India · Digital Personal Data Protection Act, 2023

The DPDP Act, made practical for your organisation.

India's Digital Personal Data Protection Act, 2023 governs digital personal data through consent and certain legitimate uses. This guide covers scope, the rights of Data Principals, the duties of Data Fiduciaries, the additional obligations that fall on Significant Data Fiduciaries, the DPDP Rules 2025 and their phased commencement, and the DPIA and RoPA you need in order to demonstrate any of it.

Reviewed against the Act and the DPDP Rules, 2025 on . Written by Shambhu Kumar, Vedhacon.

Overview

Eight pillars of the Act

Everything else in the Act is detail hanging off one of these eight.

Lawful processing

Personal data may be processed only for a lawful purpose, on valid consent or for a certain legitimate use.

Data Principal rights

Access, correction and erasure, grievance redressal, and nomination for death or incapacity.

Fiduciary duties

Security safeguards, data quality, breach response, and erasure once retention is no longer required.

Significant Data Fiduciary

Extra duties on notification: an India-based DPO, an independent auditor, and periodic DPIA and audit.

Data Protection Board

A digital-by-design statutory body that inquires, directs remedial measures and imposes penalties.

Cross-border transfer

A negative-list model. Transfer is permitted unless the Central Government notifies a restricted country.

Children's data

Verifiable parental consent, no processing likely to harm a child, and no tracking or targeted advertising.

Penalties to ₹250 crore

Monetary penalties scaled to the nature, gravity and duration of the contravention.

The structural difference from GDPR. There is no legitimate-interests basis, no statutory right to portability or to object, and no separate category of sensitive personal data. Consent does far more work here than it does in Europe, which is why consent design, and the records behind it, is where most DPDP programmes succeed or fail.
Commencement

The enforcement timeline

The DPDP Rules, 2025 were notified on 13 November 2025. The Act and Rules commence in phases, with different dates for different provisions.

Phase 1 · 13 Nov 2025

In force on publication: the definitions, and the framework establishing the Data Protection Board. Rules 1, 2 and 17 to 21.

Phase 2 · 13 Nov 2026

One year after publication: registration and the obligations of Consent Managers. Rule 4 and the First Schedule.

Phase 3 · 13 May 2027

Eighteen months after: every substantive obligation. Notice, security safeguards, breach intimation, children's data, SDF duties, rights, transfers and appeals. Rules 3, 5 to 16, 22 and 23.

What this means in practice. The date that matters for most organisations is 13 May 2027. Data mapping, notice and consent redesign, retention enforcement and breach readiness all take longer than the time remaining, so the work starts well before the deadline, not at it. Source: DPDP Rules, 2025, Rule 1, notified vide G.S.R. 846(E), MeitY.
Structure

The Act at a glance, nine chapters

CHAPTER I · SEC 1–3

Preliminary

Short title and commencement, definitions, and territorial and material application.

CHAPTER II · SEC 4–10

Obligations of Data Fiduciary

Grounds for processing, notice, consent, legitimate uses, general obligations, children, and SDF duties.

CHAPTER III · SEC 11–15

Rights & duties of Data Principal

Access, correction and erasure, grievance redressal, nomination, and the duties owed in return.

CHAPTER IV · SEC 16–17

Special provisions

Processing outside India, and the exemptions available under the Act.

CHAPTER V · SEC 18–26

Data Protection Board of India

Establishment, composition, terms of service, disqualifications, proceedings and powers.

CHAPTER VI · SEC 27–28

Powers & procedure of the Board

The functions of the Board and the inquiry procedure it must follow.

CHAPTER VII · SEC 29–32

Appeal & dispute resolution

Appeals to the Tribunal, executability of orders, mediation, and voluntary undertakings.

CHAPTER VIII · SEC 33–34

Penalties & adjudication

Monetary penalties under the Schedule, and crediting realised sums to the Consolidated Fund.

CHAPTER IX · SEC 35–44

Miscellaneous

Good-faith protection, information powers, blocking directions, rule-making and consequential amendments.

Section by section

All 44 sections, explained

Open a chapter to read every section in plain language.

