Live Founding Cohort open, limited seats remaining Back to main site →

Reading the Act and Rules as one instrument

The structural map. Nine chapters of the Act, twenty-three Rules, seven Schedules. Read this once and every subsequent lesson locates itself against a specific Section-Rule-Schedule triangulation.

Free preview 10 min read Verified
Legal basis
DPDP Act 2023 (No. 22 of 2023, assented 11 August 2023). DPDP Rules 2025 notified 13 November 2025 via Gazette Notifications G.S.R. 843(E), 844(E), 845(E) and 846(E). Sectoral overlays as in force August 2026: CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); RBI Draft Data Governance Framework (15 July 2026, consultation closed 17 August 2026); SEBI CSCRF (20 August 2024); IRDAI Information and Cyber Security Guidelines 2026 (6 April 2026); Telecom Cyber Security Rules 2024 (21 November 2024); Aadhaar Data Security Regulations 2016. Constitutional context: Puttaswamy v. Union of India (2017) 10 SCC 1.

Every practitioner who tries to read the DPDP Act alone gets lost inside three lessons. The Act is thin. Many provisions read "as may be prescribed". The prescription lives in the Rules. Reading them separately is a mistake. Reading them as one instrument is the trick.

The Act at a glance

The DPDP Act 2023 has nine chapters:

  1. Chapter I. Preliminary. Sections 1-3. Short title, definitions, application.
  2. Chapter II. Obligations of Data Fiduciary. Sections 4-10. Grounds for processing, notice, consent, legitimate uses, general obligations, children, SDF.
  3. Chapter III. Rights and Duties of Data Principal. Sections 11-15. Access, correction/erasure, grievance, nomination, duties.
  4. Chapter IV. Special Provisions. Sections 16-17. Cross-border, exemptions.
  5. Chapter V. Data Protection Board of India. Sections 18-26. Constitution, powers.
  6. Chapter VI. Powers, Functions and Procedure. Sections 27-28. Board functions, inquiry, orders.
  7. Chapter VII. Appellate Tribunal. Sections 29-32. Appeal, ADR, voluntary undertaking.
  8. Chapter VIII. Penalties and Adjudication. Section 33.
  9. Chapter IX. Miscellaneous. Sections 34-44. Rule-making, RTI amendment.

Plus a Schedule at the end setting out penalty ceilings.

The Rules at a glance

The DPDP Rules 2025 have 23 Rules and 7 Schedules. Grouped by function:

  • Machinery. Rules 1-2, 17-21. Title, definitions, DPB Search-cum-Selection Committees, service conditions, digital office, meetings, officers.
  • Fiduciary-facing. Rules 3-6, 8-9. Notice, Consent Manager, State processing, security safeguards, retention, contact publication.
  • Breach. Rule 7.
  • Children and disability. Rules 10-12.
  • SDF-specific. Rule 13. DPIA, algorithmic due diligence, localisation.
  • Rights. Rule 14.
  • Cross-border and research. Rules 15-16.
  • State access. Rules 22-23. Section 36 information calls and confidentiality.

Seven Schedules:

  1. First Schedule. Consent Manager conditions (Part A) and obligations (Part B).
  2. Second Schedule. Standards for State processing and research/archiving/statistical processing.
  3. Third Schedule. Retention default periods (3-year inactivity for e-commerce ≥2cr, gaming ≥50L, social media ≥2cr).
  4. Fourth Schedule. Exemptions from Section 9(1)/(3) for classes and purposes (health, education, creches).
  5. Fifth Schedule. DPB Chairperson and Members service conditions.
  6. Sixth Schedule. DPB officers and employees.
  7. Seventh Schedule. Purposes for Section 36 information calls.

How the two texts hook together

Practical Section-Rule-Schedule triangulations you will use every week:

  • Notice: Section 5 → Rule 3 → language rendering from Eighth Schedule of the Constitution.
  • Consent: Section 6 → Rule 4 → First Schedule Part A + B.
  • Security: Section 8(5) → Rule 6 → 1-year log retention.
  • Breach: Section 8(6) → Rule 7 → two-stage clock (without delay + 72 hours).
  • Erasure: Section 8(7) → Rule 8 → Third Schedule (3-year inactivity for named platforms) → Seventh Schedule (State exception).
  • DPO: Section 10(2)(a) → Rule 13(1) (DPIA + audit) → Board-of-Directors accountability.
  • Rights: Sections 11-14 → Rule 14 → 90-day response cap.
  • Cross-border: Section 16(1) → Rule 15 → negative-list mechanism.
  • State access: Section 36 → Rules 22-23 → Seventh Schedule (purposes).
  • Penalties: Section 33 → Schedule to the Act (7 items).

