DPDP Rules 2026 Notified — What Changed from the Draft, What Every Indian Data Fiduciary Must Operationalise Now

Manish Garg
Manish Garg Associate of (ISC)² · RingSafe
May 8, 2026
7 min read
Read as

Last updated: May 18, 2026

The DPDP Rules — the operational rules that flesh out the DPDP Act 2023 — were notified by MeitY in early 2026 after a year of consultation drafts. The final rules clarified consent-form structure, breach notification timelines, the SDF threshold criteria, and the cross-border transfer regime. This post covers what’s binding now, what changed from the November 2024 draft, what every Indian data fiduciary must operationalise immediately, and the specific traps for SaaS / fintech / healthtech businesses.

The DPDP Act has been law since August 2023; the Rules that turn it into operational obligation lagged for over two years. With the rules now notified, the “we’ll wait until rules are clear” delay strategy is exhausted. This post is the binding-now technical guide for compliance leads and CISOs.

The structure — Act vs Rules vs guidelines

DPDP Act 2023: the statute. Sets penalty maxima (₹250 crore for §8(5) failures), defines key terms (data fiduciary, principal, processor, SDF), creates the Data Protection Board, sets §8 obligations.

DPDP Rules 2026: the operational subordinate legislation under Section 40 of the Act. Specifies notice-of-consent format, retention schedules, breach-notification mechanics, SDF criteria, board composition.

DPB guidelines: the Data Protection Board issues binding orders and non-binding advisories. Limited so far; expect rapid increase post-rules.

What the Rules clarified

1. Consent notice — Rule 3. Must be in clear and plain language; must include itemised list of personal data being processed; must specify purpose for each item separately. Standard mobile-app “we collect data for service delivery” is no longer compliant. Indian apps need item-by-item consent: name → for account creation; phone → for OTP verification; location → for delivery; payment-card → for transaction processing. Each as a separate yes/no, not bundled.

2. Verifiable parental consent for children — Rule 10. Must verify age via “appropriate technical and organisational measures.” Self-declaration is not sufficient. Acceptable: government-ID verification (Aadhaar e-KYC, DigiLocker); credit card verification; verified parental email-+-OTP loop. The Rule explicitly mentions DigiLocker as an acceptable mechanism.

3. Breach notification — Rule 7. Two-tier:

  • Notification to Data Protection Board: within 72 hours of becoming aware. Must include nature, scope, principals affected, mitigation steps, contact for further information.
  • Notification to affected principals: “without delay.” Practical interpretation: same 72-hour window unless impractical (mass breaches with millions of principals); then no later than reasonably practicable, with reasoned justification documented.

4. SDF threshold criteria — Rule 12. The Government may notify any data fiduciary as Significant. Criteria considered: volume of personal data, sensitivity, risk to electoral democracy, risk to State sovereignty/integrity. Operational: SDFs additionally must (a) appoint Indian-resident DPO; (b) conduct DPIA on any high-risk processing; (c) conduct independent audits annually. The rules don’t list specific entities; expect first SDF notifications to follow major service providers (UPI ecosystem, large e-commerce, large healthtech).

5. Cross-border data transfer — Rule 14. Transfers permitted to countries not prohibited by the Government. The Government may issue a “negative list” of restricted countries. As of writing, no negative list has been notified — meaning transfers are broadly permitted. This is a softer regime than EU GDPR adequacy. Watch for the negative list when published; major Western jurisdictions are unlikely to be listed; specific concerning countries (likely PRC, possibly others) may be.

6. Retention — Rule 6. Personal data retained only as long as necessary for the specified purpose. After purpose served, must be erased “within reasonable timeframe.” Practical interpretation: data fiduciaries need a documented retention schedule per data category, automated erasure pipelines, and audit logs proving erasure.

What changed from the November 2024 draft

  • Breach-notification timeline was unchanged (72 hours) — earlier draft proposed an aggressive 24-hour window which industry pushed back against successfully.
  • Cross-border regime was softened — earlier draft required Government approval per transfer; final rules permit by default subject to negative list.
  • Verifiable parental consent — final rules added DigiLocker as an explicit acceptable mechanism, clearer guidance for Indian companies than the November draft.
  • SDF criteria — final rules list “risk to State sovereignty” as a criterion; this is broader than typical data-protection scope and expected to be selectively applied.
  • Grievance redress — final rules tightened response time to 30 days for first response (down from 90 in the draft).

