India's Digital Personal Data Protection Act 2023 and Rules 2025
A Complete Compliance Training Guide
Prepared by the AIGP Playbook | www.aigpplaybook.com
π Regulatory currency notice: Penalty amounts, compliance deadlines, and cross-border transfer restrictions are current as of August 2026. These details should be verified against official MeitY gazette notifications before relying on them for professional advice. The DPDP framework continues to evolve through implementing orders.
Free interactive toolWho this guide is for
This guide is written for compliance professionals, legal counsel, data protection officers, and business leaders responsible for implementing DPDP compliance in Indian organizations, or for multinational companies that process personal data of persons in India.
A note on terminology: DPDP uses India-specific terms that map β but do not identically correspond β to GDPR. Data Fiduciary β Controller. Data Principal β Data Subject. Data Processor β Processor. Consent Manager is a uniquely Indian concept with no direct GDPR equivalent.
π§ Explore this framework as a map: the DPDP Brain
Everything in this guide, as a graph you can search and filter. Trace any obligation from the Act to the Rule that operationalises it and the penalty head that backs it, or filter straight to Penalties, Children, Consent Manager or the Board.
Open the DPDP Brain β 128 cited concepts Β· 325 connections Β· DPDP Act 2023 + Rules 2025Table of Contents
- Why the DPDP Framework Exists
- The Two-Layer Structure: Act and Rules
- Scope: Who and What Is Covered
- Key Definitions and Roles
- The Seven Core Privacy Principles
- Obligations on Data Fiduciaries
- Significant Data Fiduciaries β Enhanced Obligations
- The Consent Manager β A Uniquely Indian Institution
- Rights of Data Principals
- Children's Data β Special Protections
- Cross-Border Data Transfers
- The Data Protection Board of India
- Penalties and Enforcement
- The Three-Phase Compliance Timeline
- DPDP vs GDPR β Key Comparisons
- Practical Compliance Checklist
- Knowledge Check Questions
- If You Remember Only These 25 Facts
- Glossary
1. Why the DPDP Framework Exists
The constitutional foundation
India's data-protection law did not emerge from legislation alone. Its roots lie in a landmark Supreme Court judgment.
In Puttaswamy v. Union of India (2017), a nine-judge constitutional bench unanimously held that the right to privacy is a fundamental right under Article 21 of the Indian Constitution. The judgment directed Parliament to enact a modern data-protection statute that would give practical content to this right in the digital age.
That direction produced the Digital Personal Data Protection Act, 2023 (DPDP Act) β India's first comprehensive digital data-protection statute enacted by Parliament in August 2023. The Ministry of Electronics and Information Technology (MeitY) then notified the Digital Personal Data Protection Rules, 2025 (DPDP Rules) on 13 November 2025 to operationalize the Act.
Why it was urgently needed
Several converging factors made the law overdue:
- Scale of digital penetration: Hundreds of millions of Indians use digital apps and platforms daily β food delivery, UPI, Aadhaar-linked services, streaming, social media β leaving behind vast personal-data trails.
- Foreign company dominance: Many platforms serving Indian users are incorporated abroad, outside the reach of India's previous fragmented legal framework.
- Rising harms: Phishing attacks, data breaches, deepfakes, unauthorized profiling, and financial fraud traced to leaked personal data were accelerating.
- No uniform law: Sector-specific rules (RBI, SEBI, IRDAI guidelines) were fragmented and inconsistent across industries.
The DPDP Act fills these gaps. It establishes clear rights for individuals, defined obligations for organizations, an independent enforcement body, and significant financial penalties for non-compliance.
2. The Two-Layer Structure: Act and Rules
Understanding DPDP compliance requires understanding which layer governs a given question.
| Layer | Instrument | Passed / Notified | Role |
|---|---|---|---|
| Primary legislation | Digital Personal Data Protection Act, 2023 | Parliament, August 2023 | Establishes the framework, rights, obligations, and penalty structure |
| Subordinate legislation | Digital Personal Data Protection Rules, 2025 | MeitY, 13 November 2025 | Operationalizes the Act β specifies how, in what format, and in what timeframe obligations are to be met |
Think of it this way: the Act says what must be done; the Rules say how.
π The single most important principle in this guide The DPDP Act establishes the legal duty. The DPDP Rules prescribe how that duty is operationalized.
Wherever an Act provision reads "in such manner as may be prescribed" or "as may be prescribed", that phrase is the hook on which a Rule hangs. The duty comes from the Section; the mechanics come from the Rule. Citing only the Rule for an obligation misattributes subordinate legislation as the source of statutory authority β and it will cost you marks in an exam and credibility in a compliance memo.
The pattern, applied:
| Obligation | Act β the duty | Rules β the mechanics |
|---|---|---|
| Notice | Section 5 | Rule 3 |
| Security safeguards | Section 8(5) | Rule 6 |
| Breach intimation | Section 8(6) | Rule 7 |
| Erasure and retention | Section 8(7)β(8) | Rule 8 + Third Schedule |
| Contact information | Section 8(9) | Rule 9 |
| Grievance redressal | Section 8(10), 13(2) | Rule 14(3) |
| Processor accountability | Section 8(1)β(2) | Rule 6(1)(f) |
| Children | Section 9 | Rules 10, 12 + Fourth Schedule |
| Persons with disability | Section 9(1) | Rule 11 |
| SDF obligations | Section 10 | Rule 13 |
| Data Principal rights | Sections 11β14 | Rule 14 |
| Cross-border | Section 16 | Rule 15 |
| Penalties | Schedule, read with Section 33(1) | (no penalty schedule in the Rules) |
The Rules also introduce machinery with no direct Act analogue in the same form: the Consent Manager registration process (Rule 4 + First and Second Schedules) and the procedures and digital-office functioning of the Data Protection Board (Rules 17β21).
3. Scope: Who and What Is Covered
What is covered
The DPDP Act applies to:
- Digital personal data collected within the territory of India.
- Offline data subsequently digitized β if you collect data on paper and convert it to digital form, the Act applies to the digital version.
- Data processed outside India in connection with offering goods or services to persons in India β this extraterritorial hook brings foreign companies into scope.
What is not covered
- Purely offline data that is never digitized.
- Personal or household use β saving a contact's phone number is not regulated.
- Anonymized data where re-identification is not possible.
- Research, archiving, and statistical purposes with appropriate safeguards (as notified by the Government).
- National security and law enforcement activities with notified exemptions.
The extraterritorial reach
This is the provision that changes everything for multinational companies. Any organization, regardless of where it is incorporated, that processes personal data of persons in India falls within DPDP scope. A social media platform headquartered in the United States, a cloud provider based in Singapore, a fintech company in the United Kingdom β all are subject to the Act if they process data of persons in India.
π Compliance note "Processing" is defined broadly: collection, recording, organisation, structuring, storage, adaptation, retrieval, use, disclosure, erasure β essentially anything done with personal data. If you touch Indian user data, you are processing it.
4. Key Definitions and Roles
Data Principal
The individual to whom the personal data relates β the natural person who is the source of the data. In everyday terms: the customer, user, citizen, patient, or employee.
Special cases (Section 2(j)). The definition is inclusive: the individual remains the Data Principal, and the term also includesβ
- For children (under 18), the parents or lawful guardian of the child, who gives verifiable consent under Section 9(1) and exercises the rights.
