Skip to content

03 DPDP Act (India)

India’s Digital Personal Data Protection Act, 2023 (DPDP Act) establishes the country’s primary legal framework for processing digital personal data.

The Act received Presidential assent on 11 August 2023. The Government subsequently notified the Digital Personal Data Protection Rules, 2025 in November 2025 and established the Data Protection Board of India (DPBI). Implementation is phased: some provisions are already in force, while major operational provisions have one-year or eighteen-month commencement periods from the November 2025 notifications. (MeitY)

Important: DPDP compliance should therefore be treated as an active implementation and readiness program, not simply a future privacy requirement.

A practical DPDP governance model looks like:

Applicability
Digital Personal Data
Data Principal
Data Fiduciary
Purpose & Lawful Processing
Notice & Consent / Certain Legitimate Uses
Data Principal Rights
Security Safeguards
Processor Governance
Breach Management
Retention & Erasure
Accountability

By the end of this lesson, you will be able to:

  • Explain the purpose of the DPDP Act.

  • Understand its applicability.

  • Define digital personal data.

  • Understand Data Principals.

  • Understand Data Fiduciaries.

  • Understand Data Processors.

  • Explain consent requirements.

  • Understand notice requirements.

  • Explain certain legitimate uses.

  • Understand Data Principal rights.

  • Understand Data Principal duties.

  • Understand children’s data requirements.

  • Explain Significant Data Fiduciaries.

  • Understand security safeguards.

  • Understand personal data breach obligations.

  • Understand retention and erasure.

  • Understand cross-border processing.

  • Explain processor governance.

  • Understand Consent Managers.

  • Understand the Data Protection Board of India.

  • Understand penalties and enforcement.

  • Build an enterprise DPDP compliance program.

The formal name is:

Digital Personal Data Protection Act, 2023

The Act provides a framework for processing:

Digital Personal Data

while recognizing both:

Right of Individuals
to Protect Personal Data

and:

Need to Process Personal Data
for Lawful Purposes

Enterprise compliance should now consider:

DPDP Act, 2023
+
DPDP Rules, 2025
+
Applicable Government Notifications
Operational DPDP Program

The final DPDP Rules were notified in November 2025. (MeitY)

Not all provisions commenced simultaneously.

The November 2025 commencement notification introduced a phased model:

Immediate Provisions
One-Year Provisions
Eighteen-Month Provisions

Many of the Act’s core processing obligations commence eighteen months after publication of the notification, while specific provisions have earlier commencement dates. (MeitY)

For a GRC team, this means:

Do Not Wait
Perform Gap Assessment
Build Controls
Collect Evidence
Validate Readiness

The Act applies to processing of digital personal data within India where the personal data is:

Collected in Digital Form

or:

Collected Non-Digitally
and Subsequently Digitised

The Act can also apply to processing outside India when connected with offering goods or services to Data Principals within India.

Example:

Company Outside India
Offers Digital Service
to Customers in India
Processes Their
Personal Data

DPDP applicability should therefore be assessed.

Create:

01 DPDP Applicability Assessment

Use:

Question Response Evidence
Digital personal data processed?
Individuals in India involved?
Processing performed in India?
Goods/services offered to people in India?
Exemption applicable?
DPDP applicable?

Under the Act, personal data means data about an individual who is identifiable:

By Such Data

or:

In Relation to Such Data

Examples may include:

Name
Email
Phone Number
Customer ID
Employee ID
Account Details
Device Information

where an individual is identifiable.

The DPDP framework focuses on:

Digital Personal Data

Example:

Customer Name
Entered Into CRM
Digital Personal Data

Example:

Paper Application
Scanned
Stored in HR System

The resulting digital processing can fall within the framework.

The individual to whom personal data relates is called:

Data Principal

This is broadly comparable to GDPR’s:

Data Subject
Customer
Employee
Applicant
Student
Patient
Website User
Mobile App User
DPDP GDPR
Data Principal Data Subject
Data Fiduciary Controller
Data Processor Processor

These concepts are similar but should not be assumed to be legally identical.

A:

Data Fiduciary

determines:

Purpose
+
Means

of processing personal data.

