Free Training Material Β· India Data Protection

India's Digital Personal Data Protection Act 2023 and Rules 2025

A Complete Compliance Training Guide

By Daman David Pant (AIGP) Β· Updated August 2026

India's Digital Personal Data Protection Act 2023 and Rules 2025

A Complete Compliance Training Guide

Prepared by the AIGP Playbook | www.aigpplaybook.com

πŸ“Œ Regulatory currency notice: Penalty amounts, compliance deadlines, and cross-border transfer restrictions are current as of August 2026. These details should be verified against official MeitY gazette notifications before relying on them for professional advice. The DPDP framework continues to evolve through implementing orders.


Who this guide is for

This guide is written for compliance professionals, legal counsel, data protection officers, and business leaders responsible for implementing DPDP compliance in Indian organizations, or for multinational companies that process personal data of persons in India.

A note on terminology: DPDP uses India-specific terms that map β€” but do not identically correspond β€” to GDPR. Data Fiduciary β‰ˆ Controller. Data Principal β‰ˆ Data Subject. Data Processor β‰ˆ Processor. Consent Manager is a uniquely Indian concept with no direct GDPR equivalent.

Free interactive tool

🧠 Explore this framework as a map: the DPDP Brain

Everything in this guide, as a graph you can search and filter. Trace any obligation from the Act to the Rule that operationalises it and the penalty head that backs it, or filter straight to Penalties, Children, Consent Manager or the Board.

Open the DPDP Brain β†’ 128 cited concepts Β· 325 connections Β· DPDP Act 2023 + Rules 2025

Table of Contents

  1. Why the DPDP Framework Exists
  2. The Two-Layer Structure: Act and Rules
  3. Scope: Who and What Is Covered
  4. Key Definitions and Roles
  5. The Seven Core Privacy Principles
  6. Obligations on Data Fiduciaries
  7. Significant Data Fiduciaries β€” Enhanced Obligations
  8. The Consent Manager β€” A Uniquely Indian Institution
  9. Rights of Data Principals
  10. Children's Data β€” Special Protections
  11. Cross-Border Data Transfers
  12. The Data Protection Board of India
  13. Penalties and Enforcement
  14. The Three-Phase Compliance Timeline
  15. DPDP vs GDPR β€” Key Comparisons
  16. Practical Compliance Checklist
  17. Knowledge Check Questions
  18. If You Remember Only These 25 Facts
  19. Glossary

1. Why the DPDP Framework Exists

The constitutional foundation

India's data-protection law did not emerge from legislation alone. Its roots lie in a landmark Supreme Court judgment.

In Puttaswamy v. Union of India (2017), a nine-judge constitutional bench unanimously held that the right to privacy is a fundamental right under Article 21 of the Indian Constitution. The judgment directed Parliament to enact a modern data-protection statute that would give practical content to this right in the digital age.

That direction produced the Digital Personal Data Protection Act, 2023 (DPDP Act) β€” India's first comprehensive digital data-protection statute enacted by Parliament in August 2023. The Ministry of Electronics and Information Technology (MeitY) then notified the Digital Personal Data Protection Rules, 2025 (DPDP Rules) on 13 November 2025 to operationalize the Act.

Why it was urgently needed

Several converging factors made the law overdue:

The DPDP Act fills these gaps. It establishes clear rights for individuals, defined obligations for organizations, an independent enforcement body, and significant financial penalties for non-compliance.


2. The Two-Layer Structure: Act and Rules

Understanding DPDP compliance requires understanding which layer governs a given question.

Layer Instrument Passed / Notified Role
Primary legislation Digital Personal Data Protection Act, 2023 Parliament, August 2023 Establishes the framework, rights, obligations, and penalty structure
Subordinate legislation Digital Personal Data Protection Rules, 2025 MeitY, 13 November 2025 Operationalizes the Act β€” specifies how, in what format, and in what timeframe obligations are to be met

Think of it this way: the Act says what must be done; the Rules say how.

πŸ“Œ The single most important principle in this guide The DPDP Act establishes the legal duty. The DPDP Rules prescribe how that duty is operationalized.

Wherever an Act provision reads "in such manner as may be prescribed" or "as may be prescribed", that phrase is the hook on which a Rule hangs. The duty comes from the Section; the mechanics come from the Rule. Citing only the Rule for an obligation misattributes subordinate legislation as the source of statutory authority β€” and it will cost you marks in an exam and credibility in a compliance memo.

The pattern, applied:

Obligation Act β€” the duty Rules β€” the mechanics
Notice Section 5 Rule 3
Security safeguards Section 8(5) Rule 6
Breach intimation Section 8(6) Rule 7
Erasure and retention Section 8(7)–(8) Rule 8 + Third Schedule
Contact information Section 8(9) Rule 9
Grievance redressal Section 8(10), 13(2) Rule 14(3)
Processor accountability Section 8(1)–(2) Rule 6(1)(f)
Children Section 9 Rules 10, 12 + Fourth Schedule
Persons with disability Section 9(1) Rule 11
SDF obligations Section 10 Rule 13
Data Principal rights Sections 11–14 Rule 14
Cross-border Section 16 Rule 15
Penalties Schedule, read with Section 33(1) (no penalty schedule in the Rules)

The Rules also introduce machinery with no direct Act analogue in the same form: the Consent Manager registration process (Rule 4 + First and Second Schedules) and the procedures and digital-office functioning of the Data Protection Board (Rules 17–21).


3. Scope: Who and What Is Covered

What is covered

The DPDP Act applies to:

What is not covered

The extraterritorial reach

This is the provision that changes everything for multinational companies. Any organization, regardless of where it is incorporated, that processes personal data of persons in India falls within DPDP scope. A social media platform headquartered in the United States, a cloud provider based in Singapore, a fintech company in the United Kingdom β€” all are subject to the Act if they process data of persons in India.

πŸ“˜ Compliance note "Processing" is defined broadly: collection, recording, organisation, structuring, storage, adaptation, retrieval, use, disclosure, erasure β€” essentially anything done with personal data. If you touch Indian user data, you are processing it.


4. Key Definitions and Roles

Data Principal

The individual to whom the personal data relates β€” the natural person who is the source of the data. In everyday terms: the customer, user, citizen, patient, or employee.

