The DPDP Act, made practical for your organisation.
India's Digital Personal Data Protection Act, 2023 governs digital personal data through consent and certain legitimate uses. This guide covers scope, the rights of Data Principals, the duties of Data Fiduciaries, the additional obligations that fall on Significant Data Fiduciaries, the DPDP Rules 2025 and their phased commencement, and the DPIA and RoPA you need in order to demonstrate any of it.
Reviewed against the Act and the DPDP Rules, 2025 on . Written by Shambhu Kumar, Vedhacon.
Eight pillars of the Act
Everything else in the Act is detail hanging off one of these eight.
Lawful processing
Personal data may be processed only for a lawful purpose, on valid consent or for a certain legitimate use.
Data Principal rights
Access, correction and erasure, grievance redressal, and nomination for death or incapacity.
Fiduciary duties
Security safeguards, data quality, breach response, and erasure once retention is no longer required.
Significant Data Fiduciary
Extra duties on notification: an India-based DPO, an independent auditor, and periodic DPIA and audit.
Data Protection Board
A digital-by-design statutory body that inquires, directs remedial measures and imposes penalties.
Cross-border transfer
A negative-list model. Transfer is permitted unless the Central Government notifies a restricted country.
Children's data
Verifiable parental consent, no processing likely to harm a child, and no tracking or targeted advertising.
Penalties to ₹250 crore
Monetary penalties scaled to the nature, gravity and duration of the contravention.
The enforcement timeline
The DPDP Rules, 2025 were notified on 13 November 2025. The Act and Rules commence in phases, with different dates for different provisions.
Phase 1 · 13 Nov 2025
In force on publication: the definitions, and the framework establishing the Data Protection Board. Rules 1, 2 and 17 to 21.
Phase 2 · 13 Nov 2026
One year after publication: registration and the obligations of Consent Managers. Rule 4 and the First Schedule.
Phase 3 · 13 May 2027
Eighteen months after: every substantive obligation. Notice, security safeguards, breach intimation, children's data, SDF duties, rights, transfers and appeals. Rules 3, 5 to 16, 22 and 23.
The Act at a glance, nine chapters
Preliminary
Short title and commencement, definitions, and territorial and material application.
Obligations of Data Fiduciary
Grounds for processing, notice, consent, legitimate uses, general obligations, children, and SDF duties.
Rights & duties of Data Principal
Access, correction and erasure, grievance redressal, nomination, and the duties owed in return.
Special provisions
Processing outside India, and the exemptions available under the Act.
Data Protection Board of India
Establishment, composition, terms of service, disqualifications, proceedings and powers.
Powers & procedure of the Board
The functions of the Board and the inquiry procedure it must follow.
Appeal & dispute resolution
Appeals to the Tribunal, executability of orders, mediation, and voluntary undertakings.
Penalties & adjudication
Monetary penalties under the Schedule, and crediting realised sums to the Consolidated Fund.
Miscellaneous
Good-faith protection, information powers, blocking directions, rule-making and consequential amendments.
All 44 sections, explained
Open a chapter to read every section in plain language.
Chapter I, PreliminarySections 1–3
Chapter II, Obligations of Data FiduciarySections 4–10
Chapter III, Rights & duties of the Data PrincipalSections 11–15
Chapter IV, Special provisionsSections 16–17
Chapter V, Data Protection Board of IndiaSections 18–26
Chapter VI, Powers & procedure of the BoardSections 27–28
Chapter VII, Appeal & alternate dispute resolutionSections 29–32
Chapter VIII, Penalties & adjudicationSections 33–34
Chapter IX, MiscellaneousSections 35–44
Definitions glossary
Nineteen defined terms. Search to filter.
Appellate Tribunal
The Telecom Disputes Settlement and Appellate Tribunal established under the TRAI Act, 1997.
Automated
Any digital process capable of operating automatically in response to instructions given to carry out a set of operations.
Board
The Data Protection Board of India, established under Section 18.
Certain legitimate uses
The uses listed in Section 7 on which personal data may be processed without a separate consent request.
Child
An individual who has not completed eighteen years of age.
Consent Manager
A person registered with the Board who acts as a single point of contact enabling a Data Principal to give, manage, review and withdraw consent.
Data
A representation of information, facts, concepts, opinions or instructions in a manner suitable for communication, interpretation or processing.
Data Fiduciary
Any person who alone or with others determines the purpose and means of processing personal data. The closest analogue to a controller.
Data Principal
The individual to whom the personal data relates. Where the individual is a child, it includes the parents or lawful guardian.
Data Processor
Any person who processes personal data on behalf of a Data Fiduciary.
