Every practitioner who tries to read the DPDP Act alone gets lost inside three lessons. The Act is thin. Many provisions read "as may be prescribed". The prescription lives in the Rules. Reading them separately is a mistake. Reading them as one instrument is the trick.
The Act at a glance
The DPDP Act 2023 has nine chapters:
- Chapter I. Preliminary. Sections 1-3. Short title, definitions, application.
- Chapter II. Obligations of Data Fiduciary. Sections 4-10. Grounds for processing, notice, consent, legitimate uses, general obligations, children, SDF.
- Chapter III. Rights and Duties of Data Principal. Sections 11-15. Access, correction/erasure, grievance, nomination, duties.
- Chapter IV. Special Provisions. Sections 16-17. Cross-border, exemptions.
- Chapter V. Data Protection Board of India. Sections 18-26. Constitution, powers.
- Chapter VI. Powers, Functions and Procedure. Sections 27-28. Board functions, inquiry, orders.
- Chapter VII. Appellate Tribunal. Sections 29-32. Appeal, ADR, voluntary undertaking.
- Chapter VIII. Penalties and Adjudication. Section 33.
- Chapter IX. Miscellaneous. Sections 34-44. Rule-making, RTI amendment.
Plus a Schedule at the end setting out penalty ceilings.
The Rules at a glance
The DPDP Rules 2025 have 23 Rules and 7 Schedules. Grouped by function:
- Machinery. Rules 1-2, 17-21. Title, definitions, DPB Search-cum-Selection Committees, service conditions, digital office, meetings, officers.
- Fiduciary-facing. Rules 3-6, 8-9. Notice, Consent Manager, State processing, security safeguards, retention, contact publication.
- Breach. Rule 7.
- Children and disability. Rules 10-12.
- SDF-specific. Rule 13. DPIA, algorithmic due diligence, localisation.
- Rights. Rule 14.
- Cross-border and research. Rules 15-16.
- State access. Rules 22-23. Section 36 information calls and confidentiality.
Seven Schedules:
- First Schedule. Consent Manager conditions (Part A) and obligations (Part B).
- Second Schedule. Standards for State processing and research/archiving/statistical processing.
- Third Schedule. Retention default periods (3-year inactivity for e-commerce ≥2cr, gaming ≥50L, social media ≥2cr).
- Fourth Schedule. Exemptions from Section 9(1)/(3) for classes and purposes (health, education, creches).
- Fifth Schedule. DPB Chairperson and Members service conditions.
- Sixth Schedule. DPB officers and employees.
- Seventh Schedule. Purposes for Section 36 information calls.
How the two texts hook together
Practical Section-Rule-Schedule triangulations you will use every week:
- Notice: Section 5 → Rule 3 → language rendering from Eighth Schedule of the Constitution.
- Consent: Section 6 → Rule 4 → First Schedule Part A + B.
- Security: Section 8(5) → Rule 6 → 1-year log retention.
- Breach: Section 8(6) → Rule 7 → two-stage clock (without delay + 72 hours).
- Erasure: Section 8(7) → Rule 8 → Third Schedule (3-year inactivity for named platforms) → Seventh Schedule (State exception).
- DPO: Section 10(2)(a) → Rule 13(1) (DPIA + audit) → Board-of-Directors accountability.
- Rights: Sections 11-14 → Rule 14 → 90-day response cap.
- Cross-border: Section 16(1) → Rule 15 → negative-list mechanism.
- State access: Section 36 → Rules 22-23 → Seventh Schedule (purposes).
- Penalties: Section 33 → Schedule to the Act (7 items).
What is not in the Rules
Two things a first-time reader expects and does not find:
First, the Rules do not define "child". The Act at Section 2(f) defines a child as anyone under 18 [L3-C1]. The Rules do not deviate.
Second, the Rules do not set numeric SDF thresholds. Section 10(1) lists factors (volume, sensitivity, risk, sovereignty, electoral democracy, State security, public order); the actual designation is a Government notification of specific Fiduciaries or classes [L3-C2]. Industry reads the Third Schedule's 2 cr / 50 lakh cut-offs as a proxy for "large scale", but that is inference, not text.
How to read the Rules in the correct order
A practitioner reading the Rules for the first time should go in this order, not in numerical order:
- Rule 1 (commencement calendar)
- Rule 2 (definitions)
- Rule 3 (notice) and Rule 4 (Consent Manager) together
- Rule 6 (security) and Rule 7 (breach) together
- Rule 8 (retention) with the Third Schedule
- Rule 14 (rights) with Rule 13 grievance points
- Rules 10-12 (children and disability) with the Fourth Schedule
- Rule 13 (SDF) with Section 10 of the Act
- Rule 15 (cross-border) with Section 16
- Rules 22-23 (state access) with Section 36
Each module of this course follows a similar order.
Where the DPB rules will sit
Separately from the DPDP Rules 2025, the Board will issue its own procedural rules under Section 28. As of August 2026 these have not been published; the digital-office mode is default under Rule 19 of the DPDP Rules. Watch the DPB website (once the Chairperson and Members are appointed) for Board Regulations on inquiry, evidence, and adjudication procedure.