What a DPIA is under the DPDPA
Section 2(f) defines a Data Protection Impact Assessment as a process that describes the rights of Data Principals and the purpose of processing, assesses and manages the risk to those rights, and covers such other matters as may be prescribed. The focus is the risk to the individual, not only the risk to the organisation.
A DPIA is distinct from a general information security assessment. It starts from the Data Principal: what personal data is processed, on what lawful ground, for what purpose, and what could go wrong for the person if the processing fails.
When a DPIA is mandatory
A DPIA is a standing duty only for a Significant Data Fiduciary. The Central Government may notify a Data Fiduciary, or a class of them, as significant under Section 10(1), considering factors such as the volume and sensitivity of personal data processed, the risk to Data Principals, and the potential effect on the sovereignty and integrity of India and on electoral democracy.
Once notified, Section 10(2)(c) requires the organisation to undertake a Data Protection Impact Assessment and a periodic audit, and to take such other measures as prescribed. Rule 13 of the DPDP Rules, 2025 sets the operational detail and the yearly cadence, and provides for the outcome to reach the Board.
How to run a DPIA
A DPIA follows a consistent sequence, whatever the processing. Each step produces a record that becomes part of the assessment.
- 01
Describe the processing
Record the data sets, sources, purposes, lawful ground under Section 6 or Section 7, recipients, retention and any cross-border transfer.
- 02
Test necessity and proportionality
Ask whether each data element is needed for the stated purpose, and whether a less intrusive option would serve it.
- 03
Assess the risk to the individual
Identify what could harm the Data Principal, such as loss, misuse, unlawful access, or processing beyond the notice, and rate likelihood and severity.
- 04
Decide the controls
Set the measures that reduce each risk, including safeguards under Section 8(5) and Rule 6, consent design, and minimisation.
- 05
Record and sign off
Document the residual risk, the decision to proceed or change, and the owner. Keep it as part of the compliance record.
- 06
Review on cycle
Repeat on the Rule 13 cadence for a Significant Data Fiduciary, and whenever the processing changes materially.
A working structure for the DPIA report
A DPIA report does not need to be long, but it should be complete. A workable structure includes:
- Processing description and data inventory, linked to the record of processing activities.
- Lawful ground for each purpose under Section 6 or Section 7.
- Rights of the Data Principal engaged, under Sections 11 to 14.
- Risk register with likelihood, severity and the control for each risk.
- Residual risk, sign-off, and the review date.
How AMLEGALS runs DPIAs
AMLEGALS is an Indian law firm. Its data privacy practice is led by Anandaday Misshra, Founder and Managing Partner, with Rohit Lalwani, Associate Partner, working on DPDPA compliance.
The team runs the DPIA against the organisation’s own data flows, ties each finding to the provision it rests on, and produces a report the board and, where relevant, the Data Protection Board can follow.

