# Data Adhikaar — Agentic DPDPA Compliance Fabric (full content) > Data Adhikaar is an agentic DPDPA compliance fabric for India — ten specialist AI agents that automate consent, data principal rights, breach response, DPIAs, vendor management and audit evidence. Connect via SDK, API or MCP. Compliant in days, not quarters. Company: Qodequay Technologies Pvt. Ltd. — Hinjawadi Phase 1, Pune, Maharashtra, India. Contact: shashikant.kalsha@qodequay.com · +91 98226 28174 · sales@qodequay.com Security & trust: ISO 27001 Certified · SOC 2 Type II · ISO 27701 (in progress); data residency AWS Mumbai (ap-south-1) · DR Hyderabad (ap-south-2). DPDPA Phase II enforcement milestone: 13 November 2026. Canonical site: https://dapro.in · Contents index: https://dapro.in/llms.txt · Sitemap: https://dapro.in/sitemap.xml This document contains the full text of the site's DPDPA guide pillars, industry guides, agent profiles and FAQ bank. Content is informational and not legal advice. --- # The Ten Agents ## Sutradhaar (सूत्रधार) — Orchestrator / DPO Copilot Your DPO Copilot. Coordinates all nine specialists, routes escalations, and answers any DPDPA question with statutory and tenant-data citations. Always one keystroke away in the console. ## Drishti (दृष्टि) — Discovery Continuously scans connected systems, classifies personal data, and maintains your live Record of Processing Activities and data-flow map. Flags children’s, financial, health and biometric data the instant it appears unregistered. ## Sammati (सम्मति) — Consent Owns the consent lifecycle: capture, refresh, expiry, withdrawal and proof. Issues a decision on every /consent/check. Detects mass-withdrawal events and consent-fatigue patterns before they become problems. ## Adhikari (अधिकारी) — Rights Receives requests from portal, email, phone and in-app. Verifies identity, locates the data, fulfils straightforward requests automatically, and escalates the ambiguous ones — all inside the statutory SLA. ## Suraksha (सुरक्षा) — Breach Response Watches your security signal feeds. Opens incidents, classifies severity, drafts Data Protection Board and principal notifications, and runs the war-room timeline. Humans approve every transmission. ## Vivek (विवेक) — DPIA Screens every new and changed processing activity. Auto-files the low-risk; prepares full Data Protection Impact Assessments for the rest, with mitigation tasks attached. ## Vidhi (विधि) — Regulatory Intelligence Reads everything MeitY, the Data Protection Board and sectoral regulators publish — daily. Translates regulatory change into specific, approvable updates to your posture. ## Lekhak (लेखक) — Policy Drafting Drafts and versions notices, internal policies, processor annexures and children’s-consent flows in English plus your configured Indian languages. Nothing publishes without human approval. ## Sambandh (सम्बन्ध) — Vendor / Processor Inventories processors, scores vendor risk, chases attestations, and alerts you when a sub-processor change requires principal notification. ## Saakshi (साक्षी) — Audit The witness. Continuously assembles evidence against every statutory obligation and generates exhibit packs an auditor can verify independently. --- # DPDPA Guide — Pillar Articles ## What is the DPDPA? India’s Digital Personal Data Protection Act, 2023 Explained URL: https://dapro.in/dpdpa-guide/what-is-dpdpa · Last updated: 2026-07-06 **What is the DPDPA?** The DPDPA is India’s Digital Personal Data Protection Act, 2023 — the country’s first comprehensive data protection law. It governs how organisations process the digital personal data of individuals in India, gives individuals enforceable rights over their data, and allows penalties of up to ₹250 crore for non-compliance. The Digital Personal Data Protection Act, 2023 (DPDPA) is India’s landmark data protection law. After more than half a decade of drafts and consultations, it establishes a single national framework for how personal data is collected, stored, used and shared — replacing the limited protections that previously existed under the Information Technology Act and its 2011 rules. The Act is built around a simple idea: individuals (called Data Principals) have rights over their personal data, and organisations that process that data (called Data Fiduciaries) have corresponding duties. The Digital Personal Data Protection Rules, 2025 add the operational detail — exactly what notices must say, how breaches are reported, and what extra obligations significant organisations carry. ## Who does the DPDPA apply to? The DPDPA applies to the processing of digital personal data within India where the data is collected in digital form, or collected on paper and later digitised. Crucially, it also applies extra-territorially: an organisation outside India must comply if it processes the personal data of individuals in India in connection with offering them goods or services. In practice, this means almost every modern business is covered — e-commerce stores, SaaS companies, banks, hospitals, schools, startups and enterprises alike. If you hold customer, employee or user data in digital form, you are a Data Fiduciary with obligations under the Act. > **A narrow set of exemptions** — Certain processing is exempt or lightly regulated — for example, purely personal or domestic use, and specified state functions in the interest of sovereignty, security or public order. Most commercial processing is fully in scope. ## What are the key DPDPA definitions? Understanding the DPDPA starts with its vocabulary. These terms appear throughout the Act and the Rules. **Personal data**: Any data about an individual who is identifiable by or in relation to such data. **Data Principal**: The individual to whom the personal data relates — including parents/guardians for children and guardians for persons with disabilities. **Data Fiduciary**: Any person who, alone or with others, determines the purpose and means of processing personal data (similar to a GDPR “controller”). **Data Processor**: A person who processes personal data on behalf of a Data Fiduciary. **Significant Data Fiduciary (SDF)**: A Data Fiduciary notified by the government as “significant” based on volume and sensitivity of data and risk, carrying extra duties. **Consent Manager**: A registered, accountable intermediary through which a Data Principal can give, manage and withdraw consent. ## What are the core principles of the DPDPA? The Act codifies a set of data-protection principles that should guide every processing activity: - Lawful purpose — personal data may be processed only for a lawful purpose, on the basis of consent or certain legitimate uses. - Notice and consent — a clear notice must precede consent, and consent must be free, specific, informed, unconditional and unambiguous. - Purpose limitation — data is used only for the purpose for which it was collected. - Data minimisation — only the personal data necessary for that purpose is collected. - Accuracy — reasonable efforts are made to keep data correct and up to date. - Storage limitation — data is erased once the purpose is served and retention is no longer required. - Reasonable security safeguards — appropriate technical and organisational measures protect the data. - Accountability — the Data Fiduciary is responsible for compliance, including where processing is outsourced. ## How does consent work under the DPDPA? Consent is the primary basis for processing personal data under the Act. Section 5 requires that, on or before requesting consent, the Data Fiduciary gives the Data Principal an itemised notice describing the personal data to be collected, the purpose of processing, how the individual can exercise their rights, and how to complain to the Data Protection Board. The notice must be available in English or any language listed in the Eighth Schedule to the Constitution. Section 6 sets the standard for consent itself: it must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and limited to the data necessary for the stated purpose. Equally important, a Data Principal can withdraw consent at any time — and withdrawing it must be as easy as giving it. Beyond consent, the Act permits processing for a defined set of “legitimate uses” (Section 7) — for example, where the individual has voluntarily provided data for a specified purpose, or for certain employment, medical-emergency and disaster-response situations. ## What rights do individuals have? The DPDPA grants Data Principals a clear set of rights that organisations must be able to honour: - Right to access — obtain a summary of the personal data being processed and the processing activities. - Right to correction and erasure — correct, complete, update or erase personal data. - Right to grievance redressal — a readily available mechanism to raise complaints. - Right to nominate — appoint another individual to exercise rights in the event of death or incapacity. ## What duties do Data Fiduciaries have? Section 8 places the operational burden on the Data Fiduciary. You must process data only for the consented purpose, ensure accuracy, implement reasonable security safeguards, erase data when the purpose is served, publish the contact details of a person who can answer processing questions, and notify the Data Protection Board and affected individuals in the event of a personal data breach. You remain accountable even when a Data Processor handles the data on your behalf. > **Breach notification is mandatory** — A personal data breach must be reported to the Data Protection Board and to affected Data Principals. The DPDP Rules 2025 set out the form and timeline — speed and completeness matter. ## Are there special rules for children’s data? Yes. Section 9 treats anyone under 18 as a child. Processing a child’s personal data requires verifiable consent from a parent or lawful guardian, and the Act prohibits processing that is likely to cause harm to a child, as well as tracking, behavioural monitoring and targeted advertising directed at children. ## What are the penalties for non-compliance? The Schedule to the Act empowers the Data Protection Board to impose significant financial penalties. The headline figure is up to ₹250 crore for failing to take reasonable security safeguards to prevent a personal data breach. Other failures — such as breach-notification lapses or breaches of children’s-data obligations — carry penalties up to ₹200 crore, assessed per instance based on the nature, gravity and duration of the violation. > The cost of non-compliance is no longer theoretical: penalties scale to ₹250 crore, and they are assessed per instance. ## Who enforces the DPDPA? The Act establishes the Data Protection Board of India — a digital-first adjudicatory body that investigates complaints and breaches, directs remedial measures, and imposes penalties. Appeals from the Board lie to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT). The Board is designed to operate as a digital office, so engaging with it — and proving your compliance — will itself be a largely digital exercise. ## How should businesses prepare? DPDPA readiness is an operating capability, not a one-off policy document. The practical starting points are: build a data inventory, deploy compliant consent notices and a consent-management capability, stand up a Data Principal rights workflow, tighten security safeguards, prepare a breach-response plan, and govern your vendors through data-processing agreements. From there, maintain continuous evidence so you can demonstrate compliance whenever the Board asks. > **Start with a benchmark** — Run a free DPDPA readiness assessment to see exactly where your gaps are and get a prioritised action plan before you invest in tooling. ### FAQs — What is the DPDPA? India’s Digital Personal Data Protection Act, 2023 Explained **Q: Is the DPDPA the same as the GDPR?** A: No. The DPDPA is India’s own law. It shares concepts with the GDPR (notice, consent, individual rights, accountability) but is shorter, uses different terms (Data Fiduciary/Principal), takes a “blacklist” approach to cross-border transfers, and is enforced by the Data Protection Board of India. **Q: Does the DPDPA apply to companies outside India?** A: Yes. If an organisation outside India processes the personal data of individuals in India in connection with offering goods or services to them, it must comply with the DPDPA. **Q: What is the difference between a Data Fiduciary and a Data Processor?** A: A Data Fiduciary decides why and how personal data is processed and is accountable for compliance. A Data Processor processes data only on the Fiduciary’s instructions. The Fiduciary remains responsible even when processing is outsourced. **Q: When does the DPDPA take effect?** A: The Act was enacted in 2023 and is being operationalised in phases through the DPDP Rules 2025, with transition periods for different obligations. Businesses should begin compliance now rather than wait for the final enforcement date. **Q: What is the maximum penalty under the DPDPA?** A: Up to ₹250 crore per instance for failing to take reasonable security safeguards to prevent a personal data breach, with other violations attracting penalties up to ₹200 crore. ## DPDPA Penalties: How Much Can DPDPA Non-Compliance Cost? URL: https://dapro.in/dpdpa-guide/dpdpa-penalties · Last updated: 2026-07-06 **What are the penalties under the DPDPA?