- For persons with disability, the lawful guardian acting on her behalf.
The distinction matters: the parent does not replace the child as Data Principal, and the data being protected is still the child's.
Data Fiduciary
Any person or entity that determines the purpose and means of processing personal data. This is the primary obligated party under the Act β analogous to a "Controller" under GDPR.
Every organization that decides what personal data to collect and why β a bank, a startup, a hospital, an e-commerce platform, a government body β is a Data Fiduciary.
Data Processor
A person or entity that processes personal data on behalf of a Data Fiduciary, under its instructions. A cloud storage provider, a payroll outsourcing firm, or a third-party analytics company acting on a Data Fiduciary's instructions is a Data Processor.
The key distinction: the Data Fiduciary decides the purpose; the Data Processor executes the processing.
Consent Manager
A registered intermediary that maintains an interoperable platform through which Data Principals can give, manage, review, and withdraw consent across multiple Data Fiduciaries. Consent Managers must be registered with the Data Protection Board, must be incorporated as Indian companies, and are prohibited from sub-contracting their core obligations. They must maintain records of consents for at least seven years.
This is a uniquely Indian institution with no direct GDPR equivalent, designed to centralize consent management for a market with hundreds of millions of mobile-first users.
Significant Data Fiduciary (SDF)
A Data Fiduciary designated by the Central Government based on the volume and sensitivity of data processed, potential national security or public-order risk, risk to rights of children, and impact on sovereignty and integrity of India. SDFs carry enhanced obligations above and beyond standard Data Fiduciary requirements.
5. The Seven Core Privacy Principles
The DPDP Act is built on seven principles that apply to all personal data processing:
| # | Principle | What it means in practice |
|---|---|---|
| 1 | Consent and transparency | Consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action (Section 6(1)). Notices must be in plain language β not buried in lengthy terms and conditions. |
| 2 | Purpose limitation | Data collected for a specific purpose can only be used for that purpose. A mobile number collected to send OTPs cannot be used for marketing. |
| 3 | Data minimization | Only collect what is genuinely necessary. A food-delivery app needs a delivery address; it does not need employment history. |
| 4 | Accuracy | Data must be accurate and kept up to date. Organizations have a responsibility to maintain current records. |
| 5 | Storage limitation | Data must be erased once the purpose for which it was collected is fulfilled, or when consent is withdrawn. No indefinite retention. |
| 6 | Security safeguards | Appropriate technical and organizational measures β encryption, access controls, audits, secure design β must protect personal data from breach. |
| 7 | Accountability | Data Fiduciaries are responsible for ensuring compliance and can be held liable for misuse, whether by themselves or by their processors. |
π Study tip Purpose limitation is the most commonly violated principle in practice. Data collected lawfully for one purpose cannot be repurposed for another β including AI training β without fresh, specific consent covering the new purpose.
6. Obligations on Data Fiduciaries
π How to read this section Every obligation below is cited in two layers. The Act establishes the legal duty. The Rules prescribe how that duty is operationalized. Where an Act provision says "as may be prescribed," that is the hook the corresponding Rule hangs on.
6.1 Notice and consent β Section 5 of the Act + Rule 3 of the Rules
Act: Section 5(1) requires that every request for consent be accompanied or preceded by a notice informing the Data Principal of the personal data and purpose, the manner of exercising rights, and the manner of complaining to the Board β "in such manner as may be prescribed." Section 5(2) covers pre-commencement consent. Section 5(3) requires the Data Fiduciary to give the Data Principal the option to access the notice in English or any language specified in the Eighth Schedule to the Constitution (the 22 scheduled languages).
Rules: Rule 3 prescribes the manner. The notice must:
- Be presented and understandable independently of any other information β standalone, not bundled into terms and conditions.
- Give, in clear and plain language, an itemised description of the personal data and the specified purpose, including a specific description of the goods, services, or uses enabled.
- Give the communication link and a description of other means by which the Data Principal may withdraw consent (with ease comparable to giving it), exercise rights, and complain to the Board.
Training takeaway: Section 5 creates the notice duty and the language option. Rule 3 dictates its form and minimum content.
6.2 Security safeguards β Section 8(5) of the Act + Rule 6 of the Rules
Act: Section 8(5) requires a Data Fiduciary to protect personal data in its possession or control β including data processed on its behalf by a Data Processor β by taking reasonable security safeguards to prevent personal data breach.
Rules: Rule 6(1) prescribes the minimum safeguards:
- Encryption, obfuscation, masking, or virtual tokens for securing personal data.
- Access control over the computer resources used by the Fiduciary or Processor.
- Visibility on access through logs, monitoring, and review, to detect and investigate unauthorized access.
- Continuity measures such as data backups, for compromise of confidentiality, integrity, or availability.
- Retention of logs and personal data for one year to enable detection, investigation, and remediation, unless another law requires otherwise.
- Contractual provision requiring the Data Processor to take reasonable security safeguards.
- Appropriate technical and organisational measures to ensure effective observance.
Training takeaway: Section 8(5) sets the "reasonable safeguards" standard; Rule 6 converts it into a checklist with a floor. The statutory word is still "reasonable" β calibrated to the nature, volume, and sensitivity of data held β but Rule 6 items are the minimum, not the ceiling.
6.3 Personal data breach notification β Section 8(6) of the Act + Rule 7 of the Rules
Act: Section 8(6) requires the Data Fiduciary, in the event of a personal data breach, to give the Board and each affected Data Principal intimation of the breach, "in such form and manner as may be prescribed."
Rules: Rule 7 prescribes two distinct tracks, with different clocks.
To each affected Data Principal β Rule 7(1): on becoming aware of the breach, without delay, in a concise, clear and plain manner, through their user account or a registered mode of communication. Content must include: a description of the breach (nature, extent, timing); the consequences likely to arise for that individual; mitigation measures implemented or being implemented; safety measures the individual may take; and business contact information of a person who can respond to queries.
To the Board β Rule 7(2), a two-stage obligation:
- Without delay β a description of the breach: nature, extent, timing and location of occurrence, and likely impact.
- Within seventy-two hours of becoming aware (or a longer period the Board allows on written request) β updated and detailed information, the broad facts and reasons leading to the breach, mitigation measures, any findings on who caused it, remedial measures to prevent recurrence, and a report on the intimations given to affected Data Principals.
Notification to individuals must be direct β not a generalized public announcement β in plain language with no technical jargon.
β Key trap Two traps here, and most GDPR-trained teams hit both.
First: notification is NOT contingent on completing the root-cause investigation. The obligation is to notify promptly upon becoming aware that a breach has occurred. Waiting for a completed investigation exposes the organization to the full βΉ200 crore non-notification penalty under Section 8(6).
Second: DPDP does have a 72-hour clock β it is just not GDPR's. Under GDPR, 72 hours is the deadline for the initial notification to the supervisory authority. Under Rule 7(2), the initial intimation to the Board is due without delay, and 72 hours is the deadline for the detailed follow-up report. DPDP is the stricter of the two on the first notification.