CloudShop decides:

Collect Customer Address
To Deliver Product

CloudShop determines:

Why
+
How

the information is processed.

CloudShop therefore acts as:

Data Fiduciary

for that activity.

A:

Data Processor

processes personal data on behalf of a Data Fiduciary.

Example:

CloudShop
Cloud CRM Provider

The provider may process customer data on CloudShop’s behalf.

Data Principal
Data Fiduciary
Data Processor
Supporting Service Providers

Processor governance therefore becomes an important enterprise control.

Processing covers automated operations performed on digital personal data.

Examples include:

Collection
Recording
Organisation
Storage
Use
Sharing
Retrieval
Modification
Erasure

Personal data should be processed:

For a Lawful Purpose

based on:

Consent

or:

Certain Legitimate Uses

as provided under the Act.

This distinction is important.

GDPR provides six Article 6 lawful bases.

DPDP structures processing primarily around:

Consent
OR
Certain Legitimate Uses

Do not simply copy a GDPR lawful-basis register and assume it satisfies DPDP.

Consent under DPDP should be:

Free
Specific
Informed
Unconditional
Unambiguous

and involve:

Clear Affirmative Action

Consent should be limited to personal data necessary for the specified purpose.

Example:

Purpose:

Deliver Online Purchase

Necessary:

Name
Delivery Address
Contact Details

Potentially unnecessary:

Passport Number

Example:

Purchase a Book
Mandatory Consent
to Access Phone Contacts

If contact access is unnecessary for the purchase:

Consent Design
Requires Review

Before or alongside seeking consent as required, the Data Fiduciary should provide an appropriate notice.

The final Rules require notice to be clear and understandable and to explain the personal data and purpose involved, together with relevant mechanisms for withdrawal, rights, and complaints. (MeitY)

What Data?
Why?
What Service / Use?
How to Withdraw?
How to Exercise Rights?
How to Complain?

Avoid burying important privacy information inside:

40 Pages of
Terms & Conditions

The operational objective is:

Clear
Accessible
Understandable

Create:

02 DPDP Notice Register

Use:

Notice Data Purpose Channel Owner Last Review

Organizations should maintain evidence demonstrating consent where processing depends on it.

Create:

03 DPDP Consent Register

Use:

Principal Purpose Data Consent Date Source Status

A Data Principal can withdraw consent.

Operationally:

Consent Given
Processing
Consent Withdrawn
Stop Relevant Processing
Erase Where Required

subject to lawful retention or other applicable provisions.

The Rules reinforce that withdrawal should be made accessible through appropriate mechanisms. (MeitY)

Weak:

Consent:
One Click
Withdrawal:
Email Legal Department
+
Paper Form
+
30-Day Manual Process

Stronger:

Account
Privacy Settings
Withdraw Consent

The DPDP framework introduces:

Consent Manager

A registered Consent Manager provides a mechanism through which Data Principals can give, manage, review, and withdraw consent.

The final Rules establish registration and operational requirements for Consent Managers, including organizational and technical requirements. (MeitY)

A Consent Manager is therefore not simply:

Any SaaS Consent Tool

The Act identifies circumstances in which processing may occur for:

Certain Legitimate Uses

without relying on ordinary consent.

Depending on statutory conditions, these can include areas such as:

Voluntarily Provided Data
State Functions
Legal Obligations
Medical Emergencies
Disasters
Employment-Related Purposes

34. Legitimate Use Is Not a Blanket Exception

Section titled “34. Legitimate Use Is Not a Blanket Exception”

Weak:

Business Needs Data
Legitimate Use

Wrong mindset.

Instead:

Processing Scenario
Specific Statutory Provision
Conditions Met?
Document Decision

Create:

04 DPDP Processing Basis Register

Use:

Activity Purpose Consent / Legitimate Use Rationale Owner

A Data Fiduciary remains responsible for compliance regarding processing undertaken by it or on its behalf.

