{"id":38,"date":"2026-03-31T12:42:56","date_gmt":"2026-03-31T12:42:56","guid":{"rendered":"https:\/\/www.lexemer.com\/articles\/?p=38"},"modified":"2026-04-19T08:09:28","modified_gmt":"2026-04-19T08:09:28","slug":"overview-of-the-dpdp-act-2023-and-dpdp-rules-2025","status":"publish","type":"post","link":"https:\/\/www.lexemer.com\/articles\/overview-of-the-dpdp-act-2023-and-dpdp-rules-2025\/","title":{"rendered":"Overview of the DPDP Act 2023 and DPDP Rules 2025"},"content":{"rendered":"\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7] wp-block-paragraph\">The Digital Personal Data Protection (DPDP) Act was enacted on August 11, 2023.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Subsequently, on November 14, 2025, the Government of India notified the DPDP Rules, 2025 to operationalise the said Act.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Given below is a factual summary of the core definitions, the primary provisions of the 2023 Act and the specific procedures introduced by the 2025 Rules.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>Key Definitions<\/strong><\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Data Principal: The individual to whom the personal data relates.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">In the case of children or persons with disabilities, the expression includes their lawful guardian.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Data Fiduciary: The person or entity which determines the purpose and means of processing of personal data.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Consent Manager: A registered entity providing an accessible platform for a Data Principal to give, manage, review and withdraw consent.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>Core Provisions of the DPDP Act (2023)<\/strong><\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Consent and Notice: Personal data can be processed only for a lawful purpose and with the free, specific, informed and unambiguous consent of the Data Principal.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Every request for consent shall be accompanied by a notice specifying the personal data to be processed and the purpose thereof.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Rights of the Data Principal: The individuals have the right to access information about their data, to request correction or erasure of the same and to access grievance redressal mechanisms.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">They further have the right to nominate any other individual to exercise the said rights in the event of death or incapacity.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Penalties: The Act prescribes specific financial penalties for non-compliance.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Failure on the part of a Data Fiduciary to take reasonable security safeguards to prevent a data breach may attract penalty upto \u20b9 250 crore.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Failure to intimate the Board and the affected individuals of a breach, or non-observance of obligations qua children, may attract penalty upto \u20b9 200 crore.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\"><strong>Key Additions and Timelines in the DPDP Rules (2025)<\/strong><\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">The 2025 Rules lay down the specific procedures and timelines required for compliance with the 2023 Act.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Compliance Timeline: The Rules provide a period of 18 months for phased compliance in respect of most of the provisions.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Personal Data Breach Notifications: In the event of a personal data breach, the Data Fiduciary shall intimate every affected Data Principal without delay.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">The Data Fiduciary shall also intimate the Data Protection Board without delay.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Detailed information regarding the breach shall be furnished within 72 hours.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Grievance Redressal Deadlines: The Data Fiduciaries and the Consent Managers are required to establish a grievance redressal system.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">They shall respond to the grievances of the users within a maximum period of 90 days.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Data Erasure and Inactivity: The data shall be erased after a prescribed period of inactivity.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">The said period may vary depending upon the nature of the platform and the purpose thereof.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">The Third Schedule prescribes a three-year inactivity threshold for erasure in respect of the following entities:<\/p>\r\n<ul class=\"[li_&amp;]:mb-0 [li_&amp;]:mt-1 [li_&amp;]:gap-1 [&amp;:not(:last-child)_ul]:pb-1 [&amp;:not(:last-child)_ol]:pb-1 list-disc flex flex-col gap-1 pl-8 mb-3\">\r\n<li class=\"whitespace-normal break-words pl-2\">E-commerce entities having at least 2 crore registered users in India.<\/li>\r\n<li class=\"whitespace-normal break-words pl-2\">Online gaming intermediaries having at least 50 lakh registered users in India.<\/li>\r\n<li class=\"whitespace-normal break-words pl-2\">Social media intermediaries having at least 2 crore registered users in India.<\/li>\r\n<\/ul>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Processing Children&#8217;s Data: Before processing the personal data of a child, the Data Fiduciary shall obtain verifiable parental consent.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">The 2025 Rules provide that the verification of the parent&#8217;s identity and age may be done voluntarily by the individual or through a virtual token issued by an authorised entity, such as a Digital Locker service provider.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Certain exemptions to these obligations apply in specific situations, such as processing by clinical establishments or educational institutions for the purposes of health, safety or educational tracking of the child.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">Digital Data Protection Board: The Data Protection Board of India as well as the Appellate Tribunal shall function as digital offices.<\/p>\r\n<p class=\"font-claude-response-body break-words whitespace-normal leading-[1.7]\">They shall adopt techno legal measures to conduct proceedings, receive complaints and hold hearings digitally without requiring the physical presence of individuals.<\/p>\r\n","protected":false},"excerpt":{"rendered":"<p>The Digital Personal Data Protection (DPDP) Act was enacted on August 11, 2023. Subsequently, on November 14, 2025, the Government of India notified the DPDP Rules, 2025 to operationalise the said Act. Given below is a factual summary of the core definitions, the primary provisions of the 2023 Act and the specific procedures introduced by [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":32,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-38","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-laws"],"_links":{"self":[{"href":"https:\/\/www.lexemer.com\/articles\/wp-json\/wp\/v2\/posts\/38","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lexemer.com\/articles\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.lexemer.com\/articles\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.lexemer.com\/articles\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lexemer.com\/articles\/wp-json\/wp\/v2\/comments?post=38"}],"version-history":[{"count":2,"href":"https:\/\/www.lexemer.com\/articles\/wp-json\/wp\/v2\/posts\/38\/revisions"}],"predecessor-version":[{"id":134,"href":"https:\/\/www.lexemer.com\/articles\/wp-json\/wp\/v2\/posts\/38\/revisions\/134"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.lexemer.com\/articles\/wp-json\/wp\/v2\/media\/32"}],"wp:attachment":[{"href":"https:\/\/www.lexemer.com\/articles\/wp-json\/wp\/v2\/media?parent=38"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.lexemer.com\/articles\/wp-json\/wp\/v2\/categories?post=38"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lexemer.com\/articles\/wp-json\/wp\/v2\/tags?post=38"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}