Reference

The Act and the Rules, section by section.

The plain-language guide is for understanding. This page is for working: a compact summary of what each part of the DPDP Act 2023 requires, followed by the DPDP Rules 2025 provisions that turn those requirements into things you must configure, log and be able to show. Read it beside your own systems, not on its own.

This is educational material written by practitioners who run security and compliance programmes, not by lawyers. It will make you a better-informed client of legal advice — it does not replace it.

The Act, 2023

What each section requires.

§ 3

Application

Digital personal data processed in India, and processing outside India where goods or services are offered to people in India. Paper-only records are out — until someone scans or types them.

§ 4

Grounds for processing

Personal data may be processed only for a lawful purpose, and only with consent or under a listed legitimate use. There is no third option.

§ 5

Notice

Itemised description of data, purpose, how to exercise rights, how to withdraw, and how to complain to the Board. Also applies retrospectively to consent obtained before the Act.

§ 6

Consent

Free, specific, informed, unconditional, unambiguous, by clear affirmative action, limited to data necessary for the stated purpose. Withdrawal must be as easy as grant.

§ 7

Legitimate uses

The closed list: voluntary provision for an evident purpose, state functions and benefits, legal obligations, court orders, medical emergency, disaster, epidemic, and employment purposes.

§ 8

Duties of a Data Fiduciary

Accuracy, security safeguards, breach notification, erasure on withdrawal or purpose completion, a published grievance contact, and accountability for processors engaged under contract.

§ 9

Children and persons with disability

Verifiable parental or guardian consent, no tracking, no behavioural monitoring, no targeted advertising directed at children.

§ 10

Significant Data Fiduciaries

Where notified: an India-resident Data Protection Officer reporting to the board, an independent data auditor, periodic impact assessments and algorithmic due diligence.

§ 11–14

Rights of Data Principals

Information, correction and erasure, grievance redressal, and nomination — with the fiduciary's grievance channel to be used before approaching the Board.

§ 15

Duties of Data Principals

Do not impersonate, do not suppress material information, do not file false or frivolous complaints. Breach attracts a penalty of up to ₹10,000.

§ 16

Cross-border transfer

Transfers are permitted except to countries the Central Government restricts by notification, and sectoral rules requiring localisation continue to apply.

§ 17

Exemptions

Enforcement of legal rights, judicial and regulatory functions, approved research, notified state instrumentalities, and a lighter regime for certain startups by notification.

§ 18–26

The Board and enforcement

Composition, digital-by-design proceedings, powers of inquiry, voluntary undertakings, monetary penalties, and appeal to the Telecom Disputes Settlement and Appellate Tribunal.

The Rules, 2025

Where the law stops being abstract.

The Act sets principles; the Rules set formats, timelines and retention periods. Commencement is staggered, so plan against the dates that apply to each provision rather than one imagined go-live.

Rule 3

Notice served by the fiduciary

The notice must be understandable on its own, in clear plain language, itemising the data and the purpose, and giving a working link or route to withdraw consent and to raise a grievance.

Rule 4

Consent Managers

Registration conditions with the Board, minimum net worth, interoperable platform obligations, and a duty to keep consent records available to the individual.

Rule 6

Reasonable security safeguards

Encryption or equivalent protection, access control, logs retained for one year, backups for continuity, contractual security obligations on processors, and the capability to investigate an incident.

Rule 7

Breach intimation

Describe the nature, extent, timing and likely consequences to affected individuals without delay, and file the detailed report to the Board within 72 hours of awareness.

Rule 8

Erasure and retention

Defined retention periods, deletion when the purpose lapses, and advance notice to the individual before erasing on grounds of prolonged inactivity.

Rule 10

Verifiable parental consent

Reliable identity and age verification of the adult granting consent, including through a virtual token issued against a government-issued identifier.

Rule 12

Additional SDF obligations

Annual data protection impact assessment and audit, algorithmic verification for risks to individual rights, and localisation of specified traffic and personal data as notified.

From clause to control

Four things auditors find missing every time.

We have walked into enough readiness reviews to know where the gaps sit. They are rarely exotic.

Evidence, not intent

For every obligation, decide now which artefact proves it: a versioned notice, a consent record, an access log, a retention job report, a signed processor contract. If no artefact exists, the obligation is unmet in practice.

Two clocks on one incident

CERT-In wants qualifying incidents in six hours; the Data Protection Board wants the report in seventy-two. Build one escalation path that satisfies the shorter clock and the longer one follows.

Detection is a legal control

Reasonable safeguards include the ability to know an incident happened and reconstruct it. That is monitoring and log retention, sitting squarely inside the clause with the highest penalty ceiling.

Processors inherit your duties

Whatever the Act asks of you, your contract must ask of your vendor — scope, security, sub-processing, breach notice to you, deletion at exit, and a right to inspect.