The commencement ledger
The Digital Personal Data Protection Act, 2023 (No. 22 of 2023) received Presidential assent on 11 August 2023. Section 1(2) provides for commencement on dates appointed by Central Government notification, with different dates permitted for different provisions.
Under the Digital Personal Data Protection Rules, 2025, Rules 1, 2 and 17–21 commence on Gazette publication; Rule 4 is scheduled one year after publication; and Rules 3, 5–16, 22 and 23 are scheduled eighteen months after publication. Rules 6, 7 and 8 therefore sit in that future eighteen-month tranche. The exact Gazette publication date was not verified, so this page does not convert that interval into a calendar date.
Official MeitY Rules PDF (opens in a new tab)
Seven readiness points
1 · Rule 6(1)(a) / working-paper item (i)
Requirement: Encryption, obfuscation, masking or virtual tokens as reasonable security safeguards.
PDI control outcome: Mask / Vault / Strip for supported structured data, subject to policy and legal hold.
Boundary: Structured-data remediation only; it does not establish that the full safeguard duty is legally sufficient.
2 · Rule 6(1)(c) / working-paper item (iii)
Requirement: Logs, monitoring and review enabling detection, investigation and remediation.
PDI control outcome: Kestryl audit row product capability supports review evidence.
Boundary: Audit rows support the control; they do not by themselves satisfy all monitoring, detection, investigation or remediation duties.
3 · Section 8(7) and Rule 8
Requirement: Erase on withdrawal or when the specified purpose is no longer served, whichever is earlier, unless legal retention is necessary. Rule 8/Third Schedule adds a three-year inactivity trigger only for specified classes and thresholds: e-commerce entities with at least 2 crore registered users, online gaming intermediaries with at least 50 lakh users, and social-media intermediaries with at least 2 crore users, subject to stated exclusions; give at least 48 hours’ pre-erasure notice.
PDI control outcome: Strip for supported structured data plus erasure evidence.
Boundary: Subject to policy, legal hold, applicable retention law, class/threshold scoping and downstream processor duties. Documents and attachments are inventoried, not altered.
Official source (opens in a new tab) Official source (opens in a new tab)
4 · Rule 7 (implementing Section 8(6))
Requirement: Inventory the nature, extent, timing and location of the breach; notify affected Data Principals without delay; notify the Board without delay and provide the detailed report within 72 hours of awareness, unless the Board allows longer on written request.
PDI control outcome: Discovery and inventory can support breach scoping and evidence preparation.
Boundary: Documents and attachments are scanned and inventoried, not altered. PDI does not send notices or determine legal reportability.
Official source (opens in a new tab) Official source (opens in a new tab)
5 · Section 6(10)
Requirement: The burden is on the Data Fiduciary to prove notice and consent only where consent is relied upon.
PDI control outcome: Evidence packs support review of notice/consent artefacts and related data locations.
Boundary: Evidence packs do not prove legal sufficiency, validity of consent, or that consent is the correct lawful basis.
6 · Section 33(2)(e)
Requirement: The Board must consider whether mitigation occurred and the timeliness and effectiveness of that action when determining a monetary penalty.
PDI control outcome: The discovery-to-review-to-remediation chain supports evidence of mitigation activity and timing.
Boundary: Technical evidence supports review; it does not determine the Board’s penalty or prove effectiveness.
7 · Aadhaar (Sharing of Information) Regulations, 2016
Requirement: Core biometric information may not be shared; core biometrics captured for authentication by a requesting entity may not be stored or shared; identity information is purpose- and consent-constrained.
PDI control outcome: OCR identifies Aadhaar text in scans, images and shared drives for inventory and review.
Boundary: PDI does not mask, redact or otherwise alter source documents or attachments.
How Kestryl fits
Kestryl supports discovery and inventory across structured data and unstructured attachments or images, creates audit rows and evidence packs, and offers Mask, Vault, and Strip modes for supported structured data under approved policy. It does not alter source attachments or documents, perform legal notice, establish valid consent, satisfy erasure by itself, or prove legal compliance.
Educational information, not legal advice. Confirm commencement notifications, applicability, exceptions, and operative text before relying on this mapping.