DPDPA Questions Answered: Consent, Breach, Penalties, Sectors
DPDPA Questions Answered: Consent, Breach, Penalties, Sectors
Argument 01 Resilience, not implementation →
What is the difference between DPDPA implementation and DPDPA resilience? +
Implementation produces the artefacts the Act requires: notices, consent flows, contracts, policies. Resilience is whether those artefacts hold under stress, such as a breach, a mass withdrawal of consent or a Board inquiry. The Act's penalties are triggered by failures in practice, so resilience is what reduces exposure.
When do most DPDPA obligations take effect? +
The DPDP Rules, 2025 were notified in November 2025 with a phased timeline. Provisions on the Data Protection Board applied at once, consent manager registration follows after twelve months, and most Data Fiduciary obligations apply eighteen months after notification.
Does DPDPA require a breach response plan? +
The Act requires reasonable security safeguards and intimation of a personal data breach to the Board and to each affected Data Principal. The Rules require a detailed report to the Board within 72 hours. Meeting that without a rehearsed plan is unrealistic.
Argument 02 Unclear thinking is the first breach →
Does DPDPA apply to B2B companies? +
Yes. DPDPA applies to digital personal data of any individual, including employees, job candidates, client contacts and vendor staff. A B2B business model does not remove those Data Principals from scope.
Is consent the only lawful basis under DPDPA? +
No. Section 7 sets out certain legitimate uses, including specified employment purposes, compliance with law and medical emergencies. Everything else generally needs consent that is free, specific, informed, unconditional and unambiguous.
Can a company keep personal data indefinitely under DPDPA? +
Generally no. Section 8(7) requires erasure once the specified purpose is no longer served, unless retention is necessary to comply with law. The Rules add fixed timelines for certain large platforms.
Argument 03 You cannot protect what you have not named →
Is a data map mandatory under DPDPA? +
The Act does not use the term, but its obligations on notice, purpose limitation, security, erasure and Data Principal rights cannot be met without knowing where personal data sits. Significant Data Fiduciaries must also carry out data protection impact assessments, which depend on one.
What should a DPDPA data inventory contain? +
At minimum: the category of Data Principal, data fields, source, purpose, legal basis, storage location, processors, cross-border transfers, retention period and accountable owner.
Argument 04 Consent is a contract you have to prove →
What makes consent valid under DPDPA? +
Section 6 requires consent to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to personal data necessary for the specified purpose. It must be as easy to withdraw as to give.
Does DPDPA allow pre-ticked consent boxes? +
Consent must be signified by a clear affirmative action. A pre-ticked box is not an action by the Data Principal and is unlikely to meet the standard.
Who are consent managers under DPDPA? +
Consent managers are entities registered with the Data Protection Board that let Data Principals give, manage, review and withdraw consent through an accessible, interoperable platform. They act on behalf of the Data Principal.
Argument 05 The first 72 hours →
What is the breach notification timeline under DPDPA? +
Under the DPDP Rules, 2025 a Data Fiduciary must intimate the Board and each affected Data Principal without delay on becoming aware of a personal data breach, and give the Board a detailed report within 72 hours, or a longer period the Board allows.
What is the penalty for failing to notify a breach under DPDPA? +
Failure to give the Board or affected Data Principals intimation of a personal data breach attracts a penalty of up to ₹200 crore under the Schedule to the Act.
Argument 06 Your vendor is your liability →
Is a Data Fiduciary liable for its Data Processor under DPDPA? +
Yes. Section 8(1) makes the Data Fiduciary responsible for complying with the Act in respect of processing undertaken by it or on its behalf by a Data Processor.
Does DPDPA require a contract with Data Processors? +
Yes. Section 8(2) allows a Data Fiduciary to engage a Data Processor only under a valid contract.
Argument 07 The board question →
What is a Significant Data Fiduciary under DPDPA? +
A Significant Data Fiduciary is a Data Fiduciary or class notified by the Central Government under Section 10, considering factors such as volume and sensitivity of data, risk to Data Principals, and impact on sovereignty, security and public order.
What are the obligations of a Significant Data Fiduciary? +
It must appoint a Data Protection Officer based in India who is responsible to the board, appoint an independent data auditor, and carry out periodic data protection impact assessments and audits, along with measures in the Rules.
Argument 08 What the Schedule actually costs →
What is the maximum penalty under DPDPA? +
The highest ceiling in the Schedule is up to ₹250 crore, for failure of a Data Fiduciary to take reasonable security safeguards to prevent a personal data breach.
