S. 1
Short title and commencement
The Act commences in phases by Government notification; different provisions may start on different dates.
Ch 1 · Preliminary
What we deliverCommencement tracker mapped to your programme plan, so no obligation is missed as each phase is notified.
S. 2
Definitions
Defines Data Principal, Data Fiduciary, Data Processor, personal data, processing, consent manager and more.
Ch 1 · Preliminary
What we deliverDefinition mapping workshop that classifies your entities and datasets against every defined term.
S. 3
Application of the Act
Applies to digital personal data processed in India, and to processing outside India connected with offering goods or services to Data Principals in India.
Ch 1 · Preliminary
What we deliverApplicability and extraterritoriality opinion, with a documented scoping decision you can defend.
S. 4
Grounds for processing personal data
Processing is lawful only on consent or a legitimate use. No other ground exists.
Ch 2 · Obligations of Data Fiduciary
What we deliverLawful basis register for every processing activity, with evidence for each determination.
S. 5
Notice
A clear, itemised notice must accompany or precede the consent request, in English or any Eighth Schedule language.
Ch 2 · Obligations of Data Fiduciary
What we deliverPlain-language notice suite, versioned, with multilingual variants and a change log.
S. 6
Consent
Consent must be free, specific, informed, unconditional, unambiguous, with clear affirmative action, and as easy to withdraw as to give.
Ch 2 · Obligations of Data Fiduciary
What we deliverConsent architecture and withdrawal flows, wired to downstream systems so withdrawal actually stops processing.
S. 7
Certain legitimate uses
Sets out the specific legitimate uses, including voluntary provision, State functions, medical emergency and employment purposes.
Ch 2 · Obligations of Data Fiduciary
What we deliverLegitimate use assessment templates with documented necessity and proportionality reasoning.
S. 8
General obligations of Data Fiduciary
Accountability for processing by processors, data accuracy, security safeguards, breach handling, erasure and grievance redressal.
Ch 2 · Obligations of Data Fiduciary
What we deliverAccountability framework: RACI, processor oversight, retention schedule and grievance workflow.
S. 9
Processing of personal data of children
Verifiable parental consent required; no tracking, behavioural monitoring or targeted advertising directed at children.
Ch 2 · Obligations of Data Fiduciary
What we deliverAge assurance and parental consent design, plus a tracking and advertising control review.
S. 10
Additional obligations of Significant Data Fiduciary
Appoint a DPO in India, appoint an independent data auditor, conduct periodic DPIAs and audits.
Ch 2 · Obligations of Data Fiduciary
What we deliverDPO mandate, independent audit programme and a repeatable DPIA methodology with evidence retention.
S. 11
Right to access information about personal data
Data Principals may obtain a summary of personal data processed and the identities of recipients.
Ch 3 · Rights and Duties of Data Principal
What we deliverAccess request workflow with system-of-record discovery and a defensible response pack.
S. 12
Right to correction and erasure of personal data
Right to correction, completion, updating and erasure of personal data.
Ch 3 · Rights and Duties of Data Principal
What we deliverCorrection and erasure runbooks that propagate across primary, backup and downstream systems.
S. 13
Right of grievance redressal
Data Fiduciary must provide a readily available grievance mechanism and respond within a prescribed period.
Ch 3 · Rights and Duties of Data Principal
What we deliverGrievance intake, SLA tracking and escalation path, with an auditable response register.
S. 14
Right to nominate
Data Principals may nominate another individual to exercise rights in the event of death or incapacity.
Ch 3 · Rights and Duties of Data Principal
What we deliverNomination capture and verification process built into your rights portal.
S. 15
Duties of Data Principal
Data Principals must not impersonate, suppress information or register false grievances.
Ch 3 · Rights and Duties of Data Principal
What we deliverDuty notices embedded in your rights portal, with abuse handling guidance.
S. 16
Processing of personal data outside India
The Central Government may restrict transfer of personal data to notified territories.
Ch 4 · Special provisions
What we deliverTransfer mapping, restricted-territory monitoring and contractual safeguards for each route.
S. 17
Exemptions
Sets out exemptions including enforcement of legal rights, judicial functions, and processing of non-resident data under foreign contract.
Ch 4 · Special provisions
What we deliverExemption applicability assessment, documented so reliance can be evidenced on inspection.
S. 18
Power of Central Government to amend Schedule
The Government may amend the Schedule of penalties, subject to limits.
Ch 4 · Special provisions
What we deliverPenalty exposure model refreshed whenever the Schedule changes.
S. 19
Establishment of Board
Establishes the Data Protection Board of India.
Ch 5 · Data Protection Board of India
What we deliverRegulator engagement briefing so your team knows who decides what.
S. 20
Composition and qualifications for appointment of Chairperson and Members
Composition, qualifications and expertise requirements for the Board.
Ch 5 · Data Protection Board of India
What we deliverIncluded in the regulator engagement briefing.
