AMLEGALS — Strategic Lawyering
On this page Artefacts Obligations Readiness 56 exhibits Exposure 72-hour clock Requests Answers
India · DPDP Act 2023 · DPDP Rules 2025

Compliance is not a claim. It is a file.

Software can automate a workflow. It cannot stand before the Data Protection Board and prove that your consent was free, your notice was itemised, and your breach clock started when the incident did.

AMLEGALS builds the DPDPA file: every obligation in the Act and the Rules mapped to a named control, a named owner, and a dated artefact a regulator can read. Counsel-led. Evidence-first. Privileged where it matters.

No certification body exists under DPDPA. Anyone selling you a certificate is selling you a document with no statutory backing.

44
Sections in the Act, each with a control consequence
23
Rules notified in 2025, plus 7 Schedules
72h
To file the detailed breach report after intimation
250Cr
Maximum penalty for failed security safeguards
0
DPDPA certification bodies in existence
The short answer

What DPDPA compliance actually requires of an Indian or India-facing business

DPDPA compliance means five things, in this order. One, you can state every purpose for which you process digital personal data and show the itemised notice that disclosed it. Two, every purpose rests on a lawful basis — consent under Section 6 or a certain legitimate use under Section 7 — with a record that survives audit. Three, you hold reasonable security safeguards under Section 8(5) and can evidence them as designed, deployed and tested. Four, you can run the Rule 7 breach sequence from detection to a 72-hour detailed report without improvising. Five, you can serve a Data Principal's rights request inside your published timeline and prove you did. Everything else — DPIAs, audits, consent managers, cross-border registers — is a consequence of one of those five.

There is no size or revenue threshold. Section 3 reaches offshore processing tied to offering goods or services in India. And because the Act creates no certification regime, the only defence that exists is a contemporaneous evidence file.

STATUTE Digital Personal Data Protection Act, 2023 — assented 11 August 2023.
RULES DPDP Rules, 2025 — G.S.R. 846(E) dated 13 November 2025 under Section 40. The Act's own commencement is G.S.R. 843(E) of the same date; Rule 1 counts the 12- and 18-month phases from Gazette publication.
WHO IS BOUND Every Data Fiduciary processing digital personal data in India, plus offshore entities within Section 3(b).
REGULATOR Data Protection Board of India. Appeal lies to the Appellate Tribunal (TDSAT) under Section 29.
EXPOSURE Up to ₹250 crore per instance under Section 33 read with the Schedule.
OUT OF SCOPE Non-digitised paper records, and personal data made publicly available by the Principal under a legal duty.
REVIEWED 4 September 2026 by AMLEGALS DPDPA practice. Corrections logged publicly.
What the file looks like when it is built

Five artefacts. Each one answers a question the Board will actually ask.

Not screenshots of software — these are the working documents an engagement leaves behind, shown the way they sit on a compliance desk.

Artefact 01 · Obligation map

Every section of the Act mapped to a named control, an owner and a status

Forty-four sections and twenty-three rules, each resolved to a control with an owner and a dated artefact. Gaps are visible by section, not buried in a policy — so remediation starts where the exposure is largest.

Read Part one · Foundations
Control framework · DPDPA
Act 2023 · Rules 2025 · 56 mapped controls
Live
S.5 · Itemised notice
7/7
S.6 · Consent and withdrawal
7/8
S.8(5) · Rule 6 safeguards
4/6
Rule 7 · Breach intimation
2/5
S.11–14 · Principal rights
5/6
S.9 · Children
1/4
Gap register 9 open · 3 owners
Artefact 02 · Rights workflow

Access, correction, erasure and grievance served inside a published clock

Six stages from intake to retention, each timestamped. Verification is proportionate, scope comes from the purpose register, and the record survives the erasure it executes.

Walk a request through the stages
DP-2041 · ACCESS REQUEST
Summary of personal data and processing
Day 3 of 30
Intake
Verify
Scope
4Execute
5Respond
6Retain
VERIFICATION
In-session · proportionate
SYSTEMS IN SCOPE
CRM · Warehouse · 2 processors
27d remaining on the
published timeline
Artefact 03 · Purpose register

Visibility into what you process, on which lawful basis, and where it flows

One row per purpose, per system, per vendor. Consent under Section 6 or a named Section 7 limb — and where neither exists, the purpose stops. The register is what makes notice, consent and rights answerable.