Operational checklist — implement now

  1. Audit your consent flows. Item-by-item granularity. Test that each consent toggle is independently togglable. Document the audit.
  2. Draft your DPDP Notice. Public-facing privacy notice in plain language. Include data categories, purposes, retention periods, principal rights, grievance officer contact, DPB contact.
  3. Appoint a Grievance Officer. Must be Indian-resident. Publish name + email on the website. Stand up the SLA-tracked response process for principal requests (access, correction, erasure, withdrawal of consent).
  4. Build your retention-and-erasure pipeline. Per data category, define retention. Implement automated erasure. Maintain audit logs.
  5. Document your DPIA process. Even for non-SDFs, having a DPIA template ready proves due diligence under §8(5).
  6. Update your incident-response runbook. Include the DPB notification path. Test the 72-hour timeline in a tabletop exercise.
  7. Vendor reviews. Update DPAs with all data processors. They must agree to your DPDP obligations contractually. Existing vendor agreements likely don’t have this.
  8. Re-train your customer-support and product teams on the principal-rights workflow.

Sector-specific traps

Fintech / payments: KYC data retention often retained for 5-10 years per RBI rules. DPDP says “as long as necessary.” These conflict; the resolution is “longer of the two regulator-mandated periods, with documented reasoning.” Don’t shorten KYC retention without RBI guidance.

Healthtech: ABDM data retention rules + DPDP retention. Health is sensitive personal data under DPDP § 2(t). Retention longer than purpose requires explicit justification. Linking ABHA-tagged records and consumer telemedicine logs creates large data sets needing item-by-item consent.

SaaS / B2B: most SaaS will be data processors not fiduciaries — but you’re a fiduciary for your customer’s contact data, employees’ data, billing records. Both roles apply simultaneously. DPA template needs to handle both.

Government / quasi-government: Section 17 exemptions for State are broader than industry expected. Government data fiduciaries (PSUs, banks, regulators) have lighter obligations than private sector. The asymmetry will create litigation.

Penalty calibration — what’s at stake

Section 33 lists schedule of penalties:

  • §8(5) reasonable security failure: up to ₹250 crore
  • §9 children’s data violation: up to ₹200 crore
  • §8(6) breach notification failure: up to ₹200 crore
  • §10 SDF obligations failure: up to ₹150 crore
  • Other obligations: up to ₹50 crore

The DPB has discretion within the maxima; “factors to be considered” listed in §33(2) include nature, gravity, prior breaches, mitigation. Realistic first-year enforcement: smaller penalties as the DPB establishes precedent. Industry expectation: ₹1-25 crore range for typical violations of mid-size organisations; the ₹250 crore tier reserved for catastrophic large-organisation breaches.

FAQ

What’s the deadline to comply with the rules?

The rules typically have a “phased” enforcement provision — usually 6-12 months for smaller fiduciaries, immediate for SDFs. Check the gazette notification carefully for the operative date for your category.

Is consent required for B2B contact data (LinkedIn-style outreach)?

Currently murky. DPDP applies to “personal data of data principals.” Business contact data of named individuals processed for B2B sales arguably is personal data and requires lawful basis. Industry practice will likely settle on legitimate-interest framings until the DPB rules either way.

Can we still send marketing emails to existing customers?

Yes, with explicit opt-in consent specified at the time of collection (post-rules), or implied consent for transactional communication that customers reasonably expect. Pre-existing customer lists where consent was generic — re-confirm consent or stop processing.

How do non-resident data fiduciaries comply?

Section 3 makes the Act extraterritorial — applies to data fiduciaries outside India processing personal data of principals in India. They must appoint an Indian-resident grievance officer. Foreign SaaS without Indian presence will need a local representative.

How does DPDP interact with sectoral regulators (RBI, SEBI, IRDAI)?

Section 38 — sectoral regulator’s rules generally prevail in their domain (e.g., RBI on banking data). DPDP fills gaps. Concrete case: bank’s data retention follows RBI; bank’s grievance officer for non-banking-context data complaints follows DPDP. Most regulated entities will end up running both regimes in parallel.


⚖️ Legal: This is an analysis post, not legal advice. For binding compliance decisions, engage Indian privacy counsel. RingSafe operates DPDP-readiness assessments and DPIA workshops as services — see /services/. The DPDP Penalty Calculator at /tools/dpdp-penalty-calculator/ is an estimating tool, not legal advice.


Related engagement → How we delivered DPDP Act readiness for a multi-million-user fintech

DPDP Act in your stack?

Get a DPDP gap assessment

Free 30-minute call. We map your data flows against DPDP §8 obligations and tell you exactly which gaps to fix first. Auditor-defensible output.

Book DPDP scoping call Replies in 4 working hrs · India-only · Senior consultants