach.

A board, not an independent regulator

The second structural weakness is the referee. The Data Protection Board is an adjudicatory body, not an independent authority in the sense the word carries in most privacy regimes. It does not make rules — the government does. Its members are appointed by the executive, on terms the executive sets, and eligibility is open to serving officials. A regulator whose principal hard cases will involve the state, staffed by people the state appoints and can decline to reappoint, starts from an awkward position. That is not an accusation about any individual; it is an observation about incentives, and incentives are what institutions run on.

There is a third loss that got less attention than it deserved. The Act amended the Right to Information Act’s personal-information exemption, as reported through Section 44(3), removing the carve-out that allowed personal information to be disclosed where a larger public interest justified it. That provision was how journalists and citizens established things like officials’ qualifications and beneficiary lists. Privacy law was used to narrow transparency law — and the transparency it narrowed was the kind that points at power, not at ordinary people.

A privacy law that constrains the corner shop’s mailing list more tightly than the state’s surveillance file has not mistaken its priorities. It has chosen them.

A right is only as real as the exemptions around it

I don’t want to be unfair to the Rules. Measured against nothing, which is what India had, they are a substantial improvement. A company that loses your data must now tell you. A company that no longer needs your data must now delete it. A company that wants your data must now ask in language you can read and keep proof that it did. Those are wins, and they will change the behaviour of thousands of Indian businesses over the next year.

But the shape of the law is the point. The rights are strongest where the data is least consequential, and weakest where it is most. Your grocery app will face a tighter consent regime than the systems that decide whether you receive a ration, appear on a watchlist, or have your face matched at a station. This is precisely the pattern I traced in how technology gets captured: rules written in the language of protection, structured so that the largest actor is the least constrained by them. Capture rarely announces itself. It shows up as a carefully drafted exception.

The useful test for any rights framework is not what it grants but what it excludes. On that test, the DPDP Rules give Indians a working set of tools against the private sector and a polite notice about the public one. The fix is not complicated in principle — a genuinely independent regulator, exemptions narrowed to what is necessary and proportionate with judicial oversight, transparency reporting on state data demands, and the restoration of the public-interest override in RTI. None of it requires reopening the Act’s architecture. All of it requires the political appetite to be bound by your own law.

Until then, use what you have been given. Read the notices. Withdraw consent where you don’t need the service. Ask companies what they hold on you, because the right to ask only becomes real when people use it — and a right nobody exercises is indistinguishable from a right that was never granted. That is the practical heart of data dignity: not waiting to be protected, but insisting on the protection already written down.

Kenney Jacob is the author of Captured, a history of who takes, who pays, and who fights back.

Frequently asked questions

What are the DPDP Rules and how do they differ from the Act?

The Digital Personal Data Protection Act set the framework; the Rules are the operating detail that makes it enforceable — how consent must be obtained and recorded, how consent managers are registered, what a breach notification must contain and when, retention periods, and the phased timelines businesses get to comply. The Act says what; the Rules say how and by when.

What rights does the DPDP regime give you?

Broadly: to be told what is collected and why, to have data processed only for a stated purpose on a valid basis, to access and correct it, to seek erasure, to nominate someone to act for you, and to a grievance process. How strong they are in practice depends on enforcement capacity and on how widely the exemptions are read.

What are the criticisms of India's data law?

The most persistent is the breadth of government exemptions — the state can exempt its own agencies from significant obligations on grounds like sovereignty and security, which critics argue leaves the largest data collector least constrained. Others point to the regulator's independence, limits on data-portability rights, and the weakening of earlier transparency provisions.

← All articles