Chapter I, PreliminarySections 1–3
Section 1, Short title and commencement. Names the Act and provides that it comes into force on dates the Central Government appoints, with different dates permitted for different provisions.
Section 2, Definitions. Defines personal data, digital personal data, processing, Data Principal, Data Fiduciary, Data Processor, Consent Manager, child, personal data breach, the Board, and Significant Data Fiduciary.
Section 3, Application of the Act. Applies to digital personal data processed in India, and to processing outside India connected with offering goods or services to individuals in India. It does not apply to purely personal or domestic processing, or to certain publicly available personal data.
Chapter II, Obligations of Data FiduciarySections 4–10
Section 4, Grounds for processing. Personal data may be processed only for a lawful purpose, and only with consent or for a certain legitimate use.
Section 5, Notice. A consent request must be accompanied or preceded by a notice setting out the data, the purpose, how rights are exercised, and how to complain to the Board, available in English or any language in the Eighth Schedule to the Constitution.
Section 6, Consent. Consent must be free, specific, informed, unconditional and unambiguous, given by clear affirmative action, limited to what is necessary, and as easy to withdraw as it was to give. It may be given, managed and withdrawn through a Consent Manager.
Section 7, Certain legitimate uses. The uses that do not require a fresh consent request, including voluntarily provided data, State benefits and services, legal obligations, compliance with judgments, medical emergencies, epidemics, disasters, and specified employment purposes.
Section 8, General obligations. The Fiduciary remains accountable even where a Processor carries out the work. It must ensure accuracy where data drives a decision or is shared, implement reasonable security safeguards, report breaches, erase when the purpose is served, publish a contact point, and provide grievance redressal.
Section 9, Children's data. Verifiable consent of a parent or lawful guardian is required, no processing likely to cause detrimental effect on a child is permitted, and tracking, behavioural monitoring and targeted advertising to children are prohibited, subject to notified exemptions.
Section 10, Significant Data Fiduciary. The Government may notify an SDF by reference to volume and sensitivity of data, risk to Data Principals, risk to electoral democracy, security of the State and public order. An SDF must appoint an India-based DPO answerable to the board, appoint an independent data auditor, and conduct periodic DPIAs and audits.
Chapter III, Rights & duties of the Data PrincipalSections 11–15
Section 11, Right to access information. A summary of the personal data being processed, the processing activities undertaken, and the identities of other Fiduciaries and Processors with whom it has been shared.
Section 12, Right to correction and erasure. Correction, completion, updating and erasure of personal data, unless retention is necessary for the specified purpose or required by law.
Section 13, Right of grievance redressal. A readily available means of registering a grievance with the Fiduciary or Consent Manager, answered within the prescribed period, and to be exhausted before approaching the Board.
Section 14, Right to nominate. A Data Principal may nominate another individual to exercise their rights in the event of death or incapacity.
Section 15, Duties of the Data Principal. To comply with applicable law, not to impersonate another, not to suppress material information, not to register false or frivolous grievances, and to furnish only authentic information.
Chapter IV, Special provisionsSections 16–17
Section 16, Processing outside India. The Central Government may restrict transfer of personal data to a notified country or territory. Where another Indian law affords a higher degree of protection, that law continues to apply.
Section 17, Exemptions. Exemptions for enforcing legal rights and claims, judicial and regulatory functions, prevention and investigation of offences, processing of non-resident data under a foreign contract, approved corporate restructuring, and research, archiving or statistical purposes, plus notified State instrumentalities and certain classes of start-up.
Chapter V, Data Protection Board of IndiaSections 18–26
Section 18, Establishment. Establishes the Data Protection Board of India as a body corporate.