Enterprise obligations include areas such as:

Lawful Processing
Accuracy Where Required
Security Safeguards
Breach Notification
Erasure
Rights Handling
Grievance Management

37. Responsibility Cannot Simply Be Outsourced

Section titled “37. Responsibility Cannot Simply Be Outsourced”

Weak:

Vendor Processes It
Vendor Is Responsible

Stronger:

Data Fiduciary
Processor Contract
Security Requirements
Monitoring
Evidence

Where personal data is used to make decisions affecting a Data Principal or disclosed to another Data Fiduciary, applicable accuracy obligations become important.

Controls may include:

Validation
Correction
Source Verification
Periodic Review

Data Fiduciaries must implement reasonable security safeguards to prevent personal data breaches.

A practical control model:

Identity & Access Management
Encryption
Logging
Monitoring
Backups
Vulnerability Management
Incident Response
Secure Configuration

The Rules further operationalize security requirements around safeguards and breach handling. (MeitY)

This means GRC teams should map:

Legal Requirement
Security Control
Technical Implementation
Evidence

Create:

05 DPDP Security Control Matrix

Use:

Risk Control System Owner Evidence

Risk:

Unauthorized CRM Access

Control:

MFA
+
Role-Based Access

Evidence:

IAM Configuration
Access Review
Authentication Logs

A personal data breach can involve unauthorized processing or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access that compromises confidentiality, integrity, or availability.

Customer Database Exposed
Laptop Lost
Wrong Recipient Email
Cloud Bucket Public
Ransomware
Credential Compromise
Unauthorized Employee Access
Incident Detected
Contain
Personal Data Involved?
Determine Scope
Notify Internal Stakeholders
DPDP Notification Assessment
Board / Data Principal Actions
Remediation
Evidence

The DPDP framework requires notification of personal data breaches to:

Data Protection Board

and affected:

Data Principals

in the manner prescribed.

This is an important exam and operational distinction.

GDPR commonly uses:

72 Hours

for qualifying supervisory-authority notification.

Do not automatically apply that timeline to DPDP.

Use:

DPDP Act
+
Applicable DPDP Rules
+
Current Notification Requirements

Create:

06 DPDP Personal Data Breach Register

Use:

Incident Data Principals Impact Notification Status

Maintain:

Detection Time
Containment
Affected Systems
Affected Data
Affected Individuals
Root Cause
Notifications
Corrective Actions

Personal data should not simply remain forever.

A practical lifecycle:

Purpose
Processing
Purpose Completed
Retention Requirement?
Erase When Required

Create:

07 DPDP Retention & Erasure Register

Use:

Data Purpose Trigger Retention Erasure Method Owner

Examples:

Account Closure
Consent Withdrawal
Contract End
Employment Termination
Purpose Completion

Erasure does not mean:

Delete Everything Immediately

There may be legal requirements requiring retention.

Example:

Financial Record
Purpose Completed
Statutory Retention Required

The Act establishes rights for Data Principals.

These include areas such as:

Access to Information
Correction
Completion
Updating
Erasure
Grievance Redressal
Nomination

A Data Principal can seek prescribed information concerning personal data processing.

An enterprise needs:

Request Intake
Identity Validation
Data Discovery
Response
Evidence

Data Principals can request correction of inaccurate or misleading personal data, subject to applicable requirements.

Incomplete personal data may require:

Completion

Outdated personal data may require:

Updating

Data Principals may request erasure subject to statutory conditions and retention requirements.

A Data Principal should have an accessible mechanism for raising grievances.

Create:

08 DPDP Grievance Register

Use:

Grievance Principal Received Owner Status Closure

The Act introduces a notable right enabling a Data Principal to nominate another individual to exercise rights in specified circumstances such as death or incapacity.

Data Principal
Nominee Recorded
Qualifying Event
Identity / Authority Validation
Rights Exercise

Create:

09 DPDP Data Principal Rights Register

Use:

Request Right Received Owner Status Evidence

DPDP also establishes duties for Data Principals.

This distinguishes the framework from privacy discussions focused only on rights.

Data Principals should not:

Impersonate Another Person
Suppress Material Information
in Specified Circumstances
Submit False or Frivolous Complaints

and should provide authentic information when exercising certain rights.

