The DPDP Rules 2025 Compliance Calendar: What Law Firms and Legal-Tech Vendors Need to Track
4 September 2026 · 7 min read
This article provides general information for educational purposes only and does not constitute legal advice. It should not be relied upon as a substitute for advice from a qualified advocate familiar with your specific facts and circumstances.
What actually got notified, and when
The Ministry of Electronics and Information Technology (MeitY) notified the Digital Personal Data Protection Rules, 2025 on 14 November 2025, under the Digital Personal Data Protection Act, 2023 (DPDP Act). The Rules are the operational layer the Act itself had largely left to subordinate legislation - they specify how obligations like consent, breach notification, and cross-border transfer restrictions actually work in practice.
A phased timeline, not a single cutover date
The Rules don't take full effect all at once. Government notifications have staged enforcement of different provisions over roughly an eighteen-month window following the initial notification, giving Data Fiduciaries time to build the required technical and governance controls rather than facing a single hard deadline. Because staged effective dates can be clarified or adjusted by further notification, anyone tracking this for compliance purposes should confirm the current status against MeitY's own notifications rather than relying on a fixed date from any single secondary source, including this one.
The core mechanics worth understanding
Consent Managers: the Rules establish a framework for registered, interoperable Consent Manager platforms, and Data Fiduciaries are expected to have systems technically capable of accepting and honoring consent signals routed through them.
Breach notification: on becoming aware of a personal data breach, a Data Fiduciary has to notify affected Data Principals without delay, and provide a more detailed report to the Data Protection Board of India within a set window after discovery (72 hours, per the notified Rules).
Cross-border transfer: the Rules take a 'blacklist' approach - transfers outside India are generally permitted unless the Central Government specifically restricts a particular country or a particular category of transfer by order, rather than requiring a jurisdiction to be pre-approved before any transfer can happen.
What this means for a law firm or legal-tech vendor specifically
A firm or vendor handling client and matter data can sit in either the Data Fiduciary role (for its own account and billing data) or a Data Processor role (processing client/matter data on an advocate's behalf), sometimes both for different data categories on the same platform. Practical steps worth having in place regardless of the exact phased deadline: a specific, non-generic privacy notice; a documented breach-response process that can meet the notification windows above; and documented security safeguards - encryption, access controls, logging, audit trails - rather than an informal, undocumented practice that happens to be reasonably secure.
What this is, and isn't
This is a general overview of a real, notified set of Rules, not a compliance certification, and not legal advice. Whether and how these Rules apply to a specific firm's specific data flows depends on facts this article can't know - that determination needs qualified counsel reviewing the actual processing activities involved.
See our Privacy Policy for how LegalDreams currently applies these principles to its own website, and our Security & Trust Center for what's implemented today versus what's still planned.
See how this fits LegalDreams
LegalDreams is being built around the principles in this article - source-grounded, reviewable legal work for Indian advocates.