** DPDPA penalties are civil financial penalties imposed by the Data Protection Board of India, scaling up to ₹250 crore for failing to take reasonable security safeguards to prevent a data breach. Fines are assessed per instance based on the nature, gravity, duration and impact of the violation. The Digital Personal Data Protection Act, 2023 (DPDPA) backs its obligations with real financial teeth. Where earlier Indian data rules carried only token consequences, the DPDPA empowers the Data Protection Board of India to impose penalties that can reach ₹250 crore for a single category of failure — making non-compliance a board-level financial risk rather than a paperwork issue. Crucially, the DPDPA is a civil-penalty regime. It does not create new criminal offences or prison terms for breaching its provisions; the consequence of non-compliance is a monetary penalty determined through an adjudication process. That changes how organisations should think about risk — the exposure is quantifiable, repeatable, and tied directly to how well you can evidence your controls. ## What is the penalty Schedule under the DPDPA? The penalties are set out in the Schedule to the Act, which fixes a maximum penalty for each category of breach. These are ceilings, not fixed amounts — the Board decides the actual figure within each cap based on the circumstances of the case. **Maximum penalties under the Schedule to the DPDP Act, 2023** | Violation | Maximum penalty | | --- | --- | | Failure to take reasonable security safeguards to prevent a personal data breach (Section 8(5)) | Up to ₹250 crore | | Failure to notify the Data Protection Board or affected Data Principals of a personal data breach | Up to ₹200 crore | | Non-fulfilment of additional obligations in relation to children (Section 9) | Up to ₹200 crore | | Non-fulfilment of additional obligations of a Significant Data Fiduciary (Section 10) | Up to ₹150 crore | | Breach of any other provision of the Act or the Rules | Up to ₹50 crore | | Breach of a Data Principal’s duties | Up to ₹10,000 | > **Security failure carries the highest exposure** — The single largest penalty — up to ₹250 crore — attaches to failing to take reasonable security safeguards. Because almost every serious incident begins with a security lapse, this is the cap most organisations should plan against first. ## How are DPDPA penalties assessed? The Schedule sets the maximum; the actual penalty is decided by the Data Protection Board after giving the organisation a reasonable opportunity to be heard. Section 33 directs the Board to have regard to a defined set of factors when fixing the amount, so the penalty is proportionate rather than automatic. - The nature, gravity and duration of the breach. - The type and nature of the personal data affected by the breach. - Whether the breach is repetitive — repeat conduct attracts a higher penalty. - Whether, as a result of the breach, the person realised a gain or avoided a loss. - Whether the person took any action to mitigate the breach, and how timely and effective that action was. - Whether the penalty is proportionate and effective having regard to securing compliance and deterring further breaches. - The likely impact of the penalty on the person. In practice this means two organisations that suffer the same incident can face very different penalties. The one that detected the breach quickly, notified promptly, mitigated harm and can produce contemporaneous evidence of reasonable safeguards will be treated far more leniently than one that ignored warnings or cannot demonstrate any controls at all. > **Evidence reduces exposure** — Maintaining continuous, timestamped evidence of your safeguards, consent records and breach response is the most reliable way to push a penalty toward the lower end of the band — or avoid one entirely. ## Who imposes DPDPA penalties? Penalties are imposed by the Data Protection Board of India, an independent adjudicatory body established under the Act. The Board investigates complaints from Data Principals and personal data breaches, issues directions for remedial or mitigation measures, and conducts inquiries before deciding whether to impose a financial penalty. It is designed to function as a digital-first office, so much of the process — from complaint to inquiry — is conducted electronically. The Board acts on complaints, on references from the Central Government, and on intimations of breaches. It is the only authority empowered to impose the penalties in the Schedule; there is no separate sectoral fine on top of the DPDPA penalty for the same conduct. ## Can you appeal a DPDPA penalty? Yes. An organisation aggrieved by an order or direction of the Data Protection Board can appeal to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), which acts as the Appellate Tribunal under the Act. Appeals must generally be filed within 60 days of receiving the Board’s order. The Tribunal hears the matter using a digital process and can confirm, vary or set aside the Board’s decision. A further appeal on a question of law lies to the Supreme Court of India. > The DPDPA does not threaten imprisonment — it threatens balance-sheet impact. A single security failure can cost up to ₹250 crore, decided per instance by the Data Protection Board. ## Are DPDPA penalties criminal? Is there imprisonment? No. The DPDPA is a civil-penalty statute. Unlike some earlier proposals and unlike provisions of the Information Technology Act, the DPDPA does not prescribe imprisonment for breaching its data-protection obligations. The consequence of non-compliance is a monetary penalty determined by the Board, not a custodial sentence. (Separate criminal liability could still arise under other laws — for example for fraud or theft — but that is outside the DPDPA itself.) ## Are DPDPA penalties charged per instance? The figures in the Schedule are maximum penalties per instance of breach rather than a single annual cap. Because the Board weighs whether conduct is repetitive, an organisation with multiple distinct failures — or a pattern of the same failure — can face penalties that compound well beyond the headline number for one violation. The practical lesson is that systemic, unaddressed gaps are far more dangerous than a single isolated lapse. ## How can businesses reduce their penalty exposure? Because the Board explicitly weighs safeguards, mitigation and timeliness, penalty exposure is something you can actively manage. The most effective levers are: implementing and documenting reasonable security safeguards under Section 8(5), running a tested breach-response plan so notification is fast and complete, keeping clean consent and rights records, and maintaining continuous evidence of compliance so you can demonstrate good faith if the Board ever asks. > **Know your exposure before the Board does** — Run a free DPDPA readiness assessment to map your highest-penalty gaps — especially around security safeguards and breach response — and get a prioritised plan to close them. ### FAQs — DPDPA Penalties: How Much Can DPDPA Non-Compliance Cost? **Q: What is the maximum DPDPA penalty?** A: The maximum penalty under the DPDPA is up to ₹250 crore, which applies to failing to take reasonable security safeguards to prevent a personal data breach under Section 8(5). It is a ceiling per instance, not a fixed amount — the Data Protection Board sets the actual figure based on the circumstances. **Q: Who decides the amount of a DPDPA penalty?** A: The Data Protection Board of India decides the amount, within the maximum set by the Schedule, after an inquiry and an opportunity to be heard. Section 33 requires the Board to weigh the nature, gravity and duration of the breach, any gains made, mitigation efforts and the likely impact of the penalty. **Q: Are DPDPA penalties charged per instance or per year?** A: They are maximum penalties per instance of breach, not a single annual cap. Multiple distinct violations — or repeated instances of the same failure — can attract penalties that add up well beyond the headline figure for one breach, especially where the Board finds the conduct repetitive. **Q: Can directors be personally liable under the DPDPA?** A: The DPDPA imposes penalties on the Data Fiduciary (the organisation), not automatically on individual directors. There is no provision making directors personally and automatically liable for the company’s penalty, though directors remain responsible for ensuring the organisation builds and evidences compliance to avoid that exposure. **Q: Is there imprisonment under the DPDPA?** A: No. The DPDPA is a civil-penalty regime and does not prescribe imprisonment for breaching its data-protection obligations. The consequence of non-compliance is a monetary penalty imposed by the Data Protection Board, not a custodial sentence. **Q: How do you appeal a DPDPA penalty?** A: An organisation can appeal an order of the Data Protection Board to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT), generally within 60 days. The Tribunal can confirm, vary or set aside the Board’s decision, and a further appeal on a question of law lies to the Supreme Court. **Q: What is the penalty for failing to report a data breach?** A: Failure to notify the Data Protection Board or affected Data Principals of a personal data breach attracts a penalty of up to ₹200 crore under the Schedule. Prompt, complete notification is also a mitigating factor that the Board weighs when setting any penalty. **Q: Can a Data Principal be penalised under the DPDPA?** A: Yes, but only modestly. Breach of a Data Principal’s duties — such as filing false or frivolous complaints or registering false particulars — can attract a penalty of up to ₹10,000, far below the penalties that apply to organisations. ## Data Fiduciary Obligations Under the DPDPA: A Complete Guide URL: https://dapro.in/dpdpa-guide/data-fiduciary-obligations · Last updated: 2026-07-06 **What are the obligations of a Data Fiduciary under the DPDPA?** A Data Fiduciary must process personal data only for the consented or lawful purpose, keep it accurate, apply reasonable security safeguards, notify breaches to the Board and affected individuals, erase data when no longer needed, publish a contact for queries, and run a grievance mechanism (Section 8). It stays accountable even when a Data Processor handles the data. Under India’s Digital Personal Data Protection Act, 2023 (DPDPA), a Data Fiduciary is any person who — alone or with others — determines the purpose and means of processing personal data. If you decide why and how customer, employee or user data is processed, you are a Data Fiduciary, and Section 8 of the Act places a clear set of operational duties on you regardless of your size or sector. These obligations are not optional policy aspirations. The Data Protection Board of India can impose penalties of up to ₹250 crore for failing to take reasonable security safeguards, so understanding and operationalising Section 8 — alongside the notice duty in Section 5 and the legitimate uses in Section 7 — is the core of DPDPA compliance. ## What is a Data Fiduciary under the DPDPA? Section 2(i) defines a Data Fiduciary as any person who, alone or in conjunction with other persons, determines the purpose and means of processing of personal data. This is the DPDPA equivalent of a “controller” under the GDPR. The role carries accountability: the Fiduciary is the legally responsible party, even when day-to-day processing is carried out by a Data Processor on its behalf under Section 8(2). A Data Fiduciary may itself be a regular Fiduciary or, where notified by the Central Government under Section 10, a Significant Data Fiduciary (SDF) with additional duties. This guide covers the baseline Section 8 obligations that apply to every Data Fiduciary. ## What are the Section 8 obligations of a Data Fiduciary? Section 8 is the heart of the Data Fiduciary’s duties. It runs from the basis on which you may process data to how you must wind it down. These are the key obligations: **Lawful purpose (Section 8(1))**: Process personal data only in accordance with the Act and for the purpose for which the Data Principal consented, or for a legitimate use under Section 7 — and remain responsible for compliance including for any processing on your behalf. **Accountability for processors (Section 8(2))**: You may engage a Data Processor to process personal data only under a valid contract. The accountability for compliance stays with you — outsourcing the activity does not outsource the responsibility. **Data accuracy (Sections 8(3)–8(4))**: Ensure the completeness, accuracy and consistency of personal data where it is used to make a decision affecting the Data Principal, or where it is disclosed to another Data Fiduciary. **Reasonable security safeguards (Section 8(5))**: Protect personal data in your possession or control by taking reasonable security safeguards to prevent a personal data breach. **Breach notification (Section 8(6))**: On becoming aware of a personal data breach, notify the Data Protection Board and each affected Data Principal in the form and manner prescribed by the DPDP Rules 2025. **Data erasure (Sections 8(7)–8(8))**: Erase personal data — and cause your processors to erase it — once the Data Principal withdraws consent or the specified purpose is served and retention is no longer necessary under any law. **Published contact (Section 8(9))**: Publish the business contact information of a Data Protection Officer (if applicable) or other person able to answer questions about the processing on behalf of the Fiduciary. **Grievance redressal (Section 8(10))**: Establish an effective mechanism to redress the grievances of Data Principals, and respond within the period the DPDP Rules prescribe. ## What does “lawful purpose” mean for processing? Section 8(1) anchors everything else: you may process a Data Principal’s personal data only in accordance with the Act, and only for the purpose for which consent was given — or for a permitted legitimate use. You must also remain responsible for that processing, including processing carried out by a Data Processor on your behalf. In practice this means purpose limitation is enforceable: data collected to fulfil an order cannot be quietly repurposed for unrelated marketing without a fresh basis. Before consent is the trigger, the notice duty applies. Under Section 5, on or before requesting consent you must give an itemised notice describing the personal data to be collected and the purpose of processing, how the Data Principal can exercise their rights, and how to complain to the Data Protection Board — available in English or any language listed in the Eighth Schedule to the Constitution. ## What are the legitimate uses under Section 7? Consent is the primary basis, but Section 7 sets out a defined list of “legitimate uses” where personal data may be processed without separate consent. These are narrow and specific, not a general-purpose exemption. They include: - Where the Data Principal has voluntarily provided their personal data for a specified purpose and has not indicated they do not consent to its use. - For the State and its instrumentalities to provide a