Section 19, Composition and qualifications. A Chairperson and Members appointed for ability, integrity and standing, with expertise in data governance, law, technology or related fields, including at least one legal expert.
Section 20, Salary, allowances and term. Members hold office for two years and are eligible for re-appointment.
Section 21, Disqualifications. Grounds including insolvency, conviction for an offence involving moral turpitude, physical or mental incapacity, and conflict of interest. Removal requires a reasonable opportunity to be heard.
Section 22, Resignation and vacancy. Resignation and filling of vacancies, with a one-year restriction on taking employment with a Fiduciary involved in proceedings before the Board.
Section 23, Proceedings of the Board. Prescribed procedure, use of digital means, and validity of proceedings despite vacancies or procedural defects.
Section 24, Officers and employees. The Board may appoint officers and employees with the approval of the Central Government.
Section 25, Public servants. Members, officers and employees are deemed public servants when acting under the Act.
Section 26, Powers of the Chairperson. General superintendence, authorising scrutiny of complaints, and allocating proceedings among Members.
Chapter VI, Powers & procedure of the BoardSections 27–28
Section 27, Powers and functions. On a breach or a complaint, the Board may direct urgent remedial or mitigation measures, inquire into the contravention, impose penalties, and issue binding directions that it may later vary or revoke.
Section 28, Procedure. The Board functions as an independent, digital-by-design office, follows the principles of natural justice, holds specified powers of a civil court, records reasons, and may impose costs where a complaint proves false or frivolous.
Chapter VII, Appeal & alternate dispute resolutionSections 29–32
Section 29, Appeal to the Appellate Tribunal. Appeals lie to TDSAT within sixty days of the Board's order. The Tribunal operates as a digital office and endeavours to dispose of an appeal within six months.
Section 30, Orders executable as a decree. Tribunal orders are executable as a decree of a civil court.
Section 31, Alternate dispute resolution. The Board may refer a complaint for mediation where that is likely to secure resolution.
Section 32, Voluntary undertaking. The Board may accept a voluntary undertaking at any stage. Acceptance bars further proceedings on that subject, but breach of the undertaking is itself treated as a breach of the Act.
Chapter VIII, Penalties & adjudicationSections 33–34
Section 33, Penalties. Where the Board concludes that a contravention is significant, it may impose the penalty specified in the Schedule, having regard to the nature, gravity and duration, the type of data affected, repetition, any gain or loss avoided, mitigating action taken, and whether the penalty is proportionate and effective.
Section 34, Crediting to the Consolidated Fund. All sums realised as penalties are credited to the Consolidated Fund of India.
Chapter IX, MiscellaneousSections 35–44
Section 35, Protection of action in good faith. No suit or proceeding lies against the Government, the Board, its Chairperson or Members for anything done in good faith under the Act.
Section 36, Power to call for information. The Central Government may require the Board, a Data Fiduciary or an intermediary to furnish specified information.
Section 37, Power to issue directions. After a Fiduciary has been penalised on two or more occasions, the Government may, in the interests of the general public, direct that access to its information be blocked.
Section 38, Consistency with other laws. The Act is in addition to and not in derogation of other laws, and prevails to the extent of any inconsistency.
Section 39, Bar of jurisdiction. Civil courts may not entertain suits in respect of matters the Board or the Tribunal is empowered to determine.
Section 40, Power to make rules. The rule-making power that produced the DPDP Rules, 2025, covering notice, consent managers, security, breach intimation, retention, DPIAs, rights and appeals.
Section 41, Laying of rules and notifications. Rules and certain notifications must be laid before both Houses of Parliament.
Section 42, Power to amend the Schedule. The Government may amend the Schedule, but may not more than double any specified penalty.
Section 43, Power to remove difficulties. Orders to remove difficulties may be made within three years of commencement.
Section 44, Amendments to certain Acts. Consequential amendments to the TRAI Act 1997, the Information Technology Act 2000 including omission of section 43A, and the Right to Information Act 2005.
Section 2

