India's Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 and commence in three phases. Definitions and the Data Protection Board took effect on notification. Registration of Consent Managers follows one year after publication, around 12 November 2026. The substantive obligations — notice and consent, security safeguards, retention and erasure, breach intimation, data principal rights, Significant Data Fiduciary duties and the children's data framework — follow eighteen months after publication, around 12 May 2027. In a learning context the Rules become relevant wherever learner data is collected, retained, analysed or passed onward, and the institution and the platform operator can occupy different roles under them.
This is general information, not legal advice.
DPDP obligations depend on the facts of your organisation and how it processes personal data. The Rules are phased and some provisions have not yet commenced. Before you act on anything here, take advice from a qualified professional on your own circumstances.
Key takeaways
- The DPDP Rules, 2025 were notified on 13 November 2025 and commence in three phases under rule 1(2): on publication, on the expiry of one year, and on the expiry of eighteen months.
- Almost everything with day-to-day consequence — notice and consent, security safeguards, retention and erasure, breach intimation, data principal rights and the whole children's framework — sits in the eighteen-month phase.
- The Act separates a Data Fiduciary, which determines the purpose and means of processing, from a Data Processor acting on its behalf. In a learning deployment the institution and the platform operator can fall on different sides of that line, and the classification follows the facts rather than a label in a contract.
- Part A of the Fourth Schedule lists classes of Data Fiduciary, educational institutions among them, for whom two sub-sections of section 9 do not apply, subject to conditions stated in that Part. The prohibition on processing likely to have a detrimental effect on a child's wellbeing is not among the provisions disapplied.
- Rule 7 requires intimation to each affected Data Principal without delay and a detailed report to the Data Protection Board within seventy-two hours; the Schedule to the Act sets penalty ceilings, the highest being two hundred and fifty crore rupees.
What the Rules say, and when each part applies
The Digital Personal Data Protection Act, 2023 was passed three years ago, but for most of that time it had no operative machinery. That changed on 13 November 2025, when the Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025 by gazette notification G.S.R. 846(E), alongside the Act's own commencement notification.
Rule 1(2) of the Rules sets out a three-part commencement. Rules 1, 2 and 17 to 21 — the short title, the definitions, and the constitution, procedure and transitional provisions of the Data Protection Board — came into force on the date of publication. Rule 4, governing the registration of Consent Managers, comes into force on the expiry of one year from publication. Rules 3, 5 to 16, 22 and 23 come into force on the expiry of eighteen months.
| Commences | Rules | What that phase carries |
|---|---|---|
| 13 November 2025 already in force | 1, 2, 17–21 | Short title and commencement, definitions, and the Data Protection Board's constitution, procedure and transitional provisions. The regulator exists from this date. |
| Around 12 November 2026 one year from publication | 4 | Registration of Consent Managers and the conditions attached to it, including the net worth condition in the First Schedule. |
| Around 12 May 2027 eighteen months from publication | 3, 5–16, 22, 23 | Notice, consent and its withdrawal, reasonable security safeguards, retention and erasure, intimation of personal data breach, children's data, Significant Data Fiduciary obligations, data principal rights and grievance redressal, and processing outside India. |
A note on those two later dates. Published commentary states them variously as 12 or 13 November 2026 and 12 or 13 May 2027, depending on how “the expiry of one year” and “the expiry of eighteen months” from a 13 November 2025 publication are counted. Both readings are defensible on the text; the earlier date in each pair is the more conservative and therefore the safer basis to plan against, and this post uses it on that footing.
Who the Rules treat as a Data Fiduciary in a learning context
The Act turns on two definitions. A Data Fiduciary is any person who alone or in conjunction with others determines the purpose and means of processing personal data. A Data Processor is a person who processes personal data on behalf of a Data Fiduciary. The obligations in the Rules attach overwhelmingly to the Fiduciary; the Processor's position is largely governed by the contract the Rules require the Fiduciary to put in place.
Applied to a learning deployment, that distinction usually falls somewhere along the following lines, though it is a question of fact rather than of naming:
- A university, school or employer that decides which learners are enrolled, what is recorded about them and for what purpose is typically the party determining purpose and means for that data.
- A platform operator hosting and running the system under that organisation's instruction is typically processing on its behalf in respect of the same data.
- The same operator can simultaneously be a Data Fiduciary in its own right for data whose purpose it sets itself — enquiries from its own website, its own marketing lists, or a product sold directly to learners rather than through an institution.
- Where a platform reuses learner data for a purpose the institution did not set — model training, product analytics, benchmarking across customers — the party setting that purpose is determining purpose and means for it.
No single allocation holds across every deployment. The Rules do not assign roles by industry; they assign them by who is deciding what, and for which purpose.