How does the Data Protection Board decide the penalty amount? +
Under Section 33(2) the Board considers the nature, gravity and duration of the breach, the type of personal data, whether it is repetitive, any gain or loss avoided, mitigation and its timeliness, proportionality, and the likely impact of the penalty.
Sector · Banking & BFSI Banking & BFSI →
Does DPDPA override RBI data retention requirements? +
No. Section 8(7) requires erasure when the purpose is served unless retention is necessary for compliance with law. Records a law such as PMLA requires to be kept may be retained for that period and purpose.
Do banks need consent for cross-selling under DPDPA? +
Using data collected for account opening to market other products is a new purpose. Unless a legitimate use applies, it generally requires specific consent.
Sector · Fintech & NBFC Fintech & NBFC →
Is an Android or iOS permission valid consent under DPDPA? +
An operating-system permission grants technical access; it does not by itself provide the notice of purpose and the specific consent Section 5 and Section 6 require. Apps should pair permissions with a clear notice and choice.
Are lending service providers Data Processors under DPDPA? +
Where they process borrower data on behalf of a regulated lender, they generally act as Data Processors, and the lender as Data Fiduciary remains responsible under Section 8(1).
Sector · Healthcare & Pharma Healthcare & Pharma →
Does DPDPA have a sensitive personal data category for health data? +
No. DPDPA does not create separate categories. However, under Section 33 the Board considers the type and nature of personal data when determining penalties, so health data breaches are likely to be treated as more serious.
Can hospitals process patient data without consent under DPDPA? +
Section 7 permits certain processing without consent, including responding to a medical emergency involving a threat to life or health. Routine care, research and marketing should be assessed separately and often need consent.
Sector · EdTech EdTech & children's data →
Who is a child under DPDPA? +
Under Section 2(f) a child is an individual who has not completed eighteen years of age.
What does DPDPA require for processing children's data? +
Section 9 requires verifiable consent of the parent or lawful guardian, prohibits processing likely to cause detrimental effect on a child's well-being, and bars tracking, behavioural monitoring and targeted advertising directed at children, subject to exemptions in the Rules. Breach can attract a penalty of up to ₹200 crore.
Sector · E-commerce & D2C E-commerce & D2C →
Do e-commerce companies need separate consent for marketing under DPDPA? +
Generally yes. Consent must be specific to a purpose. Processing an order and sending marketing are different purposes, so marketing typically requires its own consent that can be refused and withdrawn.
What is the three-year erasure rule in the DPDP Rules? +
The Rules require certain classes of large Data Fiduciaries, including e-commerce entities above a user threshold, to erase personal data of users who have not engaged for three years, after notifying them in advance.
Sector · SaaS & IT services SaaS & IT services →
Is a SaaS company a Data Fiduciary or Data Processor under DPDPA? +
It depends on each activity. Processing client data on the client's instructions is typically as a Data Processor. Processing for the company's own purposes, such as analytics, benchmarking or marketing, makes it a Data Fiduciary for that activity.
Does DPDPA apply to Indian IT companies processing foreign clients' data? +
Section 17(1)(d) exempts certain provisions for processing personal data of persons not within India under a contract with a person outside India. Obligations such as security safeguards and the company's own employee data remain relevant.
Sector · Telecom Telecom →
Are telecom companies Significant Data Fiduciaries under DPDPA? +
Only the Central Government can notify Significant Data Fiduciaries. Given the volume and sensitivity of subscriber data, large telecom operators are strong candidates and should prepare for Section 10 obligations.
Do retailers who collect SIM KYC count as Data Processors? +
Where retailers collect and handle subscriber data on behalf of an operator, they generally act as Data Processors, and the operator remains responsible under Section 8(1).
Sector · Insurance Insurance →
Are insurance agents and brokers Data Processors under DPDPA? +
When they collect and handle customer data on behalf of an insurer, they generally act as Data Processors, and the insurer remains responsible. Some brokers may act as independent fiduciaries for their own purposes.
Can insurers keep claims data indefinitely under DPDPA? +
No. Data should be erased once its purpose is served, unless retention is required by law. Insurers should align retention with regulatory requirements and limitation periods.
Sector · HR & Staffing HR & Staffing →
Does DPDPA require consent for employee data? +
Section 7(i) allows processing without consent for employment purposes and to safeguard the employer from loss or liability, among other listed purposes. Processing outside those purposes may require consent.