subsidy, benefit, service, certificate, licence or permit. - For performing a function under any law, or in the interest of the sovereignty and integrity of India or security of the State. - For fulfilling a legal obligation to disclose information to the State. - For compliance with a judgment, decree or order under any law. - For responding to a medical emergency, providing medical treatment during an epidemic or threat to public health, or ensuring safety during a disaster or breakdown of public order. - For purposes of employment, or to safeguard the employer from loss or liability (for example, preventing corporate espionage or providing services/benefits to employees). Even when you rely on a legitimate use rather than consent, the rest of Section 8 still applies — you must still keep data accurate, secure it, erase it when no longer needed, and run a grievance mechanism. ## How must a Data Fiduciary keep data accurate? Sections 8(3) and 8(4) impose a targeted accuracy duty. You must ensure the completeness, accuracy and consistency of personal data in two high-stakes situations: where the data is likely to be used to make a decision that affects the Data Principal, and where it is likely to be disclosed to another Data Fiduciary. The logic is to prevent harm flowing from stale or incorrect data — a wrong address, an outdated credit flag or an incorrect identity field — when that data drives a decision or moves to a third party. ## What security safeguards are required? Section 8(5) requires every Data Fiduciary to protect the personal data in its possession or under its control — including data processed on its behalf by a Data Processor — by taking reasonable security safeguards to prevent a personal data breach. The DPDP Rules 2025 give shape to “reasonable”, expecting measures such as encryption, masking or tokenisation, access controls, logging and monitoring, backups, and contractual security obligations on processors. This is the obligation that carries the heaviest exposure: failure to take reasonable security safeguards to prevent a personal data breach can attract a penalty of up to ₹250 crore — the single largest figure in the Schedule to the Act. > **You remain accountable for your processors** — Engaging a Data Processor under a contract (Section 8(2)) does not transfer your liability. If your vendor suffers a breach involving your data, you — the Data Fiduciary — answer to the Board. Govern processors with binding data-processing agreements, security obligations and erasure duties. ## How must breaches be notified? Section 8(6) requires that, on becoming aware of a personal data breach, the Data Fiduciary notifies both the Data Protection Board and each affected Data Principal in the form and manner prescribed. The DPDP Rules 2025 set out a two-part regime: an intimation to affected individuals describing the breach, its likely consequences and the measures they can take, and a report to the Board — initially without delay, followed by detailed information (including the broad facts, mitigation measures and remedial steps) within the prescribed window. Speed, completeness and documentation all matter here. ## When must a Data Fiduciary erase personal data? Sections 8(7) and 8(8) embed storage limitation. You must erase personal data — and cause your Data Processors to erase it — when the Data Principal withdraws consent, or as soon as it is reasonable to assume the specified purpose is no longer being served, unless retention is required by law. The DPDP Rules 2025 add specific retention-and-erasure timelines for certain classes of Data Fiduciary (such as large e-commerce, online gaming and social media intermediaries), typically requiring erasure after a defined period of Data Principal inactivity, with advance notice before deletion. ## Who must a Data Fiduciary publish as a contact? Section 8(9) requires you to publish, in the prescribed manner, the business contact information of a Data Protection Officer (where you are required to appoint one) or of another person who is able to answer, on your behalf, the questions of Data Principals about the processing of their personal data. In practice this is a clearly reachable contact point — typically on your privacy notice and website — so individuals know who to ask. ## What grievance mechanism is required? Section 8(10) requires every Data Fiduciary to establish an effective mechanism to redress the grievances of Data Principals. This works alongside the Data Principal’s right to grievance redressal under Section 13: an individual must be able to raise a complaint about your processing or about an unanswered rights request, and you must respond within the period the DPDP Rules prescribe. Only after exhausting your mechanism (or being unsatisfied with it) does the individual approach the Data Protection Board. ## What is your Data Fiduciary obligations checklist? Translate Section 8 into an operating checklist. Work through these obligations in order: 1. Establish a lawful basis — process only for a consented purpose (Section 6) or a legitimate use (Section 7), and serve a compliant itemised notice first (Section 5). 2. Apply purpose limitation — use personal data only for the purpose for which it was collected, and obtain a fresh basis before repurposing. 3. Keep data accurate — ensure completeness, accuracy and consistency wherever data drives a decision affecting the individual or is shared with another Fiduciary (Sections 8(3)–8(4)). 4. Implement reasonable security safeguards — encryption, access control, logging, backups and processor security obligations to prevent a breach (Section 8(5)). 5. Stand up a breach-response plan — detect, contain and notify the Board and affected individuals in the prescribed form and timeline (Section 8(6)). 6. Govern erasure and retention — delete data when consent is withdrawn or the purpose is served and retention is no longer required by law (Sections 8(7)–8(8)). 7. Publish a contact point — make the DPO or responsible person’s business contact details readily available (Section 8(9)). 8. Run a grievance mechanism — provide an effective, responsive channel for Data Principal complaints (Section 8(10)). 9. Govern your processors — use binding contracts, flow down security and erasure duties, and remember accountability stays with you (Section 8(2)). 10. Maintain evidence — keep records, consent artefacts and audit trails so you can demonstrate compliance to the Board on demand. > **Turn the checklist into evidence** — Run a free DPDPA readiness assessment to map your processing against every Section 8 duty and get a prioritised action plan before you invest in tooling. ### FAQs — Data Fiduciary Obligations Under the DPDPA: A Complete Guide **Q: What is the difference between a Data Fiduciary and a Data Processor?** A: A Data Fiduciary determines the purpose and means of processing and is accountable for compliance under the DPDPA. A Data Processor processes personal data only on the Fiduciary’s instructions under a contract (Section 8(2)). The Fiduciary remains responsible even when processing is outsourced. **Q: Does a Data Fiduciary remain liable if its vendor causes a breach?** A: Yes. Under Section 8(2) and 8(5), accountability stays with the Data Fiduciary even when a Data Processor handles the data. If a vendor suffers a breach involving your data, you must notify the Board and affected individuals and you face the penalty exposure — so govern processors with binding contracts. **Q: When must a Data Fiduciary erase personal data?** A: Under Sections 8(7)–8(8), you must erase personal data when the Data Principal withdraws consent or when the specified purpose is served and retention is no longer required by any law. You must also cause your Data Processors to erase it. The DPDP Rules 2025 set specific timelines for certain classes of Fiduciary. **Q: Do Data Fiduciaries need to appoint a Data Protection Officer?** A: Only Significant Data Fiduciaries (SDFs) notified under Section 10 must appoint a DPO based in India. A regular Data Fiduciary need not appoint a DPO, but under Section 8(9) it must publish the contact of a person who can answer Data Principals’ questions about processing. **Q: What is the penalty for failing Data Fiduciary obligations?** A: The Schedule to the Act sets penalties up to ₹250 crore for failing to take reasonable security safeguards to prevent a breach (Section 8(5)). Breach-notification failures and other obligation breaches attract penalties up to ₹200 crore, assessed per instance by the Data Protection Board. **Q: Does a Data Fiduciary need consent to process every type of data?** A: Not always. Consent (Section 6) is the primary basis, but Section 7 permits a defined set of legitimate uses — such as voluntarily provided data, employment purposes, legal obligations and medical emergencies — without separate consent. The rest of the Section 8 obligations still apply in those cases. **Q: What must a Data Fiduciary include in its grievance mechanism?** A: Under Section 8(10), you must establish an effective channel for Data Principals to raise complaints about your processing or unanswered rights requests, and respond within the period prescribed by the DPDP Rules 2025. The mechanism must be reachable and operate before an individual escalates to the Board. ## Consent Management Under the DPDPA: How to Build a Compliant Consent Flow URL: https://dapro.in/dpdpa-guide/consent-management · Last updated: 2026-07-06 **What does consent management require under the DPDPA?** Under the DPDPA, you must serve an itemised, plain-language notice (Section 5), then obtain consent that is free, specific, informed, unconditional and unambiguous through clear affirmative action (Section 6). Consent must be limited to necessary data, granular per purpose, easy to withdraw, logged for proof, and refreshed on any material change of purpose. Consent is the primary basis for processing personal data under India’s Digital Personal Data Protection Act, 2023 (DPDPA). Getting consent right is therefore the foundation of compliance — and the most visible touchpoint between your organisation and every Data Principal. A compliant consent flow is built from two sections working together: the notice in Section 5 and the consent standard in Section 6. This guide walks through what the notice must say, what valid consent looks like, how withdrawal must work, the role of registered Consent Managers, and the operational details — granular per-purpose consent, audit trails and re-consent — that separate a compliant flow from a pre-ticked checkbox. ## What must the Section 5 consent notice contain? Section 5 requires that, on or before requesting consent, the Data Fiduciary gives the Data Principal a notice. Where consent was obtained before the Act commenced, a notice must be given as soon as reasonably practicable. The notice must be in clear and plain language and must include, as a minimum: - An itemised description of the personal data to be collected. - The purpose for which the personal data is proposed to be processed. - The manner in which the Data Principal may exercise their rights under Section 6(4) (to withdraw consent) and Section 13 (grievance redressal). - The manner in which the Data Principal may make a complaint to the Data Protection Board of India. The Data Principal must be given the option to access the notice in English or in any language listed in the Eighth Schedule to the Constitution of India — which lists 22 scheduled languages including Hindi, Bengali, Tamil, Telugu, Marathi, Gujarati and more. The DPDP Rules 2025 reinforce that the notice should be understandable on its own, presented separately from other information, and give an explicit means to withdraw consent as easily as it was given. ## What is the Section 6 standard for valid consent? Section 6(1) sets a strict quality bar. Consent for processing personal data must be: **Free**: Given without coercion, pressure or detriment for refusal — and not bundled with the provision of a service where the data is not necessary for it. **Specific**: Tied to a clearly stated purpose, not a vague or open-ended permission to use data for anything. **Informed**: Preceded by the Section 5 notice so the individual understands what data is collected and why. **Unconditional**: Not made a condition for receiving a service unless the personal data is genuinely necessary for that service. **Unambiguous, with clear affirmative action**: Signalled by a positive act — such as ticking an unticked box or clicking “I agree” — never by silence, inactivity or a pre-ticked box. **Limited to necessary data**: Section 6(1) limits consent to the personal data necessary for the specified purpose; any processing beyond that purpose falls outside the consent. Section 6(2) makes the consequence explicit: if consent extends to personal data not necessary for the specified purpose, that excess is invalid to the extent it is unnecessary. In short, you cannot collect more than you need and lean on a broad consent to justify it. ## How must consent withdrawal work? Section 6(4) gives the Data Principal the right to withdraw consent at any time. Critically, Section 6(5) requires that the ease of withdrawing consent must be comparable to the ease with which it was given — you cannot make signing up a single click but force a phone call or a multi-step process to opt out. Section 6(6) addresses what happens next: on withdrawal, the Data Fiduciary must — within a reasonable time — cease processing the Data Principal’s personal data, and cause its Data Processors to cease processing, unless that processing is required or authorised under the Act or any other law. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and it may carry legitimate consequences (for example, you may no longer be able to provide a service that depended on the data). ## What is a Consent Manager under the DPDPA? The DPDPA introduces a distinctive concept: the Consent Manager. Under Section 6(7)–6(9), a Data Principal may give, manage, review and withdraw consent through a Consent Manager — a single point of contact that acts on behalf of the individual. A Consent Manager must be registered with the Data Protection Board and must be interoperable, meeting the technical and financial conditions the DPDP Rules 2025 prescribe (including a minimum net worth and obligations to act in a fiduciary capacity towards the Data Principal). For Data Fiduciaries, this means consent may arrive not only directly through your own interface but also via a registered Consent Manager’s platform, with a verifiable record of what the individual agreed to. Designing your consent flow to interoperate with Consent Managers future-proofs it. ## Why must consent be granular and per-purpose? Because consent must be specific and limited to necessary data, you cannot bundle multiple unrelated purposes behind a single checkbox. Each distinct purpose — fulfilling an order, sending marketing, sharing with a partner, analytics — needs its own clearly described consent that the individual can grant or decline independently. - No bundling — do not combine consent for the core service with consent for optional purposes like marketing or profiling. - No pre-ticked boxes — every consent must require a positive, affirmative action by the Data Principal. - Independent toggles — let individuals accept some purposes and decline others without losing the core service. - Plain-language purpose statements — each toggle should describe its purpose so consent is genuinely informed. ## How do you prove consent was validly obtained? Section 6(10) places the burden of proof on the Data Fiduciary: in the event of a question, you must be able to demonstrate that notice was given and that valid consent was obtained in accordance with the Act and the Rules. That makes an audit trail essential. For every consent event you should be able to produce a tamper-evident record capturing the version of the notice shown, the exact purposes consented to, the timestamp, the consent artefact or identifier, and any subsequent withdrawal — so you can reconstruct precisely what each individual agreed to and when. ## When do you need to re-consent? Consent is anchored to a specific purpose. If you materially change the purpose of processing — adding a new use of the data, sharing it with a new category of recipient, or extending it beyond what the original notice described — the original consent no longer covers that new activity. You must serve a fresh Section 5 notice and obtain new, specific consent before processing for the changed purpose. Treat material change as a re-consent trigger rather than an internal update. ## When can you process without consent (legitimate uses)? Consent is the primary basis, but Section 7 provides an alternative: a defined list of “legitimate uses” where personal data may be processed without separate consent. These include data the individual has voluntarily provided for a specified purpose, certain State functions and subsidy/benefit delivery, compliance with legal obligations and court orders, responding to medical emergencies and disasters, and specified employment purposes. Legitimate uses are narrow and purpose-bound — they are not a fallback for processing you simply forgot to get consent for, and the Section 8 obligations still apply. ## How do you build a compliant consent flow? Bringing Sections 5, 6 and 7 together, a compliant consent flow can be built in six steps: 1. Map your purposes and data — list each distinct processing purpose and the minimum personal data necessary for it, so consent can be specific and limited. 2. Draft an itemised, plain-language notice — describe the data collected, the purposes, how to exercise rights and withdraw consent, and how to complain to the Board, available in English and Eighth Schedule languages. 3. Capture consent by clear affirmative action — present granular, unticked, per-purpose toggles with no bundling and no pre-selection, so each consent is free, specific and unambiguous. 4. Make withdrawal as easy as giving — provide a one-step, equally accessible way to withdraw any consent, and cease the relevant processing (and instruct processors to cease) within a reasonable time. 5. Log a tamper-evident audit trail — record the notice version, purposes, timestamp, consent artefact and any withdrawal for every event, so you can prove compliance under Section 6(10). 6. Re-consent on material change and support Consent Managers — re-notify and re-collect consent when purposes change, and design the flow to interoperate with registered Consent Managers. > **Generate a compliant notice fast** — Use the Consent Notice Generator to produce an itemised, plain-language Section 5 notice — with rights, withdrawal and Board-complaint details — tailored to your purposes. Start at /tools/consent-notice-generator. ### FAQs — Consent Management Under the DPDPA: How to Build a Compliant Consent Flow **Q: What makes consent valid under the DPDPA?** A: Under Section 6, consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and limited to the personal data necessary for the specified purpose. It must be preceded by the Section 5 notice. Pre-ticked boxes, silence or bundled consent do not meet the standard. **Q: Can I use one checkbox for all my data processing purposes?** A: No. Consent must be specific and limited to necessary data, so distinct purposes — such as the core service, marketing and data sharing — need separate, granular consent that the Data Principal can grant or decline independently. Bundling unrelated purposes behind one checkbox is non-compliant. **Q: How easy must it be to withdraw consent?** A: Section 6(5) requires that withdrawing consent be as easy as giving it. If signing up is a single click, opting out must be comparably simple. On withdrawal, you must cease processing within a reasonable time and instruct your Data Processors to do the same (Section 6(6)). **Q: What is a Consent Manager?** A: A Consent Manager is a person registered with the Data Protection Board who acts as a single, interoperable point of contact enabling a Data Principal to give, manage, review and withdraw consent (Section 6(7)–6(9)). They act in a fiduciary capacity toward the individual and must meet conditions set in the DPDP Rules 2025. **Q: In what languages must the consent notice be available?** A: Under Section 5, the Data Principal must have the option to access the notice in English or any language listed in the Eighth Schedule to the Constitution of India, which covers 22 scheduled languages such as Hindi, Bengali, Tamil, Telugu and Marathi. **Q: Do I need fresh consent if my processing purpose changes?** A: Yes. Consent is tied to the specific purpose described in the notice. If you materially change the purpose — a new use, a new recipient or a broader scope — you must serve a fresh Section 5 notice and obtain new, specific consent before processing for the changed purpose. **Q: Who must prove that valid consent was obtained?** A: The Data Fiduciary. Section 6(10) places the burden of proof on you to demonstrate that notice was given and valid consent was obtained. That is why a tamper-evident audit trail capturing the notice version, purposes, timestamp and any withdrawal is essential. **Q: Can I process personal data without consent?** A: Only for the “legitimate uses” defined in Section 7 — such as voluntarily provided data, certain State functions, legal obligations, medical emergencies and specified employment purposes. These are narrow and purpose-bound, and the Section 8 obligations still apply. They are not a general substitute for consent. ## Significant Data Fiduciary (SDF): Extra DPDPA Obligations Explained URL: https://dapro.in/dpdpa-guide/significant-data-fiduciary · Last updated: 2026-07-06 **What is a Significant Data Fiduciary under the DPDPA?** A Significant Data Fiduciary (SDF) is a Data Fiduciary notified by the Central Government under Section 10 of the DPDPA, based on factors like data volume, sensitivity and risk. An SDF carries extra duties: appoint an India-based DPO, appoint an independent data auditor, and conduct periodic Data Protection Impact Assessments and audits. Most organisations under India’s Digital Personal Data Protection Act, 2023 (DPDPA) are ordinary Data Fiduciaries, bound by the Section 8 obligations. But the Act recognises that some Fiduciaries process data at a scale or with a sensitivity that warrants stricter oversight. These are Significant Data Fiduciaries (SDFs), defined and regulated under Section 10. Being an SDF does not replace your baseline duties — it layers additional, more demanding obligations on top of them: a dedicated Data Protection Officer based in India, an independent data auditor, and periodic Data Protection Impact Assessments and audits. This guide explains how the government decides who is an SDF, what the extra duties involve, and how to tell whether you might be caught. ## What is a Significant Data Fiduciary? A Significant Data Fiduciary is a Data Fiduciary, or a class of Data Fiduciaries, that the Central Government notifies as “significant” under Section 10(1). The designation is not automatic and is not something you self-declare — it follows a government notification, which may target a specific organisation or an entire category of them. Once notified, an SDF remains subject to every Section 8 obligation that applies to any Data Fiduciary, and additionally must comply with the heightened measures set out in Section 10(2) and any further requirements the DPDP Rules prescribe. ## How does the government decide who is an SDF? Section 10(1) lists the factors the Central Government must take into account when notifying a Data Fiduciary or class as significant. These are not weighted equally — the government assesses them together: - The volume and sensitivity of personal data processed. - The risk to the rights of Data Principals. - The potential impact on the sovereignty and integrity of India. - The risk to electoral democracy. - The security of the State. - Public order. In practice, this points toward large-scale data processors and platforms whose handling of personal data could affect individuals or national interests at scale — for example, very large social media or e-commerce platforms, major data aggregators, or organisations processing highly sensitive data such as financial or health information about millions of people. ## What extra obligations does Section 10 impose? Section 10(2) sets out the additional duties an SDF must meet, on top of the general Section 8 obligations: **Data Protection Officer (DPO)**: An individual the SDF must appoint who is based in India, represents the SDF under the Act, reports to the board of directors or similar governing body, and acts as the point of contact for the grievance redressal mechanism. **Independent data auditor**: An auditor the SDF must appoint to carry out data audits — independent of the SDF’s management — to evaluate the SDF’s compliance with the provisions of the Act. **Data Protection Impact Assessment (DPIA)**: A periodic assessment that describes the rights of Data Principals, the purpose of processing, an assessment and management of risk to those rights, and other matters the Rules prescribe. In summary, every SDF must: appoint a DPO based in India who reports to its board or governing body and is the contact point for grievances; appoint an independent data auditor to evaluate compliance; undertake periodic Data Protection Impact Assessments and periodic audits; and undertake such other measures as the Rules prescribe. > **SDF duties are additive, not a substitute** — Being notified as a Significant Data Fiduciary does not reduce your baseline burden. You must still meet every Section 8 obligation — purpose limitation, accuracy, security safeguards, breach notification, erasure, published contact and grievance redressal — and then satisfy the extra Section 10 measures on top. ## Does an SDF need a DPO based in India? Yes. Section 10(2)(a) is explicit: an SDF must appoint a Data Protection Officer who is based in India. The DPO represents the SDF under the Act, must report to the board of directors or other similar governing body of the SDF, and serves as the point of contact for the grievance redressal mechanism. This is a meaningful governance requirement — the DPO must have real seniority and a direct line to the board, not a nominal title. For a foreign organisation notified as an SDF, it means establishing an accountable, India-resident point of contact. ## What is a DPIA and how often is it required? A Data Protection Impact Assessment is a structured process that documents the rights of Data Principals, the purpose of the processing, and an assessment and management of the risks that processing poses to those rights, together with any other matters the Rules prescribe. Under Section 10(2)(c), an SDF must undertake DPIAs periodically — not as a one-off. The same provision requires periodic audits, with the independent data auditor evaluating compliance. The DPIA is the SDF’s primary tool for identifying and mitigating data-protection risk before it materialises into harm. ## What other measures might the Rules require? Section 10(2)(c) closes with a catch-all: an SDF must undertake “such other measures” as may be prescribed. This gives the DPDP Rules room to impose further, more technical obligations on SDFs, which may include: - Algorithmic due diligence — verifying that the algorithms used to process personal data are not likely to pose a risk to the rights of Data Principals. - Restrictions on transferring certain categories of personal data outside India, as may be specified. - Enhanced record-keeping and reporting obligations beyond those of an ordinary Data Fiduciary. - Specific traffic and data-flow conditions for very large platforms. Because these measures are set by notification and Rules, an SDF should monitor government notifications closely and treat the published Rules as a living source of obligations. ## How do I tell if I might be an SDF? You become an SDF only when notified, so no business is an SDF by default. But you can assess your likelihood against the Section 10(1) factors and prepare accordingly. You are more likely to be in scope if several of the following are true: 1. You process personal data about a very large number of individuals in India — typically millions of Data Principals. 2. You handle sensitive categories such as financial, health, biometric or children’s data at scale. 3. Your processing — through profiling, targeting or large-scale decisioning — could materially affect individuals’ rights. 