Special cases (Section 2(j)). The definition is inclusive: the individual remains the Data Principal, and the term also includesβ€”

The distinction matters: the parent does not replace the child as Data Principal, and the data being protected is still the child's.

Data Fiduciary

Any person or entity that determines the purpose and means of processing personal data. This is the primary obligated party under the Act β€” analogous to a "Controller" under GDPR.

Every organization that decides what personal data to collect and why β€” a bank, a startup, a hospital, an e-commerce platform, a government body β€” is a Data Fiduciary.

Data Processor

A person or entity that processes personal data on behalf of a Data Fiduciary, under its instructions. A cloud storage provider, a payroll outsourcing firm, or a third-party analytics company acting on a Data Fiduciary's instructions is a Data Processor.

The key distinction: the Data Fiduciary decides the purpose; the Data Processor executes the processing.

Consent Manager

A registered intermediary that maintains an interoperable platform through which Data Principals can give, manage, review, and withdraw consent across multiple Data Fiduciaries. Consent Managers must be registered with the Data Protection Board, must be incorporated as Indian companies, and are prohibited from sub-contracting their core obligations. They must maintain records of consents for at least seven years.

This is a uniquely Indian institution with no direct GDPR equivalent, designed to centralize consent management for a market with hundreds of millions of mobile-first users.

Significant Data Fiduciary (SDF)

A Data Fiduciary designated by the Central Government based on the volume and sensitivity of data processed, potential national security or public-order risk, risk to rights of children, and impact on sovereignty and integrity of India. SDFs carry enhanced obligations above and beyond standard Data Fiduciary requirements.


5. The Seven Core Privacy Principles

The DPDP Act is built on seven principles that apply to all personal data processing:

# Principle What it means in practice
1 Consent and transparency Consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action (Section 6(1)). Notices must be in plain language β€” not buried in lengthy terms and conditions.
2 Purpose limitation Data collected for a specific purpose can only be used for that purpose. A mobile number collected to send OTPs cannot be used for marketing.
3 Data minimization Only collect what is genuinely necessary. A food-delivery app needs a delivery address; it does not need employment history.
4 Accuracy Data must be accurate and kept up to date. Organizations have a responsibility to maintain current records.
5 Storage limitation Data must be erased once the purpose for which it was collected is fulfilled, or when consent is withdrawn. No indefinite retention.
6 Security safeguards Appropriate technical and organizational measures β€” encryption, access controls, audits, secure design β€” must protect personal data from breach.
7 Accountability Data Fiduciaries are responsible for ensuring compliance and can be held liable for misuse, whether by themselves or by their processors.

πŸ“˜ Study tip Purpose limitation is the most commonly violated principle in practice. Data collected lawfully for one purpose cannot be repurposed for another β€” including AI training β€” without fresh, specific consent covering the new purpose.


6. Obligations on Data Fiduciaries

πŸ“Œ How to read this section Every obligation below is cited in two layers. The Act establishes the legal duty. The Rules prescribe how that duty is operationalized. Where an Act provision says "as may be prescribed," that is the hook the corresponding Rule hangs on.

6.1 Notice and consent β€” Section 5 of the Act + Rule 3 of the Rules

Act: Section 5(1) requires that every request for consent be accompanied or preceded by a notice informing the Data Principal of the personal data and purpose, the manner of exercising rights, and the manner of complaining to the Board β€” "in such manner as may be prescribed." Section 5(2) covers pre-commencement consent. Section 5(3) requires the Data Fiduciary to give the Data Principal the option to access the notice in English or any language specified in the Eighth Schedule to the Constitution (the 22 scheduled languages).

Rules: Rule 3 prescribes the manner. The notice must:

Training takeaway: Section 5 creates the notice duty and the language option. Rule 3 dictates its form and minimum content.

6.2 Security safeguards β€” Section 8(5) of the Act + Rule 6 of the Rules

Act: Section 8(5) requires a Data Fiduciary to protect personal data in its possession or control β€” including data processed on its behalf by a Data Processor β€” by taking reasonable security safeguards to prevent personal data breach.

Rules: Rule 6(1) prescribes the minimum safeguards:

Training takeaway: Section 8(5) sets the "reasonable safeguards" standard; Rule 6 converts it into a checklist with a floor. The statutory word is still "reasonable" β€” calibrated to the nature, volume, and sensitivity of data held β€” but Rule 6 items are the minimum, not the ceiling.

6.3 Personal data breach notification β€” Section 8(6) of the Act + Rule 7 of the Rules

Act: Section 8(6) requires the Data Fiduciary, in the event of a personal data breach, to give the Board and each affected Data Principal intimation of the breach, "in such form and manner as may be prescribed."

Rules: Rule 7 prescribes two distinct tracks, with different clocks.

To each affected Data Principal β€” Rule 7(1): on becoming aware of the breach, without delay, in a concise, clear and plain manner, through their user account or a registered mode of communication. Content must include: a description of the breach (nature, extent, timing); the consequences likely to arise for that individual; mitigation measures implemented or being implemented; safety measures the individual may take; and business contact information of a person who can respond to queries.

To the Board β€” Rule 7(2), a two-stage obligation:

  1. Without delay β€” a description of the breach: nature, extent, timing and location of occurrence, and likely impact.
  2. Within seventy-two hours of becoming aware (or a longer period the Board allows on written request) β€” updated and detailed information, the broad facts and reasons leading to the breach, mitigation measures, any findings on who caused it, remedial measures to prevent recurrence, and a report on the intimations given to affected Data Principals.

Notification to individuals must be direct β€” not a generalized public announcement β€” in plain language with no technical jargon.

⚠ Key trap Two traps here, and most GDPR-trained teams hit both.

First: notification is NOT contingent on completing the root-cause investigation. The obligation is to notify promptly upon becoming aware that a breach has occurred. Waiting for a completed investigation exposes the organization to the full β‚Ή200 crore non-notification penalty under Section 8(6).

Second: DPDP does have a 72-hour clock β€” it is just not GDPR's. Under GDPR, 72 hours is the deadline for the initial notification to the supervisory authority. Under Rule 7(2), the initial intimation to the Board is due without delay, and 72 hours is the deadline for the detailed follow-up report. DPDP is the stricter of the two on the first notification.

