SECURISTI PRIVACY PRACTICE · 8 MIN READ
The Digital Personal Data Protection Rules, 2025 were published in the Official Gazette on 13 November 2025. The single most important thing to understand about them is not any individual rule, it's the clock. Commencement is staggered, and the dates dictate your build sequence.
The Rules commence in three tranches. The machinery provisions, definitions and the constitution of the Data Protection Board of India, took effect on publication; the Board itself was established the same day, headquartered in the National Capital Region. Consent Manager registration and obligations under Rule 4 follow one year later, around November 2026. The operative heart of the regime, notice standards, security safeguards, breach reporting, children's data, Significant Data Fiduciary duties and data-principal rights, becomes enforceable eighteen months after publication, around May 2027.
The practical read: as of mid-2026, most operative obligations are future-dated, but "future-dated" is not "optional". May 2027 is a delivery deadline for programmes that typically take twelve to eighteen months to build properly.
Section 5 of the Act, operationalised by Rule 3, requires a standalone, plain-language notice for every consent-based purpose, itemising the personal data collected and the specified purpose, with working links to withdraw consent, exercise rights and complain to the Board. Notices must be capable of being given in the languages of the Eighth Schedule. If your current privacy notice is a single omnibus document inherited from a GDPR programme, it will not pass, the DPDPA model is purpose-specific, not layered.
Consent must be free, specific, informed, unconditional and unambiguous, given by clear affirmative action. Withdrawal must be as easy as the giving of consent, and you must retain demonstrable proof of every notice served and every consent taken. Note what the Act does not contain: there is no "legitimate interests" basis. Processing rests on consent or on one of the specified legitimate uses in section 7, nothing else. Teams reasoning from GDPR habit routinely get this wrong.
Under section 8(6) and Rule 7, a personal data breach requires notification to each affected data principal without delay, and to the Board, an initial intimation without delay, followed by a full report within 72 hours. There is no materiality threshold to hide behind. If your incident response runbook doesn't have Board-notification templates drafted and owners named, that's a gap with a hard deadline.
Sequence matters more than coverage. Our recommended order: first, the processing inventory and lawful-basis mapping, everything else depends on it. Second, notice and consent re-engineering, because re-papering legacy consents takes longest. Third, the breach runbook rehearsed against the 72-hour clock. Fourth, retention and erasure that actually executes across production, backups and analytics. Fifth, rights and grievance workflows inside the 90-day outer limit. SDF candidates should run the designation assessment in parallel, DPO-in-India, annual DPIA and audit duties are substantial if they land on you.
Where to start today: our 40-point DPDPA Readiness Checklist walks all ten obligation clusters with section-level references. Score yourself, then bring us the gaps.
This article is informational and does not constitute legal advice. Obligations described are as at July 2026; verify commencement notifications with counsel.