6.4 Erasure and retention β Section 8(7)β(8) of the Act + Rule 8 of the Rules
Act: Section 8(7) requires the Data Fiduciary β unless retention is necessary for compliance with any law in force β to erase personal data upon the Data Principal withdrawing consent, or as soon as it is reasonable to assume the specified purpose is no longer being served, whichever is earlier, and to cause its Data Processor to erase data made available to it. Section 8(8) provides that the purpose is deemed no longer served if the Data Principal neither approaches the Fiduciary for the specified purpose nor exercises any rights, for such time period as may be prescribed β with different periods permitted for different classes of Fiduciaries and purposes.
Rules: Rule 8 supplies those prescribed periods, and adds two obligations that cut the other way.
| Rule | Requirement |
|---|---|
| Rule 8(1) + Third Schedule | Fiduciaries of specified classes must erase after the corresponding period. Currently: three years of Data Principal inactivity, for e-commerce entities with β₯2 crore registered users in India, online gaming intermediaries with β₯50 lakh, and social media intermediaries with β₯2 crore β excluding data needed to access the user account or a stored virtual token. |
| Rule 8(2) | The Fiduciary must inform the Data Principal at least forty-eight hours before the erasure period completes, so they can log in or exercise a right to prevent it. |
| Rule 8(3) + Seventh Schedule | The Fiduciary must retain personal data, associated traffic data, and processing logs for a minimum of one year from the date of processing, before erasure β unless another law requires longer. |
β Key trap Rule 8 is not simply "erase when done." It contains a mandatory retention floor. Rule 8(3) requires one year of retention of the data and logs even where the purpose has been served and the user has deleted their account. An erasure-on-completion pipeline that deletes immediately is non-compliant with Rule 8(3), not compliant with Section 8(7).
Note also that the Third Schedule deeming periods apply only to the specified classes above the stated user thresholds. For everyone else, the Section 8(7) test governs directly: erase when consent is withdrawn or when it is reasonable to assume the purpose is no longer served.
6.5 Contact information and grievance redressal β Section 8(9)β(10) of the Act + Rules 9 and 14(3)
Act: Section 8(9) requires the Data Fiduciary to publish, in the prescribed manner, the business contact information of a Data Protection Officer, if applicable, or a person who is able to answer the Data Principal's questions about processing. Section 8(10) requires the Fiduciary to establish an effective mechanism to redress grievances of Data Principals.
Rules: Rule 9 requires that contact information be published prominently on the website or app, and be included in every response to a request for the exercise of rights. Rule 14(3) requires the Fiduciary (and Consent Manager) to prominently publish the period within which grievances are responded to under its grievance redressal system β a reasonable period not exceeding ninety days β and to implement technical and organisational measures ensuring the system actually meets it.
π Terminology caution "Grievance Officer" is not a term used in the DPDP Act or the DPDP Rules. Do not treat "DPO or Grievance Officer" as interchangeable statutory roles. Section 8(9) contemplates a DPO where applicable, or otherwise a person able to answer questions. A DPO is mandatory only for Significant Data Fiduciaries under Section 10(2)(a) β for whom the DPO is also the point of contact for grievance redressal. A non-SDF Data Fiduciary must publish a responsible contact; it is not required to appoint a DPO.
6.6 Processor accountability β Section 8(1)β(2) of the Act
Act: Section 8(1) makes the Data Fiduciary responsible for complying with the Act and the Rules in respect of any processing undertaken by it or on its behalf by a Data Processor β irrespective of any agreement to the contrary, and irrespective of the Data Principal's own failure to perform their duties. Section 8(2) permits engaging a Data Processor for activity related to offering goods or services to Data Principals only under a valid contract.
Rules: Rule 6(1)(f) separately requires that contract to contain appropriate provision for the Processor to take reasonable security safeguards. Rule 8(3) requires the Fiduciary to ensure its Processor also observes the one-year retention floor.
Training takeaway: Accountability is an Act-level, non-delegable duty. Outsourcing processing does not transfer it. The contract is a statutory precondition to engagement, not merely good practice.
7. Significant Data Fiduciaries β Enhanced Obligations
SDFs have enhanced obligations under Section 10 of the Act and Rule 13 of the Rules, including prescribed impact-assessment, audit, DPO and other requirements. The exact Rule reference for each is given below.
Act β Section 10(1), designation criteria. The Central Government may notify a Data Fiduciary or class of Data Fiduciaries as an SDF on the basis of an assessment of such relevant factors as it may determine, including:
- The volume and sensitivity of personal data processed.
- Risk to the rights of Data Principals.
- Potential impact on the sovereignty and integrity of India.
- Risk to electoral democracy.
- Security of the State.
- Public order.
Enhanced obligations:
| Obligation | Source | Details |
|---|---|---|
| Data Protection Officer | Section 10(2)(a) | Must represent the SDF under the Act, be based in India, be an individual responsible to the Board of Directors or similar governing body, and be the point of contact for grievance redressal. |
| Independent data auditor | Section 10(2)(b) | An independent data auditor must be appointed to carry out a data audit evaluating the SDF's compliance with the Act. |
| Periodic DPIA and audit | Section 10(2)(c)(i)β(ii) + Rule 13(1) | The Act requires a periodic DPIA and periodic audit. Rule 13(1) sets the period: once in every twelve months from the date of SDF notification. Rule 13(2) requires the person carrying them out to furnish a report of significant observations to the Board. |
| Algorithmic due diligence | Rule 13(3) | The SDF must observe due diligence to verify that technical measures including algorithmic software it adopts for hosting, display, upload, modification, publication, transmission, storage, updating or sharing of personal data are not likely to pose a risk to the rights of Data Principals. |
| Localization of specified data | Rule 13(4)β(5) | The SDF must ensure that personal data specified by the Central Government β on the recommendation of a committee it constitutes β and the traffic data pertaining to its flow, is not transferred outside India. Category-specific, not general localization. |
β Do not over-read the DPIA trigger A DPIA under Rule 13(1) is a periodic, twelve-monthly obligation tied to SDF status. It is not triggered by the act of deploying AI, biometrics, or profiling. If an SDF deploys algorithmic software, the provision that bites is Rule 13(3) β a continuous due-diligence duty on risk to Data Principals' rights β not a deployment-gating DPIA.
Note also that neither the Act nor the Rules require the independent data auditor to be registered with the Data Protection Board. Section 10(2)(b) requires only that the auditor be independent.
β Compliance note for SDFs The penalty for failing SDF obligations is up to βΉ150 crore. Combined with other penalty heads, a single incident can create exposure well above βΉ500 crore. DPDP compliance at SDF level must sit at board level β not just with the CISO or legal team.
8. The Consent Manager β A Uniquely Indian Institution
The Consent Manager is one of the most innovative features of the DPDP framework β a registered intermediary that allows users to manage all their data consents through a single platform.
What a Consent Manager does:
- Allows Data Principals to give consent to multiple Data Fiduciaries through a single interface.
- Provides a clear view of what consents have been given, to whom, and for what purpose.
- Enables consent withdrawal from any Data Fiduciary at any time.
- Maintains a full log of data-sharing activities across all connected platforms.
