DPDPA Studio — Interactive Experience of India's Digital Personal Data Protection Act, 2023

By AMLEGALS — 27+ Years of Regulatory Practice | 10 Offices Across India


DPDPA Studio is an immersive interactive experience by AMLEGALS exploring every dimension of India's Digital Personal Data Protection Act, 2023 (DPDPA).

The Digital Personal Data Protection Act, 2023 received Presidential Assent on 11 August 2023. The DPDP Rules, 2025 were notified on 21 March 2025. Enforcement begins 13 May 2027.

DPDPA Studio contains eleven interactive modules:

1. DPDPA Tour: An 8-stop scroll narrative covering Section 2 (definitions and Data Principal), Section 6 (consent architecture — free, specific, informed, unambiguous, withdrawable), Section 8(5) (reasonable security safeguards — penalty up to ₹250 Crore), Section 12 (right to erasure), Data Principal rights (Sections 11-14), the penalty Schedule (₹250 Cr, ₹200 Cr, ₹200 Cr, ₹150 Cr, ₹50 Cr ceilings), and the enforcement timeline.

2. Anonymous — How Anonymous is Anonymous?: Interactive demonstration of Section 2(t) of the DPDPA, showing how anonymised data can be re-identified through attribute combination. A 40,000-person crowd visualisation toggles PIN code, sex, employer, and date of birth to progressively narrow identification — proving that four quasi-identifiers can uniquely identify an individual even without a name.

3. Data Lifecycle — Follow Your Data: Visual data-flow pipeline with six nodes (Collect → Consent → Store → Process → Share → Erase). Animated particle travels the rail while toggle controls (Consent valid/missing, Breach none/occurred, Erasure requested) dynamically shift the compliance gauge — mapping Sections 5, 6, 8, 9, 12, and 13 to each lifecycle stage.

4. Compliance Journey: End-to-end Section-by-Section implementation pathway from data inventory through consent management, processing legitimacy, security safeguards, breach response, rights fulfilment, to Board-level governance.

5. Rights — Your Data, Your Move: Interactive exercise of all five Data Principal rights under Sections 11-14 (access, correction, erasure, grievance redressal, nomination). Each right triggers the corresponding Fiduciary obligation in real time, with escalation path to the Data Protection Board when a grievance goes unresolved.

6. Inference — The Data You Never Gave: Demonstrates how five ordinary data points (grocery purchases, location, search history, contacts, app-open times) generate sensitive inferences (health conditions, religion, sexual orientation, political leaning). Maps the gap between consent given and conclusions drawn under Section 2(t) and Section 6.

7. Basis — Consent, or not?: Interactive exercise across Sections 6 and 7 of the DPDPA. Eight real-world data-processing scenarios — each requires the practitioner to choose between the Section 6 consent door and the Section 7 legitimate-use door. Covers employment records, law-enforcement cooperation, medical emergencies, credit scoring, merger due-diligence, subsidies, judicial orders, and voluntary user data. Auto-play cycles through correct statutory reasoning.

8. Significant Data Fiduciary — When You Cross the Line: Section 10 threshold interactive. Five assessment factors — volume and sensitivity of data, risk to Data Principal rights, data sovereignty impact, electoral democracy considerations, and security of the State — each on a graduated slider. A real-time meter shows where the organisation stands against the Significant Data Fiduciary threshold. When the threshold is crossed, three additional statutory duties illuminate: mandatory Data Protection Officer appointment, independent data auditor engagement, and periodic Data Protection Impact Assessments. Profile presets (small startup, growing platform, large-scale platform) demonstrate how different organisational profiles trigger different duty levels.

9. Field Guide: Practitioner-grade statutory reference with DPDP Rules 2025 cross-references. Section-by-section analysis with implementation notes, risk indicators, and compliance checklists.

10. Governance: Section 36 mandate — every person responsible for the business of the body corporate is deemed liable. Includes interactive boardroom test, resolution toolkit, evidence file, accountability matrix (RACI), and penalty exposure analysis.

11. First Principles: The foundational premises of DPDPA's legislative architecture — why the Act was structured as it was, what separates it from GDPR, and the philosophical underpinnings of India's approach to data protection.

Penalty Schedule under DPDPA:
- Section 8(5) — Failure to take reasonable security safeguards: up to ₹250 Crore
- Section 8(6) — Failure to notify Board and Data Principal of breach: up to ₹200 Crore
- Section 9 — Breach of obligations regarding children's data: up to ₹200 Crore
- Section 10 — Breach of additional obligations by Significant Data Fiduciary: up to ₹150 Crore
- Breach of any other provision of the Act or Rules: up to ₹50 Crore

Key DPDPA Terminology:
- Data Fiduciary: Any person who alone or in conjunction with other persons determines the purpose and means of processing personal data (Section 2(i))
- Data Processor: Any person who processes personal data on behalf of a Data Fiduciary (Section 2(k))
- Data Principal: The individual to whom the personal data relates (Section 2(j))
- Consent Manager: A person registered with the Board who acts as a single point of contact for Data Principals to manage consent (Section 2(g))
- Significant Data Fiduciary: A Data Fiduciary notified by the Central Government based on volume, sensitivity, risk to sovereignty/security, etc. (Section 10)
- Data Protection Board of India: The adjudicatory body established under Section 18

AMLEGALS offices: New Delhi, Ahmedabad, Mumbai, Bengaluru, Pune, Kolkata, Chennai, Prayagraj, Surat, Vadodara.
Contact: [email protected]
Managing Partner: Anandaday Misshra (27+ years regulatory experience)
Proprietary Framework: Vibe Data Privacy™ — Signal, Pulse, Drift, Dividend, Culture