What the Rules say about children's data, and what the exemption leaves in place
This is the part of the framework that matters most in education, and it is also the part most often summarised too briefly. A child, under the Act, is an individual who has not completed eighteen years of age. Three provisions of section 9 sit behind everything else:
- Section 9(1) requires verifiable consent of the parent or lawful guardian before processing a child's personal data. Rule 10 sets out how: appropriate technical and organisational measures, and due diligence to check that the individual identifying herself as the parent is an adult identifiable by reliable identity details or by a virtual token mapped to a verified identity.
- Section 9(2) prohibits processing likely to cause any detrimental effect on the wellbeing of a child.
- Section 9(3) prohibits tracking or behavioural monitoring of children and targeted advertising directed at children.
Rule 12 then creates exemptions, and their shape is worth stating precisely. Rule 12(1) provides that sub-sections (1) and (3) of section 9 do not apply to processing of a child's personal data by the classes of Data Fiduciary listed in Part A of the Fourth Schedule — a list that includes educational institutions, alongside clinical and mental health establishments, healthcare professionals, crèches and child day-care centres, and entities engaged by educational institutions for the transport of children. Rule 12(2) does the same for the purposes listed in Part B. Both exemptions are expressly subject to the conditions specified in the relevant Part.
Those conditions are the operative limit. For educational institutions the exemption is stated in terms of tracking and behavioural monitoring for the educational activities of the institution, or in the interests of the safety of the children enrolled with it. Two consequences follow directly from the text, and they are worth holding together with the exemption rather than separately from it:
- Section 9(2) is not among the provisions disapplied. Rule 12 lifts sub-sections (1) and (3) only. Processing likely to cause a detrimental effect on the wellbeing of a child remains prohibited, for every Data Fiduciary, including those listed in the Fourth Schedule.
- The exemption is bounded by its purpose. Tracking or behavioural monitoring for a purpose outside the institution's educational activities or the child's safety is not covered by the condition, and targeted advertising directed at children is the clearest case of something that sits outside it.
One question the text does not settle
Learning platforms commonly score engagement — time on page, login cadence, submission patterns — and surface learners as at risk. Where the learner is under eighteen and the institution is relying on the Fourth Schedule condition, whether that scoring falls within “the educational activities of such institution” or outside it is not resolved by the language of the Rules, and no authoritative interpretation had been issued as this was written. Both readings are arguable. The narrower reading — that the condition covers monitoring tied to the institution's own educational activity and not analytics carried out for other ends — is the more conservative of the two. This post raises the question and does not answer it, because it does not have a settled answer.
For any particular school, college or training provider, the answer to a question in this area depends on facts a published article does not have: what is actually collected, by whom, for which stated purpose, and under what arrangement with whichever platform holds it. That is a conversation for the institution's own legal advisers and for whoever carries its data protection responsibilities.
The obligations in plain language
Stated at the level the Rules state them, and without translating any of it into a to-do list:
Notice and consent
Rule 3 requires the notice given to a Data Principal to be presented independently of any other information, in clear and plain language, with an itemised description of the personal data and the specified purpose, and the means to withdraw consent, to exercise rights, and to complain to the Board.
Reasonable security safeguards
Rule 6 lists them: securing personal data by encryption, obfuscation, masking or virtual tokens; control of access to computer resources; visibility over access through logs, monitoring and review, so unauthorised access can be detected; measures for continued processing in the event of a loss of confidentiality, integrity or availability, such as data backups; appropriate provision in the contract with any Data Processor; and retention of those logs and the personal data for a period of one year, unless another law in force requires otherwise.
Retention and erasure
Rule 8 sets a fixed erasure clock for the classes named in the Third Schedule — e-commerce entities and social media intermediaries with at least two crore registered users, and online gaming intermediaries with at least fifty lakh — under which data is erased after three years of no contact from the Data Principal, with at least forty-eight hours' notice before erasure. Educational institutions and learning platforms are not among those classes, so that particular clock is not the one that runs against them. The general position, that personal data is erased once the specified purpose is no longer being served, comes from the Act rather than from the Third Schedule.
Intimation of a personal data breach
Rule 7 requires, on becoming aware of a breach, intimation to each affected Data Principal — without delay, in concise, clear and plain language, describing the breach, its nature and extent, its likely consequences, the mitigation measures being taken, and the safety measures the individual might take. The Board receives an initial intimation of the breach's description and nature, followed by a detailed report within seventy-two hours of becoming aware of the breach, or within a longer period the Board allows on written request.