Data Protection Officer
An individual appointed by a Significant Data Fiduciary under Section 10(2)(a), based in India and answerable to the board of directors.
Digital personal data
Personal data in digital form. The Act does not reach purely offline records that are never digitised.
Notification
A notification published in the Official Gazette, the mechanism by which the Government designates SDFs, restricted countries and exemptions.
Personal data
Any data about an individual who is identifiable by or in relation to such data. Note there is no separate sensitive category under this Act.
Personal data breach
Any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises confidentiality, integrity or availability.
Processing
A wholly or partly automated operation on digital personal data, including collection, recording, storage, use, sharing, indexing, erasure or destruction.
Significant Data Fiduciary
Any Data Fiduciary, or class of them, notified by the Central Government under Section 10, attracting additional obligations.
Specified purpose
The purpose mentioned in the notice given to the Data Principal. Processing may not drift beyond it without fresh consent.
State
The State as defined under Article 12 of the Constitution of India.
No matching term. Try consent, breach, child, processor or Board.
Certain legitimate uses
The only alternative to consent. The list is closed, so if a use is not here, consent is required.
Voluntarily provided
Data the individual voluntarily gave for a specified purpose, where they have not indicated that they object to its use.
State benefits & services
Provision by the State of a subsidy, benefit, service, certificate, licence or permit, subject to Second Schedule standards.
Sovereignty & State function
Performance of any function under law, and the sovereignty, integrity and security of India.
Legal obligation & orders
Disclosure required by law, and compliance with any judgment, decree or order in India or abroad.
Medical & public health
Medical emergencies threatening life or health, and provision of health services during an epidemic or outbreak.
Disaster & employment
Safety during a disaster or breakdown of public order, and employment purposes including safeguarding the employer from loss.
Key exemptions
Processing necessary for enforcing any legal right or claim.
Processing by a court, tribunal or other body entrusted by law with judicial, quasi-judicial, regulatory or supervisory functions.
Prevention, detection, investigation or prosecution of any offence or contravention of law.
Processing in India of the personal data of individuals outside India, under a contract with a person outside India. This is the limb most Indian outsourcing and GCC operations rely on.
Mergers, demergers, amalgamations or reconstructions approved by a competent court or authority.
Where carried out in accordance with the standards in the Second Schedule, and not used to take any decision specific to a Data Principal.
The Government may exempt notified State instrumentalities, and certain classes of start-up from specified provisions, having regard to the volume and nature of data processed.
Rights of Data Principals
Five rights, and the duties owed in return. Note what is absent: there is no portability right and no general right to object.
A summary of the data processed, the activities undertaken, and the identities of Fiduciaries and Processors with whom it was shared.
Correction, completion, updating and erasure, unless retention remains necessary for the specified purpose or is required by law.
A readily available mechanism, answered within the Rule 14 period, and to be exhausted before approaching the Board.
To nominate another individual to exercise these rights in the event of death or incapacity. An unusual provision, and one few systems are built to handle.
Withdrawal must be as easy as giving consent, and the consequences of withdrawal fall on the Data Principal. Processing must cease within a reasonable time.
Not to impersonate, not to suppress material information, not to raise false or frivolous grievances, and to furnish authentic information.
What every Data Fiduciary must do
These apply to every Fiduciary, of any size, from the first record processed. Engaging a Processor does not transfer accountability, it only distributes the work.
The Fiduciary is responsible for compliance in respect of any processing undertaken by it or on its behalf by a Data Processor.
An itemised description of the data and purposes, in plain language, with links to withdraw consent, exercise rights, and complain to the Board.
Completeness, accuracy and consistency where the data is used to make a decision affecting the Data Principal, or is disclosed to another Fiduciary.
Rule 6 names them: encryption, obfuscation, masking or virtual tokens; access control; monitoring and review logs retained for one year; backups; and contractual measures binding Processors.
Intimate both the Board and every affected Data Principal, in the form and within the timelines set by Rule 7.
Erase on withdrawal of consent or once the purpose is no longer being served, unless retention is required by law, with 48 hours' advance notice to the individual under Rule 8.
The business contact of a DPO, or of a person able to answer questions about processing, displayed on the website and in every notice.
Publish how rights are exercised and respond within the period specified under Rule 14, which may not exceed ninety days.
Significant Data Fiduciary, the obligations on top
You become an SDF by Government notification, not by self-assessment. But the criteria are known, so the sensible move is to assess whether you are likely to be designated, and prepare accordingly.
Appoint a DPO
Based in India, representing the SDF under the Act, answerable to the board of directors or equivalent, and named as the point of contact for grievance redressal.
Appoint an independent auditor
An independent data auditor to evaluate compliance, whose findings are reported to the board rather than to the team being audited.