4. Your platform or service is large enough that its handling of data could affect public order, electoral democracy or national interests. 5. You operate a very large social media, e-commerce, gaming or data-aggregation platform of the kind regulators commonly scrutinise. If most of these describe you, plan as though SDF designation is plausible: the cost of being ready early is far lower than scrambling after a notification. ## How should an organisation prepare for SDF status? Preparation is straightforward once you treat the Section 10 duties as a programme. Identify a DPO candidate based in India with the seniority to report to your board and own grievance redressal. Engage an independent data auditor and define an audit cadence. Build a repeatable DPIA methodology and run it on your highest-risk processing first. Establish algorithmic governance for any automated decisioning, and review your cross-border data flows. Above all, maintain continuous evidence so that, if you are notified, compliance is a matter of demonstrating what you already do rather than building it from scratch. > **Benchmark your SDF readiness** — Run a free DPDPA readiness assessment to test your processing against the Section 10(1) factors and the extra SDF duties, and get a prioritised plan for DPO, auditor and DPIA readiness. ### FAQs — Significant Data Fiduciary (SDF): Extra DPDPA Obligations Explained **Q: Am I a Significant Data Fiduciary?** A: You are an SDF only if the Central Government notifies you — or your class of Fiduciary — as significant under Section 10(1). It is not self-declared. The government weighs factors like the volume and sensitivity of data you process and the risk to Data Principals, India’s sovereignty, electoral democracy, State security and public order. **Q: Does an SDF need a DPO in India?** A: Yes. Section 10(2)(a) requires an SDF to appoint a Data Protection Officer based in India who represents the SDF under the Act, reports to its board of directors or similar governing body, and is the point of contact for the grievance redressal mechanism. **Q: What extra obligations does an SDF have compared with a regular Data Fiduciary?** A: On top of all Section 8 duties, an SDF must appoint an India-based DPO, appoint an independent data auditor, conduct periodic Data Protection Impact Assessments and periodic audits, and undertake such other measures as the Rules prescribe — for example, algorithmic due diligence and possible data-transfer restrictions. **Q: What is a Data Protection Impact Assessment (DPIA)?** A: A DPIA is a periodic assessment, required of SDFs under Section 10(2)(c), that documents the rights of Data Principals, the purpose of processing, and the assessment and management of risk to those rights, plus any other matters the Rules prescribe. It must be undertaken periodically, not just once. **Q: Who appoints the independent data auditor for an SDF?** A: The SDF itself must appoint an independent data auditor under Section 10(2)(b). The auditor carries out data audits to evaluate the SDF’s compliance with the Act, and must be independent of the SDF’s management so the evaluation is objective. **Q: Is every large company automatically a Significant Data Fiduciary?** A: No. Size alone does not make you an SDF — designation requires a government notification under Section 10(1). However, organisations processing very large volumes of sensitive data or operating major platforms are the most likely candidates and should prepare proactively. **Q: Does SDF status replace the ordinary Section 8 obligations?** A: No. SDF duties are additive. A Significant Data Fiduciary must still meet every general obligation in Section 8 — purpose limitation, accuracy, security safeguards, breach notification, erasure, published contact and grievance redressal — and then satisfy the extra Section 10 measures on top. ## DPDPA Compliance Checklist: A Step-by-Step Guide for 2025 URL: https://dapro.in/dpdpa-guide/dpdpa-checklist · Last updated: 2026-07-06 **What does a DPDPA compliance checklist include?** A DPDPA compliance checklist covers building a data inventory, fixing a lawful basis, issuing Section 5 consent notices, enabling easy consent withdrawal, honouring Data Principal rights, securing data under Section 8(5), running a breach-response plan, governing vendors with DPAs, and meeting children’s-data and SDF duties. Complying with the Digital Personal Data Protection Act, 2023 (DPDPA) is less about a single policy document and more about standing up a repeatable operating capability. The Act sets the obligations; the Digital Personal Data Protection Rules, 2025 fill in the operational detail — how notices read, how consent is managed, how breaches are reported, and what extra duties significant organisations carry. This checklist breaks DPDPA readiness into ten practical steps, mapped to the relevant sections of the Act. Work through them in order: the early steps (knowing what data you hold and on what basis) are prerequisites for everything that follows. > **Use the sections as your audit map** — Each step below references the controlling section — Section 5 for notices, Section 6 for consent, Sections 11–13 for rights, Section 8 for fiduciary duties, Section 9 for children, Section 10 for SDFs. Treat the section numbers as the headings for your internal evidence file. ## Step 1 — Build a data inventory and RoPA You cannot protect or account for data you have not mapped. Start by building a complete inventory of the digital personal data you process — what you collect, where it lives, who can access it, why you hold it, and who you share it with. This Record of Processing Activities (RoPA) is the foundation for every other obligation. 1. Catalogue every system, application and third party that touches personal data. 2. Record the categories of data, the data subjects, the purpose and the lawful basis for each flow. 3. Map data sharing with processors and across borders. 4. Keep the inventory live — review it whenever a new system or vendor is onboarded. ## Step 2 — Establish a lawful basis for each purpose Under the DPDPA, personal data may be processed only for a lawful purpose, on the basis of consent or one of the “legitimate uses” permitted by Section 7. For every processing activity in your inventory, confirm and document the basis you are relying on. Where you rely on a legitimate use, make sure it genuinely fits — most direct-to-customer marketing and analytics still requires consent. ## Step 3 — Deploy a Section 5 consent notice Section 5 requires that, on or before requesting consent, you give the Data Principal an itemised notice. The notice must describe the personal data to be collected and the purpose of processing, explain how the individual can exercise their rights and how to complain to the Data Protection Board, and be available in English or any language listed in the Eighth Schedule to the Constitution. - Itemise the personal data and the specific purpose — no bundled, vague catch-alls. - Explain how to exercise rights and how to withdraw consent. - Provide the contact details for grievances and for the Data Protection Board. - Offer the notice in English and the Eighth Schedule languages you serve. ## Step 4 — Build consent management and easy withdrawal Section 6 sets the standard for consent: free, specific, informed, unconditional and unambiguous, given through a clear affirmative action and limited to the data necessary for the stated purpose. Equally important, a Data Principal can withdraw consent at any time, and withdrawal must be as easy as giving it. Stand up a consent-management capability that records, time-stamps and lets users revoke consent — and consider a registered Consent Manager where appropriate. ## Step 5 — Stand up a Data Principal rights workflow Sections 11 to 13 give Data Principals enforceable rights that you must be able to honour quickly and consistently. Build a workflow that can receive a request, verify identity, action it within a reasonable period and log the outcome as evidence. - Right to access information about personal data being processed (Section 11). - Right to correction, completion, updating and erasure of personal data (Section 12). - Right of grievance redressal through a readily available mechanism (Section 13). - Right to nominate another individual to exercise rights in case of death or incapacity (Section 14). ## Step 6 — Provide grievance redressal Section 13 requires every Data Fiduciary to publish and operate a readily available grievance-redressal mechanism, and to respond within the period prescribed by the Rules. Publish a clear point of contact, track every grievance to closure, and only after exhausting your mechanism can a Data Principal escalate to the Data Protection Board — so a well-run desk reduces both complaints and regulatory exposure. ## Step 7 — Enforce data minimisation, retention and erasure Section 8 requires you to collect only the data necessary for the stated purpose and to erase personal data once the purpose is served and retention is no longer required by law. Define retention periods per data category, automate deletion where you can, and ensure that erasing data on the front end actually removes it from backups and downstream systems. ## Step 8 — Implement reasonable security safeguards Section 8(5) obliges you to protect personal data in your possession or control with reasonable security safeguards to prevent a breach — and it is the obligation carrying the highest penalty, up to ₹250 crore. Implement and document technical and organisational measures appropriate to the risk. - Encryption, access controls and the principle of least privilege. - Logging, monitoring and alerting on access to personal data. - Regular backups, patching and vulnerability management. - Contractual security obligations on every processor that holds your data. ## Step 9 — Prepare a breach-response plan A personal data breach must be reported to the Data Protection Board and to affected Data Principals, in the form and within the timeline set by the DPDP Rules 2025. Because speed and completeness are both penalty-relevant and explicitly weighed by the Board, prepare and rehearse a plan before you need it. 1. Define detection, triage and escalation paths with named owners. 2. Prepare notification templates for the Board and for affected individuals. 3. Run tabletop exercises so the team can act inside the prescribed timeline. 4. Capture timestamped evidence of detection, containment and notification. ## Step 10 — Govern processors, children’s data and SDF duties Three obligations sit on top of the core programme. Under Section 8(2) you may only engage a Data Processor under a valid contract, so put a data-processing agreement (DPA) in place with every vendor — you remain accountable even when processing is outsourced. Under Section 9, processing a child’s data (anyone under 18) requires verifiable parental consent and prohibits tracking, behavioural monitoring and targeted advertising directed at children. And if you are notified as a Significant Data Fiduciary (SDF) under Section 10, you must additionally appoint a Data Protection Officer based in India, appoint an independent data auditor, and carry out periodic Data Protection Impact Assessments and audits. > **Accountability is not transferable** — Outsourcing processing to a vendor does not outsource your liability. Without a valid Section 8(2) contract and oversight, a processor’s lapse becomes your penalty. ## How do you keep DPDPA compliance current? Compliance is a continuous capability, not a one-time project. Re-run your data inventory as systems change, refresh notices and consent flows when purposes change, re-test breach response periodically, and maintain continuous, timestamped evidence so you can demonstrate compliance whenever the Data Protection Board asks. Treat the ten steps above as a recurring cycle rather than a checklist you complete once. > **Start with a free readiness assessment** — Benchmark your programme against this checklist with a free DPDPA readiness assessment at /tools/dpdpa-readiness-assessment — it pinpoints your highest-risk gaps and returns a prioritised action plan. ### FAQs — DPDPA Compliance Checklist: A Step-by-Step Guide for 2025 **Q: What is the first step in DPDPA compliance?** A: Building a data inventory or Record of Processing Activities (RoPA). You cannot fix a lawful basis, secure data, honour rights requests or respond to a breach unless you first know exactly what personal data you hold, where it lives, why you have it and who you share it with. **Q: Do small businesses need to comply with the DPDPA?** A: Yes. The DPDPA applies to any organisation that processes the digital personal data of individuals in India, regardless of size. Smaller organisations may face lighter operational expectations, but the core duties — lawful basis, consent notice, rights, security and breach notification — still apply. **Q: What is a Section 5 consent notice?** A: It is the itemised notice you must give on or before requesting consent. It describes the personal data to be collected and the purpose, explains how to exercise rights and complain to the Data Protection Board, and must be available in English or any language in the Eighth Schedule to the Constitution. **Q: How easy must consent withdrawal be under the DPDPA?** A: Section 6 requires that withdrawing consent be as easy as giving it. If a user can opt in with one action, they should be able to opt out with comparable ease — you cannot make withdrawal slower, harder or more buried than the original consent. **Q: Who is a Significant Data Fiduciary (SDF)?** A: An SDF is a Data Fiduciary notified by the government as “significant” based on the volume and sensitivity of data processed and the risk involved. Under Section 10, SDFs carry extra duties: appointing a Data Protection Officer in India, an independent data auditor, and conducting periodic DPIAs and audits. **Q: What are the obligations for processing children’s data?** A: Under Section 9, anyone under 18 is a child. Processing a child’s personal data requires verifiable consent from a parent or lawful guardian, and the Act prohibits processing likely to harm a child as well as tracking, behavioural monitoring and targeted advertising directed at children. **Q: Do I need a contract with my data-processing vendors?