Read Part two · Notice and consent
CRM
Consent · S.6
PURPOSE REGISTER 31 purposes
31 lawful bases
Owner · DPO
Warehouse
Retention · S.8(7)
Support desk
Consent · S.6
Ad SDK
No basis · stop
App events
Analytics · consent
Payroll vendor
S.7 employment
Artefact 04 · Transfer register

Processors and cross-border flows, with the sectoral overlay that Section 16 does not disturb

Data class, destination, purpose, sectoral overlay and cost to repatriate. Rule 6(2) flow-down in one addendum applied to every processor, so a future restriction is a configuration change rather than a migration.

Read Part seven · Transfers
Transfer register
S.16 · Rule 15 · Rule 6(2)
PROCESSORROLEREGIONOVERLAYSTATUS
Cloud hostInfrastructureap-south-1NoneAddendum
Payments PSPProcessorIndiaRBI localisationCompliant
Support SaaSProcessorus-eastRule 15 watchAddendum
Analytics vendorSub-processoreu-westNoneNo contract
Marketing cloudProcessorus-westChildren flagReview
REPATRIATION COST
6 weeks · 1 vendor swap
Artefact 05 · Incident record

Detection to the Rule 7(2) report inside seventy-two hours, with proof of every intimation

Awareness logged at hour zero, both intimations out without delay, root cause and remediation timestamped, report filed on time. The second penalty head — up to ₹200 crore — never opens.

Run the 72-hour clock
INC-0117 · PERSONAL DATA BREACH
Unauthorised access · support database
Filed · 71h 20m
0hAwareness logged
2hRoom convened
6hBoth intimations
48hRoot cause fixed
72hRule 7(2) report
DATA PRINCIPAL INTIMATION
84,210 sent · 99.2% delivered · proof archived
Rule 7(1)
Second penalty head closed
Interactive · Obligation explorer

Pick an obligation. See the control, the evidence and the exposure.

Seven obligations, each expressed the way we build them: statutory duty, operating control, artefact for the file, penalty head.

Obligation 01 · Itemised noticeResidual head · up to ₹50 cr

A notice is a standalone document, not a link in a footer

Section 5 requires the notice to accompany or precede the request for consent, and Rule 3 requires it to be itemised, in plain language, and independently understandable. If the reader has to open a second document to learn what you take and why, the notice has failed on its face.

Test every notice by reading it aloud to someone outside the company.

Duty
Itemise data and purpose
Field-level list, one purpose per line, each separately refusable.
Control
Versioned notice service
Notices rendered from a store, not hard-coded in each surface.
Evidence
Notice archive
Every version, with the exact dates it was live and the locales served.
Failure
Policy-as-notice
A privacy policy doing the work of a notice. The most common defect we find.
See this exhibit in the index →
Interactive · Readiness assessment

Eight questions. Answer them honestly and the file grades itself.

Each question is a document a regulator can ask for. Nothing is stored, nothing is sent — the score is computed in your browser.

Can you produce the itemised notice exactly as it was served, for any purpose, on any date in the last year?S.5 · Rule 3
Does every processing purpose have a recorded lawful basis — consent, or a named Section 7 limb?S.6 · S.7
Is each consent stored with the notice version and the exact text the user saw?S.6(1)
Are logs, monitoring and access records retained for at least twelve months?S.8(5) · Rule 6
Have you defined in writing the triggers that start the breach clock, and rehearsed them?Rule 7
Can you serve access, correction and erasure inside a published timeline, and prove it?S.11–13 · Rule 14
Do you know which users are under eighteen, and is targeting suppressed at the ad-call layer?S.9 · Rule 10
Do you hold a transfer register keyed to data class, destination and sub-processor?S.16 · Rule 15
The exhibit index

Fifty-six exhibits. Each one answers a question a regulator, a buyer or a board will actually ask.

Read it end to end as an implementation map, or jump to the obligation you are being asked about this week.

