Short title and commencement
1. (1) These rules may be called the Digital Personal Data Protection Rules, 2025.
(2) Rules 1, 2 and 17 to 21 shall come into force on the date of their publication in the Official Gazette.
(3) Rule 4 shall come into force one year after the date of publication of this Gazette.
(4) Rules 3, 5 to 16, 22 and 23 shall come into force eighteen months after the date of publication of this Gazette.
What this means: The rules do not all apply immediately. This gives companies a grace period to upgrade their systems.
- Basic rules and board appointments start immediately.
- Consent Manager rules (Rule 4) start in 1 year.
- The heavy compliance rules (notices, security, child data) start in 18 months.
Key Practical Takeaways for Compliance Teams
-
•
Delegated Specificity: This rule provides concrete operational criteria that must be reflected in technical architectures and compliance records.
-
•
Audit Readiness: Ensure written SOPs, consent logs, and security controls correspond directly to the statutory wording of Rule 1.
-
•
Statutory Traceability: In any legal interpretation, the exact Gazette text above takes precedence over internal summaries.