Answer three questions and see exactly which of India's Digital Personal Data Protection Rules, 2025 apply to you, when each one bites, and what to do in the first 72 hours of a breach. Every claim below cites its rule number and links the Gazette text.
Rules 1, 2 and 17 to 21 have been in force since publication in the Official Gazette on 13 November 2025 (Rule 1(2)). Countdowns run on your device clock.
Applicability shown here is based only on the three answers above. The Rules apply to a Data Fiduciary processing digital personal data in India, and to processing outside India connected with offering goods or services to Data Principals in India.
Rule 7 — Intimation of personal data breach. There is no materiality threshold: every personal data breach is reportable, however small.
Rule 3 requires the notice to be given independently of any other information, in clear and plain language, giving a fair account of the details needed for the Data Principal to give specific and informed consent. This draft is a starting point built from your tick-boxes — replace the bracketed fields and have it reviewed.
If you have a working GDPR programme, most of your muscle transfers. These are the gaps where GDPR habits will quietly put you out of compliance.
| Topic | GDPR | DPDP Rules, 2025 |
|---|---|---|
| Breach threshold | Report only if the breach is likely to result in a risk to the rights and freedoms of individuals | No threshold — every personal data breach is reportable (Rule 7) |
| Breach deadline | 72 hours to the supervisory authority; without undue delay to individuals if high risk | 72 hours to the Board for the detailed report, plus intimation on coming to know; without delay to every affected individual regardless of risk (Rule 7(1), 7(2)) |
| Grievance response | One month to respond to a data subject request | Published timeline of not more than ninety days for grievance redressal (Rule 14) |
| Transfer mechanism | Standard Contractual Clauses, adequacy decisions, BCRs | No SCCs exist — transfer abroad is permitted subject to requirements the Central Government may specify by general or special order (Rule 15) |
| Small-org relief | Some, e.g. records-of-processing exemption under 250 staff | None — no small-business or startup exemption; obligations are uniform regardless of size |
| Consent middleman | No equivalent role | Consent Managers — registered with the Board, and must be companies incorporated in India (Rule 4, First Schedule) |
| Children's data | Age of digital consent set by each member state, 13–16 | Verifiable consent of a parent or lawful guardian for anyone under 18 (Rule 10), with limited exemptions (Rule 12) |
| Retention limit | General storage-limitation principle, no fixed clock | Fixed three-year erasure clock, but only for the classes listed in the Third Schedule, with 48 hours' notice before erasure (Rule 8) |
Rule 13 sets additional obligations for a Significant Data Fiduciary — an annual data protection impact assessment and audit, verification that algorithmic software does not pose a risk to Data Principals' rights, and localisation of personal data and traffic data designated on the recommendation of a government committee. No Significant Data Fiduciaries have been designated yet. You become one only when the Central Government notifies you. Turnover and user-count figures circulating in vendor decks as "SDF thresholds" are interpretation, not statute — this tool will not quote them.
Read the rule text first. Most of what the Rules ask a mid-sized company to do is process work you can staff internally: write a compliant notice (Rule 3), publish a contact for data questions (Rule 9), document your security measures (Rule 6), stand up a grievance route with a published timeline (Rule 14), and write the breach runbook (Rule 7). The heavy items — annual audits, DPIAs, algorithmic verification — sit in Rule 13 and apply only once you are notified as a Significant Data Fiduciary. Price the work against the rule numbers you actually fall under, and ask any vendor to point at the rule behind each line of their quote.
Where this tool states a rule number, it was checked against the MeitY Gazette text linked above. Where a claim could not be tied to a specific rule number, the topic is cited without one.