logo

DPDP Rules Are Here: What Changed from the Draft?

ID: e8d19ea4-f9ad-55b8-8714-73e092da7b87

STIX ID: report--e8d19ea4-f9ad-55b8-8714-73e092da7b87

Feed Name: Seqrite Blog

Date Published: 2025-11-14

Date Updated: 2026-04-30

Author: Seqrite

...
...

India’s final Digital Personal Data Protection (DPDP) Rules, 2025 transform the Act into an enforceable regime with a phased rollout (immediate foundational provisions, consent manager registration at 12 months, broader operational obligations at 18 months), mandating standalone consent notices, immediate user breach notification with DPB reporting within 72 hours, baseline security controls (encryption, masking/tokenization, strong access control, and 1-year log retention), retention/erasure rules (3-year deletion for inactive users with 48-hour notice), protections for children and vulnerable persons, and elevated SDF duties (annual DPIAs/audits, algorithmic transparency, potential localization). The rules establish the Data Protection Board, adopt a cross-border transfer blacklist model, and set clear governance expectations, urging organizations to shift from policy to operational privacy, with Seqrite positioning its solutions to support compliance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.