Why the Rules matter more than the Act
The Digital Personal Data Protection Act, 2023 states the principles. The subordinate Rules supply the mechanics: what a notice must contain, how consent managers register and operate, how quickly a breach must be reported, how long certain classes of data may be retained, and what "verifiable" parental consent looks like in practice. For most organisations, the Rules are where compliance budgets are actually spent.
Notice: itemised, standalone, plain language
The Rules push notices toward a standalone, plain-language format that is understandable on its own, without cross-references to a long privacy policy. Practical expectations:
- An itemised list of the personal data collected, not broad categories such as "usage data"
- The specific purpose for each item, with a description of the goods, services or benefit enabled
- Clear routes to withdraw consent, exercise rights and lodge a complaint with the Data Protection Board
- Availability in English and the languages listed in the Eighth Schedule of the Constitution
What this means for you: consent screens become per-purpose, not a single "I agree" checkbox, and product teams must own notice content as a release artefact.
Consent Managers: a new regulated intermediary
The Rules establish registration conditions for Consent Managers — entities that let Data Principals give, manage, review and withdraw consent through an interoperable platform, with net worth, independence, technical and record-keeping obligations. If your sector adopts consent managers, your systems need APIs to accept and honour consent artefacts issued outside your own interface, and to reconcile them with internal consent records.
Reasonable security safeguards, spelled out
Where the Act says "reasonable security safeguards", the Rules describe expected measures, including:
- Encryption, obfuscation, masking or the use of virtual tokens
- Access control on computer resources holding personal data
- Logs, monitoring and review to enable detection and investigation of unauthorised access
- Continuity measures such as backups for personal data and its processing means
- Retention of logs and personal data for a prescribed period to support investigation
- Contractual security obligations flowed down to Data Processors
What this means for you: these map almost one-to-one onto ISO/IEC 27001 Annex A controls. Organisations with a certified ISMS can evidence most of this from existing control operation rather than building something new.
Breach reporting: two clocks
The Rules split breach notification into two timelines:
| Notification | Recipient | Expected timing |
|---|---|---|
| Intimation of the breach | Affected Data Principals | Without delay, in clear language, describing the nature, extent, likely consequences, mitigation measures and contact for queries |
| Initial intimation | Data Protection Board | Without delay on becoming aware |
| Detailed report | Data Protection Board | Within 72 hours (extendable on request), covering facts, circumstances, cause, mitigation, remedial measures and the notice given to Data Principals |
What this means for you: a 72-hour detailed report is only achievable with pre-built forensics, log retention and a named decision-maker. Rehearse it; do not write it for the first time during an incident.
Retention limits for large platforms
The Rules prescribe erasure after a defined period of user inactivity for specified classes of Data Fiduciary above user thresholds — such as large e-commerce platforms, online gaming intermediaries and social media intermediaries — with advance notice to the Data Principal before erasure. Automated lifecycle management, not manual clean-ups, is the only sustainable answer.
Verifiable parental consent
For Data Principals under 18, the Rules require reliable verification that the consenting adult is the parent or lawful guardian, using identity details already held or a virtual token mapped to a verified identity, including through a Digital Locker service provider. Exemptions exist for clinical establishments, educational institutions, crèches and certain child-safety and legal purposes.
Cross-border transfer and government access
Transfers outside India remain permitted subject to requirements the Central Government may specify for particular countries or classes of Fiduciary, and transfers can be restricted where processing takes place under a contract with the Government. Keep a live register of transfer destinations and sub-processors so that a change in restrictions does not require a discovery exercise.
A pragmatic implementation sequence
- Re-baseline your data inventory — purposes, itemised data elements, retention, transfers, processors
- Rebuild notice and consent — per-purpose, multilingual, versioned, logged with audit trails
- Engineer rights fulfilment — access, correction, erasure, nomination and grievance, with measured SLAs
- Harden and evidence security — align to ISO/IEC 27001, add ISO/IEC 27701:2025 for privacy-specific controls
- Build the 72-hour breach machine — detection, severity model, log retention, notification templates, tabletop drills
- Automate retention — inactivity-based erasure with advance notice where thresholds apply
- Govern processors — contracts, due diligence, audit rights, sub-processor transparency
- Assure and repeat — DPIAs for high-risk processing, internal audit, independent data audit where notified as significant
Key takeaways
- The Rules convert principles into engineering requirements: notices, consent artefacts, logs, retention jobs, breach timelines
- Breach response is the hardest deadline to meet retroactively — build it first
- Most prescribed safeguards already exist inside a functioning ISMS
- Consent managers and verifiable parental consent introduce genuinely new integration work
- Phased compliance beats a single big-bang programme, because notice and consent changes touch every product surface
Treat the transition window as delivery time, not planning time. Organisations that already run ISO/IEC 27001 and ISO/IEC 27701 controls have the shortest path, because their evidence trail is already operating.