6.4 Erasure and retention β€” Section 8(7)–(8) of the Act + Rule 8 of the Rules

Act: Section 8(7) requires the Data Fiduciary β€” unless retention is necessary for compliance with any law in force β€” to erase personal data upon the Data Principal withdrawing consent, or as soon as it is reasonable to assume the specified purpose is no longer being served, whichever is earlier, and to cause its Data Processor to erase data made available to it. Section 8(8) provides that the purpose is deemed no longer served if the Data Principal neither approaches the Fiduciary for the specified purpose nor exercises any rights, for such time period as may be prescribed β€” with different periods permitted for different classes of Fiduciaries and purposes.

Rules: Rule 8 supplies those prescribed periods, and adds two obligations that cut the other way.

Rule Requirement
Rule 8(1) + Third Schedule Fiduciaries of specified classes must erase after the corresponding period. Currently: three years of Data Principal inactivity, for e-commerce entities with β‰₯2 crore registered users in India, online gaming intermediaries with β‰₯50 lakh, and social media intermediaries with β‰₯2 crore β€” excluding data needed to access the user account or a stored virtual token.
Rule 8(2) The Fiduciary must inform the Data Principal at least forty-eight hours before the erasure period completes, so they can log in or exercise a right to prevent it.
Rule 8(3) + Seventh Schedule The Fiduciary must retain personal data, associated traffic data, and processing logs for a minimum of one year from the date of processing, before erasure β€” unless another law requires longer.

⚠ Key trap Rule 8 is not simply "erase when done." It contains a mandatory retention floor. Rule 8(3) requires one year of retention of the data and logs even where the purpose has been served and the user has deleted their account. An erasure-on-completion pipeline that deletes immediately is non-compliant with Rule 8(3), not compliant with Section 8(7).

Note also that the Third Schedule deeming periods apply only to the specified classes above the stated user thresholds. For everyone else, the Section 8(7) test governs directly: erase when consent is withdrawn or when it is reasonable to assume the purpose is no longer served.

6.5 Contact information and grievance redressal β€” Section 8(9)–(10) of the Act + Rules 9 and 14(3)

Act: Section 8(9) requires the Data Fiduciary to publish, in the prescribed manner, the business contact information of a Data Protection Officer, if applicable, or a person who is able to answer the Data Principal's questions about processing. Section 8(10) requires the Fiduciary to establish an effective mechanism to redress grievances of Data Principals.

Rules: Rule 9 requires that contact information be published prominently on the website or app, and be included in every response to a request for the exercise of rights. Rule 14(3) requires the Fiduciary (and Consent Manager) to prominently publish the period within which grievances are responded to under its grievance redressal system β€” a reasonable period not exceeding ninety days β€” and to implement technical and organisational measures ensuring the system actually meets it.

πŸ“˜ Terminology caution "Grievance Officer" is not a term used in the DPDP Act or the DPDP Rules. Do not treat "DPO or Grievance Officer" as interchangeable statutory roles. Section 8(9) contemplates a DPO where applicable, or otherwise a person able to answer questions. A DPO is mandatory only for Significant Data Fiduciaries under Section 10(2)(a) β€” for whom the DPO is also the point of contact for grievance redressal. A non-SDF Data Fiduciary must publish a responsible contact; it is not required to appoint a DPO.

6.6 Processor accountability β€” Section 8(1)–(2) of the Act

Act: Section 8(1) makes the Data Fiduciary responsible for complying with the Act and the Rules in respect of any processing undertaken by it or on its behalf by a Data Processor β€” irrespective of any agreement to the contrary, and irrespective of the Data Principal's own failure to perform their duties. Section 8(2) permits engaging a Data Processor for activity related to offering goods or services to Data Principals only under a valid contract.

Rules: Rule 6(1)(f) separately requires that contract to contain appropriate provision for the Processor to take reasonable security safeguards. Rule 8(3) requires the Fiduciary to ensure its Processor also observes the one-year retention floor.

Training takeaway: Accountability is an Act-level, non-delegable duty. Outsourcing processing does not transfer it. The contract is a statutory precondition to engagement, not merely good practice.


7. Significant Data Fiduciaries β€” Enhanced Obligations

SDFs have enhanced obligations under Section 10 of the Act and Rule 13 of the Rules, including prescribed impact-assessment, audit, DPO and other requirements. The exact Rule reference for each is given below.

Act β€” Section 10(1), designation criteria. The Central Government may notify a Data Fiduciary or class of Data Fiduciaries as an SDF on the basis of an assessment of such relevant factors as it may determine, including:

Enhanced obligations:

Obligation Source Details
Data Protection Officer Section 10(2)(a) Must represent the SDF under the Act, be based in India, be an individual responsible to the Board of Directors or similar governing body, and be the point of contact for grievance redressal.
Independent data auditor Section 10(2)(b) An independent data auditor must be appointed to carry out a data audit evaluating the SDF's compliance with the Act.
Periodic DPIA and audit Section 10(2)(c)(i)–(ii) + Rule 13(1) The Act requires a periodic DPIA and periodic audit. Rule 13(1) sets the period: once in every twelve months from the date of SDF notification. Rule 13(2) requires the person carrying them out to furnish a report of significant observations to the Board.
Algorithmic due diligence Rule 13(3) The SDF must observe due diligence to verify that technical measures including algorithmic software it adopts for hosting, display, upload, modification, publication, transmission, storage, updating or sharing of personal data are not likely to pose a risk to the rights of Data Principals.
Localization of specified data Rule 13(4)–(5) The SDF must ensure that personal data specified by the Central Government β€” on the recommendation of a committee it constitutes β€” and the traffic data pertaining to its flow, is not transferred outside India. Category-specific, not general localization.

⚠ Do not over-read the DPIA trigger A DPIA under Rule 13(1) is a periodic, twelve-monthly obligation tied to SDF status. It is not triggered by the act of deploying AI, biometrics, or profiling. If an SDF deploys algorithmic software, the provision that bites is Rule 13(3) β€” a continuous due-diligence duty on risk to Data Principals' rights β€” not a deployment-gating DPIA.

