The operative regulatory framework enacted by the Central Government under Section 40 of the DPDP Act, 2023. Browse verified statutory rules, plain-language explanations, parent Act mappings, and compliance tools.
What this means: The rules do not all apply immediately. This gives companies a grace period to upgrade their systems.- Basic r...
What this means: Clarifies that "User Account" is a broad term. It doesn't just mean a username and password; it legally includ...
What this means: The era of hiding data collection in 50-page Terms of Service documents is over.Privacy notices must now be in...
What this means: Companies can register to become "Consent Managers" (platforms where users can manage all their app permission...
What this means: This outlines the minimum cybersecurity standards companies must follow. They cannot store data in plain text;...
What this means: If a hack or leak happens, the company cannot cover it up.- They must notify users "without delay" via email/a...
What this means: Companies cannot hoard data forever.If a user abandons an app (e-commerce, gaming, or social media) and does n...
What this means: Apps must verify that a parent actually gave permission for a child to use the app. The safest way for a compa...
What this means: Large companies (SDFs) have very strict compliance deadlines. They must conduct a massive Data Protection Impa...
What this means: Companies cannot make it difficult for you to exercise your rights (like asking them to delete your data). The...
The DPDP Rules are statutory instruments enacted under the rulemaking powers conferred by Section 40 of the Digital Personal Data Protection Act, 2023. While the Act establishes primary obligations, rights, and penalties, the Rules detail operational parameters—including notice formats, breach notification timelines, consent manager standards, and data principal verification procedures.