DPDP Knowledge Hub
All 14 chapters of the Digital Personal Data Protection Rules 2025, from preliminary definitions to penalties and adjudication.
At a glance
14 chapters
28 minutes total
Your reading path
Read what you need, in order.
Each chapter pairs the rule with practical impact, rights, and an action you can take.
chapter
Chapter 1: Preliminary
Introduces the Act's scope and key terms, together with the Rules' title, commencement structure, and definitions.
2 min read
chapter
Chapter 2: Registration of Consent Managers
Establishes registration requirements and eligibility criteria for Consent Managers, the digital intermediaries users can use to manage consent across platforms.
2 min read
chapter
Chapter 3: Manner of Giving Notice
Sets out how Data Fiduciaries must notify Data Principals about data collection, in clear, itemized, and accessible language.
2 min read
chapter
Chapter 4: Consent and Withdrawal
Explains the Act's requirements for valid consent, consent requests, withdrawal, and proof of notice and consent.
2 min read
chapter
Chapter 5: Verifiable Consent and Children
Covers verifiable consent for children and persons with disabilities who have lawful guardians, together with specified child-data exemptions.
2 min read
chapter
Chapter 6: Manner of Exercising Rights
Specifies the process Data Fiduciaries must follow when Data Principals exercise their rights to access, correct, or erase personal data.
2 min read
chapter
Chapter 7: Retention and Erasure
Explains when personal data must be erased, the notified retention rules for specified classes and purposes, and the legal-retention exceptions.
2 min read
chapter
Chapter 8: Manner of Nominating Another Individual
Explains how Data Principals can nominate someone else to exercise their data rights in the event of death or incapacity.
2 min read
chapter
Chapter 9: Grievance Redressal Mechanism
Sets requirements for a Data Fiduciary's internal grievance redressal mechanism, including response timelines.
2 min read
chapter
Chapter 10: Data Breach Notification
Covers the timeline and content requirements for notifying the Data Protection Board and affected users of a personal data breach.
2 min read
chapter
Chapter 11: Data Fiduciaries & SDFs
Lays out baseline obligations for all Data Fiduciaries and additional requirements for Significant Data Fiduciaries (SDFs).
2 min read
chapter
Chapter 12: Data Protection Board
Describes the composition, powers, and procedures of the Data Protection Board of India.
2 min read
chapter
Chapter 13: Inquiry, Penalties, and Appeals
Details the penalty framework and adjudication process for violations of the DPDP Act.
2 min read
chapter
Chapter 14: Transfers, Exemptions, and Commencement
Covers cross-border-transfer conditions, research and statistical exemptions, government information requests, and phased commencement.
2 min read
New to DPDP? Start with Chapter 1 for the definitions and scope that shape everything that follows.