** A: Yes. Section 8(2) allows you to engage a Data Processor only under a valid contract, so you need a data-processing agreement (DPA) with each vendor. You remain accountable for compliance even when a processor handles the data on your behalf. **Q: How long does DPDPA compliance take?** A: It varies with your data footprint, but most organisations should treat it as a phased programme rather than a one-off. Start now with a readiness assessment to identify gaps, prioritise the highest-risk items (security and breach response), then build the consent, rights and governance capabilities iteratively. ## DPDPA vs GDPR: Key Differences for Indian Businesses URL: https://dapro.in/dpdpa-guide/dpdpa-vs-gdpr · Last updated: 2026-07-06 **What is the difference between the DPDPA and the GDPR?** The DPDPA is India’s data law and the GDPR is the EU’s. Both protect personal data and grant individual rights, but the DPDPA is shorter, has no separate “sensitive data” category, treats anyone under 18 as a child, uses a negative-list for cross-border transfers, and caps penalties at ₹250 crore. India’s Digital Personal Data Protection Act, 2023 (DPDPA) is frequently compared to the EU’s General Data Protection Regulation (GDPR) — and for good reason. Many Indian businesses already comply with the GDPR because they serve European customers, and the DPDPA borrows several of its core ideas. But the two laws are far from identical, and assuming GDPR compliance equals DPDPA compliance is a costly mistake. At a high level, the DPDPA is deliberately leaner. The GDPR runs to 99 articles with detailed prescriptions; the DPDPA is a compact, principles-based statute that leaves much of the operational detail to the Digital Personal Data Protection Rules, 2025. This section unpacks where the two overlap and where the differences will change how an Indian business operates. ## How do the DPDPA and GDPR compare at a glance? The table below summarises the most consequential differences across the dimensions that matter most when designing a compliance programme. **DPDPA (India) vs GDPR (EU) — key differences** | Aspect | DPDPA (India) | GDPR (EU) | | --- | --- | --- | | Terminology | Data Fiduciary (controller) and Data Principal (the individual) | Data Controller and Data Subject | | Scope of data | Digital personal data only; no separate “sensitive personal data” category | All personal data, with special categories (health, biometrics, etc.) given extra protection | | Legal bases | Consent plus a defined set of “legitimate uses” (Section 7) | Six lawful bases, including legitimate interests and contractual necessity | | Cross-border transfers | Transfers allowed except to countries on a government “negative list” (blacklist) | Transfers need an adequacy decision, Standard Contractual Clauses (SCCs) or other safeguards (allow-list) | | Age of a child | Under 18 | Under 16 by default; member states may lower it to 13 | | DPO requirement | Mandatory only for Significant Data Fiduciaries (Section 10) | Required for public authorities and large-scale or sensitive processing — a broader set | | Maximum penalty | Up to ₹250 crore per instance | Up to €20 million or 4% of global annual turnover, whichever is higher | | Regulator | Data Protection Board of India (a single national body) | National Data Protection Authorities in each member state, coordinated by the EDPB | | Breach notification | Notify the Data Protection Board and affected Data Principals (form/timeline per DPDP Rules 2025) | Notify the supervisory authority within 72 hours; notify individuals if high risk | ## How does the terminology differ? The DPDPA uses distinctly Indian vocabulary. The organisation that decides why and how data is processed is a “Data Fiduciary” (the GDPR’s “controller”), and the individual is a “Data Principal” (the GDPR’s “data subject”). The word “fiduciary” is deliberate — it frames the organisation as holding data in trust on the individual’s behalf, signalling a duty of care rather than mere control. A processor is a “Data Processor” under both laws. ## How does the scope of protected data differ? This is one of the most important practical differences. The GDPR protects all personal data and carves out “special categories” — such as health, biometric, genetic, racial or religious data — for heightened protection. The DPDPA, by contrast, applies only to digital personal data (collected digitally, or on paper and later digitised) and does not create a separate “sensitive personal data” category. Every category of personal data is treated under one regime, although the special rules for children’s data add nuance. > **No “sensitive data” tier — but don’t relax** — The absence of a sensitive-data category does not mean health or financial data carries less risk under the DPDPA. The Board still weighs the type and nature of the data affected when assessing penalties, so high-impact data deserves stronger safeguards regardless. ## How do the legal bases for processing differ? The GDPR offers six lawful bases for processing: consent, contract, legal obligation, vital interests, public task and legitimate interests. The DPDPA is narrower: it relies primarily on consent, supplemented by a defined list of “legitimate uses” in Section 7 — such as where the individual voluntarily provided data for a purpose, certain employment situations, medical emergencies and disaster response. Notably, the DPDPA has no broad “legitimate interests” basis equivalent to the GDPR’s, so Indian businesses cannot lean on that catch-all and will rely on consent far more often. ## How do cross-border transfer rules differ? The two laws take opposite default stances. The GDPR works on an allow-list logic: transfers outside the EEA are restricted unless there is an adequacy decision, Standard Contractual Clauses, binding corporate rules or another approved safeguard. The DPDPA works on a negative-list (blacklist) logic: transfers of personal data outside India are permitted by default, except to countries the Central Government specifically restricts by notification. This makes the DPDPA more permissive on transfers in principle, though sector-specific data-localisation rules may still apply. ## How does the treatment of children differ? Under the DPDPA (Section 9), a child is anyone under 18, and processing a child’s data requires verifiable parental or guardian consent, with tracking, behavioural monitoring and targeted advertising to children prohibited. The GDPR sets a lower default threshold of 16 for a child to consent to information-society services, and allows member states to lower it to as low as 13. India’s under-18 line is therefore significantly stricter and captures teenage users that many global services treat as adults. > **Under-18 is a real operational gap** — A service that relies on GDPR-style age gates at 13 or 16 is not DPDPA-compliant. India’s under-18 standard means you may need verifiable parental consent for a far larger group of users than your EU programme assumes. ## How do DPO and accountability requirements differ? The GDPR requires a Data Protection Officer for public authorities and for organisations whose core activities involve large-scale or sensitive processing — a relatively broad set. The DPDPA reserves the mandatory DPO requirement for Significant Data Fiduciaries (SDFs) notified under Section 10, who must also appoint an independent data auditor and conduct periodic Data Protection Impact Assessments and audits. For most ordinary Data Fiduciaries, the DPDPA instead requires a published point of contact rather than a formally designated DPO. ## How do penalties and regulators differ? The headline numbers are structured differently. The DPDPA caps penalties at fixed rupee ceilings — up to ₹250 crore per instance for failing to take reasonable security safeguards — while the GDPR ties its top tier to a percentage of global turnover (up to €20 million or 4% of worldwide annual turnover, whichever is higher), which can be far larger for a multinational. On enforcement, the DPDPA centralises authority in a single Data Protection Board of India with appeals to TDSAT, whereas the GDPR relies on a national Data Protection Authority in each member state, coordinated through the European Data Protection Board. > GDPR compliance is a strong head start, not a substitute. The DPDPA’s under-18 rule, consent-heavy bases and negative-list transfers all demand India-specific changes. ## What overlaps and what is unique to India? The shared DNA is substantial: both laws are built on notice, consent, individual rights, purpose limitation, data minimisation, security safeguards, breach notification and accountability — and both apply extra-territorially to organisations serving their residents. If you already run a mature GDPR programme, your data inventory, rights workflows and security controls transfer well. - Unique to India: no separate sensitive-data category, a negative-list approach to cross-border transfers, an under-18 definition of a child, a single national Data Protection Board, and rupee-denominated penalty caps. - Heavier reliance on consent: with no broad “legitimate interests” basis, many activities a GDPR programme handles via legitimate interests must be re-based on consent or a Section 7 legitimate use. - Different breach mechanics: notification goes to the Data Protection Board and affected individuals on the timeline set by the DPDP Rules 2025, rather than the GDPR’s fixed 72-hour rule. - Shared foundations: notice, consent, individual rights, minimisation, security, accountability and extra-territorial reach. > **Bridge the gap, don’t rebuild** — Run a free DPDPA readiness assessment to see exactly where your existing GDPR programme already satisfies the DPDPA and where India-specific gaps — children’s consent, lawful bases, breach process — still need work. ### FAQs — DPDPA vs GDPR: Key Differences for Indian Businesses **Q: Is the DPDPA the same as the GDPR?** A: No. The DPDPA is India’s own law. It shares concepts with the GDPR — notice, consent, individual rights and accountability — but is shorter, uses different terms (Data Fiduciary and Data Principal), has no separate sensitive-data category, treats anyone under 18 as a child, and uses a negative-list approach to cross-border transfers. **Q: If I comply with the GDPR, am I DPDPA-compliant?** A: Not automatically. GDPR compliance gives you a strong foundation, but the DPDPA differs on key points: the under-18 definition of a child, heavier reliance on consent (no broad legitimate-interests basis), negative-list transfer rules, and a different breach-notification process. You need India-specific adjustments on top of a GDPR programme. **Q: What is the DPDPA equivalent of a GDPR controller?** A: The DPDPA calls it a Data Fiduciary — the person who, alone or with others, determines the purpose and means of processing personal data. The individual whose data it is, equivalent to the GDPR’s data subject, is called the Data Principal. **Q: Does the DPDPA have a sensitive data category like the GDPR?** A: No. Unlike the GDPR, which gives special categories such as health and biometric data extra protection, the DPDPA does not create a separate sensitive-personal-data category. It applies one regime to all digital personal data, though the Board weighs the type and nature of data when assessing penalties. **Q: How do cross-border transfer rules differ between the DPDPA and GDPR?** A: The GDPR uses an allow-list: transfers need adequacy decisions, SCCs or similar safeguards. The DPDPA uses a negative list: transfers outside India are allowed by default, except to countries the Central Government specifically restricts by notification — making the DPDPA more permissive in principle. **Q: What is the difference in the age of a child?** A: The DPDPA treats anyone under 18 as a child and requires verifiable parental consent for their data. The GDPR sets a default of 16 for consenting to information-society services and lets member states lower it to as low as 13 — so India’s standard is significantly stricter. **Q: How do DPDPA and GDPR penalties compare?** A: The DPDPA caps penalties at fixed amounts — up to ₹250 crore per instance for security-safeguard failures. The GDPR’s top tier is up to €20 million or 4% of global annual turnover, whichever is higher, which can be far larger for a multinational because it scales with revenue. **Q: Who enforces the DPDPA compared with the GDPR?** A: The DPDPA is enforced by a single national body, the Data Protection Board of India, with appeals to the TDSAT. The GDPR is enforced by a Data Protection Authority in each EU member state, coordinated by the European Data Protection Board. --- # DPDPA by Industry ## DPDPA Compliance for Healthcare URL: https://dapro.in/industries/healthcare Healthcare organisations process highly sensitive patient data, making DPDPA compliance critical. Hospitals, clinics, diagnostics labs and health-tech firms must obtain clear consent, secure health records, honour patient rights, and report breaches to the Data Protection Board — with penalties up to ₹250 crore for security failures. Patient data is among the most sensitive personal data any organisation holds — diagnoses, prescriptions, lab results, insurance details and identifiers. Under the DPDPA, every hospital, clinic, diagnostic chain, pharmacy and health-tech platform is a Data Fiduciary with full obligations, and the reputational and financial stakes of a health-data breach are uniquely high. **Personal data typically processed:** - Patient identifiers, contact details and demographics - Medical history, diagnoses, prescriptions and lab results - Insurance, billing and payment information - Appointment, telemedicine and device/wearable data **Key obligations:** - **Consent for treatment vs. marketing**: Separate the lawful basis for delivering care (which may rely on legitimate uses such as medical emergencies under Section 7) from consent for marketing, research or analytics. Bundle nothing. - **Security safeguards for health records**: Encryption, strict role-based access and audit logging are expected for health data; failure to maintain reasonable safeguards risks the ₹250 crore penalty under Section 8(5). - **Children’s health data**: Paediatric records require verifiable parental consent and a prohibition on tracking or targeting (Section 9). - **Breach notification**: A breach of patient data must be notified to the Data Protection Board and affected patients under Section 8(6) and the DPDP Rules. **Risk profile:** - Large volumes of sensitive health data increase breach impact and penalty exposure. - Third-party labs, billing vendors and cloud EHR providers expand the processor surface you remain accountable for. - Likely candidate for Significant Data Fiduciary designation at scale (Section 10). **Regulatory overlap:** DPDPA sits alongside the Ayushman Bharat Digital Mission (ABDM) framework, telemedicine guidelines and clinical-establishment rules — health-tech must satisfy both. **Q: Does the DPDPA apply to hospitals and clinics?