The Rules That Operationalise the Act

The Digital Personal Data Protection Rules 2025 were notified by the Ministry of Electronics and Information Technology on 13 November 2025, 26 months after the parent Act received Presidential assent. They transform the DPDP Act 2023's principles into specific operational requirements — prescribing formats, timelines, technical safeguards, and procedures that every Data Fiduciary must implement.

The distinction matters practically: the Act defines what must be done. The Rules define how it must be done, and by when. For Indian enterprises — especially BFSI organisations already navigating RBI, SEBI, IRDAI, and CERT-In mandates — the Rules represent a concrete compliance workload that cannot be deferred to the enforcement deadline.

Key principle

The Data Fiduciary bears primary accountability for compliance even where processing is carried out by a Data Processor. Contracts with cloud providers, analytics vendors, and fintech processors must include appropriate security provisions as required by Rule 6(f) — the vendor's non-compliance is the fiduciary's liability.

BFSI context

Banks, NBFCs, insurance companies, and AMCs are among the highest-risk Data Fiduciaries under DPDP. They process financial data, health data (insurance), biometrics (KYC), and children's accounts at scale — triggering the Act's heaviest penalty provisions. Many are likely to be designated as Significant Data Fiduciaries (SDFs) once MeitY announces the designation criteria.

"If the Act defines what must be done, the Rules define how it must be done."

— DPDP Rules 2025 implementation framework

The Five Operational Obligation Areas

1. Breach Notification — 72-Hour Requirement

The Rules prescribe a specific format and a hard 72-hour notification window. The clock starts from the moment the enterprise becomes aware of the breach — not when internal investigation concludes, not when root cause is confirmed. For regulated BFSI entities already managing CERT-In's 6-hour reporting obligation, DPDP adds a second, parallel reporting track to the Data Protection Board.

The notification to the Board must include the nature of the breach, categories of personal data affected, approximate number of Data Principals affected, likely consequences, and measures taken or proposed. The 72-hour window is hard — no grace period, no extensions for ongoing investigations.

After 72 hours, affected Data Principals must also be notified in plain language they can understand. For large-scale breaches, public notice may substitute individual notification.

Penalty at stake

₹200 Crore — failure to notify the Board or Data Principals of a breach (§8(6)). This is separate from, and in addition to, any CERT-In penalties under the IT Act.

2. Notice Requirements — Plain Language, 22 Languages

Before or at the point of collecting personal data, Data Fiduciaries must provide a notice containing: the personal data proposed to be collected, the purpose of processing, how Data Principals may exercise their rights, how complaints may be made to the Board, and contact details of the Grievance Officer.

The Rules require notice in English as mandatory. Optionally, it may also be provided in any of the 22 Scheduled languages under the Eighth Schedule of the Constitution. For BFSI organisations with rural or non-metro customer bases — co-operative banks, rural NBFCs, regional insurance intermediaries — this creates an operational obligation to maintain multi-language notice infrastructure.

Critically, the notice must be available before consent is obtained, not buried in terms and conditions. This requires reviewing every customer onboarding flow, mobile app, website form, and branch process.

3. Consent Manager Framework

The Rules establish a Consent Manager registration process with the Data Protection Board, with the framework becoming operational by November 13, 2026 (12 months from notification). Consent Managers are registered intermediaries that maintain verifiable consent records on behalf of Data Principals.

Enterprises that process data through Consent Managers must: integrate with DPB-registered Consent Managers, maintain verifiable consent artefacts for every processing activity, and produce consent evidence on demand for Board investigations. Enterprises maintaining equivalent internal consent record systems must implement the same standard of auditability.

For BFSI, this is significant. Many banks and NBFCs currently maintain consent via physical forms, e-NACH mandates, or click-wrap agreements. These must be mapped to the Consent Manager framework or an equivalent auditable system before November 2026.

4. Significant Data Fiduciary (SDF) Obligations

Entities designated as Significant Data Fiduciaries by MeitY face additional obligations. While the designation criteria are pending publication, the Rules prescribe what SDFs must do once designated:

Who is likely to be an SDF?

MeitY has not published designation criteria yet. However, based on the Act's language (volume of data, sensitivity, risk to rights), the following BFSI categories are at high risk of SDF designation: large private sector banks, major insurance aggregators, CIBIL and credit bureaus, large fintech platforms (BNPL, UPI apps), and national payment network operators.

5. Children's Data Processing

The Rules operationalise the Act's children's data provisions with operational specificity. Verifiable parental consent must be obtained before processing any child's (under 18) personal data. "Verifiable" means the method must reliably confirm the consent-giver is the parent or guardian — not merely a checkbox.

