Infosek
INFOSEK

The DPDP Act vs the DPDP Rules: Why You Need Both

People conflate these constantly, and it causes real errors, because the operational detail and every commencement date live in the Rules, not the Act.

The DPDP Act vs the DPDP Rules: Why You Need Both

Two documents, different jobs

The Act received assent on 11 August 2023 as Act No. 22 of 2023. It defines the roles, sets the duties of a Data Fiduciary, establishes the rights of a Data Principal, creates the Data Protection Board, and sets the penalties in its Schedule.

The Rules were notified on 13 November 2025 as G.S.R. 846(E). They set out how the duties are discharged: what a notice must contain, what security safeguards mean at minimum, how a breach is intimated, when data must be erased, how parental consent is verified.

How they pair up

Where the penalties sit

In the Act, in its Schedule, read with section 33. But the conduct that breaches them is largely defined in the Rules. The Schedule penalises failure to take reasonable security safeguards under section 8(5), and what those safeguards are is Rule 6.

Citing the Act alone tends to produce advice that is directionally right and operationally useless. The Rules are where the answers are.

Infosek Team

A note on reading them

Both are public. The Act is Act No. 22 of 2023; the Rules are G.S.R. 846(E) dated 13 November 2025, published in the Gazette of India, Extraordinary, Part II, Section 3, Sub-section (i). Anything you rely on should be traceable to one of them.

Common questions

What is the difference between the DPDP Act and the DPDP Rules?

The Digital Personal Data Protection Act 2023 is primary legislation setting out duties, rights, penalties and the Data Protection Board. The Digital Personal Data Protection Rules 2025, notified as G.S.R. 846(E) on 13 November 2025, are subordinate legislation setting out how those duties are discharged in practice and when each provision commences.

Which one sets the compliance deadlines?

The Rules. Rule 1 sets a staggered commencement: Rules 1, 2 and 17 to 21 from 14 November 2025, Rule 4 from 14 November 2026, and Rules 3, 5 to 16, 22 and 23 from 14 May 2027.

Working out which document governs what?

Infosek handles the whole of DPDP: data mapping, consent and notices, security controls, vendor contracts, breach readiness and the audit itself. We do the work, not just the gap report.

Book Free 30-Min Assessment