Security & Compliance 8 min read

DPDPA Rules 2025: what should businesses prepare for now?

India's data protection framework is moving from legislation towards operational implementation. The important question for businesses is no longer simply what the law says — it is what needs to change across data, processes, technology and accountability.

Read featured insight

The Digital Personal Data Protection Rules, 2025 move India's data protection framework closer to practical implementation. For businesses, readiness should not begin with another policy. It should begin by understanding how personal information actually moves through the organisation and what needs to change before the operational requirements take effect.

01

Understand the rollout before planning the response.

The final Digital Personal Data Protection Rules, 2025 were published in November 2025.

Importantly, the framework does not bring every requirement into operation at the same time. Different provisions have different commencement periods.

Phase 01

On publication

Rules 1, 2 and 17 to 21 came into force on publication of the final Rules.

Phase 02

One year

Rule 4, relating to registration and obligations of Consent Managers, comes into force one year after publication.

Phase 03

Eighteen months

Rules 3, 5 to 16, 22 and 23 come into force eighteen months after publication.

A future compliance date should not become a future starting date.

Data discovery, consent redesign, security controls, contractual review and operational workflows can involve multiple business functions.

Organisations that start early have more time to understand their current environment, prioritise important gaps and introduce changes progressively.

02

Follow the personal data through the business.

Compliance becomes difficult when an organisation cannot clearly see where personal data exists or how it moves.

Consider a customer enquiry submitted through a website. The information may move into a CRM, trigger an email, appear in an ERP system, become part of a spreadsheet, reach an external service provider and eventually remain inside a backup environment.

Website CRM ERP Email Vendor Backup
Practical perspective

One business process can create multiple copies of the same personal information across different teams, systems and technologies.

A useful data-discovery exercise should therefore follow the complete business process rather than simply producing an application inventory.

01 / Identify

What personal data?

Identify the categories of personal information collected, stored or otherwise processed.

02 / Purpose

Why is it required?

Connect each processing activity to a clear and understandable business purpose.

03 / Flow

Where does it move?

Identify applications, integrations, exports and external recipients.

04 / Ownership

Who is responsible?

Establish business ownership and operational responsibility for important processing.

03

Notice and consent need to work in practice.

Where consent is relied upon, the experience should clearly explain what personal data is involved and why it is being processed.

The final Rules require the notice to be independently understandable and to provide, in clear and plain language, an itemised description of the relevant personal data together with the specified purpose of processing.

The notice must also provide a route through which an individual can withdraw consent, exercise rights under the Act and make a complaint to the Board.

What data? Why? What purpose? What choice? How to withdraw?

Could a customer understand why you need their information without reading an entire privacy policy?

Consent should therefore be reviewed across websites, forms, portals, applications, CRM processes and marketing activities rather than treated as a single legal statement.

04

Turn Data Principal rights into operational workflows.

It is relatively easy to describe rights in a privacy policy.

The operational challenge begins when an actual request reaches the organisation.

Someone needs to identify the requester, locate relevant personal information, determine which systems and teams are involved, complete the appropriate action and maintain evidence of the response.

Example operating workflow
01 Request received
02 Verify requester
03 Locate relevant data
04 Review requirement
05 Complete action
06 Respond and retain evidence

Workflow automation can be useful here. Requests can be captured, assigned, tracked, escalated and evidenced without relying entirely on spreadsheets and email chains.

05

Privacy readiness depends on security readiness.

Personal data protection cannot operate separately from cybersecurity and technology controls.

The final Rules identify minimum areas within reasonable security safeguards, including appropriate data-security measures, access control, logging and monitoring, continuity measures such as backups, processor-contract provisions and appropriate technical and organisational measures.

01 / Protect

Protect the data

Use appropriate safeguards such as encryption, masking, obfuscation or virtual tokens where applicable.

02 / Access

Control access

Limit access to computer resources involved in processing personal data.

03 / Monitor

Maintain visibility

Use appropriate logging, monitoring and review to help detect unauthorised access.

04 / Recover

Prepare for disruption

Maintain appropriate measures for continued processing and recovery, including backups.

Prepare for a personal-data breach before one occurs.

When the relevant breach provisions commence, organisations need an operating process that connects security, technology, business ownership and communications.

Detect Contain Assess Notify Recover Improve

The Rules provide for notification to affected Data Principals without delay. The Board must also receive an initial description without delay, followed by specified further information within seventy-two hours unless a longer period is allowed.

Operational question

If an incident occurred today, would your teams know who decides whether personal data is involved, who gathers the evidence and who coordinates the response?

06

Follow personal data beyond your own organisation.

Most organisations depend on external technology platforms and service providers.

Customer information may be processed through cloud platforms, CRM systems, payroll providers, marketing services, IT support companies and other business partners.

Third-party readiness should therefore look beyond whether a contract simply exists.

  • What personal data does the provider receive?
  • Why does the provider need that information?
  • Who can access the information?
  • What security safeguards are expected?
  • How long should the information be retained?
  • What happens to the information when the relationship ends?

Can your organisation identify the external parties currently processing personal data on its behalf?

If answering that question requires searching multiple contracts, spreadsheets and email chains, third-party data mapping is an important readiness activity.

07

Build a practical readiness roadmap.

DPDPA readiness does not need to become one enormous transformation programme.

A phased approach makes the work easier to prioritise, execute and measure.

01

Discover

Identify important processes, personal-data flows, systems, integrations and third parties.

02

Assess

Compare current practices with applicable requirements and identify operational gaps.

03

Prioritise

Focus first on higher-volume, higher-exposure and business-critical processing activities.

04

Implement

Put practical controls into forms, access, systems, vendors, retention, requests and incident handling.

05

Test

Simulate rights requests, consent withdrawal and personal-data incidents to validate the process.

06

Evidence

Maintain records demonstrating that important controls operate as intended.

Compliance is the requirement. Better data governance is the opportunity.

DPDPA will understandably encourage organisations to review notices, consent practices, security, contracts and regulatory responsibilities.

But organisations that stop at documentation may miss the larger opportunity.

A practical readiness exercise can expose unnecessary data collection, excessive access, duplicate information, unmanaged spreadsheets, forgotten integrations and personal information being retained without a clear purpose.

Addressing those issues can reduce security exposure, simplify operations, improve data quality and create better foundations for analytics, automation and AI.

Know the data. Understand the flow. Control the access. Prepare the response. Keep the evidence.

A practical place to begin is with one important business process.

Follow personal information from the moment it enters the organisation until the point at which it should no longer be required.

The gaps discovered through that exercise will often tell you more about your true readiness than a compliance checklist alone.

DPDPA Readiness

Turn data protection requirements into practical operational controls.

Epicarp helps organisations understand personal-data flows, identify readiness gaps and establish practical controls across data, processes, technology and governance.

This article is intended for general informational purposes only and does not constitute legal advice. Organisations should assess applicable legal and regulatory requirements based on their individual circumstances and obtain appropriate professional advice where required.