Discuss this page with an LLM

What This Means In Practice

Use this table to brief your legal, product and marketing teams.

Question DPDP Direction Rules: Key Differences Direction Practical Impact
Can we process by default? Often consent-first Often depends on a different legal model India flows may need earlier consent design.
Is a global privacy model enough? No Not always Global privacy work does not map one-to-one to DPDP.
Are children protected differently? Under 18 Check local age thresholds Indian child-user products need stricter review.
Is breach risk enough to trigger work? Yes Yes Security, response and evidence matter in both systems.

Three Questions To Ask Internally

  1. Are we copying a non-India privacy model into an Indian product?
  2. Do our consent flows work for Indian users?
  3. Which global privacy controls can be reused, and which must be redesigned for DPDP?

If you operate across India and another market, do not assume one privacy program covers both. Use the stricter flow where user trust and evidence matter most.

Want all of this handled, end to end? Sanctum is the all-in-one DPDP compliance programme behind this site: legal position, data map, gap analysis, implementation, tooling, training, readiness opinion, and breach cover under one accountable owner. How all-in-one DPDP compliance works or see the Sanctum programme.

Framework vs. Operation

The Act provides the legal skeleton for data protection in India. It defines who is responsible for data and what rights individuals have. The Rules provide the muscle and movement. While the Act says you must protect data, the Rules explain the exact security standards and reporting formats you must use.

Concrete Timelines and Forms

The Act establishes the duty to report data breaches but does not set a clock. The Rules define a strict 72-hour window for notifying the Data Protection Board. Similarly, the Act gives users the right to file grievances, but the Rules set a 15-day limit for companies to resolve those complaints.

FeatureDPDP Act 2023DPDP Rules 2025
PurposeSets legal obligationsDefines operational steps
Breach ReportingGeneral duty to report72-hour reporting deadline
Consent NoticeMandates a clear noticeLists specific notice items
Grievance RedressalRight to file complaints15-day resolution timeline
Childrenโ€™s DataVerifiable parental consentMethods for age verification
SDF CriteriaDefines the categorySets user count thresholds
User RightsRight to access and eraseSpecific forms for requests
Consent ManagersRegistration requirementTechnical and audit standards

Notice Requirements

The Act requires a notice to be โ€œclear and plain.โ€ The Rules go further by listing exactly what must be in that notice. This includes the contact details of the Data Protection Officer and the specific procedure for a user to withdraw their consent. If your notice lacks these specific fields, it does not meet the standards set by the Rules.

This week

Review your internal grievance handling process. Update your documentation to ensure that every user complaint is tracked and resolved within 15 days to meet the timeline set by the Rules.

FAQ

Q: Do the Rules replace the Act? A: No, the Rules supplement the Act. The Act provides the legal power, while the Rules provide the specific steps, forms, and timelines for compliance.

Q: What happens if the Act and Rules overlap? A: The Act is the primary law and takes precedence. The Rules are designed to fill in the gaps for daily operations and do not change the core legal duties.

Q: Are the timelines in the Rules mandatory? A: Yes. Once the Rules are notified, the specific windows for reporting breaches and answering user requests become legal requirements for all companies.

Confused by the differences?

Dual compliance is tricky. Our experts can help you navigate both Rules: Key Differences and DPDP requirements.

Book Strategy Call
Book clarity call