Definitions glossary

Nineteen defined terms. Search to filter.

Appellate Tribunal

The Telecom Disputes Settlement and Appellate Tribunal established under the TRAI Act, 1997.

Automated

Any digital process capable of operating automatically in response to instructions given to carry out a set of operations.

Board

The Data Protection Board of India, established under Section 18.

Certain legitimate uses

The uses listed in Section 7 on which personal data may be processed without a separate consent request.

Child

An individual who has not completed eighteen years of age.

Consent Manager

A person registered with the Board who acts as a single point of contact enabling a Data Principal to give, manage, review and withdraw consent.

Data

A representation of information, facts, concepts, opinions or instructions in a manner suitable for communication, interpretation or processing.

Data Fiduciary

Any person who alone or with others determines the purpose and means of processing personal data. The closest analogue to a controller.

Data Principal

The individual to whom the personal data relates. Where the individual is a child, it includes the parents or lawful guardian.

Data Processor

Any person who processes personal data on behalf of a Data Fiduciary.

Data Protection Officer

An individual appointed by a Significant Data Fiduciary under Section 10(2)(a), based in India and answerable to the board of directors.

Digital personal data

Personal data in digital form. The Act does not reach purely offline records that are never digitised.

Notification

A notification published in the Official Gazette, the mechanism by which the Government designates SDFs, restricted countries and exemptions.

Personal data

Any data about an individual who is identifiable by or in relation to such data. Note there is no separate sensitive category under this Act.

Personal data breach

Any unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises confidentiality, integrity or availability.

Processing

A wholly or partly automated operation on digital personal data, including collection, recording, storage, use, sharing, indexing, erasure or destruction.

Significant Data Fiduciary

Any Data Fiduciary, or class of them, notified by the Central Government under Section 10, attracting additional obligations.

Specified purpose

The purpose mentioned in the notice given to the Data Principal. Processing may not drift beyond it without fresh consent.

State

The State as defined under Article 12 of the Constitution of India.

No matching term. Try consent, breach, child, processor or Board.

Section 7

Certain legitimate uses

The only alternative to consent. The list is closed, so if a use is not here, consent is required.

Voluntarily provided

Data the individual voluntarily gave for a specified purpose, where they have not indicated that they object to its use.

State benefits & services

Provision by the State of a subsidy, benefit, service, certificate, licence or permit, subject to Second Schedule standards.

Sovereignty & State function

Performance of any function under law, and the sovereignty, integrity and security of India.

Legal obligation & orders

Disclosure required by law, and compliance with any judgment, decree or order in India or abroad.

Medical & public health

Medical emergencies threatening life or health, and provision of health services during an epidemic or outbreak.

Disaster & employment

Safety during a disaster or breakdown of public order, and employment purposes including safeguarding the employer from loss.

A common mistake. The employment limb is narrower than it sounds. It covers the employment relationship itself, corporate espionage, confidentiality, intellectual property, and services or benefits sought by an employee. It is not a general basis for any processing of employee data, and marketing to employees is not covered by it.
Section 17

Key exemptions

Legal rights and claims

Processing necessary for enforcing any legal right or claim.

Judicial and regulatory functions

Processing by a court, tribunal or other body entrusted by law with judicial, quasi-judicial, regulatory or supervisory functions.

Prevention of offences

Prevention, detection, investigation or prosecution of any offence or contravention of law.

Non-resident data under a foreign contract

Processing in India of the personal data of individuals outside India, under a contract with a person outside India. This is the limb most Indian outsourcing and GCC operations rely on.

Corporate restructuring

Mergers, demergers, amalgamations or reconstructions approved by a competent court or authority.

Research, archiving and statistics

Where carried out in accordance with the standards in the Second Schedule, and not used to take any decision specific to a Data Principal.

Notified State bodies and start-ups

The Government may exempt notified State instrumentalities, and certain classes of start-up from specified provisions, having regard to the volume and nature of data processed.

Chapter III

Rights of Data Principals

Five rights, and the duties owed in return. Note what is absent: there is no portability right and no general right to object.

Right to access information

A summary of the data processed, the activities undertaken, and the identities of Fiduciaries and Processors with whom it was shared.

Right to correction and erasure

Correction, completion, updating and erasure, unless retention remains necessary for the specified purpose or is required by law.

Right of grievance redressal

A readily available mechanism, answered within the Rule 14 period, and to be exhausted before approaching the Board.

Right to nominate

To nominate another individual to exercise these rights in the event of death or incapacity. An unusual provision, and one few systems are built to handle.

Right to withdraw consent

Withdrawal must be as easy as giving consent, and the consequences of withdrawal fall on the Data Principal. Processing must cease within a reasonable time.

Duties of the individual

Not to impersonate, not to suppress material information, not to raise false or frivolous grievances, and to furnish authentic information.

Section 8

What every Data Fiduciary must do

Implementation service

These apply to every Fiduciary, of any size, from the first record processed. Engaging a Processor does not transfer accountability, it only distributes the work.

Remain accountable

The Fiduciary is responsible for compliance in respect of any processing undertaken by it or on its behalf by a Data Processor.

Give clear notice

An itemised description of the data and purposes, in plain language, with links to withdraw consent, exercise rights, and complain to the Board.