Note also that neither the Act nor the Rules require the independent data auditor to be registered with the Data Protection Board. Section 10(2)(b) requires only that the auditor be independent.

⚠ Compliance note for SDFs The penalty for failing SDF obligations is up to β‚Ή150 crore. Combined with other penalty heads, a single incident can create exposure well above β‚Ή500 crore. DPDP compliance at SDF level must sit at board level β€” not just with the CISO or legal team.


8. The Consent Manager β€” A Uniquely Indian Institution

The Consent Manager is one of the most innovative features of the DPDP framework β€” a registered intermediary that allows users to manage all their data consents through a single platform.

What a Consent Manager does:

Key requirements for Consent Managers:

Requirement Detail
Registration Must be registered with the Data Protection Board.
Incorporation Must be an Indian company β€” jurisdiction and accountability remain within India.
No sub-contracting Core obligations cannot be outsourced to third parties.
Record retention Must maintain records of consents, notices, and data-sharing activities for at least 7 years.
Conflicts of interest Must avoid any conflict of interest with Data Fiduciaries.
Independent certification Platform must be independently certified as meeting the Board's data protection standards.

Timeline: Consent Manager registration opens in Phase 2 (13 November 2026). Organizations planning to operate as Consent Managers should begin certification and registration preparations well before that date.


9. Rights of Data Principals

Every individual whose personal data is processed has the following rights under the DPDP Act:

Right Source What it means
Right to access Section 11 Obtain a summary of personal data being processed and the processing activities, the identities of other Fiduciaries and Processors with whom it has been shared, and any other prescribed information.
Right to correction Section 12 Require inaccurate or misleading data to be corrected, completed, or updated; and erasure where retention is no longer necessary for the specified purpose.
Right to erasure Section 12 Require personal data to be erased, subject to retention required by law.
Right to grievance redressal Section 13 Have a readily available means of grievance redressal in respect of any act or omission of the Data Fiduciary, and escalate to the Board where redressal is not obtained.
Right to nomination Section 14 + Rule 14(4) Nominate one or more individuals to exercise rights in the event of death or incapacity.
Right to withdraw consent Section 6(4)–(6) Withdraw consent at any time, with ease comparable to giving it. Withdrawal does not affect the lawfulness of prior processing.

Rule 14 β€” how rights are exercised. The Data Fiduciary and, where applicable, the Consent Manager must prominently publish on its website or app: the means by which a request may be made, and any particulars (username or other identifier) needed to identify the Data Principal under its terms of service.

πŸ“˜ Key point β€” where the 90 days actually applies Section 13(2) requires the Data Fiduciary or Consent Manager to respond to grievances within such period as may be prescribed. Rule 14(3) prescribes it: they must prominently publish the period within which their grievance redressal system responds β€” a reasonable period not exceeding ninety days β€” and implement technical and organisational measures ensuring it is met.

The ninety days is therefore a ceiling on the published grievance-response period, anchored in Section 13(2) and the Section 8(10) duty to maintain an effective mechanism. It is not a general statutory deadline for every access, correction, or erasure request. Those are governed by Sections 11–12 and the Fiduciary's own published terms. Treating 90 days as a universal DPDP response SLA is a common overstatement β€” and note the ceiling is a maximum, not a target: publishing 90 days and using all of it is unlikely to read as "effective" redressal for a simple request.

Section 13(3) also requires the Data Principal to exhaust the Fiduciary's grievance mechanism before approaching the Board.


10. Children's Data β€” Special Protections

The DPDP Act imposes some of its strictest rules on the processing of children's personal data. Section 9 of the Act establishes the substantive protections; Rules 10, 11 and 12 prescribe how they are implemented.

Who is a child: Any person under the age of 18 in India. This is a higher threshold than the GDPR default of 16.

Act β€” Section 9:

Rules β€” the operational layer:

Rule What it prescribes
Rule 10 β€” children The Fiduciary must adopt appropriate technical and organisational measures to ensure verifiable parental consent is obtained before processing, and observe due diligence to check that the individual identifying herself as the parent is an adult who is identifiable if required for compliance with law β€” by reference to reliable identity and age details already held, or details voluntarily provided.
Rule 11 β€” persons with disability A different test, for a different group. Where consent is obtained from someone identifying as the lawful guardian of a person with disability, the Fiduciary must observe due diligence to verify that the guardian is appointed by a court of law, a designated authority, or a local level committee under the law applicable to guardianship.
Rule 12 + Fourth Schedule Carves out the Section 9(4) exemptions: Section 9(1) and 9(3) do not apply to the classes of Data Fiduciaries in Part A or the purposes in Part B of the Fourth Schedule, subject to the stated conditions.

Penalty for non-compliance: Up to β‚Ή200 crore (Schedule, entry 3 β€” breach of additional obligations in relation to children under Section 9).

⚠ Compliance note "Verifiable" is not satisfied by a checkbox asking "are you over 18?" Data Fiduciaries serving or potentially serving children need genuine verification β€” Rule 10 requires due diligence that the purported parent is an identifiable adult, not a nominal affirmation.

Do not confuse Rule 10 with Rule 11. Rule 10 governs children and its test is is this person a verifiable adult parent. Rule 11 governs persons with disability who have a lawful guardian and its test is was this guardian formally appointed under guardianship law. Applying the Rule 11 court-appointment test to ordinary parental consent is a common misreading.


11. Cross-Border Data Transfers

India has adopted a blacklist (negative-list) model for cross-border transfers β€” significantly more permissive than GDPR's adequacy framework. Section 16 of the Act creates the restriction power; Rule 15 of the Rules adds a separate requirement. They are two distinct mechanisms and are often wrongly merged.

Act β€” Section 16(1): the Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary to a notified country or territory outside India. Section 16(2) preserves any other law in force that imposes a higher degree of protection or restriction β€” so sector regulators (RBI, IRDAI, SEBI) remain fully in play.

Rules β€” Rule 15: personal data may be transferred outside India subject to the Data Fiduciary meeting such requirements as the Central Government may, by general or special order, specify in respect of making that data available to any foreign State, or to any person or entity under the control of or any agency of such a State.

