Live Founding Cohort open, limited seats remaining Back to main site →

Where DPDP came from and why the 2025 Rules matter now

India's data protection law took eight years to reach a working form. Understanding that arc explains why the November 2025 Rules changed everything and why 13 May 2027 is the date that will pay for this course many times over.

Free preview 10 min read Verified
Legal basis
DPDP Act 2023 (No. 22 of 2023, assented 11 August 2023). DPDP Rules 2025 notified 13 November 2025 via Gazette Notifications G.S.R. 843(E), 844(E), 845(E) and 846(E). Sectoral overlays as in force August 2026: CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); RBI Draft Data Governance Framework (15 July 2026, consultation closed 17 August 2026); SEBI CSCRF (20 August 2024); IRDAI Information and Cyber Security Guidelines 2026 (6 April 2026); Telecom Cyber Security Rules 2024 (21 November 2024); Aadhaar Data Security Regulations 2016. Constitutional context: Puttaswamy v. Union of India (2017) 10 SCC 1.

Every DPO training course starts in the same place: someone reads Section 8 of the DPDP Act 2023 out loud, calls the class to attention, and moves on. That is a mistake. If you do not know where the Act came from, you cannot predict where it is going, and DPDP is a moving target.

The constitutional starting point

The story starts in 2017. A nine-judge Bench of the Supreme Court of India ruled in Justice K.S. Puttaswamy v. Union of India that the right to privacy is a fundamental right under Article 21 of the Constitution [L1-C1]. The Court held that any restriction on privacy must satisfy three tests: legality, legitimate State aim, and proportionality. That ruling created an immediate policy problem. If privacy is a fundamental right, what statute protects it? India had nothing comprehensive.

The eight-year arc

The Central Government constituted the Srikrishna Committee in July 2017. It submitted its report and draft Bill in July 2018. That draft became the Personal Data Protection Bill 2019, which was reworked into the Data Protection Bill 2021, withdrawn from Parliament in August 2022, and finally re-introduced as the Digital Personal Data Protection Bill 2023. The Bill was passed by both Houses in August 2023 and received Presidential assent on 11 August 2023 as Act No. 22 of 2023 [L1-C2].

Then the Act sat. For over two years. Nothing to implement it. The Act was on the statute book but had no rules, no Board, no notified commencement of any substantive provision. Practitioners spoke of DPDP as if it were live, but a lawyer asked to prosecute a breach in early 2025 had nothing to file.

What changed on 13 November 2025

On 13 November 2025 the Ministry of Electronics and Information Technology (MeitY) issued four Gazette Notifications on the same day [L1-C3]:

  • G.S.R. 843(E) — commencement of specific Sections of the DPDP Act 2023
  • G.S.R. 844(E) — establishment of the Data Protection Board of India
  • G.S.R. 845(E) — appointment of officers and preliminary machinery
  • G.S.R. 846(E) — the Digital Personal Data Protection Rules, 2025

Together, these four notifications turned DPDP from a paper statute into a working regime. Not fully. Not immediately. But finally.

Why the Rules matter more than the Act right now

Most of the operational obligations live in the Rules, not the Act. The Act says "the Fiduciary shall give notice in such manner as may be prescribed" over and over. The prescribing happens in the Rules. Read the Rules and the Act reads differently.

A concrete example: the Act at Section 8(6) says "in the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed". Read alone, that sentence tells you nothing. Read alongside Rule 7, it tells you: intimate the affected Data Principal without delay in plain language, intimate the Board without delay of the initial description, and file the detailed report within 72 hours of becoming aware [L1-C4]. The Rule is the specification.

Why 13 May 2027 is the date

Rule 1(2) sets out a phased commencement. Machinery Rules (1, 2, 17-21) came into force on notification. Rule 4 on Consent Manager registration comes into force on 13 November 2026. Rules 3, 5-16, 22 and 23 come into force on 13 May 2027 [L1-C5]. That final date is when substantive obligations bite. Every DPO programme in India today is a countdown to 13 May 2027.

Practitioner rule of thumb: if you have not started implementation by August 2026, you are 21 months behind. If you have not started by January 2027, you are running critical path with no slack. The course is designed to close that gap.

The state of play in August 2026

Several things are pending as of the day this lesson was written and need re-checking on the day you act:

  1. The Data Protection Board is constituted but its Chairperson and Members are not fully appointed [L1-C6]. There is no active regulator to inquire into a breach today. This will change.
  2. No entity has been formally designated a Significant Data Fiduciary. The Section 10(1) power exists; no notification has issued.
  3. No Consent Manager has been registered. Rule 4 opens the registration window on 13 November 2026. MeitY has shortlisted six prototype builders (Jio Platforms, IDfy, Redacto, Zoop, Concur, Aurelion Future Forge).
  4. No country has been notified as restricted under Rule 15 for cross-border transfers. The negative list on paper is empty in practice.
  5. A batch of writ petitions challenging Section 36, Rules 22-23 and Section 44(3) is pending before the Supreme Court after referral to a larger bench on 16 February 2026. No interim stay [L1-C7].

Every one of these will change. The course keeps you on the current side of each. In lessons that touch these items, the "as of August 2026" flag appears explicitly.

Why this matters for a DPO career

DPO salary bands in August 2026 already reflect the coming enforcement. SDF-scale DPOs at BFSI and big-tech firms command ₹60 lakh to ₹1.2 crore per year. Mid-size Data Fiduciary DPOs command ₹25 to 50 lakh. Fractional and outsourced DPO retainers are ₹4 to 15 lakh per month. Nobody in the market is being priced this way because they read the DPDP Act. They are being priced this way because they can operate the Rules, run a Rule 13 SDF programme, file a Rule 7 breach report, and reconcile all of it with CERT-In and RBI and SEBI parallel clocks. That is what the next seven modules teach.