** A: Yes. Any healthcare provider processing patient data in digital form is a Data Fiduciary and must comply with the DPDPA, including consent, security safeguards, patient rights and breach notification. **Q: Can we treat patients without consent in an emergency?** A: The Act recognises certain legitimate uses, including medical emergencies and threats to public health, where processing may proceed without prior consent. Marketing and non-care uses still require consent. **Q: Is patient data “sensitive” under the DPDPA?** A: The DPDPA does not create a separate “sensitive data” category like the GDPR, but health data’s high risk means regulators expect stronger safeguards and it materially raises breach and penalty exposure. ## DPDPA Compliance for Fintech URL: https://dapro.in/industries/fintech Fintech platforms process financial identifiers, KYC documents and transaction data, so DPDPA compliance is essential. Lending, payments, neobanking and wealth-tech firms must obtain granular consent, secure financial data, honour data principal rights, and notify breaches — alongside RBI and Account Aggregator requirements. Fintech sits on a mountain of high-value personal data — PAN, Aadhaar-linked KYC, bank details, transaction histories and credit information. The DPDPA layers a consent-and-rights regime on top of existing RBI, NPCI and Account Aggregator obligations, and the combination demands disciplined, provable data handling. **Personal data typically processed:** - KYC documents and government identifiers - Bank account, card and UPI details - Transaction history and credit/repayment data - Device, location and behavioural signals used for risk scoring **Key obligations:** - **Granular, purpose-bound consent**: Onboarding, credit assessment, cross-selling and marketing are distinct purposes and need distinct consent. Bundled consent will not survive scrutiny. - **Data minimisation in KYC**: Collect only the KYC data necessary for the stated purpose and erase it once retention obligations lapse (Section 8). - **Strong security safeguards**: Financial data attracts the highest breach impact; reasonable safeguards under Section 8(5) are non-negotiable. - **Withdrawal & rights**: Customers can withdraw consent and request access, correction and erasure; build a workflow that respects statutory retention for financial records. **Risk profile:** - High-value data and large user bases make fintechs prime breach targets and likely Significant Data Fiduciaries. - Complex processor chains (cloud, KYC vendors, AAs, collection agencies) expand accountability. - ₹250 crore exposure for security-safeguard failures. **Regulatory overlap:** DPDPA complements RBI master directions, the Account Aggregator (DEPA) consent framework, NPCI rules and KYC norms — fintech consent flows must satisfy both DPDPA and sectoral rules. **Q: How does the DPDPA interact with RBI and Account Aggregator rules?** A: The DPDPA is a baseline data-protection law that applies in addition to sectoral rules. Where RBI directions or the Account Aggregator framework impose stricter or specific requirements, you must satisfy both. **Q: Can we keep KYC data after a customer leaves?** A: Only for as long as a legal or regulatory retention obligation requires. Once that lapses and the purpose is served, the DPDPA requires erasure (Section 8). **Q: Are fintechs likely to be Significant Data Fiduciaries?** A: Larger fintechs processing high volumes of sensitive financial data are strong candidates for SDF designation, which adds DPO, DPIA and independent-audit duties (Section 10). ## DPDPA Compliance for EdTech URL: https://dapro.in/industries/edtech EdTech platforms process the data of students — many of them children — so the DPDPA’s children’s-data rules apply directly. Education platforms must obtain verifiable parental consent for under-18s, avoid tracking and targeted advertising to children, secure student data, and honour data principal rights. Education technology lives at the intersection of the DPDPA’s strictest provisions: much of the user base is under 18. Section 9 imposes verifiable parental consent and bans behavioural tracking and targeted advertising directed at children — making age assurance and parental-consent flows the defining compliance challenge for edtech. **Personal data typically processed:** - Student names, ages, grades and contact details - Parent/guardian contact and payment information - Learning activity, assessment scores and progress data - Device, session and engagement analytics **Key obligations:** - **Verifiable parental consent**: For any user under 18, you must obtain verifiable consent from a parent or lawful guardian before processing their data (Section 9). - **No tracking or targeting of children**: Behavioural monitoring and targeted advertising directed at children are prohibited. Analytics on minors must be re-examined. - **Age assurance**: Implement a mechanism to determine which users are children and route them through parental-consent flows. - **Data minimisation**: Collect only what the learning purpose requires and retain it no longer than necessary. **Risk profile:** - Children’s-data violations carry penalties up to ₹200 crore. - Ad-tech and analytics SDKs may inadvertently track minors — a direct compliance breach. - Reputational risk is acute when minors are involved. **Regulatory overlap:** Edtech must reconcile DPDPA children’s-data rules with education-sector norms and any institutional data-sharing arrangements with schools and universities. **Q: Who counts as a child under the DPDPA?** A: Anyone under the age of 18 is a child under the DPDPA. Processing their personal data requires verifiable consent from a parent or lawful guardian. **Q: Can edtech platforms show targeted ads to students?** A: No. The DPDPA prohibits behavioural tracking and targeted advertising directed at children, so ad targeting to under-18 users is not permitted. **Q: How do we verify parental consent?** A: You need a reliable mechanism to confirm the consenting adult is the child’s parent or guardian. The DPDP Rules describe acceptable verification approaches; a consent platform can operationalise them. ## DPDPA Compliance for E-commerce URL: https://dapro.in/industries/ecommerce E-commerce platforms process customer data at scale — orders, addresses, payments and browsing behaviour — so DPDPA compliance is essential. Online retailers and D2C brands must obtain consent for marketing and analytics, manage notices and cookies, honour customer rights, and secure data against breaches. E-commerce runs on personal data: accounts, delivery addresses, payment details, wishlists and a rich trail of browsing and purchase behaviour used for personalisation and remarketing. The DPDPA requires that this data be collected with clear consent, used only for stated purposes, and erased when no longer needed — a meaningful shift for marketing-driven retail. **Personal data typically processed:** - Account, contact and delivery address details - Order history and payment information - Browsing, cart and wishlist behaviour - Marketing preferences and loyalty data **Key obligations:** - **Consent for marketing & personalisation**: Transactional processing to fulfil an order differs from marketing, profiling and remarketing — the latter need clear, granular consent. - **Notice & cookie management**: Present an itemised Section 5 notice and manage analytics/marketing cookies through a consent mechanism with easy withdrawal. - **Customer rights at scale**: Automate access, correction and erasure requests across a large customer base within statutory timelines. - **Vendor governance**: Logistics, payment and marketing vendors are Data Processors you remain accountable for (Section 8(2)). **Risk profile:** - Massive customer bases mean high breach impact and likely SDF status. - Aggressive remarketing without consent is a common, visible violation. - ₹250 crore exposure for security-safeguard failures. **Q: Do we need consent to send marketing emails?** A: Yes. Fulfilling an order is one purpose; marketing is another. Sending promotional communications generally requires the customer’s clear, specific consent, with an easy way to withdraw it. **Q: Are cookies covered by the DPDPA?** A: Where cookies and similar technologies process personal data for analytics or marketing, that processing needs a lawful basis — typically consent — and should be managed through a consent mechanism. **Q: How long can we keep customer data?** A: Only as long as necessary for the purpose it was collected for (plus any legal retention period). Once that ends, the DPDPA requires erasure. ## DPDPA Compliance for SaaS URL: https://dapro.in/industries/saas SaaS companies are often both a Data Fiduciary (for their own users) and a Data Processor (for customer data they host). DPDPA compliance means clear consent for your own processing, robust Data Processing Agreements with customers and sub-processors, strong security, and breach support — with up to ₹250 crore at stake. SaaS businesses occupy two DPDPA roles at once. For sign-ups, billing and marketing you are a Data Fiduciary. For the data your customers store in your product, you are typically a Data Processor acting on their instructions. Getting both roles — and the contracts that bind them — right is the core SaaS compliance task. **Personal data typically processed:** - Your own users’ account, billing and usage data (Fiduciary role) - Customer end-user data hosted in your product (Processor role) - Support tickets, logs and telemetry - Sub-processor and integration data flows **Key obligations:** - **Know your role per data set**: Map where you act as Fiduciary vs Processor; the duties differ. As a Processor you act only on documented instructions. - **Data Processing Agreements**: Maintain DPAs with customers and flow DPDPA obligations down to every sub-processor (Section 8(2)). - **Security & breach support**: Reasonable safeguards under Section 8(5), plus the ability to support customers’ breach-notification duties quickly. - **Assist with rights requests**: Provide tooling so customers (Fiduciaries) can fulfil their users’ access, correction and erasure rights. **Risk profile:** - A single sub-processor gap can cascade to every customer. - Customers increasingly demand DPDPA terms in procurement — non-compliance loses deals. - Processor breaches still expose the Fiduciary, and your contractual liability. **Q: Is a SaaS company a Data Fiduciary or a Data Processor?** A: Usually both. You are a Data Fiduciary for your own users (sign-ups, billing, marketing) and a Data Processor for the customer data you host on their behalf and instructions. **Q: Do we need a Data Processing Agreement?** A: Yes. Under Section 8(2) a Data Fiduciary can only engage a processor under a valid contract. SaaS vendors should maintain DPAs with customers and flow obligations down to sub-processors. **Q: What do customers ask for in DPDPA security reviews?** A: Typically: your sub-processor list, DPA terms, security safeguards, breach-notification process, data-residency and an evidence pack demonstrating controls — all of which should be readily exportable. ## DPDPA Compliance for Manufacturing URL: https://dapro.in/industries/manufacturing Manufacturers may not be consumer-facing, but they process significant personal data — employees, contractors, dealers and visitors. DPDPA compliance means lawful handling of workforce and partner data, securing HR, CCTV and access systems, governing vendors, and honouring data principal rights, with breaches reportable to the Board. It is a common misconception that the DPDPA only affects digital consumer businesses. Manufacturers hold extensive personal data across HR, payroll, contractor management, dealer networks, visitor logs and increasingly connected/IoT operations. All of it is in scope, and the workforce is a frequent source of rights requests and disputes. **Personal data typically processed:** - Employee, contractor and applicant HR and payroll data - Dealer, distributor and supplier contact data - CCTV footage, biometric access and visitor logs - Connected-equipment and operator data **Key obligations:** - **Workforce data on a lawful basis**: Employment-related processing may rely on certain legitimate uses (Section 7), but transparency, minimisation and security still apply. - **CCTV & biometrics**: Surveillance and biometric access systems process personal data and require notice, purpose limitation and strong safeguards. - **Vendor & dealer governance**: Personal data shared with dealers, staffing agencies and suppliers must be governed by contracts (Section 8(2)). - **Rights & grievance**: Employees and partners can exercise access, correction and erasure rights; provide a grievance mechanism. **Risk profile:** - HR and biometric data breaches carry significant penalty and morale impact. - Legacy on-prem systems and spreadsheets make discovery and security hard. - Staffing agencies and contractors expand the processor surface. **Q: Does the DPDPA apply to manufacturers that don’t sell online?** A: Yes. The DPDPA applies to any organisation processing digital personal data — including employee, contractor, dealer and visitor data — regardless of whether it is consumer-facing. **Q: Do we need consent to process employee data?