Privacy

    DPDP Rules: How the Draft Rules Change Day-to-Day Compliance

    Santhosh Kapalavai
    Sep 5, 2026
    Privacy

    Why the Rules matter more than the Act

    The Digital Personal Data Protection Act, 2023 states the principles. The subordinate Rules supply the mechanics: what a notice must contain, how consent managers register and operate, how quickly a breach must be reported, how long certain classes of data may be retained, and what "verifiable" parental consent looks like in practice. For most organisations, the Rules are where compliance budgets are actually spent.

    Notice: itemised, standalone, plain language

    The Rules push notices toward a standalone, plain-language format that is understandable on its own, without cross-references to a long privacy policy. Practical expectations:

    • An itemised list of the personal data collected, not broad categories such as "usage data"
    • The specific purpose for each item, with a description of the goods, services or benefit enabled
    • Clear routes to withdraw consent, exercise rights and lodge a complaint with the Data Protection Board
    • Availability in English and the languages listed in the Eighth Schedule of the Constitution

    What this means for you: consent screens become per-purpose, not a single "I agree" checkbox, and product teams must own notice content as a release artefact.

    Consent Managers: a new regulated intermediary

    The Rules establish registration conditions for Consent Managers — entities that let Data Principals give, manage, review and withdraw consent through an interoperable platform, with net worth, independence, technical and record-keeping obligations. If your sector adopts consent managers, your systems need APIs to accept and honour consent artefacts issued outside your own interface, and to reconcile them with internal consent records.

    Reasonable security safeguards, spelled out

    Where the Act says "reasonable security safeguards", the Rules describe expected measures, including:

    • Encryption, obfuscation, masking or the use of virtual tokens
    • Access control on computer resources holding personal data
    • Logs, monitoring and review to enable detection and investigation of unauthorised access
    • Continuity measures such as backups for personal data and its processing means
    • Retention of logs and personal data for a prescribed period to support investigation
    • Contractual security obligations flowed down to Data Processors

    What this means for you: these map almost one-to-one onto ISO/IEC 27001 Annex A controls. Organisations with a certified ISMS can evidence most of this from existing control operation rather than building something new.

    Breach reporting: two clocks

    The Rules split breach notification into two timelines:

    NotificationRecipientExpected timing
    Intimation of the breachAffected Data PrincipalsWithout delay, in clear language, describing the nature, extent, likely consequences, mitigation measures and contact for queries
    Initial intimationData Protection BoardWithout delay on becoming aware
    Detailed reportData Protection BoardWithin 72 hours (extendable on request), covering facts, circumstances, cause, mitigation, remedial measures and the notice given to Data Principals

    What this means for you: a 72-hour detailed report is only achievable with pre-built forensics, log retention and a named decision-maker. Rehearse it; do not write it for the first time during an incident.

    Retention limits for large platforms

    The Rules prescribe erasure after a defined period of user inactivity for specified classes of Data Fiduciary above user thresholds — such as large e-commerce platforms, online gaming intermediaries and social media intermediaries — with advance notice to the Data Principal before erasure. Automated lifecycle management, not manual clean-ups, is the only sustainable answer.

    Verifiable parental consent

    For Data Principals under 18, the Rules require reliable verification that the consenting adult is the parent or lawful guardian, using identity details already held or a virtual token mapped to a verified identity, including through a Digital Locker service provider. Exemptions exist for clinical establishments, educational institutions, crèches and certain child-safety and legal purposes.

    Cross-border transfer and government access

    Transfers outside India remain permitted subject to requirements the Central Government may specify for particular countries or classes of Fiduciary, and transfers can be restricted where processing takes place under a contract with the Government. Keep a live register of transfer destinations and sub-processors so that a change in restrictions does not require a discovery exercise.

    A pragmatic implementation sequence

    1. Re-baseline your data inventory — purposes, itemised data elements, retention, transfers, processors
    2. Rebuild notice and consent — per-purpose, multilingual, versioned, logged with audit trails
    3. Engineer rights fulfilment — access, correction, erasure, nomination and grievance, with measured SLAs
    4. Harden and evidence security — align to ISO/IEC 27001, add ISO/IEC 27701:2025 for privacy-specific controls
    5. Build the 72-hour breach machine — detection, severity model, log retention, notification templates, tabletop drills
    6. Automate retention — inactivity-based erasure with advance notice where thresholds apply
    7. Govern processors — contracts, due diligence, audit rights, sub-processor transparency
    8. Assure and repeat — DPIAs for high-risk processing, internal audit, independent data audit where notified as significant

    Key takeaways

    • The Rules convert principles into engineering requirements: notices, consent artefacts, logs, retention jobs, breach timelines
    • Breach response is the hardest deadline to meet retroactively — build it first
    • Most prescribed safeguards already exist inside a functioning ISMS
    • Consent managers and verifiable parental consent introduce genuinely new integration work
    • Phased compliance beats a single big-bang programme, because notice and consent changes touch every product surface

    Treat the transition window as delivery time, not planning time. Organisations that already run ISO/IEC 27001 and ISO/IEC 27701 controls have the shortest path, because their evidence trail is already operating.

    Hi! I'm your AI Assistant 💬