Periodic DPIA and audit
Rule 13 requires both to be conducted annually, with the DPO submitting a report on significant observations to the SDF.
Algorithmic due diligence
Verify that algorithmic software used for processing does not pose a risk to the rights of Data Principals. A direct link between DPDP and AI governance.
Transfer restrictions
Ensure that specified categories of personal data, and the traffic data relating to their flow, are not transferred outside India where the Government so directs.
Designation criteria
Volume and sensitivity of data, risk to Data Principals, risk to electoral democracy, security of the State, and public order.
DPDP Rules, 2025, the operational rulebook
The Act states the obligation. The Rules tell you what satisfying it actually looks like.
Notice to the Data Principal
Standalone, understandable on its own, in plain language, with an itemised list of data and purposes, and links to withdraw consent, exercise rights and complain.
Consent Managers
Registration with the Board, a minimum net worth of ₹2 crore, and the detailed obligations in the First Schedule.
State processing standards
Second Schedule standards where the State processes data for a subsidy, benefit, service, certificate, licence or permit.
Reasonable security safeguards
Encryption or masking, access control, one-year monitoring and access logs, backups for continuity, and security clauses in Processor contracts.
Breach intimation
Affected individuals told without delay. The Board told without delay, with a fuller report following within 72 hours.
Retention & erasure
Third Schedule periods after which data must be erased, 48 hours' advance notice to the individual, and one-year log retention.
Contact information
Publish the business contact of a DPO or of a person able to answer questions about processing, on the website and in every notice.
Verifiable consent
Due diligence to confirm that a self-identified parent is an identifiable adult, and to verify that a guardian is lawfully appointed.
Children's data exemptions
Fourth Schedule classes and purposes exempt from parts of Section 9, including healthcare, education and child-safety contexts, subject to conditions.
SDF additional obligations
Annual DPIA and audit, algorithmic software diligence, and observance of specified-data transfer restrictions.
Exercise of rights
Publish the means and the particulars required to identify a requester, and answer grievances within a published period not exceeding ninety days.
Transfer outside India
Transfers are subject to any requirement the Central Government may specify in respect of a foreign State or an entity controlled by it.
Research & statistics
The Act does not apply to research, archiving or statistical purposes carried out to Second Schedule standards.
The Board
Selection and appointment, terms of service, meeting procedure, functioning as a digital office, and staff terms.
Appeal to the Tribunal
Digital filing, adherence to natural justice, and payment of fees through UPI or other authorised systems.
Calling for information
The Government may require a Fiduciary or intermediary to furnish specified information for Seventh Schedule purposes.
The seven schedules
Consent Managers
Conditions of registration and the detailed obligations placed on a Consent Manager.
State & research standards
Processing standards for the State, and for research, archiving and statistical purposes.
Retention periods
A three-year retention limit for large e-commerce entities, online gaming intermediaries and social media intermediaries.
Children's data exemptions
The classes of Fiduciary and the purposes exempt from parts of Section 9.
Board members' service
Salary, allowances and terms of service of the Chairperson and Members.
Board staff
Terms and conditions of the officers and employees of the Board.
Information & authorities
The purposes for which information may be called for, and the authorised persons who may call for it.
The penalty Schedule
The Schedule to the Act itself, referred to in Section 33, listing the maximum penalty for each contravention.
DPIA, assessing risk before you process
A DPIA is a structured way to identify and reduce the data-protection risks of a processing activity before it begins. Under the DPDP Act it is a periodic obligation for Significant Data Fiduciaries under Section 10 and Rule 13. For everyone else it is not named in the statute, but it remains the only practical way to show that you considered the risk to Data Principals at all.
When a DPIA is needed
New systems or products, processing at scale, profiling or automated decisions, a new vendor or data-sharing arrangement, children's data, biometrics or location, any use of AI on personal data, and on a periodic basis for every SDF.
What a DPIA must cover
A description of the processing and its purposes, an assessment of necessity and proportionality, the risks to the rights of Data Principals, and the measures that reduce those risks to an acceptable level.
The DPIA in eight steps
Describe
Map the processing, the data flows, the purposes, and every system and vendor involved.
Test necessity
Lawful ground, purpose limitation and minimisation. Is every field genuinely needed?
Consult
Engage the owning team, security, legal, and where useful the Data Principals themselves.
Identify risks
Assess likelihood and severity of harm to individuals, not inconvenience to the business.
Mitigate
Assign controls: minimisation, encryption, retention limits, access control, contract terms.
Sign off
Record the residual risk and obtain DPO or accountable-owner approval before go-live.
Review
Revisit when the processing, the vendors or the law change, and on the annual SDF cycle.