The default rule: absent a Section 16(1) notification and outside the scope of a Rule 15 order, personal data may be transferred to any country or territory outside India.

πŸ“˜ Keep the two apart Rule 15 is not the source of the cross-border framework. Section 16 restricts transfers to countries. Rule 15 attaches conditions to making data available to foreign States and their agencies β€” a narrower and differently-aimed provision. A summary that reads "Rule 15 / Section 16" as a single blacklist rule loses that distinction.

What this means in practice:

The SDF exception: Significant Data Fiduciaries may be required to maintain certain categories of sensitive personal data locally within India. This is not blanket data localization β€” it is category-specific and Government-notified.

Consent Manager records must be stored in India β€” a jurisdictional requirement specific to Consent Managers, not a general data-localization mandate.

⚠ Important caveat The cross-border transfer framework is explicitly subject to change. The Government can notify restrictions at any time. Organizations relying on free data flow should monitor official gazette notifications and not assume the current permissive position is permanent.


12. The Data Protection Board of India

The Data Protection Board of India (DPBI) is the regulatory and enforcement body established under the DPDP Act. It became operational on 13 November 2025.

Structure:

Powers and functions:

Function Details
Complaint adjudication Receives and adjudicates complaints from Data Principals against Data Fiduciaries; powers equivalent to a civil court.
Investigations Can investigate data breaches, privacy violations, and non-compliance β€” on complaint or its own motion.
Summons and hearings Can summon documents and persons, conduct hearings, and commission audits.
Penalty imposition Imposes financial penalties within the Schedule amounts (see Section 13).
Voluntary undertakings May accept a voluntary undertaking from a Data Fiduciary to remedy non-compliance.
Uniform enforcement Ensures consistent application across all sectors β€” tech, health, fintech, government.

Digital-first design:

Appeals: Parties aggrieved by a Board decision can appeal to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).


13. Penalties and Enforcement

The Schedule to the Act β€” read with Section 33(1) β€” specifies the maximum monetary penalties for specified contraventions. Rule non-compliance carries penalty consequences because Schedule entry 7 covers breach of "any other provision of this Act or the rules made thereunder." Penalties are stated as "may extend to" ceilings, apply per violation, and can stack β€” a single breach incident can trigger multiple heads simultaneously.

Violation Maximum penalty Schedule entry / reference
Breach of the obligation to take reasonable security safeguards β‚Ή250 crore Entry 1 β€” Section 8(5)
Breach of the obligation to give the Board or affected Data Principals notice of a breach β‚Ή200 crore Entry 2 β€” Section 8(6)
Breach of additional obligations in relation to children β‚Ή200 crore Entry 3 β€” Section 9
Breach of additional obligations of a Significant Data Fiduciary β‚Ή150 crore Entry 4 β€” Section 10
Breach of the duties of a Data Principal β‚Ή10,000 Entry 5 β€” Section 15
Breach of any term of a voluntary undertaking accepted by the Board Up to the extent applicable to the breach for which Section 28 proceedings were instituted Entry 6 β€” Section 32
Breach of any other provision of the Act or the Rules β‚Ή50 crore Entry 7

πŸ“˜ How Rule breaches attract penalties There is no separate penalty schedule in the Rules. A Rule violation becomes exposure because the Act requires compliance with the rules made under it β€” Section 8(1) makes the Data Fiduciary responsible for complying with "the provisions of this Act and the rules made thereunder" β€” and Schedule entry 7 then catches it as a residual head. So the chain is Act β†’ Rules β†’ Schedule, not "Rule violation = automatically β‚Ή50 crore." Where a Rule operationalizes a specific Act duty, the higher specific entry applies instead: a failure of Rule 6 safeguards is an entry 1 matter at β‚Ή250 crore, not an entry 7 matter at β‚Ή50 crore.

Stacking example: A single breach incident involving inadequate security (β‚Ή250 crore) + failure to notify (β‚Ή200 crore) + SDF obligation failure (β‚Ή150 crore) could produce cumulative exposure of β‚Ή600 crore.

Factors the Board considers in setting penalties:

πŸ“˜ Compliance note The penalty schedule is designed as a deterrent to make non-compliance more expensive than compliance. The Board has discretion to impose penalties below the maximums; early voluntary disclosure, prompt remediation, and cooperation with the Board are relevant factors.


14. The Three-Phase Compliance Timeline

The DPDP Rules roll out in three phases across an 18-month window from the date of notification (13 November 2025). The phasing comes from Rule 1 of the DPDP Rules, which commences different Rules on different dates.

What Rule 1 actually says:

Provision Commencement Date What becomes operative
Rule 1(2) On publication in the Official Gazette 13 Nov 2025 Rules 1, 2 and 17–21: short title, definitions, and the Board machinery β€” appointment of Chairperson and Members (17), salary and service terms (18), meetings and authentication of orders (19), functioning of the Board as a digital office (20), and terms of service of Board officers and employees (21).
Rule 1(3) One year after publication 13 Nov 2026 Rule 4 only β€” registration and obligations of Consent Managers.
Rule 1(4) Eighteen months after publication 13 May 2027 Rules 3, 5–16, 22 and 23 β€” the entire substantive compliance layer, plus Rule 22 (appeal to the Appellate Tribunal) and Rule 23 (calling for information).

⚠ Read the phasing precisely Two points that are easy to get wrong.

Phase 2 contains exactly one Rule. The only thing that commences on 13 November 2026 is Rule 4, Consent Manager registration. Nothing else.

The Rules do not commence the Act. Rule 1 governs when Rules come into force. When the Act's own provisions β€” including the penalty and adjudication provisions and the Schedule β€” commence is a matter for the Central Government's commencement notification under Section 1(2) of the Act, not for Rule 1. Do not infer a penalty start date from the Rules' phasing. Verify the operative commencement notification before advising on enforcement exposure.

Note also that Rule 22, the appeal mechanism to the Appellate Tribunal (TDSAT), falls in the 18-month bucket β€” Phase 3, not Phase 2.

The diagram below is a pedagogical summary. Where it and the Rule 1 table above differ in detail, the table governs.

