New

DPDP Rules 2025 compliance checklist is live —

Read now
← All articles Regulation

DPDP Rules 2025: what changed and what to do first

VaultDef Team18 Aug 20262 min read

The Digital Personal Data Protection Act gave India its first comprehensive data-protection statute. The 2025 Rules are where the abstract obligations become operational — timelines, notice formats, consent-manager mechanics, and the evidence a Data Fiduciary is expected to keep.

What actually changed

The headline is not a new principle; it is specificity. Where the Act said "reasonable security safeguards," the Rules start to describe what reasonable looks like in practice, and — crucially — what you will be asked to show when a question is raised.

  • Notice and consent move from a checkbox to a record. A consent is only as good as the receipt behind it.
  • Breach reporting gains sharper timelines. The clock starts at awareness, not at convenience.
  • Data principal rights must be fulfilled within defined windows, with a trail proving you met them.

The first five moves

  1. Find the data. You cannot protect or report on what you have not mapped. Start with a discovery pass across databases, SaaS and file shares.
  2. Fix consent capture. Every consent should produce a signed, timestamped receipt you can retrieve later.
  3. Stand up a rights workflow. A single intake path with identity verification and a statutory timer.
  4. Rehearse a breach. Know who decides, what gets reported, and where the forensic timeline lives — before you need it.
  5. Keep evidence by default. The goal is not to assert compliance in a meeting; it is to produce it on request.

Compliance that only exists in a policy document is a liability. Compliance that produces evidence is an asset.

The organisations that will move fastest are the ones that treat the Rules not as a legal exercise but as an operational one — wiring the obligations into the systems that already run the business.