Before you start: three facts that shape the work
The Act applies to digital personal data, including personal data collected on paper and later digitised. It covers processing in India, and processing outside India connected with offering goods or services to people in India (Section 3).
It does not apply to personal data used by an individual for personal or domestic purposes. It also does not apply to personal data made publicly available by the person it relates to, or by someone under a legal duty to publish it.
The Rules were notified on 13 November 2025, and the core duties apply from 13 May 2027. Steps 1 to 5 should be finished first, because the later steps depend on them.
The twelve steps to DPDPA compliance
Each step says what to do, the provision it answers to and the record to keep. The order is the one that avoids rework.
- 01
Confirm your role for each activity
For each activity, decide whether you are a Data Fiduciary (you decide the purpose and means of processing) or a Data Processor (you process on behalf of a Data Fiduciary, Section 2(k)). Under Section 8(1), the Data Fiduciary stays responsible for processing done on its behalf. Record: a role register.
- 02
Map your personal data
List each data set: whose data it is (customers, employees, job candidates, vendor staff), where it comes from, why it is used, which systems hold it, which vendors receive it, whether it leaves India and how long it is kept. Record: a data map with an owner for each row.
- 03
Choose a lawful ground for each purpose
Section 4 allows processing on consent or for a legitimate use. Section 7 lists the legitimate uses, such as specified employment purposes, compliance with law and medical emergencies. If no legitimate use fits, you need consent. Record: a purpose and lawful ground column in the data map.
- 04
Rewrite your notices
Under Section 5 and Rule 3, a notice must be in clear and plain language, list the personal data and the purpose, and explain how to withdraw consent, exercise rights and complain to the Board. Section 5(3) requires an option to read the notice in English or in any language listed in the Eighth Schedule to the Constitution. Record: each notice version and the date it went live.
- 05
Fix consent and withdrawal
Section 6 requires consent to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action and limited to the data needed for the purpose. Ask for each purpose separately. Section 6(4) requires withdrawal to be as easy as giving consent. Record: consent logs showing what was shown, when, and what the person chose.
- 06
Set reasonable security safeguards
Section 8(5) and Rule 6 require reasonable security safeguards, including encryption or similar measures, access control, monitoring of access, backups so processing can continue after an incident, and logs kept for at least one year. Record: a control list with test results.
- 07
Prepare for a personal data breach
Section 8(6) and Rule 7 require intimation without delay to the Board and to each affected person, and a detailed report to the Board within 72 hours, or longer if the Board allows. A cyber security incident may also need reporting to CERT-In within six hours under its April 2022 Directions. Record: a breach plan, named decision makers and the results of a test exercise.
- 08
Set up rights and grievance handling
Sections 11 to 14 give people rights to information about their data, to correction and erasure, to grievance redressal and to nominate another person. Rule 14 requires grievances to be resolved within 90 days at most. Rule 9 requires you to publish the business contact details of a Data Protection Officer or a person who can answer questions about your processing. Record: a request log with response dates.
- 09
Set retention periods and erase on time
Section 8(7) requires erasure once the purpose is no longer served, unless a law requires you to keep the data. Rule 8 and the Third Schedule set fixed periods for certain large e-commerce, online gaming and social media platforms. Record: a retention schedule and erasure logs.
- 10
Put every processor under contract
Section 8(2) allows you to engage a Data Processor only under a valid contract. The list usually includes cloud hosting, analytics and advertising tools, payroll and customer support vendors. Contracts should cover security, breach reporting to you, sub-processors and deletion at the end of the service. Record: a vendor register with contract dates.
- 11
Check for children and persons with disabilities
A child is anyone under 18 (Section 2(f)). Section 9 and Rule 10 require verifiable consent of a parent or lawful guardian, and bar tracking, behavioural monitoring and targeted advertising directed at children. Rule 12 and the Fourth Schedule exempt some classes and purposes. Rule 11 covers consent from the lawful guardian of a person with a disability. Record: the age and guardian consent method, and any exemption relied on.
- 12
Keep records and review on a schedule
Keep the record from each step in one place, with an owner and a review date. Review when you add a product, a vendor or a new use of data. If you are notified as a Significant Data Fiduciary, Section 10 and Rule 13 add a data protection impact assessment and an audit every 12 months. Record: a compliance file indexed by Section and Rule.
Common errors that cause rework
These are the errors seen most often when organisations start DPDPA work. Each one sends a team back to an earlier step.
- Writing notices before the data map is finished. Notices must list the data and the purposes, so they change whenever the map changes.
- Using one checkbox for several purposes. Section 6 requires consent to be specific to each purpose.
- Treating withdrawal as an email to customer support. Section 6(4) requires withdrawal to be as easy as giving consent, so it belongs where consent was given.
- Leaving advertising pixels and analytics tools off the vendor list. Tools that receive personal data on your behalf need contracts under Section 8(2).
- Keeping data in case it is useful later. Section 8(7) requires erasure once the purpose is served, unless a law requires you to keep it.
- Planning breach reporting only for CERT-In. The DPDPA also requires intimation to the Board and to each affected person.
What records to keep
The Board decides penalties after an inquiry. Under Section 33(2), it considers matters such as the type of personal data, the duration of the breach and whether timely steps were taken to reduce its effect. Records made at the time are how an organisation shows what it did.
- Role register and data map
- Notice versions and consent logs, including withdrawals
- Security control list, access logs (kept for at least one year) and test results
- Breach plan, exercise reports and any breach reports filed
- Rights and grievance request log with response dates
- Retention schedule and erasure logs
- Vendor register and processor contracts