Algorithms
For an SDF, Rule 13 adds diligence on algorithmic software used in the processing.
RoPA, the inventory behind accountability
A Record of Processing Activities is a living inventory of how your organisation uses personal data. The DPDP Act does not name it as a standalone obligation, but nearly every duty it does impose, notice, consent, security, retention, breach scoping and rights fulfilment, is unanswerable without one. It is the evidence base the Section 8 duties and the SDF audit both read from.
| Field | What it records | DPDP anchor |
|---|---|---|
| Processing activity | The business process and the specified purpose it serves. | Sec 4, 5 |
| Categories of data | The personal data fields, flagged where they relate to children. | Sec 2, 9 |
| Data Principals | Whose data it is: customers, employees, vendors, minors. | Sec 2 |
| Lawful ground | Consent, or the specific legitimate use relied on. | Sec 4, 6, 7 |
| Recipients | Processors, sub-processors and any other Fiduciaries. | Sec 8, 11 |
| Retention | The retention period and the trigger that starts erasure. | Rule 8, Sch 3 |
| Transfers | Any transfer outside India and the restriction that applies. | Sec 16, Rule 15 |
| Safeguards | The security measures protecting that data in that system. | Sec 8, Rule 6 |
Why it matters
You cannot secure, retain or erase data you have never mapped. When a breach happens, the RoPA is what tells you within hours whose data was affected.
How it connects
It feeds notices, consent design, DPIAs, vendor contracts, breach scoping and rights fulfilment. Each of those reads from the RoPA rather than starting again.
Keeping it live
Review on change and on a set cadence. An out-of-date RoPA fails the first question any auditor asks, which is usually "when was this last reviewed".
The breach intimation clock
Rule 7 has two legs running at once, which is the detail most summaries get wrong. There is no single "72-hour rule" here. Individuals must be told without delay, and so must the Board, with a fuller report to the Board following within 72 hours.
To each affected Data Principal
Without delay, in plain language: a concise description of the breach including its nature, extent and timing; the likely consequences for that individual; the measures being taken to mitigate risk; the safety steps they themselves might take; and the business contact able to answer their questions.
To the Data Protection Board
Without delay: a description of the nature, extent, timing and likely impact. Then within 72 hours, or a longer period the Board allows on written request: updated and detailed facts, the circumstances and causes, the mitigation measures implemented, findings on the person who caused it, remedial measures to prevent recurrence, and a report on the intimations given to affected individuals.
Response, end to end
Detect
Become aware, through monitoring, a staff report or an external notification.
Assess
Establish nature, scope and severity, without letting the assessment delay notification.
Notify the Board
In the prescribed form, then follow with the detailed report within 72 hours.
Notify individuals
Tell each affected person what happened, what it means for them, and what to do.
Remediate
Fix the cause, record the response, and update the breach register for audit.
Penalty structure
The Schedule to the Act sets a maximum for each contravention. The Board decides the amount within it.
DPDP against GDPR and CCPA / CPRA
| Dimension | DPDP Act, India | GDPR, European Union | CCPA / CPRA, California |
|---|---|---|---|
| Lawful grounds | Consent, or a certain legitimate use. No legitimate-interests basis. | Six lawful bases including legitimate interests. | Notice and opt-out model rather than a basis model. |
| Sensitive data | No separate category defined. | Special categories with additional conditions. | Sensitive personal information with a right to limit use. |
| Transfers | Negative list. Permitted unless the country is notified as restricted. | Adequacy, SCCs, BCRs and derogations. | No specific cross-border transfer regime. |
| Portability | No portability right. | Portability and erasure rights. | Right to know, delete and correct. |
| Right to object | None. Withdrawal of consent is the nearest equivalent. | Right to object, including to direct marketing. | Opt-out of sale and sharing. |
| Children | Verifiable parental consent under 18. No tracking or targeted advertising. | Conditions for information society services, 13 to 16 by member state. | Opt-in required for sale of data of under-16s. |
| Breach reporting | Every breach, without delay, plus a 72-hour report to the Board. | 72 hours where a risk to rights and freedoms is likely. | Notification under separate state breach law. |
| Maximum penalty | Up to ₹250 crore per contravention. | Up to 4 percent of global annual turnover. | Per-violation civil penalties. |
| Regulator | Data Protection Board of India, appeals to TDSAT. | A supervisory authority in each member state. | California Privacy Protection Agency. |
DPDP readiness, from notice to evidence
We establish what applies to you, design notice and consent that satisfies Sections 5 and 6, build the Section 8 controls and any SDF obligations, and prepare the RoPA, DPIA and audit evidence that the Board would expect to see.