10 months ago
India Notifies DPDP Rules, Experts Welcome New Digital Privacy Regime
Imagine India now has a new set of rules, called the DPDP Rules, to protect your personal information online.
The government officially announced these rules recently.
This means companies, like social media platforms and online services, must clearly tell you what information they are collecting about you and how they plan to use it.
You will also have an easier way to say 'no' to them using your data or to report problems.
Some experts are very happy about this, saying it's a big step for privacy in India, especially with new technologies like AI.
They believe these rules will help companies handle data more responsibly.
Companies have about a year and a half to get ready and follow all the new requirements.
Experts also say it’s important for companies to build a culture of trust around data privacy, not just follow rules.
The next important step will be to see how the new Data Protection Board explains and enforces these rules.
India has officially notified the Rules under the Digital Personal Data Protection Act (DPDPA), 2023, establishing its first personal data protection regime.
Organizations, including social media and online gateways, must now explain to users what data is collected and how it will be used.
Users will have easier ways to revoke consent and complain to the Data Protection Board (DPB) about data protection infractions.
Companies have 18 months to comply with administrative requirements, while consent managers must register with the DPB within 12 months.
Industry experts welcome the move, highlighting it as a significant step for digital privacy, AI governance, and establishing operational accountability and a culture of trust.
- Who
- Ministry of Electronics and Information Technology (MeitY), social media sites, online gateways, organizations handling personal data, users, consent managers, industry experts (Ivana Bartoletti, Nikhil Narendran, Jaspreet Singh), Data Protection Board (DPB).
- What
- Notification of Rules under the Digital Personal Data Protection Act (DPDPA), 2023, establishing India's personal data protection regime.
- Where
- India
- When
- Rules notified on Friday (November 14, 2025, assumed date for context), with compliance deadlines of 18 months for companies and 12 months for consent managers.
- Why
- To operationalize India's first dedicated personal-data protection regime, strengthen digital ecosystem, promote trust, and ensure accountability in data handling.
Emphasis on New Era and Robust Governance
Focus on Operationalization and Future Interpretation
Significance of DPDP Rules Notification
Emphasis on New Era and Robust Governance
Experts like Ivana Bartoletti emphasize that the notification of DPDP Rules marks a new era of privacy in India, crucial for AI development and strengthening the digital ecosystem, highlighting robust data governance, clear responsibilities, consent, and privacy by design.
Focus on Operationalization and Future Interpretation
Nikhil Narendran sees the notification as putting an end to uncertainty for India Inc., providing an 18-month runway for compliance and focusing on the practical steps organizations need to take, such as data mapping and training, and anticipating how the Data Protection Authority will interpret and enforce the rules.
Compliance Approach for Organizations
Emphasis on New Era and Robust Governance
Ivana Bartoletti suggests that the new rules enable organizations to grow sustainably and accountably as technology becomes more embedded in daily life.
Focus on Operationalization and Future Interpretation
Jaspreet Singh stresses that compliance is not a checklist but a culture of trust and privacy governance that must be institutionalized, with a focus on embedding privacy by design and operationalizing privacy as a continuous assurance function.
Key facts
- Law Name
- Digital Personal Data Protection Act (DPDPA), 2023
- Rules Notification Date
- Friday (November 14, 2025, assumed date for context)
- Compliance Deadline for Companies
- 18 months from notification
- Registration Deadline for Consent Managers
- 12 months from notification
- Key Requirements for Organizations
- Provide detailed explanation of data gathered and its use, enable easy consent revocation, clear responsibilities, consent, privacy by design
- Governing Body
- Data Protection Board (DPB)
Timeline
India drafted new data privacy rules.
These rules included protections for minors and the disabled.
The DPDP Rules 2025 are now law.
Quotes
Ivana Bartoletti
Chief Privacy and AI Governance Officer, Wipro
“There is no doubt that India has entered a new era of privacy. In the age of AI, trust is crucial. And because AI depends on large volumes of data, strong privacy protections must come first. This development marks an important step in strengthening India’s digital ecosystem and aligns closely with the country’s recent AI governance guidelines.”
thehansindia.com
“as innovation accelerates and technology becomes ever more embedded in daily life”
thehansindia.com
Nikhil Narendran
Partner – TMT [Technology, Media and Telecommunications], Trilegal
“With the notification of the Rules and the Act, the government has finally put all uncertainty to rest.”
thehansindia.com
“India Inc. now has an 18-month runway to gear up for full compliance. For most organisations, it will be necessary to start with data mapping, redesigns of consent and notice flows, and training programs to ensure compliance, with the help of lawyers, technologists, and privacy professionals. The real focus will also be on the constitution of the new Data Protection Authority and how this regulator interprets these rules, prioritises enforcement, and how early guidance shapes India’s digital industry.”
thehansindia.com
Jaspreet Singh
Partner and Chief Revenue Officer, Grant Thornton Bharat
“Compliance under DPDPA is not a checklist; it's a culture of trust every organisation must now institutionalise. The DPDPA era demands boardroom fluency in privacy governance; executives will now be measured by controls they can evidence, not promises they make.”
thehansindia.com
“The 2025 Rules make one thing clear -- data fiduciaries must embed privacy by design before regulators force it by default. As DPDPA Rules take effect, the next advantage belongs to organizations that operationalise privacy as a continuous assurance function.”
thehansindia.com
Sources
Govt notifies DPDP Rules 2025: New data protection norms to roll out over 12–18 month
Govt notifies DPDP Act operationalising India’s first digital privacy law
Govt issues DPDP Rules with phased rollout and new requirements for data fiduciaries
E-commerce, social media firms must erase inactive user data after 3 years: DPDP Act
DPDP Act mandates e-commerce, social media firms to delete inactive user data after 3 years
Centre notifies Digital Personal Data Protection Rules 2025 — Check provisions, implementation plan, penalties
Centre issues DPDP Act rules, puts India’s first digital privacy law into effect
After two years, India’s data privacy law comes to force
Centre Notifies DPDP Rules To Regulate Personal Data
Data privacy law comes into force
Govt released rules for Digital Personal Data Protection
Centre Notifies Digital Personal Data Protection (DPDP) Act Rules
Small-Town Businesses Race To Understand New Data Rules As Compliance Deadline Nears
Businesses must race to meet 18-month deadline for data protection norms: Experts on DPDP rules
Startups, Big Tech and Cloud Firms Brace for India’s New Data Compliance Era
Businesses must race to meet 18-month deadline for data protection norms: Experts on DPDP rules
India Notifies DPDP Rules, 2025, Bringing Landmark Data Law Into Force
DPDP Rules: Firms get breathing space, but work begins now
Clearer Consent, Faster Breach Alerts: What India’s New Data Rules Mean For Users
DPDPA Rules 2025: Experts welcome India’s first digital privacy law
Mint Explainer: What the new data privacy law means for India's startups