Key requirements for Consent Managers:
| Requirement | Detail |
|---|---|
| Registration | Must be registered with the Data Protection Board. |
| Incorporation | Must be an Indian company β jurisdiction and accountability remain within India. |
| No sub-contracting | Core obligations cannot be outsourced to third parties. |
| Record retention | Must maintain records of consents, notices, and data-sharing activities for at least 7 years. |
| Conflicts of interest | Must avoid any conflict of interest with Data Fiduciaries. |
| Independent certification | Platform must be independently certified as meeting the Board's data protection standards. |
Timeline: Consent Manager registration opens in Phase 2 (13 November 2026). Organizations planning to operate as Consent Managers should begin certification and registration preparations well before that date.
9. Rights of Data Principals
Every individual whose personal data is processed has the following rights under the DPDP Act:
| Right | Source | What it means |
|---|---|---|
| Right to access | Section 11 | Obtain a summary of personal data being processed and the processing activities, the identities of other Fiduciaries and Processors with whom it has been shared, and any other prescribed information. |
| Right to correction | Section 12 | Require inaccurate or misleading data to be corrected, completed, or updated; and erasure where retention is no longer necessary for the specified purpose. |
| Right to erasure | Section 12 | Require personal data to be erased, subject to retention required by law. |
| Right to grievance redressal | Section 13 | Have a readily available means of grievance redressal in respect of any act or omission of the Data Fiduciary, and escalate to the Board where redressal is not obtained. |
| Right to nomination | Section 14 + Rule 14(4) | Nominate one or more individuals to exercise rights in the event of death or incapacity. |
| Right to withdraw consent | Section 6(4)β(6) | Withdraw consent at any time, with ease comparable to giving it. Withdrawal does not affect the lawfulness of prior processing. |
Rule 14 β how rights are exercised. The Data Fiduciary and, where applicable, the Consent Manager must prominently publish on its website or app: the means by which a request may be made, and any particulars (username or other identifier) needed to identify the Data Principal under its terms of service.
π Key point β where the 90 days actually applies Section 13(2) requires the Data Fiduciary or Consent Manager to respond to grievances within such period as may be prescribed. Rule 14(3) prescribes it: they must prominently publish the period within which their grievance redressal system responds β a reasonable period not exceeding ninety days β and implement technical and organisational measures ensuring it is met.
The ninety days is therefore a ceiling on the published grievance-response period, anchored in Section 13(2) and the Section 8(10) duty to maintain an effective mechanism. It is not a general statutory deadline for every access, correction, or erasure request. Those are governed by Sections 11β12 and the Fiduciary's own published terms. Treating 90 days as a universal DPDP response SLA is a common overstatement β and note the ceiling is a maximum, not a target: publishing 90 days and using all of it is unlikely to read as "effective" redressal for a simple request.
Section 13(3) also requires the Data Principal to exhaust the Fiduciary's grievance mechanism before approaching the Board.
10. Children's Data β Special Protections
The DPDP Act imposes some of its strictest rules on the processing of children's personal data. Section 9 of the Act establishes the substantive protections; Rules 10, 11 and 12 prescribe how they are implemented.
Who is a child: Any person under the age of 18 in India. This is a higher threshold than the GDPR default of 16.
Act β Section 9:
- Section 9(1): before processing any personal data of a child β or of a person with disability who has a lawful guardian β the Data Fiduciary must obtain verifiable consent of the parent or lawful guardian, in such manner as may be prescribed.
- Section 9(2): no processing that is likely to cause any detrimental effect on the well-being of a child.
- Section 9(3): no tracking or behavioural monitoring of children, and no targeted advertising directed at children.
- Section 9(4): sub-sections (1) and (3) may be disapplied for prescribed classes of Fiduciaries, purposes, and conditions.
- Section 9(5): the Central Government may notify an age above which a Fiduciary with verifiably safe processing is exempt from (1) and (3).
Rules β the operational layer:
| Rule | What it prescribes |
|---|---|
| Rule 10 β children | The Fiduciary must adopt appropriate technical and organisational measures to ensure verifiable parental consent is obtained before processing, and observe due diligence to check that the individual identifying herself as the parent is an adult who is identifiable if required for compliance with law β by reference to reliable identity and age details already held, or details voluntarily provided. |
| Rule 11 β persons with disability | A different test, for a different group. Where consent is obtained from someone identifying as the lawful guardian of a person with disability, the Fiduciary must observe due diligence to verify that the guardian is appointed by a court of law, a designated authority, or a local level committee under the law applicable to guardianship. |
| Rule 12 + Fourth Schedule | Carves out the Section 9(4) exemptions: Section 9(1) and 9(3) do not apply to the classes of Data Fiduciaries in Part A or the purposes in Part B of the Fourth Schedule, subject to the stated conditions. |
Penalty for non-compliance: Up to βΉ200 crore (Schedule, entry 3 β breach of additional obligations in relation to children under Section 9).
β Compliance note "Verifiable" is not satisfied by a checkbox asking "are you over 18?" Data Fiduciaries serving or potentially serving children need genuine verification β Rule 10 requires due diligence that the purported parent is an identifiable adult, not a nominal affirmation.
Do not confuse Rule 10 with Rule 11. Rule 10 governs children and its test is is this person a verifiable adult parent. Rule 11 governs persons with disability who have a lawful guardian and its test is was this guardian formally appointed under guardianship law. Applying the Rule 11 court-appointment test to ordinary parental consent is a common misreading.
11. Cross-Border Data Transfers
India has adopted a blacklist (negative-list) model for cross-border transfers β significantly more permissive than GDPR's adequacy framework. Section 16 of the Act creates the restriction power; Rule 15 of the Rules adds a separate requirement. They are two distinct mechanisms and are often wrongly merged.
Act β Section 16(1): the Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary to a notified country or territory outside India. Section 16(2) preserves any other law in force that imposes a higher degree of protection or restriction β so sector regulators (RBI, IRDAI, SEBI) remain fully in play.
Rules β Rule 15: personal data may be transferred outside India subject to the Data Fiduciary meeting such requirements as the Central Government may, by general or special order, specify in respect of making that data available to any foreign State, or to any person or entity under the control of or any agency of such a State.
The default rule: absent a Section 16(1) notification and outside the scope of a Rule 15 order, personal data may be transferred to any country or territory outside India.
π Keep the two apart Rule 15 is not the source of the cross-border framework. Section 16 restricts transfers to countries. Rule 15 attaches conditions to making data available to foreign States and their agencies β a narrower and differently-aimed provision. A summary that reads "Rule 15 / Section 16" as a single blacklist rule loses that distinction.
What this means in practice:
- As of August 2026, no country has been added to a restricted list.
- Transfers are therefore permitted to all jurisdictions until the Government notifies otherwise.
- No adequacy decisions, standard contractual clauses (SCCs), or binding corporate rules (BCRs) are required β unlike GDPR.
- The burden is on the Government to prohibit; not on businesses to justify.
The SDF exception: Significant Data Fiduciaries may be required to maintain certain categories of sensitive personal data locally within India. This is not blanket data localization β it is category-specific and Government-notified.
Consent Manager records must be stored in India β a jurisdictional requirement specific to Consent Managers, not a general data-localization mandate.
β Important caveat The cross-border transfer framework is explicitly subject to change. The Government can notify restrictions at any time. Organizations relying on free data flow should monitor official gazette notifications and not assume the current permissive position is permanent.