What is not in the Rules

Two things a first-time reader expects and does not find:

First, the Rules do not define "child". The Act at Section 2(f) defines a child as anyone under 18 [L3-C1]. The Rules do not deviate.

Second, the Rules do not set numeric SDF thresholds. Section 10(1) lists factors (volume, sensitivity, risk, sovereignty, electoral democracy, State security, public order); the actual designation is a Government notification of specific Fiduciaries or classes [L3-C2]. Industry reads the Third Schedule's 2 cr / 50 lakh cut-offs as a proxy for "large scale", but that is inference, not text.

How to read the Rules in the correct order

A practitioner reading the Rules for the first time should go in this order, not in numerical order:

  1. Rule 1 (commencement calendar)
  2. Rule 2 (definitions)
  3. Rule 3 (notice) and Rule 4 (Consent Manager) together
  4. Rule 6 (security) and Rule 7 (breach) together
  5. Rule 8 (retention) with the Third Schedule
  6. Rule 14 (rights) with Rule 13 grievance points
  7. Rules 10-12 (children and disability) with the Fourth Schedule
  8. Rule 13 (SDF) with Section 10 of the Act
  9. Rule 15 (cross-border) with Section 16
  10. Rules 22-23 (state access) with Section 36

Each module of this course follows a similar order.

Where the DPB rules will sit

Separately from the DPDP Rules 2025, the Board will issue its own procedural rules under Section 28. As of August 2026 these have not been published; the digital-office mode is default under Rule 19 of the DPDP Rules. Watch the DPB website (once the Chairperson and Members are appointed) for Board Regulations on inquiry, evidence, and adjudication procedure.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 7 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 7 paid modules (24 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹14,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
DPDP Act 2023, Section 2 (Definitions) L3-C1
Defines key terms including Data Principal, Data Fiduciary, Data Processor, personal data, personal data breach, processing, Significant Data Fiduciary, Consent Manager, child, and Board.
DPDP Act 2023, Section 10 (Additional obligations of Significant Data Fiduciary) L3-C2
Central Government may notify any Data Fiduciary or class as Significant Data Fiduciary based on volume and sensitivity of personal data, risk to rights of Data Principals, potential impact on sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order. Every SDF must appoint an India-resident Data Protection Officer responsible to the Board of Directors, an independent Data Auditor, and undertake periodic DPIAs and audits.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: Foundations: The DPDP Act, the 2025 Rules, and the Commencement Calendar
Module 2: Notice, Consent, Cookies and the Consent Manager Ecosystem
  • Notice under Section 5 and Rule 3
  • The Section 6 consent test and withdrawal architecture
  • Cookies and the India grey zone
  • Consent Manager registration under Rule 4 and the MeitY six
Module 3: Data Discovery, RoPA and Retention
  • Data discovery and classification
  • Building a DPDP-fit Record of Processing Activities
  • Rule 8 retention and the Third Schedule
  • Layered retention across DPDP and sectoral rules
Module 4: Data Principal Rights and Grievance Management
  • Section 11 access and Rule 14 workflow
  • Section 12 correction, completion and erasure
  • Section 13 grievance mechanism and escalation to the Board
  • Section 14 nomination and Section 15 Data Principal duties
Module 5: Assessments: DPIA, Independent Audit and Algorithmic Due Diligence
  • SDF designation under Section 10 and the Rule 13 programme
  • Running a DPIA in practice
  • The DPO role in detail: qualifications, salary bands, reporting line
  • DPB adjudication and TDSAT appeal
Module 6: Breach Management: The Rule 7 Two-Stage Clock
  • What counts as a personal data breach
  • Rule 7 Stage 1 and Stage 2 mechanics
  • Parallel clocks: DPDP Rule 7 and CERT-In 6-hour
  • Rule 6 security safeguards
Module 7: Vendor Management, Cross-Border Transfers and Sector Overlays
  • Section 8(2) DPA and the ten non-negotiable clauses
  • Section 16 and Rule 15 cross-border transfer
  • Sector overlays: RBI, SEBI, IRDAI, Telecom, Aadhaar
  • Section 17 exemptions and the constitutional challenge
Module 8: Final Exam and Certificate