Ensure data quality

Completeness, accuracy and consistency where the data is used to make a decision affecting the Data Principal, or is disclosed to another Fiduciary.

Reasonable security safeguards

Rule 6 names them: encryption, obfuscation, masking or virtual tokens; access control; monitoring and review logs retained for one year; backups; and contractual measures binding Processors.

Report breaches

Intimate both the Board and every affected Data Principal, in the form and within the timelines set by Rule 7.

Erase when the purpose is served

Erase on withdrawal of consent or once the purpose is no longer being served, unless retention is required by law, with 48 hours' advance notice to the individual under Rule 8.

Publish a contact point

The business contact of a DPO, or of a person able to answer questions about processing, displayed on the website and in every notice.

Operate grievance redressal

Publish how rights are exercised and respond within the period specified under Rule 14, which may not exceed ninety days.

Section 10 & Rule 13

Significant Data Fiduciary, the obligations on top

You become an SDF by Government notification, not by self-assessment. But the criteria are known, so the sensible move is to assess whether you are likely to be designated, and prepare accordingly.

Appoint a DPO

Based in India, representing the SDF under the Act, answerable to the board of directors or equivalent, and named as the point of contact for grievance redressal.

Appoint an independent auditor

An independent data auditor to evaluate compliance, whose findings are reported to the board rather than to the team being audited.

Periodic DPIA and audit

Rule 13 requires both to be conducted annually, with the DPO submitting a report on significant observations to the SDF.

Algorithmic due diligence

Verify that algorithmic software used for processing does not pose a risk to the rights of Data Principals. A direct link between DPDP and AI governance.

Transfer restrictions

Ensure that specified categories of personal data, and the traffic data relating to their flow, are not transferred outside India where the Government so directs.

Designation criteria

Volume and sensitivity of data, risk to Data Principals, risk to electoral democracy, security of the State, and public order.

Subordinate legislation

DPDP Rules, 2025, the operational rulebook

The Act states the obligation. The Rules tell you what satisfying it actually looks like.

RULE 3

Notice to the Data Principal

Standalone, understandable on its own, in plain language, with an itemised list of data and purposes, and links to withdraw consent, exercise rights and complain.

RULE 4

Consent Managers

Registration with the Board, a minimum net worth of ₹2 crore, and the detailed obligations in the First Schedule.

RULE 5

State processing standards

Second Schedule standards where the State processes data for a subsidy, benefit, service, certificate, licence or permit.

RULE 6

Reasonable security safeguards

Encryption or masking, access control, one-year monitoring and access logs, backups for continuity, and security clauses in Processor contracts.

RULE 7

Breach intimation

Affected individuals told without delay. The Board told without delay, with a fuller report following within 72 hours.

RULE 8

Retention & erasure

Third Schedule periods after which data must be erased, 48 hours' advance notice to the individual, and one-year log retention.

RULE 9

Contact information

Publish the business contact of a DPO or of a person able to answer questions about processing, on the website and in every notice.

RULES 10 & 11

Verifiable consent

Due diligence to confirm that a self-identified parent is an identifiable adult, and to verify that a guardian is lawfully appointed.

RULE 12

Children's data exemptions

Fourth Schedule classes and purposes exempt from parts of Section 9, including healthcare, education and child-safety contexts, subject to conditions.

RULE 13

SDF additional obligations

Annual DPIA and audit, algorithmic software diligence, and observance of specified-data transfer restrictions.

RULE 14

Exercise of rights

Publish the means and the particulars required to identify a requester, and answer grievances within a published period not exceeding ninety days.

RULE 15

Transfer outside India

Transfers are subject to any requirement the Central Government may specify in respect of a foreign State or an entity controlled by it.

RULE 16

Research & statistics

The Act does not apply to research, archiving or statistical purposes carried out to Second Schedule standards.

RULES 17–21

The Board

Selection and appointment, terms of service, meeting procedure, functioning as a digital office, and staff terms.

RULE 22

Appeal to the Tribunal

Digital filing, adherence to natural justice, and payment of fees through UPI or other authorised systems.

RULE 23

Calling for information

The Government may require a Fiduciary or intermediary to furnish specified information for Seventh Schedule purposes.