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
  DPDP THREE-PHASE COMPLIANCE TIMELINE
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

  PHASE 1 β€” 13 NOVEMBER 2025 (ALREADY IN EFFECT)
  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
  β”‚  Rules 1, 2 and 17–21 in force                       β”‚
  β”‚  Board machinery: appointment (17), service terms    β”‚
  β”‚  (18), meetings and orders (19), digital office      β”‚
  β”‚  (20), Board staff (21)                              β”‚
  β”‚  Rules definitions (Rule 2) operative                β”‚
  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                          β”‚ +12 months
                          β–Ό
  PHASE 2 β€” 13 NOVEMBER 2026
  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
  β”‚  Rule 4 only                                         β”‚
  β”‚  β€’ Consent Manager registration and obligations      β”‚
  β”‚  Nothing else commences on this date under the Rules β”‚
  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                          β”‚ +6 months
                          β–Ό
  PHASE 3 β€” 13 MAY 2027 (FULL COMPLIANCE DEADLINE)
  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
  β”‚  All remaining Rules come into force:                β”‚
  β”‚  Rules 3, 5–16, 22, and 23                          β”‚
  β”‚  β€’ Consent notices (Rule 3)                          β”‚
  β”‚  β€’ Security safeguards (Rule 6)                      β”‚
  β”‚  β€’ Breach intimation protocol (Rule 7)               β”‚
  β”‚  β€’ Erasure and retention periods (Rule 8)            β”‚
  β”‚  β€’ Contact information (Rule 9)                      β”‚
  β”‚  β€’ Children (Rule 10), disability (Rule 11),         β”‚
  β”‚    child exemptions (Rule 12)                        β”‚
  β”‚  β€’ SDF obligations (Rule 13)                         β”‚
  β”‚  β€’ Data Principal rights management (Rule 14)        β”‚
  β”‚  β€’ Cross-border transfer requirements (Rule 15)      β”‚
  β”‚  β€’ Appeal to Appellate Tribunal (Rule 22)            β”‚
  β”‚  ⚠ No grace period. Full enforcement from Day 1     β”‚
  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
  ⚠ NOTE: In January 2026, MeitY proposed compressing the
  compliance window from 18 to 12 months. Nothing has been
  gazetted as of August 2026. Monitor official notifications.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

What this means right now (August 2026)

You are in the Phase 1-to-Phase 2 window. The Board's constitution and procedural machinery are in force under Rules 17–21; the substantive compliance obligations in Rules 3 and 5–16 are not yet operative.

Recommended internal roadmap

Internal phase Duration Key activities
Assessment Months 1–3 Data mapping, gap analysis, SDF determination, DPO appointment
Core implementation Months 4–12 Consent framework, security controls, breach protocol, processor contracts, Data Principal rights mechanism
Testing and validation Months 13–18 Audit readiness, DPIA completion, staff training, security testing, breach-notification dry run

15. DPDP vs GDPR β€” Key Comparisons

For compliance professionals with GDPR experience, this table maps the two frameworks.

Dimension GDPR DPDP
Primary obligated party Data Controller Data Fiduciary
Individual subject Data Subject Data Principal
Third-party processor Data Processor Data Processor
Lawful bases Six bases including legitimate interests Consent is primary; deemed consent for government/employment; no legitimate interests base
Consent standard Freely given, specific, informed, unambiguous Free, specific, informed, unconditional and unambiguous, with a clear affirmative action (s.6(1))
Cross-border transfers Adequacy / SCCs / BCRs required Blacklist model β€” permitted unless Government restricts
Enforcement body National supervisory authorities + EDPB Data Protection Board of India (single national body)
Children's age 16 (default, can be 13 by member state) 18 (uniform across India)
Unique institution None equivalent Consent Manager
Right to erasure Broad "right to be forgotten" Tied to purpose fulfillment or consent withdrawal
Maximum penalty 4% of global turnover or €20M (higher) β‚Ή250 crore per violation category (stackable)
Breach notification β€” authority 72 hours for the initial notification Two-stage (Rule 7(2)): initial description without delay, detailed report within 72 hours. Stricter than GDPR on the first notification
Breach notification β€” individuals Without undue delay where high risk Without delay, to every affected Data Principal β€” no high-risk threshold
Data localization Not generally required Not generally required; SDF categories may require it

πŸ“˜ For GDPR-ready organizations If you already have a mature GDPR program, DPDP will be familiar in principle β€” but the operational differences are significant. Legitimate interests is not available as a lawful basis. Your consent architecture needs redesigning. The Consent Manager mechanism is new and may require new vendor relationships. SDF designation scope needs early assessment.


16. Practical Compliance Checklist

Use this checklist to assess your DPDP readiness. It is a starting framework only β€” it does not substitute for qualified legal advice.

Foundational (do first)

Consent and notice (due May 2027)

Security and breach response (due May 2027)

Data Principal rights (due May 2027)

Cross-border transfers (due May 2027)

SDF-specific (if designated)


17. Knowledge Check Questions

1. A fintech company collects mobile numbers to send transaction OTPs. It later uses those numbers to send promotional messages. Which DPDP principle is MOST directly violated?

Answer: C. Purpose limitation requires that data collected for a specific purpose be used only for that purpose. Using an OTP number for marketing violates purpose limitation β€” the marketing use was not disclosed or consented to at the time of collection.


2. A US-based social media company has no office in India but has 200 million Indian users. Is it subject to the DPDP Act?

Answer: C. The DPDP Act has extraterritorial scope. Any entity processing personal data of persons in India falls within scope regardless of its country of incorporation or physical presence.


3. A Data Fiduciary becomes aware of a personal data breach on Monday morning. Under Rule 7, what does it owe the Data Protection Board?

Answer: B. Rule 7(2) is a two-stage obligation. Sub-rule (2)(a) requires an initial description of the breach β€” nature, extent, timing, location, likely impact β€” without delay. Sub-rule (2)(b) requires the detailed report within seventy-two hours of becoming aware, or a longer period the Board allows on written request. A is the GDPR answer, not the DPDP one: under DPDP, 72 hours is the deadline for the follow-up, not the first notification. Separately, Rule 7(1) requires intimation to each affected Data Principal without delay β€” with no high-risk threshold, which rules out D. Investigation is concurrent, never a precondition.