Under the Act, a:

Child

generally means an individual who has not completed:

18 Years

Before processing children’s personal data, Data Fiduciaries may need:

Verifiable Consent

of the:

Parent
or
Lawful Guardian

subject to the Act, Rules, and applicable exemptions.

Examples:

Education Platforms
Gaming
Social Platforms
Health Apps
Learning Applications

may require special governance.

The framework places restrictions around certain processing involving children, including specified forms of tracking, behavioural monitoring, and targeted advertising, subject to applicable provisions and exemptions.

Create:

10 Children's Data Processing Register

Track:

Processing Child Data Consent Tracking Risk Owner

An organization may need a reliable method for determining whether:

User
Is a Child

when child-specific requirements apply.

This creates both:

Privacy Risk
+
Technical Design Challenge

The Central Government may designate certain Data Fiduciaries as:

Significant Data Fiduciaries

based on relevant statutory factors.

Factors can include:

Volume of Personal Data
Sensitivity
Risk to Data Principal Rights
Impact on Sovereignty and Integrity
Electoral Democracy
Security of the State
Public Order

Significant Data Fiduciaries have additional compliance requirements.

These include areas such as:

Data Protection Officer
Independent Data Auditor
Data Protection Impact Assessment
Periodic Audit

and other prescribed measures.

An SDF must appoint a:

Data Protection Officer

meeting applicable statutory requirements.

An SDF must appoint:

Independent Data Auditor

to evaluate compliance.

Significant Data Fiduciaries must conduct:

Data Protection Impact Assessments

as required.

SDF governance includes:

Periodic Audit

to demonstrate compliance.

Create:

11 Significant Data Fiduciary Readiness Checklist

Include:

  • SDF designation monitored.

  • DPO readiness established.

  • independent auditor identified.

  • DPIA methodology established.

  • periodic audit process established.

  • risk assessments maintained.

  • compliance evidence centralized.

Organizations may use:

Cloud Providers
SaaS Providers
Payroll Providers
CRM Platforms
Marketing Platforms
Analytics Providers

to process personal data.

Create:

12 DPDP Processor Register

Use:

Processor Service Data Purpose Location Owner

Evaluate:

Security Controls
Breach Process
Retention
Deletion
Subcontractors
Data Location
Access
Audit Evidence

Contracts should operationally address areas such as:

Processing Purpose
Security
Breach Notification
Deletion
Confidentiality
Audit
Subcontracting

as appropriate.

Outsource Processing
Outsource Accountability

DPDP does not use the same international-transfer architecture as GDPR.

This distinction is critical.

GDPR commonly uses mechanisms such as:

Adequacy
SCCs
BCRs

DPDP instead allows the Central Government to restrict transfers to specified countries or territories through notification.

86. Do Not Copy GDPR Transfer Controls Blindly

Section titled “86. Do Not Copy GDPR Transfer Controls Blindly”

A multinational should maintain:

GDPR Transfer Controls

and:

DPDP Cross-Border Controls

according to each framework’s requirements.

Create:

13 DPDP Cross-Border Processing Register

Use:

Data Source Destination Processor Restriction Check Owner
Indian Customer
Application in India
Cloud Database in Singapore
Support Team in USA

Assess:

DPDP Applicability
Processor Governance
Government Restrictions
Security
Other Applicable Laws

Do not assume:

DPDP
=
All Personal Data
Must Stay in India

That is an oversimplification.

Other sectoral laws or regulatory requirements may separately impose localization or storage obligations.

The Act establishes:

Data Protection Board of India

or:

DPBI

The Government formally established the Board in November 2025. In 2026, MeitY also initiated recruitment for the Chairperson and Members. (MeitY)

The Board has functions relating to areas such as:

Personal Data Breaches
Non-Compliance
Directions
Inquiries
Penalties

under the Act.

The DPBI is designed as a technology-enabled adjudicatory institution.