12. The Data Protection Board of India
The Data Protection Board of India (DPBI) is the regulatory and enforcement body established under the DPDP Act. It became operational on 13 November 2025.
Structure:
- Headed by a Chairperson appointed by the Central Government.
- Head office in the National Capital Region.
- Members with expertise in data protection, law, and technology.
- Fully digital β no physical filing; all operations through an online portal.
Powers and functions:
| Function | Details |
|---|---|
| Complaint adjudication | Receives and adjudicates complaints from Data Principals against Data Fiduciaries; powers equivalent to a civil court. |
| Investigations | Can investigate data breaches, privacy violations, and non-compliance β on complaint or its own motion. |
| Summons and hearings | Can summon documents and persons, conduct hearings, and commission audits. |
| Penalty imposition | Imposes financial penalties within the Schedule amounts (see Section 13). |
| Voluntary undertakings | May accept a voluntary undertaking from a Data Fiduciary to remedy non-compliance. |
| Uniform enforcement | Ensures consistent application across all sectors β tech, health, fintech, government. |
Digital-first design:
- Online complaint filing portal.
- Mobile application for case-status tracking.
- Digital evidence submission.
- AI-enabled case tracking.
- Standardized online forms for all user requests.
- No physical attendance required.
Appeals: Parties aggrieved by a Board decision can appeal to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).
13. Penalties and Enforcement
The Schedule to the Act β read with Section 33(1) β specifies the maximum monetary penalties for specified contraventions. Rule non-compliance carries penalty consequences because Schedule entry 7 covers breach of "any other provision of this Act or the rules made thereunder." Penalties are stated as "may extend to" ceilings, apply per violation, and can stack β a single breach incident can trigger multiple heads simultaneously.
| Violation | Maximum penalty | Schedule entry / reference |
|---|---|---|
| Breach of the obligation to take reasonable security safeguards | βΉ250 crore | Entry 1 β Section 8(5) |
| Breach of the obligation to give the Board or affected Data Principals notice of a breach | βΉ200 crore | Entry 2 β Section 8(6) |
| Breach of additional obligations in relation to children | βΉ200 crore | Entry 3 β Section 9 |
| Breach of additional obligations of a Significant Data Fiduciary | βΉ150 crore | Entry 4 β Section 10 |
| Breach of the duties of a Data Principal | βΉ10,000 | Entry 5 β Section 15 |
| Breach of any term of a voluntary undertaking accepted by the Board | Up to the extent applicable to the breach for which Section 28 proceedings were instituted | Entry 6 β Section 32 |
| Breach of any other provision of the Act or the Rules | βΉ50 crore | Entry 7 |
π How Rule breaches attract penalties There is no separate penalty schedule in the Rules. A Rule violation becomes exposure because the Act requires compliance with the rules made under it β Section 8(1) makes the Data Fiduciary responsible for complying with "the provisions of this Act and the rules made thereunder" β and Schedule entry 7 then catches it as a residual head. So the chain is Act β Rules β Schedule, not "Rule violation = automatically βΉ50 crore." Where a Rule operationalizes a specific Act duty, the higher specific entry applies instead: a failure of Rule 6 safeguards is an entry 1 matter at βΉ250 crore, not an entry 7 matter at βΉ50 crore.
Stacking example: A single breach incident involving inadequate security (βΉ250 crore) + failure to notify (βΉ200 crore) + SDF obligation failure (βΉ150 crore) could produce cumulative exposure of βΉ600 crore.
Factors the Board considers in setting penalties:
- Nature, gravity, and duration of the violation.
- Type and sensitivity of personal data affected.
- Whether the breach was intentional or negligent.
- Whether the violation is repetitive.
- The Data Fiduciary's prior compliance history.
- Measures taken to mitigate harm after the breach.
π Compliance note The penalty schedule is designed as a deterrent to make non-compliance more expensive than compliance. The Board has discretion to impose penalties below the maximums; early voluntary disclosure, prompt remediation, and cooperation with the Board are relevant factors.
14. The Three-Phase Compliance Timeline
The DPDP Rules roll out in three phases across an 18-month window from the date of notification (13 November 2025). The phasing comes from Rule 1 of the DPDP Rules, which commences different Rules on different dates.
What Rule 1 actually says:
| Provision | Commencement | Date | What becomes operative |
|---|---|---|---|
| Rule 1(2) | On publication in the Official Gazette | 13 Nov 2025 | Rules 1, 2 and 17β21: short title, definitions, and the Board machinery β appointment of Chairperson and Members (17), salary and service terms (18), meetings and authentication of orders (19), functioning of the Board as a digital office (20), and terms of service of Board officers and employees (21). |
| Rule 1(3) | One year after publication | 13 Nov 2026 | Rule 4 only β registration and obligations of Consent Managers. |
| Rule 1(4) | Eighteen months after publication | 13 May 2027 | Rules 3, 5β16, 22 and 23 β the entire substantive compliance layer, plus Rule 22 (appeal to the Appellate Tribunal) and Rule 23 (calling for information). |
β Read the phasing precisely Two points that are easy to get wrong.
Phase 2 contains exactly one Rule. The only thing that commences on 13 November 2026 is Rule 4, Consent Manager registration. Nothing else.
The Rules do not commence the Act. Rule 1 governs when Rules come into force. When the Act's own provisions β including the penalty and adjudication provisions and the Schedule β commence is a matter for the Central Government's commencement notification under Section 1(2) of the Act, not for Rule 1. Do not infer a penalty start date from the Rules' phasing. Verify the operative commencement notification before advising on enforcement exposure.
Note also that Rule 22, the appeal mechanism to the Appellate Tribunal (TDSAT), falls in the 18-month bucket β Phase 3, not Phase 2.
The diagram below is a pedagogical summary. Where it and the Rule 1 table above differ in detail, the table governs.
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
DPDP THREE-PHASE COMPLIANCE TIMELINE
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
PHASE 1 β 13 NOVEMBER 2025 (ALREADY IN EFFECT)
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Rules 1, 2 and 17β21 in force β
β Board machinery: appointment (17), service terms β
β (18), meetings and orders (19), digital office β
β (20), Board staff (21) β
β Rules definitions (Rule 2) operative β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β +12 months
βΌ
PHASE 2 β 13 NOVEMBER 2026
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Rule 4 only β
β β’ Consent Manager registration and obligations β
β Nothing else commences on this date under the Rules β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β +6 months
βΌ
PHASE 3 β 13 MAY 2027 (FULL COMPLIANCE DEADLINE)
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β All remaining Rules come into force: β
β Rules 3, 5β16, 22, and 23 β
β β’ Consent notices (Rule 3) β
β β’ Security safeguards (Rule 6) β
β β’ Breach intimation protocol (Rule 7) β
β β’ Erasure and retention periods (Rule 8) β
β β’ Contact information (Rule 9) β
β β’ Children (Rule 10), disability (Rule 11), β
β child exemptions (Rule 12) β
β β’ SDF obligations (Rule 13) β
β β’ Data Principal rights management (Rule 14) β
β β’ Cross-border transfer requirements (Rule 15) β
β β’ Appeal to Appellate Tribunal (Rule 22) β
β β No grace period. Full enforcement from Day 1 β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β NOTE: In January 2026, MeitY proposed compressing the
compliance window from 18 to 12 months. Nothing has been
gazetted as of August 2026. Monitor official notifications.