Rules 2025

The seven schedules

FIRST

Consent Managers

Conditions of registration and the detailed obligations placed on a Consent Manager.

SECOND

State & research standards

Processing standards for the State, and for research, archiving and statistical purposes.

THIRD

Retention periods

A three-year retention limit for large e-commerce entities, online gaming intermediaries and social media intermediaries.

FOURTH

Children's data exemptions

The classes of Fiduciary and the purposes exempt from parts of Section 9.

FIFTH

Board members' service

Salary, allowances and terms of service of the Chairperson and Members.

SIXTH

Board staff

Terms and conditions of the officers and employees of the Board.

SEVENTH

Information & authorities

The purposes for which information may be called for, and the authorised persons who may call for it.

TO THE ACT

The penalty Schedule

The Schedule to the Act itself, referred to in Section 33, listing the maximum penalty for each contravention.

Data Protection Impact Assessment

DPIA, assessing risk before you process

Get the DPIA template

A DPIA is a structured way to identify and reduce the data-protection risks of a processing activity before it begins. Under the DPDP Act it is a periodic obligation for Significant Data Fiduciaries under Section 10 and Rule 13. For everyone else it is not named in the statute, but it remains the only practical way to show that you considered the risk to Data Principals at all.

When a DPIA is needed

New systems or products, processing at scale, profiling or automated decisions, a new vendor or data-sharing arrangement, children's data, biometrics or location, any use of AI on personal data, and on a periodic basis for every SDF.

What a DPIA must cover

A description of the processing and its purposes, an assessment of necessity and proportionality, the risks to the rights of Data Principals, and the measures that reduce those risks to an acceptable level.

The DPIA in eight steps

1

Describe

Map the processing, the data flows, the purposes, and every system and vendor involved.

2

Test necessity

Lawful ground, purpose limitation and minimisation. Is every field genuinely needed?

3

Consult

Engage the owning team, security, legal, and where useful the Data Principals themselves.

4

Identify risks

Assess likelihood and severity of harm to individuals, not inconvenience to the business.

5

Mitigate

Assign controls: minimisation, encryption, retention limits, access control, contract terms.

6

Sign off

Record the residual risk and obtain DPO or accountable-owner approval before go-live.

7

Review

Revisit when the processing, the vendors or the law change, and on the annual SDF cycle.

8

Algorithms

For an SDF, Rule 13 adds diligence on algorithmic software used in the processing.

Records of Processing Activities

RoPA, the inventory behind accountability

Get the RoPA workbook

A Record of Processing Activities is a living inventory of how your organisation uses personal data. The DPDP Act does not name it as a standalone obligation, but nearly every duty it does impose, notice, consent, security, retention, breach scoping and rights fulfilment, is unanswerable without one. It is the evidence base the Section 8 duties and the SDF audit both read from.

FieldWhat it recordsDPDP anchor
Processing activityThe business process and the specified purpose it serves.Sec 4, 5
Categories of dataThe personal data fields, flagged where they relate to children.Sec 2, 9
Data PrincipalsWhose data it is: customers, employees, vendors, minors.Sec 2
Lawful groundConsent, or the specific legitimate use relied on.Sec 4, 6, 7
RecipientsProcessors, sub-processors and any other Fiduciaries.Sec 8, 11
RetentionThe retention period and the trigger that starts erasure.Rule 8, Sch 3
TransfersAny transfer outside India and the restriction that applies.Sec 16, Rule 15
SafeguardsThe security measures protecting that data in that system.Sec 8, Rule 6

Why it matters

You cannot secure, retain or erase data you have never mapped. When a breach happens, the RoPA is what tells you within hours whose data was affected.

How it connects

It feeds notices, consent design, DPIAs, vendor contracts, breach scoping and rights fulfilment. Each of those reads from the RoPA rather than starting again.

Keeping it live

Review on change and on a set cadence. An out-of-date RoPA fails the first question any auditor asks, which is usually "when was this last reviewed".

DPIA and RoPA together. The RoPA tells you what you process. The DPIA tells you whether the risk of doing so is acceptable. Build the RoPA first, then run DPIAs on the high-risk activities it surfaces. Doing it the other way round produces assessments of things nobody has confirmed you actually do.
Rule 7, incident response

The breach intimation clock

Breach response service

Rule 7 has two legs running at once, which is the detail most summaries get wrong. There is no single "72-hour rule" here. Individuals must be told without delay, and so must the Board, with a fuller report to the Board following within 72 hours.

