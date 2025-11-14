The government on Friday formally notified the long-awaited Digital Personal Data Protection (DPDP) Rules, kicking off a staggered rollout of India’s new privacy regime. While several provisions come into effect immediately, others will be phased in over 12 and 18 months to give industry time to transition.

A key feature is the creation of a four-member Data Protection Board of India, which will oversee compliance, adjudicate breaches, and issue orders. The rules mandate strict breach reporting timelines: all data fiduciaries must inform the Board within 72 hours of any personal data breach, while affected users must be alerted "without undue delay."

The government has retained powers to call for information from any platform handling Indian users’ data for sovereignty, security or public order considerations. In certain sensitive cases, the Centre may also restrict fiduciaries from immediately disclosing a breach to users if such disclosure risks further harm.

Children’s data protection has been tightened substantially. Platforms must obtain verifiable parental consent, and are barred from tracking, profiling or serving targeted advertisements to minors. Government entities receive limited exemptions for specific notified functions, but not a blanket immunity.