Headline: MeitY Notifies Digital Personal Data Protection Rules, 2025, Begins Phased Rollout
Bullet Points:
- MeitY notifies digital personal data protection Rules, 2025, beginning a phased rollout of the Digital Personal Data Protection Act, 2023.
- The framework sets clear rules for how companies, digital platforms, and government bodies must collect, store, process, and manage the personal data of individuals (“Data Principals”).
- The operational rules specify a phased rollout: general duties, grievance redressal provisions, and other foundational obligations under Rules 1, 2, and 17‑21 are effective immediately; the registration and governance of Consent Managers under Rule 4 will be applicable one year from notification; and the detailed notice formats, security measures, processing conditions, data retention norms, and remaining operational rules under Rules 3, 5‑16, 22‑23 will apply in full after 18 months.
- A significant addition through the new rules is the establishment of a formal framework for Consent Managers, who must be registered with the Data Protection Board and comply with governance, transparency, and security requirements.
- The Rules also lay down standards for encryption, masking, tokenisation, access controls, activity logging, backup systems, and business-continuity planning, making these safeguards mandatory for all fiduciaries.
- In the event of a data breach, fiduciaries must provide immediate intimation to the Board and deliver a fuller report within 72 hours while simultaneously informing affected users about the nature of the breach, potential harm, and mitigation steps.
- The Digital Personal Data Protection (DPDP) Act is India’s first full-scale privacy law, introducing explicit and affirmative consent for data processing and codifying a clear set of rights for individuals, including withdrawing consent, correcting or erasing data, and seeking timely grievance redressal.
- The Act also requires mandatory breach notifications to both regulators and affected users and imposes steep penalties up to Rs 250 crore for violations.