To each affected Data Principal

Without delay, in plain language: a concise description of the breach including its nature, extent and timing; the likely consequences for that individual; the measures being taken to mitigate risk; the safety steps they themselves might take; and the business contact able to answer their questions.

To the Data Protection Board

Without delay: a description of the nature, extent, timing and likely impact. Then within 72 hours, or a longer period the Board allows on written request: updated and detailed facts, the circumstances and causes, the mitigation measures implemented, findings on the person who caused it, remedial measures to prevent recurrence, and a report on the intimations given to affected individuals.

Response, end to end

1

Detect

Become aware, through monitoring, a staff report or an external notification.

2

Assess

Establish nature, scope and severity, without letting the assessment delay notification.

3

Notify the Board

In the prescribed form, then follow with the detailed report within 72 hours.

4

Notify individuals

Tell each affected person what happened, what it means for them, and what to do.

5

Remediate

Fix the cause, record the response, and update the breach register for audit.

The clock starts at awareness, not at certainty. Every breach is reportable under Rule 7, there is no materiality threshold to filter on, and failing to notify carries a penalty of up to ₹200 crore. Decide in advance who assesses, who signs off and who notifies, because those decisions cannot be made well at speed.
Enforcement

Penalty structure

The Schedule to the Act sets a maximum for each contravention. The Board decides the amount within it.

₹250 cr
Security safeguards
Failure to take reasonable security safeguards to prevent a personal data breach.
₹200 cr
Breach notification
Failure to notify the Board or affected Data Principals of a personal data breach.
₹200 cr
Children's data
Failure to meet the additional obligations in relation to children under Section 9.
₹150 cr
SDF obligations
Failure to meet the additional obligations of a Significant Data Fiduciary under Section 10.
How the amount is set. Section 33 directs the Board to consider the nature, gravity and duration of the contravention, the type of personal data affected, whether it was repetitive, any gain made or loss avoided, whether mitigating action was taken and how promptly, and whether the penalty is proportionate and effective. Acting quickly and documenting it is itself a mitigating factor. General information, not legal advice.
Comparison

DPDP against GDPR and CCPA / CPRA

All jurisdiction guides
DimensionDPDP Act, IndiaGDPR, European UnionCCPA / CPRA, California
Lawful groundsConsent, or a certain legitimate use. No legitimate-interests basis.Six lawful bases including legitimate interests.Notice and opt-out model rather than a basis model.
Sensitive dataNo separate category defined.Special categories with additional conditions.Sensitive personal information with a right to limit use.
TransfersNegative list. Permitted unless the country is notified as restricted.Adequacy, SCCs, BCRs and derogations.No specific cross-border transfer regime.
PortabilityNo portability right.Portability and erasure rights.Right to know, delete and correct.
Right to objectNone. Withdrawal of consent is the nearest equivalent.Right to object, including to direct marketing.Opt-out of sale and sharing.
ChildrenVerifiable parental consent under 18. No tracking or targeted advertising.Conditions for information society services, 13 to 16 by member state.Opt-in required for sale of data of under-16s.
Breach reportingEvery breach, without delay, plus a 72-hour report to the Board.72 hours where a risk to rights and freedoms is likely.Notification under separate state breach law.
Maximum penaltyUp to ₹250 crore per contravention.Up to 4 percent of global annual turnover.Per-violation civil penalties.
RegulatorData Protection Board of India, appeals to TDSAT.A supervisory authority in each member state.California Privacy Protection Agency.
If you already comply with GDPR. You are well placed but not finished. The gaps that catch GDPR-mature organisations are the absence of legitimate interests, which forces consent where Europe allowed a balancing test; the under-18 threshold for children; the nomination right; and breach reporting with no materiality threshold.
How we help

DPDP readiness, from notice to evidence

We establish what applies to you, design notice and consent that satisfies Sections 5 and 6, build the Section 8 controls and any SDF obligations, and prepare the RoPA, DPIA and audit evidence that the Board would expect to see.

Get a DPDP readiness review Compare with GDPR