MeitY describes it as:

Digital-by-Design

for efficient and transparent administration. (MeitY)

Organizations should establish:

Regulatory Request
Legal / Privacy Review
Evidence Collection
Approved Response
Submission
Tracking

Create:

14 DPDP Compliance Evidence Repository

Organize:

01 Applicability
02 Notices
03 Consent
04 Processing
05 Security
06 Breaches
07 Retention
08 Rights
09 Grievances
10 Children's Data
11 SDF
12 Processors
13 Cross-Border
14 Training
15 Audits

The DPDP Act provides for significant monetary penalties depending on the nature of non-compliance.

Failure to take reasonable security safeguards to prevent personal data breaches can potentially result in penalties reaching:

₹250 Crore

under the statutory penalty schedule.

Failure to meet applicable breach-notification obligations can potentially result in substantial monetary penalties.

Failure relating to applicable obligations concerning children can also attract significant penalties.

Organizations should also consider:

Regulatory Scrutiny
Incident Cost
Operational Disruption
Customer Trust
Contractual Impact
Reputation

A mature program should connect:

Legal
Privacy
GRC
Security
Engineering
Business
Third Parties

Start with:

What Personal Data
Do We Have?

Create:

15 DPDP Personal Data Inventory

Use:

Process Data Principal Personal Data System Processor

Then determine:

Where Does It Come From?
Where Does It Go?
Who Accesses It?
Which Vendor Receives It?
Where Is It Stored?
When Is It Deleted?
Customer
Website
CRM
Payment Provider
Cloud Database
Analytics

Create:

16 DPDP Data Flow Register

Use:

Source System Destination Data Purpose Owner

For every data element ask:

Why Do We Need It?

Example:

Data Purpose
Name Customer identification
Address Delivery
Email Order communication
Phone Delivery coordination

Although terminology and legal structures differ across privacy regimes, minimization remains a useful operational privacy practice.

Weak:

Collect Everything
Because It May Be Useful

Stronger:

Defined Purpose
Required Data
Collect Only What Is Needed

Embed DPDP requirements into:

Project Intake
Architecture
Development
Procurement
Testing
Deployment
Operations

Example:

New Project
Personal Data?
├── No → Continue
└── Yes
DPDP Assessment
Notice / Consent
Security
Retention
Processor Review

Create:

17 DPDP Privacy-by-Design Checklist

Include:

  • Personal data identified.

  • purpose documented.

  • processing basis identified.

  • notice reviewed.

  • consent mechanism reviewed.

  • children assessed.

  • processors identified.

  • security assessed.

  • retention defined.

  • rights supported.

  • breach workflow integrated.

A GRC analyst may test:

Notices
Consent
Withdrawal
Rights
Grievances
Security
Breach Management
Retention
Processor Governance
Children's Data

Population:

20 Digital Services

Sample:

10

Verify:

Purpose
Notice
Consent
Evidence
Withdrawal

Actual data:

Name
Email
Location
Device ID

Notice says:

We Collect
Name and Email

Potential:

Notice Gap

Consent:

One Click

Withdrawal:

Manual Email
Identity Documents
30-Day Wait

Potential:

Consent Withdrawal
Control Gap

Policy:

Inactive User Data:
24 Months

Actual:

Accounts Inactive:
6 Years

Potential:

Retention Gap

Policy:

MFA Required
for Privileged Access

Actual:

3 Database Admins
Without MFA

Potential:

Security Safeguard Gap

Population:

30 SaaS Vendors
Processing Personal Data

Result:

24 Reviewed
6 No Privacy / Security Review

Potential:

Processor Governance Gap

Sample:

20 Data Principal Requests

Verify:

Identity
Request Type
Response
Closure
Evidence

Application allows:

Users Aged 15+

but:

No Age Verification
No Parent Consent Workflow

Potential:

Children's Data
Compliance Gap

Incident:

Customer Database
Accidentally Exposed

Verify:

Detection
Escalation
Containment
Board Assessment
Data Principal Notification
Evidence

Create:

18 DPDP Compliance Gap Register

Use:

Gap Requirement Risk Severity Owner Due Date
Finding:
No Central Consent Records

Risk:

Organization Cannot
Demonstrate Valid Consent

Why?

Each Application
Manages Consent Separately

Why?

No Enterprise
Consent Standard

Root cause:

Consent governance was implemented independently by product teams without centralized privacy requirements.

