AMLEGALS — Strategic Lawyering
DPDPA process · Impact assessment

Data Protection Impact Assessment under the DPDPA: what it is and when it is required

A Data Protection Impact Assessment is the structured way an organisation examines a processing activity before, or while, it runs: what data is used, why, the risk to the individual, and what reduces that risk. Under the DPDPA it is a defined term and, for some organisations, a standing duty.

Updated · Checked against the DPDP Act, 2023 and the DPDP Rules, 2025 · 4 min read

A gold risk-matrix grid with a magnifier highlighting a high-risk cell on a dark navy background
Short answer

A Data Protection Impact Assessment (DPIA) is defined in Section 2(f) of the Digital Personal Data Protection Act, 2023 as a process comprising a description of the rights of Data Principals and the purpose of processing, assessment and management of the risk to the rights of Data Principals, and other prescribed matters. A DPIA is mandatory for a Significant Data Fiduciary: Section 10(2)(c) requires it to undertake a DPIA and periodic audit, and Rule 13 of the DPDP Rules, 2025 sets the detail and the yearly cycle. For a Data Fiduciary that has not been notified as significant, a DPIA is not mandatory under the Act, but it remains the clearest way to show that processing was assessed for risk before launch, which supports the accountability and security duties under Section 8.

  • DPIA
  • Impact assessment
  • Significant Data Fiduciary
  • Section 10
  • Rule 13
  • Risk
  • DPDP Rules 2025
Definition
Section 2(f): risk to the rights of Data Principals, purpose, and prescribed matters
Mandatory for
Significant Data Fiduciaries, under Section 10(2)(c) and Rule 13
Cycle
DPIA and audit on the periodic basis set by Rule 13
Good practice
Recommended for high-risk processing even where not mandatory

What a DPIA is under the DPDPA

Section 2(f) defines a Data Protection Impact Assessment as a process that describes the rights of Data Principals and the purpose of processing, assesses and manages the risk to those rights, and covers such other matters as may be prescribed. The focus is the risk to the individual, not only the risk to the organisation.

A DPIA is distinct from a general information security assessment. It starts from the Data Principal: what personal data is processed, on what lawful ground, for what purpose, and what could go wrong for the person if the processing fails.

When a DPIA is mandatory

A DPIA is a standing duty only for a Significant Data Fiduciary. The Central Government may notify a Data Fiduciary, or a class of them, as significant under Section 10(1), considering factors such as the volume and sensitivity of personal data processed, the risk to Data Principals, and the potential effect on the sovereignty and integrity of India and on electoral democracy.

Once notified, Section 10(2)(c) requires the organisation to undertake a Data Protection Impact Assessment and a periodic audit, and to take such other measures as prescribed. Rule 13 of the DPDP Rules, 2025 sets the operational detail and the yearly cadence, and provides for the outcome to reach the Board.

How to run a DPIA

A DPIA follows a consistent sequence, whatever the processing. Each step produces a record that becomes part of the assessment.

  1. 01

    Describe the processing

    Record the data sets, sources, purposes, lawful ground under Section 6 or Section 7, recipients, retention and any cross-border transfer.

  2. 02

    Test necessity and proportionality

    Ask whether each data element is needed for the stated purpose, and whether a less intrusive option would serve it.

  3. 03

    Assess the risk to the individual

    Identify what could harm the Data Principal, such as loss, misuse, unlawful access, or processing beyond the notice, and rate likelihood and severity.

  4. 04

    Decide the controls

    Set the measures that reduce each risk, including safeguards under Section 8(5) and Rule 6, consent design, and minimisation.

  5. 05

    Record and sign off

    Document the residual risk, the decision to proceed or change, and the owner. Keep it as part of the compliance record.

  6. 06

    Review on cycle

    Repeat on the Rule 13 cadence for a Significant Data Fiduciary, and whenever the processing changes materially.

A working structure for the DPIA report

A DPIA report does not need to be long, but it should be complete. A workable structure includes:

  • Processing description and data inventory, linked to the record of processing activities.
  • Lawful ground for each purpose under Section 6 or Section 7.
  • Rights of the Data Principal engaged, under Sections 11 to 14.
  • Risk register with likelihood, severity and the control for each risk.
  • Residual risk, sign-off, and the review date.