** A: Much employment-related processing can rely on the “legitimate uses” provision (Section 7), but you still owe transparency, data minimisation, security and rights obligations to employees. **Q: Is CCTV and biometric attendance covered?** A: Yes. CCTV footage and biometric access data are personal data; their use requires notice, a lawful purpose, minimisation and reasonable security safeguards. ## DPDPA Compliance for BFSI URL: https://dapro.in/industries/bfsi Banks, NBFCs and insurers process vast volumes of sensitive financial and policyholder data, making DPDPA compliance — and likely Significant Data Fiduciary status — a board-level priority. BFSI must run rigorous consent, rights, security and breach programmes alongside RBI, IRDAI and SEBI obligations, with up to ₹250 crore at stake. BFSI is the most heavily regulated and data-intensive sector in scope. Banks, NBFCs, insurers and capital-market intermediaries already operate under RBI, IRDAI and SEBI frameworks; the DPDPA adds an individual-rights and consent layer on top. Given the volume and sensitivity of the data, many BFSI entities are likely to be notified as Significant Data Fiduciaries. **Personal data typically processed:** - KYC, identity and financial-account data - Credit, loan, claims and policyholder records - Transaction histories and risk/fraud signals - Nominee, beneficiary and relationship data **Key obligations:** - **Consent + sectoral retention**: Reconcile DPDPA consent and erasure with RBI/IRDAI retention mandates; retain only as long as the law requires. - **Significant Data Fiduciary duties**: Expect DPO, DPIA and independent-audit obligations under Section 10 given data volume and sensitivity. - **Breach response in 72 hours**: Stand up a war-room to notify the Board and customers within the statutory window, coordinated with CERT-In duties. - **Reasonable security safeguards**: Encryption, access control and monitoring are expected; failures risk the ₹250 crore penalty (Section 8(5)). **Risk profile:** - Highest data sensitivity and volume — top breach and penalty exposure. - Multiple overlapping regulators (RBI, IRDAI, SEBI, CERT-In) to reconcile. - Almost certain Significant Data Fiduciary designation for large entities. **Regulatory overlap:** DPDPA must be harmonised with RBI master directions, IRDAI regulations, SEBI norms and CERT-In incident-reporting timelines — BFSI compliance is inherently multi-framework. **Q: Are banks and insurers Significant Data Fiduciaries?** A: Large BFSI entities are strong candidates for SDF designation given the volume and sensitivity of data they process, which adds DPO, DPIA and independent-audit obligations under Section 10. **Q: How does the DPDPA interact with RBI and IRDAI rules?** A: The DPDPA applies in addition to sectoral regulation. Where RBI or IRDAI impose specific retention, localisation or security requirements, BFSI entities must satisfy both the DPDPA and the sectoral framework. **Q: What is the breach-notification timeline for BFSI?** A: Under the DPDPA you must notify the Data Protection Board and affected individuals of a personal data breach; many describe this as a 72-hour expectation, which BFSI must coordinate with CERT-In incident reporting. --- # DPDPA FAQ Bank ## DPDPA basics **Q: What is the DPDPA?** A: The DPDPA is the Digital Personal Data Protection Act, 2023 — India’s first comprehensive data protection law. It governs how organisations collect, store, use and share the digital personal data of individuals in India, and gives individuals (Data Principals) enforceable rights over their data. **Q: When does the DPDPA come into effect?** A: The Act was passed in August 2023 and is being brought into force in phases. The Digital Personal Data Protection Rules 2025 operationalise it, with the government providing transition periods for different obligations. Businesses should begin compliance now rather than wait for the final enforcement date. **Q: Who needs to comply with the DPDPA?** A: Any organisation that processes the digital personal data of individuals in India — whether based in India or abroad — must comply. This includes SMEs, enterprises, startups, e-commerce stores, SaaS companies and any business that handles customer, employee or user data. **Q: What are the penalties for DPDPA non-compliance?** A: The Schedule to the Act allows the Data Protection Board to impose financial penalties of up to ₹250 crore for failure to take reasonable security safeguards to prevent a breach, and up to ₹200 crore for other failures. Penalties are assessed per instance based on the nature and gravity of the violation. **Q: What is a Data Fiduciary?** A: A Data Fiduciary is any person or organisation that, alone or with others, determines the purpose and means of processing personal data. It is broadly equivalent to a "data controller" under the GDPR. Most businesses that decide why and how they use personal data are Data Fiduciaries. **Q: What is a Data Principal?** A: A Data Principal is the individual to whom the personal data relates. For children, the Data Principal includes their parents or lawful guardians; for persons with disabilities, it includes their lawful guardian. ## Consent **Q: What counts as valid consent under the DPDPA?** A: Under Section 6, consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and limited to the personal data necessary for the specified purpose. Pre-ticked boxes and bundled "accept all" consent are not valid. **Q: Can a Data Principal withdraw consent?** A: Yes. The DPDPA requires that withdrawing consent must be as easy as giving it. Once consent is withdrawn, the Data Fiduciary must stop processing the relevant personal data within a reasonable time, unless another legal basis applies. **Q: What is a Consent Manager?** A: A Consent Manager is an accountable intermediary, registered with the Data Protection Board, through which a Data Principal can give, manage, review and withdraw consent. The DPDPA envisions an interoperable consent ecosystem built around Consent Managers. **Q: Do I need a consent notice in Indian languages?** A: Yes. The Data Principal must be able to access the consent notice in English or any language listed in the Eighth Schedule to the Constitution of India. A DPDPA-compliant notice should be available in the languages of your users. ## Data Principal rights **Q: What rights do Data Principals have under the DPDPA?** A: Data Principals have the right to access information about their personal data, the right to correction, completion, updating and erasure, the right to grievance redressal, and the right to nominate another person to exercise their rights in the event of death or incapacity. **Q: How quickly must I respond to a Data Principal request?** A: The DPDPA and DPDP Rules 2025 require Data Fiduciaries to respond to rights requests within a prescribed, reasonable timeframe and to publish the contact details of a person who can answer questions about the processing. Build a workflow with clear internal SLAs. **Q: What is a grievance redressal mechanism?** A: It is the process a Data Fiduciary must provide for Data Principals to raise complaints about how their personal data is handled. You must publish a point of contact (such as a grievance officer) and respond within the prescribed period before the Data Principal escalates to the Data Protection Board. ## Obligations & special cases **Q: What is a Significant Data Fiduciary (SDF)?** A: A Significant Data Fiduciary is a Data Fiduciary (or class of them) notified by the government based on factors such as the volume and sensitivity of personal data processed and risk to Data Principals. SDFs face extra duties: appointing a Data Protection Officer in India, conducting Data Protection Impact Assessments, and commissioning independent audits. **Q: What are the rules for processing children’s data?** A: Processing the personal data of anyone under 18 requires verifiable consent from a parent or lawful guardian. The Act also restricts tracking, behavioural monitoring and targeted advertising directed at children. **Q: Am I responsible for my vendors and data processors?** A: Yes. Under Section 8(2), a Data Fiduciary remains responsible for compliance even when processing is carried out by a Data Processor on its behalf. You should flow DPDPA obligations down to vendors through a written Data Processing Agreement. **Q: Does the DPDPA restrict transferring data outside India?** A: The DPDPA permits cross-border transfer of personal data to countries except those specifically restricted by the Central Government through notification — a "blacklist" approach. Sectoral rules (for example in banking) may impose stricter data-localisation requirements. ## About Data Adhikaar **Q: How does Data Adhikaar help with DPDPA compliance?** A: Data Adhikaar runs your DPDPA programme through ten specialist AI agents that handle consent, data principal rights, breach response, DPIAs, vendor management and audit evidence. You integrate once via SDK, API or MCP, and the agents operate the routine work — escalating to humans where the law requires judgement. **Q: Is Data Adhikaar suitable for small businesses?** A: Yes. Data Adhikaar is built for organisations of every size, from startups and SMEs on the Starter plan to large enterprises, BFSI and Significant Data Fiduciaries on Enterprise, with pricing that matches your data principal volume. **Q: Is the DPDPA readiness assessment really free?** A: Yes. The Data Adhikaar readiness assessment is free and takes about three minutes. It scores your current DPDPA posture and gives you a prioritised list of recommendations. A free developer sandbox is also always available. **Q: Where is my data stored?** A: Data Adhikaar runs on AWS Mumbai (ap-south-1) with disaster recovery in Hyderabad, so personal data does not leave India by default. It is built by an ISO 27001-certified company with SOC 2 Type II controls. --- # Free Tools - DPDPA Readiness Assessment — https://dapro.in/tools/dpdpa-readiness-assessment - DPDPA Penalty Calculator — https://dapro.in/tools/penalty-calculator - Consent Notice Generator — https://dapro.in/tools/consent-notice-generator --- # Latest from the Blog - [DPIA Under DPDPA: A Practical Guide to Data Protection Impact Assessments](https://dapro.in/blog/dpia-under-dpdpa-practical-guide) — Mandatory for Significant Data Fiduciaries and wise for everyone else — how to run a DPIA under the DPDP Act: when to trigger one, what to assess, and how to keep it proportionate. - [Vendor and Processor Management Under DPDPA: You Are Accountable for Their Failures](https://dapro.in/blog/dpdpa-vendor-processor-management) — Under Section 8(2), a Data Fiduciary answers for its Data Processors. How to contract, onboard, monitor and exit vendors so a supplier’s breach does not become your ₹250 crore problem. - [Employee Data Under DPDPA: What HR Teams Can (and Cannot) Do Without Consent](https://dapro.in/blog/dpdpa-employee-hr-data) — Section 7(i) lets employers process employee data for employment purposes without consent — but the exemption is narrower than HR teams assume. BGV, monitoring, alumni data and more. - [Cross-Border Data Transfers Under DPDPA: The Negative-List Model Explained](https://dapro.in/blog/cross-border-data-transfers-under-dpdpa) — DPDPA allows personal data to flow to any country not on a government-notified restriction list — no adequacy decisions or SCCs. But sectoral rules and SDF localisation can still bind you. - [Data Principal Rights Under DPDPA: Building a Request Workflow That Scales](https://dapro.in/blog/data-principal-rights-dsar-workflow) — Access, correction, erasure, grievance redressal and nomination — DPDPA gives Data Principals enforceable rights. Here is how to build a request workflow that meets the statutory clock. - [Are You a Significant Data Fiduciary? The SDF Test and What It Triggers](https://dapro.in/blog/significant-data-fiduciary-are-you-one) — The government can notify your company as a Significant Data Fiduciary based on data volume, sensitivity and risk. SDF status triggers a DPO in India, independent audits and periodic DPIAs. - [DPDPA vs GDPR: What Global SaaS Teams Must Change for India](https://dapro.in/blog/dpdpa-vs-gdpr-for-saas) — GDPR compliance does not equal DPDPA compliance. No legitimate-interest basis, breach notification for every breach, fixed penalty ceilings and 18-as-a-child are just the start. - [Children's Data Under DPDPA Section 9: Verifiable Parental Consent, Explained](https://dapro.in/blog/childrens-data-dpdpa-verifiable-parental-consent) — Processing a child’s data in India requires verifiable parental consent — and bans tracking, behavioural monitoring and targeted advertising. What Section 9 and the DPDP Rules 2025 demand. - [DPDPA Penalties Explained: How the ₹250 Crore Fines Actually Work](https://dapro.in/blog/dpdpa-penalties-explained) — The DPDPA Schedule sets penalty ceilings from ₹10,000 to ₹250 crore. Here is how the Data Protection Board determines penalties, what drives them up, and how to reduce exposure. - [DPDPA Breach Notification: The 72-Hour Playbook Every Indian Business Needs](https://dapro.in/blog/dpdpa-breach-notification-72-hour-playbook) — A personal data breach under the DPDPA triggers notification duties to the Data Protection Board and affected Data Principals. Here is an hour-by-hour playbook to stay inside the statutory window. - [Consent Management Under DPDPA: How to Build a Compliant Consent Flow](https://dapro.in/blog/consent-management-under-dpdpa) — Consent is the backbone of the DPDPA. Learn how to design a consent flow that is free, specific, informed and unambiguous — with easy withdrawal and a full audit trail. - [DPDP Rules 2025: What Changed and What Indian Businesses Must Do Now](https://dapro.in/blog/dpdp-rules-2025-what-changed) — The Digital Personal Data Protection Rules 2025 operationalise the DPDPA. Here is what they mean for consent notices, breach reporting, children’s data and Significant Data Fiduciaries — and the actions to take now. - [DPDPA Compliance Checklist for 2025: A Step-by-Step Guide for Indian Businesses](https://dapro.in/blog/dpdpa-compliance-checklist-2025) — A practical, step-by-step DPDPA compliance checklist covering data mapping, consent notices, Data Principal rights, security safeguards and breach response under the DPDP Act 2023 and DPDP Rules 2025.