S. 21
Salary, allowances payable to and term of office
Terms of service for Chairperson and Members.
Ch 5 · Data Protection Board of India
What we deliverReference material in your compliance library.
S. 22
Disqualifications for appointment and continuation
Grounds on which a Member may be removed.
Ch 5 · Data Protection Board of India
What we deliverReference material in your compliance library.
S. 23
Resignation by Members and filling of vacancy
Resignation and vacancy procedure.
Ch 5 · Data Protection Board of India
What we deliverReference material in your compliance library.
S. 24
Proceedings of Board
Board proceedings and validity of acts.
Ch 5 · Data Protection Board of India
What we deliverReference material in your compliance library.
S. 25
Officers and employees of Board
Board may appoint officers and employees.
Ch 5 · Data Protection Board of India
What we deliverReference material in your compliance library.
S. 26
Members and officers to be public servants
Members and officers deemed public servants.
Ch 5 · Data Protection Board of India
What we deliverReference material in your compliance library.
S. 27
Powers and functions of Board
The Board directs remedial measures, inquires into breaches and imposes penalties.
Ch 6 · Powers, functions and procedure
What we deliverRegulator-ready evidence pack so you can answer a Board inquiry quickly and completely.
S. 28
Procedure to be followed by Board
Board procedure on complaints, inquiry and natural justice; functions as a digital office.
Ch 6 · Powers, functions and procedure
What we deliverInquiry response playbook with named owners and evidence retrieval steps.
S. 29
Appeal to Appellate Tribunal
Appeals against Board orders lie to the TDSAT within 60 days.
Ch 7 · Appeal and alternate dispute resolution
What we deliverAppeal readiness checklist and document retention rules for the limitation window.
S. 30
Orders passed by Appellate Tribunal to be executable as decree
Tribunal orders execute as a civil court decree.
Ch 7 · Appeal and alternate dispute resolution
What we deliverReference material in your compliance library.
S. 31
Alternate dispute resolution
The Board may refer a complaint for mediation or other dispute resolution.
Ch 7 · Appeal and alternate dispute resolution
What we deliverMediation preparation guidance within the grievance workflow.
S. 32
Voluntary undertaking
A person may give a voluntary undertaking to the Board, which bars further proceedings on that matter.
Ch 7 · Appeal and alternate dispute resolution
What we deliverVoluntary undertaking strategy and drafting support when remediation is the better route.
S. 33
Penalties
Penalties up to 250 crore rupees per the Schedule, determined after inquiry.
Ch 8 · Penalties and adjudication
What we deliverQuantified penalty exposure model by processing activity, used to sequence remediation.
S. 34
Crediting of sums realised to Consolidated Fund of India
Penalties credited to the Consolidated Fund.
Ch 8 · Penalties and adjudication
What we deliverReference material in your compliance library.
S. 35
Protection of action taken in good faith
Protects good-faith acts of the Board and Government.
Ch 9 · Miscellaneous
What we deliverReference material in your compliance library.
S. 36
Power to call for information
The Government may require information from the Board or any Data Fiduciary.
Ch 9 · Miscellaneous
What we deliverInformation request handling procedure with a single accountable owner.
S. 37
Power of Central Government to issue directions to block
Blocking of access on repeated penalty, in the interests of the general public.
Ch 9 · Miscellaneous
What we deliverEscalation and business continuity planning for a blocking scenario.
S. 38
Consistency with other laws
The Act is in addition to and not in derogation of other laws.
Ch 9 · Miscellaneous
What we deliverConflict-of-laws mapping across DPDP, IT Act, sectoral regulators and contracts.
S. 39
Bar of jurisdiction
No civil court may hear matters the Board is empowered to decide.
Ch 9 · Miscellaneous
What we deliverReference material in your compliance library.
S. 40
Power to make rules
Empowers the Government to make rules, giving effect to the DPDP Rules.
Ch 9 · Miscellaneous
What we deliverRules change monitoring wired into your regulatory tracker.
S. 41
Laying of rules and notifications before Parliament
Rules must be laid before Parliament.
Ch 9 · Miscellaneous
What we deliverReference material in your compliance library.
S. 42
Power to remove difficulties
Government may remove difficulties within three years of commencement.
Ch 9 · Miscellaneous
What we deliverReference material in your compliance library.
S. 43
Amendment to Information Technology Act, 2000
Omits Section 43A of the IT Act.
Ch 9 · Miscellaneous
What we deliverGap remediation where your contracts still cite Section 43A and reasonable security practices.
S. 44
Amendment to other Acts
Amends the Telecom Regulatory Authority of India Act and the Right to Information Act.
Ch 9 · Miscellaneous
What we deliverRTI interface review for public authorities and RTI-exposed vendors.
No obligation matches that search. Try a broader term.
R. 1
Short title and commencement
Tiered commencement. Rules 1, 2, 17 to 21 applied on notification (13 Nov 2025). Rule 4 applies from 13 Nov 2026. Rules 3, 5 to 16, 22 and 23 apply from 13 May 2027.