How AMLEGALS runs DPIAs

AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance.

The team runs the DPIA against the organisation’s own data flows, ties each finding to the provision it rests on, and produces a report the board and, where relevant, the Data Protection Board can follow.

Questions and answers

DPIA Under DPDPA: common questions

Is a DPIA mandatory under the DPDPA?

It is mandatory for a Significant Data Fiduciary under Section 10(2)(c) read with Rule 13. For other Data Fiduciaries it is not mandatory, but it is the clearest way to show processing was assessed for risk.

What is the difference between a DPIA and a privacy impact assessment?

In practice they describe the same exercise. The DPDPA uses the defined term Data Protection Impact Assessment in Section 2(f). "Privacy impact assessment" is the older, general name for it.

How often must a Significant Data Fiduciary run a DPIA?

Section 10(2)(c) requires a DPIA and periodic audit, and Rule 13 of the DPDP Rules, 2025 sets the cadence, which runs on a yearly cycle with the outcome reaching the Board.

Who should carry out the DPIA?

The Data Fiduciary is responsible. A Significant Data Fiduciary’s Data Protection Officer typically owns it, and an independent data auditor is involved in the related audit under Rule 13.

Does a DPIA have to be filed with the Board?

Rule 13 provides for the outcome of the assessment and audit to be made available to the Board in the manner it specifies. The full working papers are kept by the Data Fiduciary.

Contact

Run a Data Protection Impact Assessment

Share the processing activity you want assessed. The AMLEGALS data privacy team will scope a DPIA against the Act and the DPDP Rules, 2025.

Or write to [email protected]

Your details

Name and email are enough to start. The reply comes from [email protected].

Your information is handled in accordance with our privacy obligations. No spam, ever.

DPIA Under DPDPA: questions and answers

What is the legal framework for data protection in India?

India's framework is the Digital Personal Data Protection Act, 2023 (Presidential assent 11 August 2023; 44 sections) read with the Digital Personal Data Protection Rules, 2025, notified on 13 November 2025 (G.S.R. 846(E)) with 23 Rules and 7 Schedules.

When do DPDPA obligations apply to businesses?

The Act and Rules follow phased commencement. Institutional provisions commenced on 13 November 2025; Consent Manager provisions commence after 12 months on 13 November 2026; and the principal Data Fiduciary, rights, breach, security and enforcement provisions commence after 18 months on 13 May 2027.

What is the maximum penalty under DPDPA?

Highest listed maximum for a specified contravention: ₹250 crore under the Schedule to the Act. Penalties are imposed by the Data Protection Board of India after an inquiry, and Section 33(2) requires the Board to consider factors such as the nature, gravity and duration of the breach, the type of personal data affected, repetition, mitigation steps and proportionality.

Which provisions of the DPDPA and the DPDP Rules, 2025 are relevant to DPIA Under DPDPA?

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).

Who advises businesses on DPIA Under DPDPA under India's DPDPA?

AMLEGALS, an Indian law firm, advises Data Fiduciaries, Data Processors and foreign companies on DPIA Under DPDPA under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. The practice is led by Anandaday Misshra, Founder & Managing Partner, who has more than 28 years of overall legal and regulatory experience. Enquiries: https://amlegalsdpdpa.com/contact or [email protected] or [email protected].

What should I send AMLEGALS to get a scoped proposal on DPIA Under DPDPA?

Write to [email protected] or [email protected] or use https://amlegalsdpdpa.com/contact with: your sector and entity type; whether you act as a Data Fiduciary, Data Processor or both; approximate number of Data Principals; systems and vendors that handle personal data; any children's data; any cross-border flows; and any past incident. With these facts a partner can propose a scope for DPIA Under DPDPA rather than a generic checklist.

How do I get a first view of my DPDPA exposure on DPIA Under DPDPA?

Use the DPDPA Exposure Assessment at https://amlegalsdpdpa.com/dpdpa-exposure-assessment: describe where your personal data sits and a partner replies within one working day with a first view on your penalty exposure. Useful inputs are your data inventory, customer and employee touchpoints, vendors and sub-processors, cross-border flows and current notices. The principal obligations commence on 13 May 2027. Content is general legal information and not legal advice.

Contact AMLEGALS about DPIA Under DPDPA · DPDPA Exposure Assessment