How long can employers keep candidate data under DPDPA? +
Only as long as needed for the purpose, such as the recruitment for which it was provided, unless law requires longer. Employers should set and apply a retention period for unsuccessful candidates.
Sector · Hospitality & Travel Hospitality & Travel →
Can hotels keep copies of guest IDs under DPDPA? +
Hotels may collect and keep ID where a law requires it, for the period it requires. Retaining ID copies beyond that, or collecting more than required, is difficult to justify under Section 8(7).
Does DPDPA allow travel companies to transfer data abroad? +
Section 16 permits transfers outside India except to countries restricted by Government notification. Contracts and safeguards are still expected, and sectoral rules may add requirements.
Sector · Gaming Gaming →
How does DPDPA affect online gaming companies? +
Gaming platforms must obtain verifiable parental consent for users under 18, avoid tracking, behavioural monitoring and targeted advertising directed at children, and, for large gaming intermediaries, erase data of users inactive for three years under the Rules.
Is a self-declared age gate enough under DPDPA? +
The Rules require Data Fiduciaries to adopt appropriate measures to ensure verifiable parental consent. A self-declared birth year alone is unlikely to be seen as sufficient where children are likely users.
Sector · Government vendors Government vendors →
Does the government exemption under DPDPA apply to contractors? +
Section 17(2)(a) lets the Central Government exempt notified instrumentalities of the State in specified interests. It does not automatically exempt private vendors, and the scope of any exemption depends on the notification.
Are government IT vendors Data Processors under DPDPA? +
Where they process personal data on a department's instructions, they generally act as Data Processors. Where they use the data for their own purposes, they may be Data Fiduciaries.
Banking & BFSI · Deep dive Three reporting clocks →
Does a bank need to report a data breach to both CERT-In and the Data Protection Board? +
A cyber incident may need reporting to CERT-In under its 2022 directions, and a personal data breach must also be intimated to the Data Protection Board and each affected Data Principal under DPDPA and the Rules. Sectoral reporting to the RBI may apply as well.
What is the CERT-In reporting timeline? +
CERT-In's April 2022 directions require specified cyber security incidents to be reported within six hours of noticing them.
Banking & BFSI · Deep dive Retention versus erasure →
Can banks refuse a DPDPA erasure request because of PMLA? +
Where the law requires retention, such as KYC and transaction records under PMLA, the bank may retain those records for the required period. Data not covered by a legal requirement should be erased once its purpose is served.
How long must banks keep KYC records? +
Under the PMLA framework, records are generally kept for five years after the business relationship ends or the transaction, subject to the specific rule. Banks should confirm the period applicable to each record type.
Banking & BFSI · Deep dive Agents and partners →
Are collection agents Data Processors under DPDPA? +
When they process borrower data on behalf of a bank or NBFC, they generally act as Data Processors. The lender, as Data Fiduciary, remains responsible for compliance under Section 8(1).
Can a lender call a borrower's references or relatives? +
Processing a third person's personal data needs a lawful basis of its own. Lenders should limit collection and use of reference contacts and follow applicable RBI conduct rules.
Fintech & NBFC · Deep dive App permissions →
Is an app permission valid consent under DPDPA? +
No, not by itself. A permission grants technical access. DPDPA requires a notice of the purpose and consent that is free, specific, informed and unambiguous. Apps should show their own notice alongside permissions.
Can a lending app access a borrower's contact list? +
RBI's digital lending rules restrict access to contacts, media and call logs. DPDPA separately requires the data to be necessary for the stated purpose.
Fintech & NBFC · Deep dive Alternative-data scoring →
Can fintechs use SMS data for credit scoring under DPDPA? +
Only if the purpose was clearly notified and the customer gave specific consent for it, and subject to RBI rules on app data access. Data collected for another purpose cannot be repurposed without a new basis.
Do customers have a right to know what data a lender used? +
Section 11 gives Data Principals the right to obtain a summary of personal data being processed and the processing activities undertaken.
Fintech & NBFC · Deep dive The consent model that exists →
How does the account aggregator framework relate to DPDPA? +
Account aggregators operate under RBI regulation using consent artefacts that specify purpose, duration and revocation. The model closely reflects DPDPA's requirements for specific, informed and withdrawable consent.
Are account aggregators consent managers under DPDPA? +
They are distinct concepts. Consent managers are registered with the Data Protection Board under DPDPA. The Rules set their registration conditions.
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).