02 Who the Act reaches 03 Roles and where liability lands 04 The five-step spine 05 Four definitions that decide scope 06 Section 7 legitimate uses 07 Commencement arithmetic 08 The six-document file 09 Certificate versus file 10 Where a GDPR programme fails 11 First ninety days 12 Who signs what 13 The itemisation test 14 Anatomy of a notice 15 Five qualities of consent 16 Consent text, before and after 17 Withdrawal consequence chain 18 Consent Manager conditions 19 Dark patterns 20 Legacy consent triage 21 What the consent row holds 22 The rights and duties map 23 Rights request workflow 24 Verifying the requester 25 Grievance to Board complaint 26 Nomination and succession 27 Lawful grounds to refuse 28 The Rule 7 sequence 29 The four deadlines 30 When the clock starts 31 Principal notice v Board report 32 Two heads, one incident 33 Six tabletop drills 34 The three prohibitions 35 Verifiable parental consent 36 Fourth Schedule exemptions 37 Age assurance without surveillance 38 The five SDF duties 39 A DPIA that survives audit 40 The India-based DPO 41 Algorithmic due diligence 42 Preparing before designation 43 The negative-list model 44 Transfer register fields 45 Processor addendum 46 The localisation stack 47 The penalty ceilings 48 How quantum is decided 49 Board procedure and appeal 50 Voluntary undertaking 51 Beyond the penalty 52 What privilege protects 53 Sector exposure map 54 HR is a fiduciary 55 DPDPA in the data room 56 What you get from us
All 55 exhibits
Part one · The statute as a control system

Forty-four sections, twenty-three rules, one question: can you prove it?

The Act is short. The file it demands is not. These eleven exhibits fix scope, roles, lawful basis and the sequence in which a programme has to be built — because building them out of order is what makes remediation expensive.

Exhibit 02 · Scope S.3 · S.2(n) · S.2(t)

The five-part scope test

Run it once per system, not once per company. Most groups discover that two subsidiaries are in and one is out.

In Digital personal data Any data about an identifiable individual, in digital form or digitised later.
In Offshore processing S.3(b) — processing abroad connected to offering goods or services in India.
Out Non-digitised records Paper files never digitised stay outside the Act. Scan them and they are in.
Out Self-published data Data the Principal made public themselves, or published under a legal duty.
Out Personal or domestic use Processing by an individual for personal or domestic purposes — S.3(c)(i).
Exhibit 03 · Roles S.2(i) · S.2(k) · S.6(9)

Fiduciary, Processor, Consent Manager — and the liability that does not transfer

DPDPA does not split liability the way GDPR does. The Data Fiduciary answers for the processor it appointed, which makes the contract the control.

Role What it does Where liability lands
Data Fiduciary Determines the purpose and means of processing, alone or with others. Primary and non-delegable. Answers to the Board for its processors as well.
Data Processor Processes on behalf of a Fiduciary, under contract only. No direct duty to the Data Principal. Exposure runs through the contract and indemnity.
Consent Manager Registered platform to give, review, manage and withdraw consent. Fiduciary duty to the Data Principal; accountable to the Board under Rule 4.
Significant Data Fiduciary A notified Fiduciary or class of Fiduciaries under S.10(1). All Fiduciary duties plus DPIA, audit, algorithmic diligence, India-based DPO.
Data Principal The individual; for a child, the parent or lawful guardian. Owes statutory duties under S.15 — including no false or frivolous grievance.
Exhibit 04 · Sequence S.5 → S.15

The compliance spine, in the only order that works

Each step is worthless without the one before it. Consent captured before purposes are fixed has to be captured twice.

1
Name every purpose
Purpose inventory per system, per data element, per vendor.
2
Fix the lawful basis
Consent under S.6, or a specified legitimate use under S.7. Nothing else exists.
3
Serve an itemised notice
S.5 with Rule 3 detail, independent of any other document.
4
Safeguard and log
S.8(5) with Rule 6 measures; logs retained at least a year.
5
Answer and erase
Rights under S.11–14, erasure under S.8(7) when purpose ends.
Exhibit 05 · Definitions S.2 · S.8(7)

Four definitions that quietly decide your programme's size

Arguments about scope are almost always arguments about one of these four words.

2(t) Personal data Data about an individual identifiable by or in relation to it. No sensitivity tiers.
2(n) Digital personal data Personal data in digital form. Digitisation is the trigger, not sensitivity.
2(x) Processing Any wholly or partly automated operation — including storage and mere retention.
8(7) Purpose exhausted When the Principal withdraws or the purpose ends, erasure is the default duty.
Exhibit 06 · Lawful basis S.7

Section 7 legitimate uses, and the three that are routinely over-read

There is no legitimate-interest basis for a private business. Section 7 is a closed list, and each entry is narrower than its label suggests.