Significant Data Fiduciaries
Rule 13 attaches additional duties to Data Fiduciaries the Central Government notifies as significant: a Data Protection Impact Assessment and an audit once every twelve months, a report of significant observations to the Board, due diligence that algorithmic software the Fiduciary deploys is not likely to pose a risk to the rights of Data Principals, and restrictions on transferring outside India any personal data the government specifies. Whether an organisation is a Significant Data Fiduciary is a matter of government notification, not of self-assessment.
Penalties
The Schedule to the Act sets maximum penalties by category: up to two hundred and fifty crore rupees for failure to take reasonable security safeguards; up to two hundred crore rupees for failure to give the required breach intimation; up to two hundred crore rupees in respect of the additional obligations concerning children; up to one hundred and fifty crore rupees for the additional obligations of a Significant Data Fiduciary; and up to fifty crore rupees for breach of any other provision. These are ceilings. The amount in any instance is determined by the Board having regard to the matters the Act directs it to consider, including the nature, gravity and duration of the breach and the type of personal data affected.
How learning platforms are typically built
- Completion and assessment history retained indefinitely, because the record is the evidence
- Engagement analytics and at-risk scoring computed across the whole cohort
- SCORM and xAPI statements emitted to content hosts and statement stores outside the core system
- Plugin and integration estates accumulated over years, each with its own tables
- Proctoring, video and attendance capture switched on per course
- Backups, exports and warehouse feeds kept on their own separate schedules
What the Rules address
- Erasure once the specified purpose is no longer being served
- Tracking and behavioural monitoring of under-18s, bounded by the Fourth Schedule conditions
- Appropriate provision in the contract with every Data Processor handling the data
- An itemised description of the personal data and the purpose, in the notice
- Access control, and logs and monitoring sufficient to detect unauthorised access
- Intimation to affected individuals without delay, and a detailed report to the Board within 72 hours
Where the Rules and a learning platform meet
Read from inside a learning platform, the interesting part is not the obligations themselves but the surface they land on, which has some specific properties.
Learning records are built to be permanent. A completion record's whole value is that it still exists years later, when someone asks whether a person was trained. Erasure once a specified purpose is served, and the itemised-purpose framing in the notice provisions, run along a different axis from that. Rule 6 adds a further wrinkle in the other direction: it requires logs and personal data to be retained for one year unless another law requires otherwise. The two pulls are not contradictory, but reconciling them is a design question rather than a policy one.
Engagement analytics resemble behavioural monitoring when the learner is a minor. Nothing about at-risk scoring was designed with section 9(3) in view, because it predates it. Where the cohort is over eighteen the question does not arise in that form; where it is not, the Fourth Schedule condition is what the analysis turns on, and as set out above the boundary is not settled.
SCORM and xAPI move identifiers outward. A SCORM package reports back into the LMS, but xAPI statements are designed to travel — to a Learning Record Store, to an analytics environment, sometimes to a vendor's own infrastructure. Each statement carries an actor identifier. The processor contract requirement in rule 6, and the notice obligation to itemise what is collected and why, both assume someone knows where those statements end up.
The data map frequently does not exist. A learning estate assembled over a decade — a base platform, plugins adopted at different times, an SSO integration, a reporting warehouse, a video host, a proctoring vendor, several generations of backups — is not usually documented as a set of processing activities, because nothing previously required it to be. Constructing that inventory is generally the long pole in any of this work, and it is the part that cannot be bought.
The gap between the felt deadline and the real lead time
As this is written in late August 2026, the one-year milestone is a little under three months away and the eighteen-month milestone a little under nine. That is a shorter runway than the phrase “May 2027” tends to convey, and the framework offers nothing in between to mark the point at which remaining time stops being sufficient. Building a data inventory across a legacy estate, agreeing a retention schedule that has actual numbers in it, and renegotiating processor terms with several vendors are each measured in months rather than weeks, and they tend to run in sequence rather than in parallel. A platform migration begun in the first half of 2027 would not necessarily conclude before the eighteen-month provisions are live. That is an observation about lead times, not a prediction about anyone in particular.
What is settled, and what is not
Keeping the two apart is most of the value in reading this area at the moment.
Settled by the text: the notification date; the three-phase commencement structure in rule 1(2) and which rules sit in each phase; the content of the security safeguards in rule 6; the breach intimation obligations and the seventy-two hour report in rule 7; the Third Schedule classes and their three-year clock; the verifiable parental consent mechanism in rule 10; the structure of the Fourth Schedule exemptions and the fact that section 9(2) is not among the provisions disapplied; the additional duties of Significant Data Fiduciaries in rule 13; and the penalty ceilings in the Schedule to the Act.
