

ON January 3, 2025, the Ministry of Electronics and Information Technology (MeitY) released the Draft Digital Personal Data Protection Rules (DPDP Rules). The government invited suggestions and objections from stakeholders via the MyGov portal, with a submission deadline of February 18, 2025. An explanatory note accompanied the draft Rules to provide further context.
The draft Rules, consisting of 22 provisions and Seven Schedules, aim to operationalise the Digital Personal Data Protection Act, 2023 (DPDP Act). These Rules clarify crucial aspects, including consent management, security safeguards and procedures for handling personal data breaches.
The DPDP Act represents a significant shift in India’s approach to data privacy. It builds on years of recommendations and judicial decisions that have shaped personal data protection in the country.
In 2011, the Justice A.P. Shah Committee laid the foundation for this legislative framework by recommending privacy laws to safeguard individual data rights. This effort gained momentum after the Supreme Court’s landmark 2017 ruling in Justice K.S. Puttaswamy (Retd.) versus Union of India, which recognised the right to privacy as a fundamental constitutional right.