Validate Existing
Consent Records
Enterprise Consent Standard
Central Evidence Model
Application Integration
Periodic Testing

Track:

Metric Target
Processing Activities Inventoried 100%
Applicable Activities With Notice 100%
Consent-Dependent Processing With Evidence 100%
Rights Requests Within Internal SLA 100%
Critical Processors Reviewed 100%
High-Risk Security Findings Past Due 0
Unresolved Privacy Breaches 0
Retention Exceptions Past Due 0
Percentage of consent-dependent
processing activities with
verifiable consent evidence
Percentage of Data Principal
requests completed within
applicable timelines
Critical systems processing
personal data without required
security safeguards
Critical processors handling
personal data without
completed assurance review
Personal data stores
retained beyond
approved requirement
Personal data breaches
not escalated through
the required workflow

Use fictional:

CloudShop India

Processes:

Indian Customers
EU Customers
Employee Data
Website Visitors

Determine:

Which Processing
Falls Under DPDP?

134. Practical Activity — Data Inventory

Section titled “134. Practical Activity — Data Inventory”

Document:

Customer Orders
Marketing
Recruitment
Payroll
Customer Support
Website Analytics

Identify:

Data Principal
Personal Data
Purpose
System
Processor

Marketing wants:

Customer Email
Phone
Location
Purchase History

for:

Personalized Promotions

Assess:

Purpose
Necessary Data
Notice
Consent
Withdrawal

Existing notice says:

We Use Your Data
to Improve Services

Evaluate whether the notice provides sufficient operational clarity about:

Personal Data
Purpose
Services / Uses
Rights
Withdrawal
Complaint Mechanism

137. Practical Activity — Children’s Data

Section titled “137. Practical Activity — Children’s Data”

Learning platform serves:

Students Aged 14–20

It collects:

Name
Email
Learning Behaviour
Device Data

and uses:

Behavioural Analytics

Identify required privacy review areas.

New SaaS vendor receives:

Employee Name
Email
Salary
Performance Data

Assess:

Purpose
Security
Location
Retention
Breach Process
Contract
Deletion

Scenario:

Cloud Database
Misconfigured
50,000 Customer Records
Potentially Exposed

Build:

Containment
Investigation
Data Mapping
Notification Assessment
Communication
Corrective Action

140. Practical Activity — Rights Request

Section titled “140. Practical Activity — Rights Request”

Customer says:

Tell Me What Data
You Process About Me
and Correct My Address

Build the workflow:

Request
Identity Validation
Locate Data
Access Information
Correction
Response
Evidence

Customer closes account.

Data exists in:

CRM
Support Platform
Analytics
Data Lake
Backups
Payment Records

Determine:

What Can Be Erased?
What Must Be Retained?
Which Processors Must Act?
How Is Completion Proven?
  • Digital personal data identified.

  • India applicability assessed.

  • extraterritorial applicability considered.

  • exemptions assessed.

  • Data Principals identified.

  • personal data inventoried.

  • systems documented.

  • processors identified.

  • data flows mapped.

  • processing purpose documented.

  • consent or legitimate-use basis identified.

  • unnecessary processing challenged.

  • notices mapped to processing.

  • purposes clearly explained.

  • rights mechanism provided.

  • grievance mechanism provided.

  • withdrawal mechanism provided where applicable.

  • consent is specific.

  • consent is informed.

  • affirmative action captured.

  • evidence retained.

  • withdrawal supported.

  • access workflow established.

  • correction supported.

  • updating supported.

  • completion supported.

  • erasure supported.

  • nomination supported.

  • requests tracked.

  • grievance channel exists.

  • owner assigned.

  • complaints tracked.

  • closure evidence retained.

  • child processing identified.

  • age-related requirements assessed.

  • parent / guardian consent supported where required.

  • tracking restrictions assessed.

  • targeted advertising restrictions assessed.

  • reasonable safeguards defined.

  • IAM implemented.

  • encryption assessed.

  • logging enabled.

  • monitoring established.

  • vulnerabilities managed.

  • breach workflow established.

  • Board notification process established.

