DPDP RULES

Rule 1 - Short title and commencement.

Rule 2 - Definitions

Rule 3 - Notice given by Data Fiduciary to Data Principal

Rule 4 - Registration and obligations of Consent Manager

Rule 5 - Processing of personal data for provision or issue of subsidy, benefit, service, certificate, licence or permit by State and its instrumentalities

Rule 6 - Reasonable security safeguards

Rule 7 - Intimation of personal data breach

Rule 8 - Time period for specified purpose to be deemed as no longer being served

Rule 9 - Contact information of person to answer questions about processing

Rule 10 - Verifiable consent for processing of personal data of child

Rule 11 - Verifiable consent for processing of personal data of person with disability who has lawful guardian

Rule 12 - Exemptions from certain obligations applicable to processing of personal data of child

Rule 13 - Additional obligations of Significant Data Fiduciary

Rule 14 - Rights of Data Principals

Rule 15 - Transfer of personal data outside the territory of India

Rule 16 - Exemption from Act for research, archiving or statistical purposes

Rule 17 - Appointment of Chairperson and other Members

Rule 18 - Salary, allowances and other terms and conditions of service of Chairperson and other Members

Rule 19 - Procedure for meetings of Board and authentication of its orders, directions and instruments

Rule 20 - Functioning of Board as digital office

Rule 21 - Terms and conditions of appointment and service of officers and employees of Board

Rule 22 - Appeal to Appellate Tribunal

Rule 23 - Calling for information from Data Fiduciary or intermediary

FIRST SCHEDULE - Conditions for registration of Consent Manager

SECOND SCHEDULE - Standards for processing of personal data by State and its instrumentalities under clause (b) of section 7 and for processing of personal data necessary for the purposes specified in clause (b) of sub section (2) of section 17

THIRD SCHEDULE

FOURTH SCHEDULE - Classes of Data Fiduciaries in respect of whom provisions of sub-sections (1) and (3) of section 9 shall not apply

FIFTH SCHEDULE

SIXTH SCHEDULE - Terms and conditions of appointment and service of officers and employees of Board

SEVENTH SCHEDULE

Rule 7

Rule 7 - Intimation of personal data breach

  1. On becoming aware of any personal data breach, the Data Fiduciary shall, to the best of its knowledge, intimate to each affected Data Principal, in a concise, clear and plain manner and without delay, through her user account or any mode of communication registered by her with the Data Fiduciary,

    1. a description of the breach, including its nature, extent and the timing of its occurrence;

    2. the consequences relevant to her, that are likely to arise from the breach;

    3. the measures implemented and being implemented by the Data Fiduciary, if any, to mitigate risk;

    4. the safety measures that she may take to protect her interests; and

    5. business contact information of a person who is able to respond on behalf of the Data Fiduciary, to queries, if any, of the Data Principal. 

  2. On becoming aware of any personal data breach, the Data Fiduciary shall intimate to the Board, 

    1. without delay, a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact;

    2. within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on a request made in writing in this behalf, 

      1. updated and detailed information in respect of such description;

      2. the broad facts related to the events, circumstances and reasons leading to the breach;

      3. measures implemented or proposed, if any, to mitigate risk;

      4. any findings regarding the person who caused the breach;

      5. remedial measures taken to prevent recurrence of such breach; and

      6. a report regarding the intimations given to affected Data Principals.

Effective immediately (date of notification — 13 Nov 2025)