The country’s digital privacy rulebook has just been rewritten—and this time, the Centre has stamped it into force with a set of staggered start dates that redraw the compliance calendar for every major data handler. The Digital Personal Data Protection Rules, 2025, now officially notified, look familiar in many places but carry a few sharp turns that weren’t present when the draft appeared earlier this year.
A Calendar Carved Into Three Layers
The government has split the implementation into clear phases. The basic spine of the rules—definitions and the architecture of the Data Protection Board—kicked in the moment the Gazette ink dried. A year from now, the machinery for registering consent managers will be activated. And the heaviest lift—rules governing notice, security, deletions, grievances and appeals—has been pushed to mid-2027, giving entities eighteen months to brace themselves.
Children and Disability-linked Consent: One Rule Becomes Two
What was once a single umbrella provision has now been sliced into a pair of standalone rules. One focuses entirely on how children’s data is handled; the other isolates the standards that apply when a person with certain disabilities cannot make binding decisions. The wording hasn’t changed much—the separation is structural, not ideological.
National Security Clause, Now Standing Alone
The confidentiality shield around national security–related information requests has been lifted out of its earlier cluster and positioned as an independent rule. The shift is cosmetic rather than substantive, but it makes the government’s nondisclosure power easier to read—and tougher to miss.
The Big Surprise: A One-Year Universal Retention Mandate
Here lies the major twist. The draft rules only required a narrow category of logs to be stored for a year. The notified text goes much further. Every piece of personal data, every fragment of traffic data, every log from any processing activity must now be preserved for at least one year—regardless of whether the user has deleted their account or the business has fulfilled the original purpose. This is designed to fuel investigations and oversight laid out in the Seventh Schedule, and it dramatically expands the scope of mandatory retention across the board.
Everything Else Marches On, Unchanged
Beyond the new retention duty, the rest of the framework remains nearly word-for-word consistent with the draft.
– Data must be erased once no longer needed, with a 48-hour heads-up to the user. Certain entities must purge inactive users’ data after three years while retaining logs for a year.
– Security safeguards—from encryption to access controls to audits—remain intact.
– Consent managers follow the same design blueprint as before, including the ₹2-crore net-worth requirement and strict unreadability of routed data.
– Cross-border data transfer continues under the same “allowed unless restricted” principle.
– Significant data fiduciaries and the Data Protection Board will operate under rules nearly indistinguishable from those proposed in January.
In effect, the government has preserved the architecture of the privacy regime—but inserted a single, sweeping retention clause that reshapes how data will be stored, investigated and overseen for years to come.