The DPDP Act vs the DPDP Rules: Why You Need Both
People conflate these constantly, and it causes real errors, because the operational detail and every commencement date live in the Rules, not the Act.
Two documents, different jobs
The Act received assent on 11 August 2023 as Act No. 22 of 2023. It defines the roles, sets the duties of a Data Fiduciary, establishes the rights of a Data Principal, creates the Data Protection Board, and sets the penalties in its Schedule.
The Rules were notified on 13 November 2025 as G.S.R. 846(E). They set out how the duties are discharged: what a notice must contain, what security safeguards mean at minimum, how a breach is intimated, when data must be erased, how parental consent is verified.
How they pair up
- Section 5 requires a notice; Rule 3 says what it must contain.
- Section 8(5) requires reasonable security safeguards; Rule 6 lists them.
- Section 8(6) requires breach intimation; Rule 7 sets who, what and when.
- Section 9 requires verifiable parental consent; Rule 10 sets how it is verified.
- Section 10 creates Significant Data Fiduciary duties; Rule 13 adds the twelve month DPIA and audit cycle.
- Sections 11 to 14 create rights; Rule 14 says how a Data Principal exercises them.
Where the penalties sit
In the Act, in its Schedule, read with section 33. But the conduct that breaches them is largely defined in the Rules. The Schedule penalises failure to take reasonable security safeguards under section 8(5), and what those safeguards are is Rule 6.
Citing the Act alone tends to produce advice that is directionally right and operationally useless. The Rules are where the answers are.
Infosek Team
A note on reading them
Both are public. The Act is Act No. 22 of 2023; the Rules are G.S.R. 846(E) dated 13 November 2025, published in the Gazette of India, Extraordinary, Part II, Section 3, Sub-section (i). Anything you rely on should be traceable to one of them.
Common questions
What is the difference between the DPDP Act and the DPDP Rules?
The Digital Personal Data Protection Act 2023 is primary legislation setting out duties, rights, penalties and the Data Protection Board. The Digital Personal Data Protection Rules 2025, notified as G.S.R. 846(E) on 13 November 2025, are subordinate legislation setting out how those duties are discharged in practice and when each provision commences.
Which one sets the compliance deadlines?
The Rules. Rule 1 sets a staggered commencement: Rules 1, 2 and 17 to 21 from 14 November 2025, Rule 4 from 14 November 2026, and Rules 3, 5 to 16, 22 and 23 from 14 May 2027.
Working out which document governs what?
Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.
Book Free 30-Min Assessment