  • Data Principal notification process established.

  • incidents documented.

  • remediation tracked.

  • purpose-completion triggers defined.

  • retention requirements mapped.

  • erasure implemented.

  • processor deletion supported.

  • exceptions tracked.

  • processor inventory maintained.

  • due diligence completed.

  • security requirements documented.

  • breach obligations defined.

  • deletion requirements defined.

  • processing locations known.

  • government restrictions monitored.

  • sectoral requirements assessed.

  • international vendors tracked.

  • designation monitored.

  • DPO readiness established.

  • auditor readiness established.

  • DPIA methodology available.

  • audit process available.

  • owners assigned.

  • policies updated.

  • employees trained.

  • evidence retained.

  • controls tested.

  • gaps remediated.

Mistake 1 — Treating DPDP as Indian GDPR

Section titled “Mistake 1 — Treating DPDP as Indian GDPR”

The frameworks share privacy concepts but use different terminology, legal structures, rights, processing bases, and transfer models.

Mistake 2 — Assuming DPDP Is Still Only a Future Law

Section titled “Mistake 2 — Assuming DPDP Is Still Only a Future Law”

The Act, final Rules, Board establishment, and phased commencement framework are now in place. (MeitY)

Mistake 3 — Copying GDPR’s Six Lawful Bases

Section titled “Mistake 3 — Copying GDPR’s Six Lawful Bases”

DPDP uses a different processing structure.

Consent and notice requirements need appropriate implementation.

The organization cannot demonstrate what the individual agreed to.

Giving consent is easy while withdrawal is intentionally difficult.

Age, parental consent, tracking, and related requirements are not assessed.

Mistake 8 — Vendor Means Vendor Is Responsible

Section titled “Mistake 8 — Vendor Means Vendor Is Responsible”

The Data Fiduciary retains important compliance responsibilities.

Mistake 9 — Applying GDPR’s 72-Hour Rule Automatically

Section titled “Mistake 9 — Applying GDPR’s 72-Hour Rule Automatically”

DPDP breach requirements must be evaluated under DPDP itself.

Mistake 10 — Assuming All Data Must Stay in India

Section titled “Mistake 10 — Assuming All Data Must Stay in India”

DPDP does not impose a blanket localization rule for all personal data.

Privacy Policy
Consent Checkbox
Wait for Complaint
Applicability
Data Discovery
Processing Inventory
Purpose
Notice
Consent / Legitimate Use
Rights
Security
Processor Governance
Retention
Breach Management
Continuous Assurance

A GRC professional supporting DPDP may:

  • Perform DPDP applicability assessments.

  • maintain personal-data inventories.

  • maintain data-flow maps.

  • map processing purposes.

  • maintain notice inventories.

  • test consent mechanisms.

  • maintain consent evidence.

  • coordinate Data Principal requests.

  • maintain grievance registers.

  • assess children’s data processing.

  • support SDF readiness.

  • review processor governance.

  • maintain cross-border processing inventories.

  • map security safeguards.

  • support breach assessments.

  • maintain retention requirements.

  • test erasure controls.

  • maintain compliance evidence.

  • track remediation.

  • prepare DPDP dashboards.

  • support audits and regulatory responses.

GRC connects:

Privacy
Legal
Security
IAM
Cloud
Engineering
HR
Marketing
Product
Procurement
Third Parties
Internal Audit
Privacy Policy
Basic Consent
Incident Handling
Data Inventory
Notices
Consent Records
Rights Procedures
Retention
Processor Governance
Security Mapping
Control Testing
Grievance Management
Metrics
Privacy by Design
Automated Consent
Automated Rights
Retention Automation
Breach Orchestration
Continuous Data Discovery
Dynamic Processing Inventory
Automated Consent Validation
Continuous Control Monitoring
Real-Time Privacy Risk
Area DPDP Act GDPR
Individual Data Principal Data Subject
Organization deciding purpose/means Data Fiduciary Controller
Service provider Data Processor Processor
Primary processing model Consent + Certain Legitimate Uses Six Article 6 lawful bases
Child threshold Generally under 18 Generally under 16, with Member State variation down to 13
Regulator Data Protection Board of India EU/EEA Supervisory Authorities
Cross-border model Government may restrict specified destinations Adequacy, SCCs, BCRs and other mechanisms
Breach regime DPDP-specific notification framework Risk-based authority notification, including 72-hour rule
Nomination Explicit statutory right No directly equivalent GDPR right