4. Which BEST describes India's approach to cross-border data transfers under the DPDP Rules 2025?

Answer: B. India uses a blacklist (negative-list) model. No adequacy decisions, SCCs, or BCRs are required. Transfers are permitted to all jurisdictions unless and until the Government notifies a specific restriction.


5. A company processes health data of 50 million Indian users and uses AI-based profiling extensively. What additional obligation is MOST likely triggered?

Answer: C. *Volume and sensitivity of personal data and risk to the rights of Data Principals are among the Section 10(1) designation factors. Once designated, Rule 13(1) requires a Data Protection Impact Assessment and an audit once in every twelve months, with a report of significant observations furnished to the Board under Rule 13(2). Note the DPIA is periodic β€” it is not triggered by the act of deploying AI. The provision that speaks to the AI profiling itself is Rule 13(3): continuous due diligence that algorithmic software adopted by the SDF is not likely to pose a risk to Data Principals' rights.*


6. A 12-year-old downloads a gaming app and provides personal information with their parent's approval. Which BEST describes the position under Section 2(j)?

Answer: C. Section 2(j) defines the Data Principal as "the individual to whom the personal data relates" and provides that where that individual is a child, the term includes the parents or lawful guardian. The definition is inclusive, not substitutional β€” the child does not stop being the Data Principal. In practice the parent gives the verifiable consent required by Section 9(1) and exercises the rights. D describes a Data Fiduciary, not a Data Principal.


7. A Data Fiduciary's published grievance redressal policy states that grievances will be answered "within 120 days." What is the compliance issue?

Answer: B. Section 13(2) requires a response to grievances within such period as may be prescribed; Rule 14(3) prescribes a reasonable period not exceeding ninety days, requires it to be prominently published, and requires technical and organisational measures ensuring the system meets it. 120 days breaches the ceiling.

Note what this question is not about. The 90-day figure attaches to the grievance redressal system under Section 13(2) and Rule 14(3). It is not a general DPDP deadline for access, correction, or erasure requests under Sections 11–12 β€” a widely repeated overstatement. Note too that 90 days is a maximum, not a target: publishing 90 days and consuming it for a simple request sits poorly with the Section 8(10) duty to maintain an effective mechanism.


8. A Data Fiduciary engages a cloud storage vendor to process personal data on its behalf. A data breach occurs at the cloud vendor's infrastructure. Who is accountable to the Data Protection Board?

Answer: C. The Data Fiduciary remains accountable to the Board for how processors handle data. Accountability is non-delegable. The Fiduciary may have contractual recourse against the vendor, but its regulatory accountability does not transfer.


18. If You Remember Only These 25 Facts

For quick reference and final revision.

  1. The DPDP Act was enacted by Parliament in August 2023; the DPDP Rules were notified by MeitY on 13 November 2025.
  2. The constitutional root is Article 21 β€” right to privacy as a fundamental right, established by the Puttaswamy judgment (2017).
  3. The Act applies to digital personal data collected in India and to data of persons in India processed anywhere in the world β€” full extraterritorial reach.
  4. Purely offline data, personal/household use, and anonymized data are excluded from scope.
  5. Data Fiduciary = decides purpose and means of processing (β‰ˆ GDPR Controller).
  6. Data Principal = the individual whose data is processed (β‰ˆ GDPR Data Subject). Under Section 2(j) the term includes the parent/guardian for a child and the lawful guardian for a person with disability β€” inclusive, not substitutional.
  7. Data Processor = processes on behalf of a Data Fiduciary under its instructions.
  8. Consent Manager = registered Indian intermediary for centralized consent management. Uniquely Indian β€” no GDPR equivalent. Must retain consent records for 7 years.
  9. Consent must be free, specific, informed, unconditional and unambiguous, with a clear affirmative action (Section 6(1)). There is no legitimate interests lawful basis under DPDP.
  10. The seven privacy principles: consent/transparency, purpose limitation, data minimization, accuracy, storage limitation, security safeguards, accountability.
  11. Purpose limitation is the most commonly violated principle β€” data collected for one purpose cannot be repurposed without fresh specific consent.
  12. Personal data must be erased once purpose is served or consent is withdrawn (Section 8(7)) β€” but Rule 8(3) imposes a one-year minimum retention of data, traffic data and logs, and Rule 8(1) + Third Schedule set a three-year inactivity clock for large e-commerce, online gaming and social media Fiduciaries, with 48 hours' notice before erasure.
  13. Significant Data Fiduciaries (SDFs) face enhanced obligations under Section 10 + Rule 13: India-based DPO responsible to the board, independent data auditor, DPIA and audit once every twelve months (periodic β€” not triggered by AI deployment), algorithmic due diligence under Rule 13(3), and possible localization of Government-specified categories.
  14. Children = under 18 in India. Verifiable parental consent is required before any processing (Section 9(1) + Rule 10). No tracking, behavioural monitoring, or targeted advertising directed at children (Section 9(3)). Rule 11 is a different rule β€” persons with disability and court-appointed guardians.
  15. Cross-border transfers: blacklist model β€” Section 16(1) lets the Government restrict transfers to notified countries; Rule 15 separately conditions making data available to foreign States and their agencies. No SCCs or adequacy decisions required.
  16. On personal data breach: intimate each affected Data Principal without delay (Rule 7(1)) and the Board in two stages (Rule 7(2)) β€” initial description without delay, detailed report within 72 hours. Notification is never contingent on completing the investigation.
  17. Penalty for security safeguard failures: β‚Ή250 crore β€” the highest penalty head.
  18. Penalty for failure to notify breach: β‚Ή200 crore β€” applies per incident, in addition to other heads.
  19. Penalty for children's data non-compliance: β‚Ή200 crore.
  20. Penalty for SDF obligation failures: β‚Ή150 crore. Residual head β€” breach of any other provision of the Act or the Rules: β‚Ή50 crore (Schedule entry 7). This is how Rule breaches attract penalties; there is no separate schedule in the Rules.
  21. Penalties stack per violation β€” a single incident can trigger multiple penalty heads simultaneously, creating cumulative exposure well above individual maximums.
  22. Rule 1 phasing: Rules 1, 2 and 17–21 on 13 Nov 2025; Rule 4 only on 13 Nov 2026; Rules 3, 5–16, 22 and 23 on 13 May 2027. Rule 1 commences Rules β€” the Act's provisions commence under a Section 1(2) notification, so do not read a penalty start date off the Rules.
  23. The 90-day figure is grievance-specific β€” Section 13(2) + Rule 14(3) cap the published grievance response period. It is not a universal deadline for access, correction, or erasure requests.
  24. The Data Protection Board of India is fully digital, has civil-court powers, and can impose penalties. Appeals go to TDSAT.
  25. Accountability is non-delegable β€” a Data Fiduciary cannot transfer its accountability to a processor, a vendor, or a Consent Manager by contract.