What we deliverCommencement calendar aligned to your remediation plan, with each rule tied to an owner and a due date.
R. 3
Notice given by Data Fiduciary
The notice must be standalone, in clear plain language, itemising the personal data and purpose, and giving the withdrawal and grievance links.
What we deliverStandalone notice templates that pass the itemisation test, plus a review of every existing notice.
R. 4
Registration and obligations of Consent Manager
Consent Managers must register with the Board and meet stated conditions, including a net worth threshold.
What we deliverConsent Manager selection and due-diligence pack, or registration support if you intend to become one.
R. 5
Processing for State and its instrumentalities
Standards for processing for subsidy, benefit, service, certificate, licence or permit.
What we deliverControl set for public-sector and State-facing processing.
R. 6
Reasonable security safeguards
Encryption, obfuscation, masking, access control, logging and monitoring, backups, and contractual obligations on processors.
What we deliverSecurity control implementation and one-year log retention design, evidenced against Rule 6.
R. 7
Intimation of personal data breach
Affected Data Principals told without delay in plain language; the Board notified without delay; a detailed report filed with the Board within 72 hours.
What we deliverBreach response playbook running the CERT-In 6-hour and DPDP 72-hour clocks together, with notification templates and tabletop drills.
R. 8
Erasure and time period for specified purposes
Erasure once the purpose is no longer served. Schedule III sets a three-year limit for large e-commerce, online gaming and social media intermediaries, with 48 hours advance intimation to the Data Principal.
What we deliverRetention schedule and automated erasure jobs, with the 48-hour advance intimation built in.
R. 9
Contact information of person able to answer questions
Publish contact details of the DPO or person answering processing questions on the website and in every notice.
What we deliverContact block deployed across notices, website and app surfaces.
R. 10
Verifiable consent for children and persons with disability
Verifiable parental or guardian consent, with due diligence on identity and age.
What we deliverAge assurance design, guardian verification flow and DigiLocker-style token options.
R. 11
Exemptions from certain obligations
Exemptions for specified classes including healthcare and educational institutions for stated purposes.
What we deliverExemption reliance assessment, documented per processing activity.
R. 12
Additional obligations of Significant Data Fiduciary
Annual DPIA and audit, algorithmic due diligence, and localisation of specified personal data.
What we deliverSDF programme: annual DPIA and audit cycle, algorithmic due-diligence register and localisation controls.
R. 13
Rights of Data Principals
Publish the means to exercise rights, the identifiers required, and the response timelines.
What we deliverRights portal with published timelines, identifier rules and an auditable request register.
R. 14
Processing outside India
Conditions on making personal data available to a foreign State or its instrumentality.
What we deliverTransfer control matrix with the conditions evidenced for each destination.
R. 15
Appointment, salary and terms of Board Chairperson and Members
Board appointment machinery.
What we deliverReference material in your compliance library.
R. 16-21
Board procedure, digital office and appeals
Complaint procedure, digital office functioning, and appeal process to the Appellate Tribunal.
What we deliverInquiry and appeal response playbook.
R. 22
Schedule VII, calling for information
The Government may call for information from a Data Fiduciary or intermediary.
What we deliverInformation request handling procedure.
No rule matches that search. Try a broader term.
S. 43A
Compensation for failure to protect data
Omitted by Section 43 of the DPDP Act. Contracts and policies still citing it are now stale.
What we deliverContract and policy remediation to remove stale Section 43A and SPDI Rules references.
SPDI Rules
SPDI Rules 2011
Reasonable security practices for sensitive personal data; sector contracts still reference them widely.
What we deliverMapping from SPDI controls to Rule 6 safeguards, so nothing is lost in the transition.
S. 66E
Violation of privacy
Criminal liability for capturing or transmitting images of a private area without consent.
What we deliverPolicy and training controls covering imagery, CCTV and workplace monitoring.
S. 69
Interception, monitoring and decryption
Powers to direct interception, monitoring or decryption, with compliance duties on intermediaries.
What we deliverLawful interception request handling procedure with legal review gate.
S. 69A
Blocking of public access
Blocking directions, which interact with Section 37 of the DPDP Act.
What we deliverBlocking scenario escalation and continuity plan.
S. 70B
CERT-In directions
Six-hour cyber incident reporting, 180-day log retention in India, and KYC obligations for specified service providers.
What we deliverCERT-In six-hour reporting integration with the DPDP 72-hour clock, plus ICT log retention design.
S. 72A
Disclosure in breach of lawful contract
Criminal liability for disclosure of personal information in breach of a lawful contract.
What we deliverContractual confidentiality controls and employee handling rules.
S. 79
Intermediary liability and safe harbour
Due diligence obligations under the IT Rules 2021 as a condition of safe harbour.
What we deliverIntermediary due-diligence gap review, including grievance officer obligations.
No provision matches that search. Try a broader term.