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
What this means right now (August 2026)
You are in the Phase 1-to-Phase 2 window. The Board's constitution and procedural machinery are in force under Rules 17β21; the substantive compliance obligations in Rules 3 and 5β16 are not yet operative.
- ~3 months to Phase 2 (November 2026) β Consent Manager registration opens under Rule 4.
- ~9 months to full compliance (May 2027) β Rules 3, 5β16, 22 and 23.
- Whether and to what extent the Act's penalty provisions are operative today turns on the Central Government's commencement notification under Section 1(2) of the Act, not on the Rules' phasing. Confirm the current position against the gazette before relying on a penalty-exposure assessment.
- This is your build window. Organizations that begin implementation in early 2027 will be building under live enforcement.
Recommended internal roadmap
| Internal phase | Duration | Key activities |
|---|---|---|
| Assessment | Months 1β3 | Data mapping, gap analysis, SDF determination, DPO appointment |
| Core implementation | Months 4β12 | Consent framework, security controls, breach protocol, processor contracts, Data Principal rights mechanism |
| Testing and validation | Months 13β18 | Audit readiness, DPIA completion, staff training, security testing, breach-notification dry run |
15. DPDP vs GDPR β Key Comparisons
For compliance professionals with GDPR experience, this table maps the two frameworks.
| Dimension | GDPR | DPDP |
|---|---|---|
| Primary obligated party | Data Controller | Data Fiduciary |
| Individual subject | Data Subject | Data Principal |
| Third-party processor | Data Processor | Data Processor |
| Lawful bases | Six bases including legitimate interests | Consent is primary; deemed consent for government/employment; no legitimate interests base |
| Consent standard | Freely given, specific, informed, unambiguous | Free, specific, informed, unconditional and unambiguous, with a clear affirmative action (s.6(1)) |
| Cross-border transfers | Adequacy / SCCs / BCRs required | Blacklist model β permitted unless Government restricts |
| Enforcement body | National supervisory authorities + EDPB | Data Protection Board of India (single national body) |
| Children's age | 16 (default, can be 13 by member state) | 18 (uniform across India) |
| Unique institution | None equivalent | Consent Manager |
| Right to erasure | Broad "right to be forgotten" | Tied to purpose fulfillment or consent withdrawal |
| Maximum penalty | 4% of global turnover or β¬20M (higher) | βΉ250 crore per violation category (stackable) |
| Breach notification β authority | 72 hours for the initial notification | Two-stage (Rule 7(2)): initial description without delay, detailed report within 72 hours. Stricter than GDPR on the first notification |
| Breach notification β individuals | Without undue delay where high risk | Without delay, to every affected Data Principal β no high-risk threshold |
| Data localization | Not generally required | Not generally required; SDF categories may require it |
π For GDPR-ready organizations If you already have a mature GDPR program, DPDP will be familiar in principle β but the operational differences are significant. Legitimate interests is not available as a lawful basis. Your consent architecture needs redesigning. The Consent Manager mechanism is new and may require new vendor relationships. SDF designation scope needs early assessment.
16. Practical Compliance Checklist
Use this checklist to assess your DPDP readiness. It is a starting framework only β it does not substitute for qualified legal advice.
Foundational (do first)
- Determine whether your organization is a Data Fiduciary under the Act.
- Assess whether you might be designated a Significant Data Fiduciary.
- Complete a personal data inventory β map every category of personal data collected, its source, purpose, and destination.
- Identify all Data Processors you engage and review existing contracts.
- Publish the business contact information of a DPO (if applicable) or a person able to answer processing questions β Section 8(9), Rule 9. Appoint a DPO only if you are an SDF (Section 10(2)(a)) or otherwise choose to.
Consent and notice (due May 2027)
- Design standalone consent notices in plain language β not bundled into terms and conditions.
- Give the Data Principal the option to access the notice in English or any Eighth Schedule language β Section 5(3).
- Build a consent withdrawal mechanism that is as easy as giving consent.
- Assess whether to engage a Consent Manager or build in-house consent management.
- Implement age-verification mechanisms for services that may reach children.
- Obtain verifiable parental consent before processing any children's data.
Security and breach response (due May 2027)
- Implement reasonable security safeguards β encryption, access controls, audits.
- Retain logs and personal data for one year for detection, investigation and remediation β Rule 6(1)(e).
- Include a security safeguards clause in every Data Processor contract β Rule 6(1)(f).
- Draft and test a personal data breach response protocol.
- Establish procedures for intimation to each affected Data Principal without delay with all five Rule 7(1) content elements.
- Establish procedures for the two-stage Board intimation: initial description without delay, detailed report within 72 hours β Rule 7(2).
Data Principal rights (due May 2027)
- Build mechanisms to receive and respond to access, correction, and erasure requests β Sections 11β12.
- Prominently publish the means of making a request and any identifier particulars required β Rule 14(1).
- Publish a grievance response period not exceeding 90 days and build the measures to actually meet it β Rule 14(3).
- Implement data erasure triggers for when purpose is served or consent withdrawn β Section 8(7).
- Check whether you fall in a Third Schedule class (e-commerce β₯2 crore users, online gaming β₯50 lakh, social media β₯2 crore); if so, build the three-year inactivity clock and the 48-hour pre-erasure notice β Rule 8(1)β(2).
- Enforce the one-year minimum retention of personal data, traffic data and logs before erasure β Rule 8(3).
- Create a nomination mechanism for Data Principals β Section 14, Rule 14(4).
Cross-border transfers (due May 2027)
- Review all third-country data transfers β confirm no Government-notified restrictions apply.
- Monitor gazette notifications for any new transfer restrictions.
SDF-specific (if designated)
- Appoint a DPO based in India, responsible to the Board of Directors, who is the grievance point of contact β Section 10(2)(a).
- Appoint an independent data auditor β Section 10(2)(b).
- Run a DPIA and audit once every twelve months and furnish the report of significant observations to the Board β Rule 13(1)β(2).
- Establish due diligence on algorithmic software for risk to Data Principals' rights β Rule 13(3).
- Review localization requirements for any Government-specified data categories β Rule 13(4).
- Ensure board-level ownership of DPDP compliance program.
17. Knowledge Check Questions
1. A fintech company collects mobile numbers to send transaction OTPs. It later uses those numbers to send promotional messages. Which DPDP principle is MOST directly violated?
- A. Data minimization.
- B. Security safeguards.
- C. Purpose limitation.
- D. Storage limitation.
Answer: C. Purpose limitation requires that data collected for a specific purpose be used only for that purpose. Using an OTP number for marketing violates purpose limitation β the marketing use was not disclosed or consented to at the time of collection.
2. A US-based social media company has no office in India but has 200 million Indian users. Is it subject to the DPDP Act?
- A. No β the Act only applies to companies incorporated in India.
- B. No β only Indian government entities must comply.
- C. Yes β the Act applies based on processing of data of persons in India, regardless of where the company is incorporated.
- D. Yes β but only if the company has Indian revenue exceeding βΉ1 crore.