19. Glossary

Blacklist model (cross-border transfers): A transfer framework where data may flow to any jurisdiction by default, unless the Government restricts transfers to a notified country or territory under Section 16(1). Distinct from Rule 15, which conditions making personal data available to a foreign State, or a person, entity or agency under its control, on requirements the Government may specify by general or special order.

Consent Manager: A registered Indian intermediary that operates an interoperable platform enabling Data Principals to give, manage, review, and withdraw consent across multiple Data Fiduciaries. Must be incorporated in India and retain consent records for at least 7 years.

Data Fiduciary: Any entity (individual, company, government body) that determines the purpose and means of processing personal data. The primary obligated party under the DPDP Act. Analogous to a "Controller" under GDPR.

Data Principal: The natural person to whom personal data relates. Under Section 2(j) the term includes the parents or lawful guardian where that individual is a child, and the lawful guardian acting on her behalf where she is a person with disability. The definition is inclusive β€” the child or person with disability remains the Data Principal.

Data Processor: An entity that processes personal data on behalf of a Data Fiduciary under its instructions. Does not determine the purpose of processing. The Data Fiduciary remains accountable for the Processor's actions.

Data Protection Board of India (DPBI): The regulatory and enforcement body under the DPDP Act, operational from 13 November 2025. Fully digital, with civil-court powers for complaint adjudication and penalty imposition.

Data Protection Impact Assessment (DPIA): Defined in Section 10(2)(c)(i) as a process comprising a description of the rights of Data Principals and the purpose of processing, assessment and management of risk to those rights, and other prescribed matters. Under Rule 13(1) a Significant Data Fiduciary must undertake a DPIA and an audit once in every twelve months. It is a periodic obligation, not one triggered by deploying a particular technology.

Data Protection Officer (DPO): An individual appointed by a Significant Data Fiduciary under Section 10(2)(a) who represents it under the Act, is based in India, is responsible to the Board of Directors or similar governing body, and is the point of contact for grievance redressal. A DPO is mandatory only for SDFs; other Data Fiduciaries must publish contact information for a DPO if applicable, or a person able to answer Data Principals' questions (Section 8(9), Rule 9). "Grievance Officer" is not a term used in the Act or the Rules.

DPDP Act 2023: Digital Personal Data Protection Act, 2023 β€” India's primary data-protection statute enacted by Parliament in August 2023.

DPDP Rules 2025: Digital Personal Data Protection Rules, 2025 β€” subordinate legislation notified by MeitY on 13 November 2025, operationalizing the DPDP Act in a three-phase rollout.

Full compliance deadline: 13 May 2027 β€” the date by which all DPDP Rules obligations must be met. No grace period is expected.

MeitY: Ministry of Electronics and Information Technology β€” the ministry responsible for administering the DPDP framework and notifying implementing orders.

Personal data breach: Any unauthorized access, disclosure, alteration, destruction, or loss of personal data held by a Data Fiduciary.

Purpose limitation: The principle that personal data collected for a stated purpose may only be used for that purpose and not repurposed without fresh, specific consent.

Significant Data Fiduciary (SDF): A Data Fiduciary notified by the Central Government under Section 10(1) on the basis of volume and sensitivity of data, risk to Data Principals' rights, impact on the sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order. Subject to enhanced obligations under Section 10(2) and Rule 13.

Storage limitation: The principle that personal data must be erased once the purpose for which it was collected is fulfilled or consent is withdrawn (Section 8(7)). Subject to the Rule 8(3) one-year minimum retention of personal data, traffic data and logs, and to retention required by any other law.

Third Schedule (to the Rules): Prescribes, under Rule 8(1), the classes of Data Fiduciaries, purposes, and corresponding time periods after which personal data must be erased on Data Principal inactivity β€” currently three years for e-commerce entities with β‰₯2 crore registered users in India, online gaming intermediaries with β‰₯50 lakh, and social media intermediaries with β‰₯2 crore.

TDSAT: Telecom Disputes Settlement and Appellate Tribunal β€” the appellate body that hears appeals against Data Protection Board decisions.

Verifiable parental consent: Defined in Rule 2(1)(d) as consent as specified in Rule 10 or Rule 11. Under Rule 10 (children), the Data Fiduciary must adopt technical and organisational measures ensuring parental consent is obtained before processing, and observe due diligence that the individual identifying herself as the parent is an identifiable adult. Under Rule 11 (persons with disability), the due diligence is that the lawful guardian was appointed by a court, designated authority, or local level committee under the law applicable to guardianship. The two tests are different and are not interchangeable.


⚠ Disclaimer This guide is an educational training resource. It is not legal advice. Specific compliance positions β€” particularly regarding SDF designation, cross-border transfer restrictions, applicable penalty exposure, and SDF local-storage requirements β€” should be determined with qualified legal counsel referencing current official gazette notifications.

Regulatory details are current as of August 2026. Verify against MeitY official notifications before relying on any specific figure, date, or obligation for professional compliance decisions.


🧠 Now explore it as a map

You have read the framework end to end. The DPDP Brain is the same material as a connected graph: 128 cited concepts from the Act and the Rules, 325 connections. Trace any obligation to the Rule that operationalises it and the penalty head that backs it, or filter to just Penalties, Children or Consent Manager.

Open the DPDP Brain β†’

β€” End of DPDP Training Material β€”

www.aigpplaybook.com | By Daman David Pant, AIGP

Expanding from AI Governance to Data Compliance β€” because the principles connect.