Not settled, as this was written: whether “the expiry of one year” and “the expiry of eighteen months” land on 12 or 13 of the relevant month; where engagement scoring of an under-18 learner sits relative to the Fourth Schedule condition; which organisations will be notified as Significant Data Fiduciaries, and on what criteria; and how the Board will approach the matters it must consider in setting a penalty, none of which has yet been tested in a decided case.
Where a provision has two defensible readings, the more conservative one is the safer basis to plan against — and where a question depends on an organisation's own facts, the Rules do not answer it from a distance.
Frequently asked questions
When do the DPDP Rules 2025 take effect?
In three phases from their notification on 13 November 2025. Rules 1, 2 and 17 to 21 — short title, definitions and the Data Protection Board's constitution and procedure — took effect on publication. Rule 4, on Consent Manager registration, takes effect on the expiry of one year, around 12 November 2026. Rules 3, 5 to 16, 22 and 23, which carry notice and consent, security safeguards, retention and erasure, breach intimation, children's data, Significant Data Fiduciary duties and data principal rights, take effect on the expiry of eighteen months, around 12 May 2027.
Does the DPDP framework apply to the LMS operator or to the institution using it?
It can apply to both, in different capacities. The Act defines a Data Fiduciary as whoever determines the purpose and means of processing, and a Data Processor as whoever processes on the Fiduciary's behalf. An institution that decides what is recorded about its learners and why is typically determining purpose and means; an operator running the platform under that institution's instruction is typically processing on its behalf for the same data, while remaining a Fiduciary in its own right for data whose purpose it sets itself. The classification follows the facts of who decides what, not the label used in an agreement.
Are educational institutions exempt from the children's data provisions?
Not from all of them. Rule 12, read with Part A of the Fourth Schedule, provides that sub-sections (1) and (3) of section 9 — verifiable parental consent, and the prohibitions on tracking or behavioural monitoring and on targeted advertising directed at children — do not apply to educational institutions, subject to the conditions stated in that Part, which frame the processing in terms of the institution's educational activities or the safety of the children enrolled. Section 9(2) is not among the provisions disapplied, so processing likely to cause a detrimental effect on a child's wellbeing remains prohibited. Processing that falls outside the stated conditions is not covered by the exemption.
What do the Rules say about learning records that are meant to be permanent?
The Rules approach retention from two directions. Rule 8 sets a three-year erasure clock, but only for the classes named in the Third Schedule — large e-commerce entities, social media intermediaries and online gaming intermediaries — which do not include educational institutions or learning platforms. Rule 6, separately, requires logs and personal data to be retained for one year unless another law in force requires otherwise. The general principle that personal data is erased once the specified purpose is no longer served comes from the Act itself, and how that reads against a completion record retained as evidence depends on the purpose stated for holding it.
What are the breach reporting timelines under the Rules?
Rule 7 requires a Data Fiduciary, on becoming aware of a personal data breach, to intimate each affected Data Principal without delay, in concise, clear and plain language, covering the nature and extent of the breach, its likely consequences, the mitigation measures being taken and the safety measures the individual might take. The Data Protection Board receives an initial intimation of the breach's description and nature, followed by a detailed report within seventy-two hours of the Fiduciary becoming aware, or within a longer period the Board allows on written request.
How large can penalties be under the DPDP Act?
The Schedule to the Act sets ceilings by category: up to two hundred and fifty crore rupees for failure to take reasonable security safeguards; up to two hundred crore rupees for failure to give the required breach intimation and, separately, in respect of the additional obligations concerning children; up to one hundred and fifty crore rupees for the additional obligations of a Significant Data Fiduciary; and up to fifty crore rupees for breach of any other provision. These are maximums rather than fixed amounts, determined by the Board on the matters the Act directs it to weigh.
Does an organisation running an LMS need a Data Protection Officer?
The Rules attach that requirement to Significant Data Fiduciaries, a status conferred by Central Government notification rather than reached by self-assessment. Rule 13 sets out what follows from it, including an annual Data Protection Impact Assessment and audit and due diligence over algorithmic software. Whether any particular organisation falls into that category, and what contact details it publishes under rule 9, depends on whether and how it is notified.
Talk it through with us
We build and run learning platforms for a living, and questions about where learner data actually sits — what a plugin estate touches, what a SCORM package sends onward, what a reporting warehouse quietly accumulated — come up in almost every deployment conversation we have. If it would be useful to walk through how your own stack is put together, we are happy to sit down and map it with you.
You can also read how we approach course development, or email marketing@edzlms.com.
This article is the first in a series on the DPDP framework read from inside a learning platform. Later pieces look at the system-by-system surface, the children's provisions in detail, what organisations report as the hardest part of readiness, the cost heads involved, and the policy areas under review.