Answer: C. The DPDP Act has extraterritorial scope. Any entity processing personal data of persons in India falls within scope regardless of its country of incorporation or physical presence.
3. A Data Fiduciary becomes aware of a personal data breach on Monday morning. Under Rule 7, what does it owe the Data Protection Board?
- A. A single complete report within 72 hours of becoming aware.
- B. An initial description without delay, followed by a detailed report within 72 hours of becoming aware.
- C. Nothing until the root-cause investigation is complete, then a full report.
- D. Notification only if the breach is likely to result in a high risk to Data Principals.
Answer: B. Rule 7(2) is a two-stage obligation. Sub-rule (2)(a) requires an initial description of the breach β nature, extent, timing, location, likely impact β without delay. Sub-rule (2)(b) requires the detailed report within seventy-two hours of becoming aware, or a longer period the Board allows on written request. A is the GDPR answer, not the DPDP one: under DPDP, 72 hours is the deadline for the follow-up, not the first notification. Separately, Rule 7(1) requires intimation to each affected Data Principal without delay β with no high-risk threshold, which rules out D. Investigation is concurrent, never a precondition.
4. Which BEST describes India's approach to cross-border data transfers under the DPDP Rules 2025?
- A. A whitelist model β transfers only permitted to countries with an India adequacy agreement.
- B. A blacklist model β transfers permitted to any jurisdiction unless the Central Government specifically restricts it.
- C. A localization model β all personal data of Indian citizens must remain in India.
- D. An SCCs model β transfers require Board-approved standard contractual clauses.
Answer: B. India uses a blacklist (negative-list) model. No adequacy decisions, SCCs, or BCRs are required. Transfers are permitted to all jurisdictions unless and until the Government notifies a specific restriction.
5. A company processes health data of 50 million Indian users and uses AI-based profiling extensively. What additional obligation is MOST likely triggered?
- A. The company must register as a Consent Manager.
- B. The company must obtain a cross-border adequacy agreement.
- C. The company is likely to be designated a Significant Data Fiduciary, triggering enhanced obligations including DPIA and annual independent audit.
- D. The company must obtain Supreme Court approval before processing.
Answer: C. *Volume and sensitivity of personal data and risk to the rights of Data Principals are among the Section 10(1) designation factors. Once designated, Rule 13(1) requires a Data Protection Impact Assessment and an audit once in every twelve months, with a report of significant observations furnished to the Board under Rule 13(2). Note the DPIA is periodic β it is not triggered by the act of deploying AI. The provision that speaks to the AI profiling itself is Rule 13(3): continuous due diligence that algorithmic software adopted by the SDF is not likely to pose a risk to Data Principals' rights.*
6. A 12-year-old downloads a gaming app and provides personal information with their parent's approval. Which BEST describes the position under Section 2(j)?
- A. The child alone is the Data Principal; the parent has no status under the definition.
- B. The parent alone is the Data Principal; the child has no status until turning 18.
- C. The child is the individual to whom the data relates, and the definition of "Data Principal" also includes the parent or lawful guardian, who gives verifiable consent and exercises the rights.
- D. The gaming company is the Data Principal because it determines the purpose of processing.
Answer: C. Section 2(j) defines the Data Principal as "the individual to whom the personal data relates" and provides that where that individual is a child, the term includes the parents or lawful guardian. The definition is inclusive, not substitutional β the child does not stop being the Data Principal. In practice the parent gives the verifiable consent required by Section 9(1) and exercises the rights. D describes a Data Fiduciary, not a Data Principal.
7. A Data Fiduciary's published grievance redressal policy states that grievances will be answered "within 120 days." What is the compliance issue?
- A. There is no issue β the Fiduciary is free to set its own grievance response period.
- B. The published period exceeds the ceiling β Rule 14(3) caps it at a reasonable period not exceeding 90 days.
- C. The period should be 30 days, which is the deadline the Rules set for all Data Principal requests.
- D. Grievance periods need not be published at all, only access request periods.
Answer: B. Section 13(2) requires a response to grievances within such period as may be prescribed; Rule 14(3) prescribes a reasonable period not exceeding ninety days, requires it to be prominently published, and requires technical and organisational measures ensuring the system meets it. 120 days breaches the ceiling.
Note what this question is not about. The 90-day figure attaches to the grievance redressal system under Section 13(2) and Rule 14(3). It is not a general DPDP deadline for access, correction, or erasure requests under Sections 11β12 β a widely repeated overstatement. Note too that 90 days is a maximum, not a target: publishing 90 days and consuming it for a simple request sits poorly with the Section 8(10) duty to maintain an effective mechanism.
8. A Data Fiduciary engages a cloud storage vendor to process personal data on its behalf. A data breach occurs at the cloud vendor's infrastructure. Who is accountable to the Data Protection Board?
- A. The cloud vendor alone β it caused the breach.
- B. Neither β the breach happened at a third party.
- C. The Data Fiduciary β accountability cannot be transferred to a processor regardless of where the breach occurred.
- D. The Data Principal β they consented to the cloud storage.
Answer: C. The Data Fiduciary remains accountable to the Board for how processors handle data. Accountability is non-delegable. The Fiduciary may have contractual recourse against the vendor, but its regulatory accountability does not transfer.
18. If You Remember Only These 25 Facts
For quick reference and final revision.
- The DPDP Act was enacted by Parliament in August 2023; the DPDP Rules were notified by MeitY on 13 November 2025.
- The constitutional root is Article 21 β right to privacy as a fundamental right, established by the Puttaswamy judgment (2017).
- The Act applies to digital personal data collected in India and to data of persons in India processed anywhere in the world β full extraterritorial reach.
- Purely offline data, personal/household use, and anonymized data are excluded from scope.
- Data Fiduciary = decides purpose and means of processing (β GDPR Controller).
- Data Principal = the individual whose data is processed (β GDPR Data Subject). Under Section 2(j) the term includes the parent/guardian for a child and the lawful guardian for a person with disability β inclusive, not substitutional.
- Data Processor = processes on behalf of a Data Fiduciary under its instructions.
- Consent Manager = registered Indian intermediary for centralized consent management. Uniquely Indian β no GDPR equivalent. Must retain consent records for 7 years.
- Consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action (Section 6(1)). There is no legitimate interests lawful basis under DPDP.
- The seven privacy principles: consent/transparency, purpose limitation, data minimization, accuracy, storage limitation, security safeguards, accountability.
- Purpose limitation is the most commonly violated principle β data collected for one purpose cannot be repurposed without fresh specific consent.
- Personal data must be erased once purpose is served or consent is withdrawn (Section 8(7)) β but Rule 8(3) imposes a one-year minimum retention of data, traffic data and logs, and Rule 8(1) + Third Schedule set a three-year inactivity clock for large e-commerce, online gaming and social media Fiduciaries, with 48 hours' notice before erasure.
- Significant Data Fiduciaries (SDFs) face enhanced obligations under Section 10 + Rule 13: India-based DPO responsible to the board, independent data auditor, DPIA and audit once every twelve months (periodic β not triggered by AI deployment), algorithmic due diligence under Rule 13(3), and possible localization of Government-specified categories.
- Children = under 18 in India. Verifiable parental consent is required before any processing (Section 9(1) + Rule 10). No tracking, behavioural monitoring, or targeted advertising directed at children (Section 9(3)). Rule 11 is a different rule β persons with disability and court-appointed guardians.