Every claim in this lesson is cited. Yellow markers like [L1-C1] are clickable. Click any to see the verbatim text of the Section, Rule or judgment we're relying on. Learn how we verify content ›

Preview in progress 7 more modules waiting behind enrolment

Enjoying the preview? Here's what enrolment unlocks.

  • All 7 paid modules (24 lessons)
  • Complete citation register — every claim linked to the primary source
  • Final exam: 40 questions, unlimited retakes
  • Verifiable certificate with public verify URL and LinkedIn share
  • Founding-cohort badge on your certificate
Founding-cohort price. List: ₹14,999. Certificate on pass. LinkedIn-shareable. Lifetime access. Course updates included.
Citations
Puttaswamy v. UoI 2017, Puttaswamy v. UoI (2017) 10 SCC 1 (Right to privacy as a fundamental right) L1-C1
Nine-judge Bench of the Supreme Court unanimously held that the right to privacy is a fundamental right protected under Article 21 of the Constitution of India. This ruling is the constitutional foundation of the DPDP Act 2023. Any restriction on privacy must satisfy the tests of legality, legitimate State aim, and proportionality.
DPDP Act 2023, Section 1 (Short title, extent, commencement) L1-C2
The Act is called the Digital Personal Data Protection Act, 2023. It extends to the whole of India and comes into force on dates the Central Government appoints in the Official Gazette, and different dates may be appointed for different provisions.
DPDP Gazette 2025, G.S.R. 846(E) (Digital Personal Data Protection Rules, 2025) L1-C3
MeitY notification dated 13 November 2025 promulgating the Digital Personal Data Protection Rules, 2025. Rules are structured as 23 Rules plus Seven Schedules with three-phase commencement: 13 Nov 2025 (machinery), 13 Nov 2026 (Consent Managers), 13 May 2027 (substantive obligations).
DPDP Rules 2025, Rule 7 (DPDP breach notification (parallel to CSCRF for personal data)) L1-C4
DPDP Rules 2025 Rule 7: on becoming aware of a personal data breach, the Data Fiduciary must intimate each affected Data Principal without delay and intimate the Data Protection Board without delay. Detailed report to the Board within 72 hours of awareness (extendable on written request). For a SEBI RE handling personal data, this runs in parallel with the CSCRF 6-hour clock.
DPDP Rules 2025, Rule 1 (Short title, commencement) L1-C5
The Rules are called the Digital Personal Data Protection Rules, 2025. Commencement is phased: Rules 1, 2 and 17-21 come into force on publication (13 Nov 2025); Rule 4 (Consent Manager registration) on 13 November 2026; Rules 3, 5-16, 22-23 on 13 May 2027.
DPDP Gazette 2025, G.S.R. 844(E) (Establishment of Data Protection Board of India) L1-C6
MeitY notification dated 13 November 2025 constituting the Data Protection Board of India with headquarters in the National Capital Region. Chairperson and Members are appointed through Search-cum-Selection Committees under Rule 17. As of August 2026, Chairperson and Members have not been fully appointed despite nomination calls on 6 May 2026 and 6 June 2026.
DPDP Act 2023, Section 44(3) (Amendment to Right to Information Act) L1-C7
Section 44(3) amends Section 8(1)(j) of the RTI Act 2005 so that personal information is exempt from disclosure under RTI. Central to the constitutional challenge referred to a larger bench by the Supreme Court on 16 Feb 2026.
Free preview
Reading Module 1. Enrol to unlock the rest of the course.
Module 1: Foundations: The DPDP Act, the 2025 Rules, and the Commencement Calendar
Module 2: Notice, Consent, Cookies and the Consent Manager Ecosystem
  • Notice under Section 5 and Rule 3
  • The Section 6 consent test and withdrawal architecture
  • Cookies and the India grey zone
  • Consent Manager registration under Rule 4 and the MeitY six
Module 3: Data Discovery, RoPA and Retention
  • Data discovery and classification
  • Building a DPDP-fit Record of Processing Activities
  • Rule 8 retention and the Third Schedule
  • Layered retention across DPDP and sectoral rules
Module 4: Data Principal Rights and Grievance Management
  • Section 11 access and Rule 14 workflow
  • Section 12 correction, completion and erasure
  • Section 13 grievance mechanism and escalation to the Board
  • Section 14 nomination and Section 15 Data Principal duties
Module 5: Assessments: DPIA, Independent Audit and Algorithmic Due Diligence
  • SDF designation under Section 10 and the Rule 13 programme
  • Running a DPIA in practice
  • The DPO role in detail: qualifications, salary bands, reporting line
  • DPB adjudication and TDSAT appeal
Module 6: Breach Management: The Rule 7 Two-Stage Clock
  • What counts as a personal data breach
  • Rule 7 Stage 1 and Stage 2 mechanics
  • Parallel clocks: DPDP Rule 7 and CERT-In 6-hour
  • Rule 6 security safeguards
Module 7: Vendor Management, Cross-Border Transfers and Sector Overlays
  • Section 8(2) DPA and the ten non-negotiable clauses
  • Section 16 and Rule 15 cross-border transfer
  • Sector overlays: RBI, SEBI, IRDAI, Telecom, Aadhaar
  • Section 17 exemptions and the constitutional challenge
Module 8: Final Exam and Certificate