Additionally: no targeted advertising to children, no tracking or behavioural monitoring of children, no processing that could harm a child's well-being. For financial services offering student loans, children's savings accounts, or family products, this requires a complete review of data flows for minor account holders.

DPDP Breach Response — Dual Notification Track
CERT-In Track DPDP Track T+0 Breach detected T+6h CERT-In Initial Report IT Act §70B obligation T+30d CERT-In Final Report T+0 Becomes aware T+72h Notify DPB — Mandatory ₹200Cr penalty if missed + Notify Data Principals Plain language required CERT-In 6-hour clock and DPDP 72-hour clock run simultaneously — two separate regulatory obligations
Dual notification obligation for BFSI: CERT-In 6-hour initial report + DPDP 72-hour Board notification run in parallel on the same breach event

Penalty Framework — What's at Stake

The DPDP Act's penalty schedule under the First Schedule sets out maximum penalties by violation category. These are ceiling figures — the Data Protection Board determines actual penalties considering factors including severity, number of individuals affected, the fiduciary's compliance history, and remediation efforts.

Violation Act Section Max Penalty BFSI Relevance
Failure to implement reasonable security safeguards §8(5) ₹250 Crore Highest risk — covers all data breaches from inadequate controls
Failure to notify Board or Data Principals of breach §8(6) ₹200 Crore Direct exposure if 72-hour notification is missed
Non-compliance with children's data provisions §9 ₹200 Crore Banks with minor accounts, insurance with family policies
Failure to fulfil additional SDF obligations §10 ₹150 Crore Large BFSI entities likely to be SDF-designated
Breach of voluntary undertaking accepted by the Board §32 = Underlying penalty Compounds any enforcement action accepted as undertaking
Failure to observe duties of Data Principal §15 ₹10,000 Minimal — applies to individuals, not enterprises
Cumulative exposure

Penalties are per violation, not per incident. A single breach that also triggers a notification failure and involves inadequate security safeguards could theoretically result in ₹250Cr + ₹200Cr in separate penalty proceedings. There is no explicit cap on total penalty exposure across multiple violations in a single incident.

Compliance Obligation Map — Who Must Do What
ALL DATA FIDUCIARIES SIGNIFICANT DATA FIDUCIARIES DEADLINE Notice (plain language, multi-format) Same + Board submission May 2027 Consent mechanism + artefacts + Consent Manager integration Nov 2026 Breach notification procedure (72h) + Enhanced DPB reporting Immediate Data Principal rights handling Annual DPIA + Independent Audit May 2027 Processor contracts (Rule 6(f)) DPO appointed + registered Nov 2026 Algorithmic Impact Assessment May 2027
Obligation matrix — all Data Fiduciaries must complete left column; entities designated as SDFs must complete both columns

Compliance Timeline — Full Obligation Schedule

Obligation Deadline Applies To Status
Data Protection Board established Nov 13, 2025 MeitY / Government ✓ Done
Breach notification procedure operational Immediate All Data Fiduciaries Build now
Notice format compliance Immediate All Data Fiduciaries Review now
SDF designation assessment Q3 2026 Large enterprises Prepare now
Consent Manager framework operational Nov 13, 2026 All Data Fiduciaries Design now
DPO appointment + Board registration (SDFs) Nov 13, 2026 SDFs only Identify candidate
Annual DPIA programme (SDFs) May 13, 2027 SDFs only Design framework
Annual independent data audit (SDFs) May 13, 2027 SDFs only Identify auditor
Full compliance — notice, consent, rights, security May 13, 2027 All Data Fiduciaries 18 months remain

What Enterprises Should Be Doing Right Now

Typical enterprise DPDP compliance programmes require 9–12 months to complete gap assessment, implement controls, and achieve audit readiness. With the May 2027 enforcement deadline firm, organisations beginning compliance work in late 2026 will face execution risk. The work to be done in 2026 specifically is the planning, design, and procurement phase that enables May 2027 compliance.

2026 build agenda for BFSI

Q3 2026: Complete DPDP gap assessment against current data processing practices. Map every data flow against the Rules' notice and consent requirements. Identify processing activities involving children's data. Assess SDF designation likelihood.

Q4 2026: Implement breach notification procedure covering the 72-hour DPB requirement and Data Principal notification process. Update all consent forms and privacy notices to meet plain-language and language-option requirements. Begin Consent Manager evaluation or internal equivalent design.