For every processing activity ask:

Is this digital personal data?
Does DPDP apply?
Who is the Data Principal?
Who is the Data Fiduciary?
Which processors are involved?
Why are we processing it?
Do we have consent
or a valid legitimate use?
Is our notice accurate?
Can consent be withdrawn?
Can Data Principals
exercise their rights?
Are children involved?
Are security safeguards adequate?
Where is the data stored?
Who receives it?
When will it be erased?
What happens after a breach?
Can we demonstrate compliance?

For every new vendor ask:

What Personal Data
Will They Process?

For every new application ask:

Have DPDP Requirements
Been Built Into Design?

For every compliance claim ask:

Where Is the Evidence?

That is the practical DPDP governance mindset.

  • The DPDP Act is India’s principal framework governing digital personal data.

  • The DPDP Rules, 2025 have now been finalized and notified. (MeitY)

  • Implementation uses phased commencement rather than every provision taking effect simultaneously. (MeitY)

  • DPDP can apply to certain processing outside India when connected with offering goods or services to individuals in India.

  • Individuals are called Data Principals.

  • Organizations determining purpose and means are Data Fiduciaries.

  • Processing is structured primarily around consent and certain legitimate uses.

  • Consent must meet specific statutory requirements.

  • Notices should clearly explain the relevant personal data and processing purpose.

  • Data Principals have rights involving access information, correction, completion, updating, erasure, grievance redressal, and nomination.

  • The Act also establishes duties for Data Principals.

  • Children’s personal data receives additional protection.

  • Significant Data Fiduciaries face additional governance requirements.

  • Data Fiduciaries remain responsible for important obligations when processors are used.

  • Reasonable security safeguards are fundamental.

  • Personal data breaches require structured notification and response processes.

  • DPDP does not simply copy GDPR’s 72-hour breach rule.

  • DPDP does not impose a blanket requirement that all personal data remain in India.

  • The Data Protection Board of India has been established. (MeitY)

  • GRC operationalizes DPDP through inventories, notices, consent evidence, rights management, processor governance, security mapping, control testing, and remediation.

Before continuing, make sure you can answer:

  1. What is the DPDP Act?

  2. What are the DPDP Rules, 2025?

  3. What is digital personal data?

  4. Who is a Data Principal?

  5. What is a Data Fiduciary?

  6. What is a Data Processor?

  7. When can DPDP apply outside India?

  8. What makes consent valid?

  9. What should a DPDP notice contain?

  10. What are certain legitimate uses?

  11. What rights do Data Principals have?

  12. What duties do Data Principals have?

  13. What is the right of nomination?

  14. What requirements apply to children’s data?

  15. What is a Significant Data Fiduciary?

  16. What additional obligations can apply to an SDF?

  17. What security responsibilities apply to Data Fiduciaries?

  18. How should personal data breaches be managed?

  19. How does DPDP approach cross-border processing?

  20. What is the role of the Data Protection Board of India?

➡️ Next: 04 — HIPAA

In the next lesson, you will move from general consumer and digital privacy into the U.S. healthcare privacy and security framework centered on the Health Insurance Portability and Accountability Act (HIPAA).

You will examine:

HIPAA Applicability
Covered Entities
Business Associates
PHI & ePHI
Privacy Rule
Security Rule
Administrative Safeguards
Physical Safeguards
Technical Safeguards
Minimum Necessary
Individual Rights
Business Associate Agreements
Breach Notification
HIPAA Risk Analysis
Audit Evidence

You will also build practical artifacts including a HIPAA Applicability Assessment, PHI Inventory, Business Associate Register, HIPAA Safeguard Matrix, Risk Analysis Register, Minimum Necessary Access Matrix, Breach Assessment Register, HIPAA Evidence Repository, and HIPAA Compliance Dashboard.