India has enacted the Digital Personal Data Protection (DPDP) Rules, 2025, introducing stringent requirements for consent management, data retention, and algorithmic oversight. The new regulations require organizations to implement itemized user notices, verifiable parental consent for children's data, and fixed deletion timelines, impacting sectors such as e-commerce, gaming, and social media. Significant Data Fiduciaries—large platforms handling sensitive data—must now conduct annual data protection impact assessments and audits, and apply additional controls to algorithmic systems processing personal data.
To comply, companies must redesign their data architectures, including the deployment of consent managers, encrypted storage zones, and real-time governance tools across both cloud and on-premises environments. The rules also establish a new category of Consent Managers, mandate the maintenance of one-year processing logs, and require the appointment of officers to handle user queries. Staggered compliance deadlines give enterprises 12 to 18 months to adapt, while certain health and allied services are granted exemptions for child data processing under specific conditions.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
The new rules gave organizations phased compliance windows of 12 to 18 months to implement required controls such as consent managers, automated deletion, encrypted storage, logging, and governance processes.
India's Digital Personal Data Protection (DPDP) Rules, 2025, were introduced, establishing detailed requirements for consent management, data retention, parental verification, grievance handling, and oversight obligations for organizations processing personal data.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.