Legitimate use What it actually covers The over-read to avoid
Voluntary provision Data the Principal gave for a purpose and has not objected to that purpose. Not a licence to re-use the same data for marketing or model training.
Employment purposes Employment, safeguarding the employer from loss, and provision of benefits. Not blanket surveillance. Productivity monitoring needs its own analysis.
State functions and subsidies Benefits, licences, certificates and services by the State. Available to the State, not to a private vendor merely serving the State.
Medical emergency and epidemic Threat to life or immediate health, or public-health measures. An emergency basis does not survive into routine clinical CRM use.
Legal obligation and orders Compliance with law, judgments, orders and decrees. A general regulatory relationship is not a specific legal obligation.
Exhibit 07 · Timing Rule 1(2)–(4)

The build window, measured in months

Notified 13 November 2025. Three commencement tranches, three budget cycles.

Institutional provisions Month 0
Board constituted, definitions and machinery live from notification.
Consent Manager regime Month 12
Registration opens 13 Nov 2026; First Schedule conditions apply.
Substantive obligations Month 18
Notice, consent, safeguards, breach, children, SDF, rights, transfers — 13 May 2027.
Exhibit 08 · Artefacts Practice standard

The six documents that constitute the file

If a Board notice arrived on Monday, these are what you would send. Anything else is supporting paper.

01 Purpose and basis register Every purpose, its lawful basis, its notice version, its owner.
02 Notice archive Every notice as served, versioned, with the date range it was live.
03 Consent ledger Artefact per consent: text shown, timestamp, channel, withdrawal state.
04 Safeguards dossier Rule 6 controls as designed, as deployed, as tested.
05 Incident log Detection, assessment, intimation and 72-hour report for each incident.
06 Rights log Every request, its verification, its outcome, its clock.
Exhibit 09 · Posture No certification regime exists under the Act

Why there is nothing to be certified against

The market is selling certificates for a statute that recognises none. What the Board can act on is what you can produce, dated.

A certificate says somebody looked. A file says what they would have found.No certification regime exists under the Act
What a Board notice asks for
Documents and information under S.36 — not a vendor attestation.
What survives cross-examination
Contemporaneous records made before the incident, not reconstructions after it.
Where privilege sits
Counsel-led assessment and advice can stay privileged; the operational log cannot.
Exhibit 10 · Comparison DPDPA v GDPR

Where a mature GDPR programme fails DPDPA

Reuse the inventory, the DSAR muscle and the vendor register. Rebuild everything below.

Issue GDPR position DPDPA position — the delta
Lawful basis Six bases, including legitimate interests with a balancing test. Consent, or a closed list of legitimate uses. No balancing test for private business.
Notice Layered privacy policy is broadly accepted. Itemised, standalone, plain-language notice; access in the Eighth Schedule languages.
Children Digital-consent age between 13 and 16 by member state. Under 18 throughout, with verifiable parental consent and no targeted advertising.
Breach 72 hours to the supervisory authority, subject to a risk threshold. Intimation without delay plus a detailed 72-hour report. No risk threshold.
Sensitive data Article 9 special categories with extra conditions. No sensitivity tiers. Sensitivity re-enters through SDF designation and safeguards.
Data subject duties None. S.15 duties on the Data Principal, with a ₹10,000 penalty for breach.
Exhibit 11 · Programme 90-day plan

The first ninety days, if you are starting now

Nothing here needs a tool licence. All of it needs a decision-maker in the room.

1
Days 1–15 · Inventory
Systems, purposes, vendors, transfers, children-facing surfaces.
2
Days 16–35 · Basis triage
Classify each purpose: consent, S.7, or stop. Escalate the contested ones.
3
Days 36–60 · Draft the instruments
Notices, consent text, processor addenda, breach runbook.
4
Days 61–80 · Instrument the evidence
Consent ledger, logging, rights intake, erasure jobs.
5
Days 81–90 · Rehearse
Breach tabletop, rights drill, board sign-off with a dated gap register.
Exhibit 12 · Governance S.8(1) · S.10(2)(a) · Rule 9

Ownership map: who actually signs each obligation

Unowned obligations fail first. Name a person, not a function, and put it in the minutes.