- Cross-border transfers: blacklist model β Section 16(1) lets the Government restrict transfers to notified countries; Rule 15 separately conditions making data available to foreign States and their agencies. No SCCs or adequacy decisions required.
- On personal data breach: intimate each affected Data Principal without delay (Rule 7(1)) and the Board in two stages (Rule 7(2)) β initial description without delay, detailed report within 72 hours. Notification is never contingent on completing the investigation.
- Penalty for security safeguard failures: βΉ250 crore β the highest penalty head.
- Penalty for failure to notify breach: βΉ200 crore β applies per incident, in addition to other heads.
- Penalty for children's data non-compliance: βΉ200 crore.
- Penalty for SDF obligation failures: βΉ150 crore. Residual head β breach of any other provision of the Act or the Rules: βΉ50 crore (Schedule entry 7). This is how Rule breaches attract penalties; there is no separate schedule in the Rules.
- Penalties stack per violation β a single incident can trigger multiple penalty heads simultaneously, creating cumulative exposure well above individual maximums.
- Rule 1 phasing: Rules 1, 2 and 17β21 on 13 Nov 2025; Rule 4 only on 13 Nov 2026; Rules 3, 5β16, 22 and 23 on 13 May 2027. Rule 1 commences Rules β the Act's provisions commence under a Section 1(2) notification, so do not read a penalty start date off the Rules.
- The 90-day figure is grievance-specific β Section 13(2) + Rule 14(3) cap the published grievance response period. It is not a universal deadline for access, correction, or erasure requests.
- The Data Protection Board of India is fully digital, has civil-court powers, and can impose penalties. Appeals go to TDSAT.
- Accountability is non-delegable β a Data Fiduciary cannot transfer its accountability to a processor, a vendor, or a Consent Manager by contract.
19. Glossary
Blacklist model (cross-border transfers): A transfer framework where data may flow to any jurisdiction by default, unless the Government restricts transfers to a notified country or territory under Section 16(1). Distinct from Rule 15, which conditions making personal data available to a foreign State, or a person, entity or agency under its control, on requirements the Government may specify by general or special order.
Consent Manager: A registered Indian intermediary that operates an interoperable platform enabling Data Principals to give, manage, review, and withdraw consent across multiple Data Fiduciaries. Must be incorporated in India and retain consent records for at least 7 years.
Data Fiduciary: Any entity (individual, company, government body) that determines the purpose and means of processing personal data. The primary obligated party under the DPDP Act. Analogous to a "Controller" under GDPR.
Data Principal: The natural person to whom personal data relates. Under Section 2(j) the term includes the parents or lawful guardian where that individual is a child, and the lawful guardian acting on her behalf where she is a person with disability. The definition is inclusive β the child or person with disability remains the Data Principal.
Data Processor: An entity that processes personal data on behalf of a Data Fiduciary under its instructions. Does not determine the purpose of processing. The Data Fiduciary remains accountable for the Processor's actions.
Data Protection Board of India (DPBI): The regulatory and enforcement body under the DPDP Act, operational from 13 November 2025. Fully digital, with civil-court powers for complaint adjudication and penalty imposition.
Data Protection Impact Assessment (DPIA): Defined in Section 10(2)(c)(i) as a process comprising a description of the rights of Data Principals and the purpose of processing, assessment and management of risk to those rights, and other prescribed matters. Under Rule 13(1) a Significant Data Fiduciary must undertake a DPIA and an audit once in every twelve months. It is a periodic obligation, not one triggered by deploying a particular technology.
Data Protection Officer (DPO): An individual appointed by a Significant Data Fiduciary under Section 10(2)(a) who represents it under the Act, is based in India, is responsible to the Board of Directors or similar governing body, and is the point of contact for grievance redressal. A DPO is mandatory only for SDFs; other Data Fiduciaries must publish contact information for a DPO if applicable, or a person able to answer Data Principals' questions (Section 8(9), Rule 9). "Grievance Officer" is not a term used in the Act or the Rules.
DPDP Act 2023: Digital Personal Data Protection Act, 2023 β India's primary data-protection statute enacted by Parliament in August 2023.
DPDP Rules 2025: Digital Personal Data Protection Rules, 2025 β subordinate legislation notified by MeitY on 13 November 2025, operationalizing the DPDP Act in a three-phase rollout.
Full compliance deadline: 13 May 2027 β the date by which all DPDP Rules obligations must be met. No grace period is expected.
MeitY: Ministry of Electronics and Information Technology β the ministry responsible for administering the DPDP framework and notifying implementing orders.
Personal data breach: Any unauthorized access, disclosure, alteration, destruction, or loss of personal data held by a Data Fiduciary.
Purpose limitation: The principle that personal data collected for a stated purpose may only be used for that purpose and not repurposed without fresh, specific consent.
Significant Data Fiduciary (SDF): A Data Fiduciary notified by the Central Government under Section 10(1) on the basis of volume and sensitivity of data, risk to Data Principals' rights, impact on the sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order. Subject to enhanced obligations under Section 10(2) and Rule 13.
Storage limitation: The principle that personal data must be erased once the purpose for which it was collected is fulfilled or consent is withdrawn (Section 8(7)). Subject to the Rule 8(3) one-year minimum retention of personal data, traffic data and logs, and to retention required by any other law.
Third Schedule (to the Rules): Prescribes, under Rule 8(1), the classes of Data Fiduciaries, purposes, and corresponding time periods after which personal data must be erased on Data Principal inactivity β currently three years for e-commerce entities with β₯2 crore registered users in India, online gaming intermediaries with β₯50 lakh, and social media intermediaries with β₯2 crore.
TDSAT: Telecom Disputes Settlement and Appellate Tribunal β the appellate body that hears appeals against Data Protection Board decisions.
Verifiable parental consent: Defined in Rule 2(1)(d) as consent as specified in Rule 10 or Rule 11. Under Rule 10 (children), the Data Fiduciary must adopt technical and organisational measures ensuring parental consent is obtained before processing, and observe due diligence that the individual identifying herself as the parent is an identifiable adult. Under Rule 11 (persons with disability), the due diligence is that the lawful guardian was appointed by a court, designated authority, or local level committee under the law applicable to guardianship. The two tests are different and are not interchangeable.
β Disclaimer This guide is an educational training resource. It is not legal advice. Specific compliance positions β particularly regarding SDF designation, cross-border transfer restrictions, applicable penalty exposure, and SDF local-storage requirements β should be determined with qualified legal counsel referencing current official gazette notifications.
Regulatory details are current as of August 2026. Verify against MeitY official notifications before relying on any specific figure, date, or obligation for professional compliance decisions.
π§ Now explore it as a map
You have read the framework end to end. The DPDP Brain is the same material as a connected graph: 128 cited concepts from the Act and the Rules, 325 connections. Trace any obligation to the Rule that operationalises it and the penalty head that backs it, or filter to just Penalties, Children or Consent Manager.
Open the DPDP Brain ββ End of DPDP Training Material β
www.aigpplaybook.com | By Daman David Pant, AIGP
Expanding from AI Governance to Data Compliance β because the principles connect.