Board Accountability Adopts the policy, receives quarterly evidence, approves risk acceptance.
DPO Statutory contact India-based for an SDF; contact details published under Rule 9.
CISO Safeguards Rule 6 controls, log retention, processor security posture.
Product Notice and consent Consent surfaces, withdrawal parity, no dark patterns at the point of collection.
Exhibit 13 · Notice S.5 · Rule 3

The itemisation test: what a Rule 3 notice must say, and how notices fail

A notice that requires the reader to consult a second document has already failed. Test every line against the failure column.

Requirement Plain-language test Failure mode we see
Itemised personal data Can the reader list the fields you will hold? Categories like usage data and profile information doing all the work.
Itemised purposes Is each purpose separately stated and separately refusable? Service delivery and improvement bundled into one tick.
Goods or services enabled Does the notice say what the data buys the Principal? Purpose stated in internal language — analytics, enrichment, ops.
How to withdraw Is the withdrawal route as easy as the consent route? Consent in one tap, withdrawal by email to a shared inbox.
How to exercise rights Is the mechanism in the notice, not just the policy? A link to a portal that asks for more identity data than the account holds.
How to complain Is the Board complaint route stated alongside the internal one? Grievance officer named, Board omitted.
Language access Is the notice available in the Eighth Schedule languages? English-only flow with a translated PDF nobody links to.
Exhibit 14 · Drafting S.5(1) · Rule 3(1)

Anatomy of a notice that survives a Board reading

Five blocks, in this order, in the reader's language, on the same screen as the request.

1
What we take
The field list, in nouns the reader recognises.
2
Why we take it
One purpose per line, each independently refusable.
3
What you get
The good or service the processing enables.
4
How you stop it
Withdrawal, and the consequence of withdrawal, stated honestly.
5
Where you complain
Grievance route, then the Data Protection Board.
Exhibit 15 · Consent S.6(1)

The five qualities, each with an engineering consequence

Section 6(1) is not a drafting instruction. It is a specification for a screen and a database row.

Free No coercion Access cannot be conditioned on consent to unnecessary purposes.
Specific One purpose, one act Separate toggles, separately logged.
Informed Notice-linked The consent row must point to the notice version shown.
Uncondit- ional No bundling No take-it-all gate over the whole product.
Unambig- uous Clear affirmative act No pre-ticked boxes, no scroll-as-consent, no silence.
Exhibit 16 · Drafting S.6(1) · S.6(3)

Consent text: what we strike, and what we put in its place

Real edits from real remediation. The right column is longer to read and far shorter to defend.

Purpose Typical current text Defensible replacement
Marketing I agree to receive communications from us and our partners. Send me product emails. Separate tick for partner offers, with the partner classes named.
Analytics We use your data to improve our services. Measure which screens you use so we can fix the slow ones. Off by default.
Model training Covered by our privacy policy. Use my support conversations to train our assistant. Separate, refusable, revocable.
Enrichment We may supplement your information from third-party sources. Named sources, named fields, named purpose — or drop the purpose.
Sharing We share with affiliates and service providers. Processor list with a role for each, published and versioned.
Exhibit 17 · Withdrawal S.6(4)–(6)

What has to happen when consent is withdrawn

Withdrawal is not a preference flag. It starts a cascade with an evidentiary tail.

1
Ease parity
Withdrawal must be as easy as the original consent — same surface, same effort.
2
Stop processing
Cease within a reasonable time for that purpose only, not the whole account.
3
Cascade to processors
Instruct every processor and sub-processor; contractual duty under Rule 6(2).
4
Erase by default
S.8(7) erasure unless retention is required by law — record which limb applies.
5
Keep the proof
Retain the withdrawal artefact even after the underlying data goes.
Exhibit 18 · Consent Manager S.6(9) · Rule 4 · First Schedule

Consent Manager: what registration actually requires

A registered intermediary, not a cookie banner. Live from 13 November 2026.

Entity Incorporated in India With the net worth and governance conditions in First Schedule Part A.
Duty Fiduciary to the Principal Acts on the Principal's behalf; conflicts must be structurally excluded.
Blind No content access Routes and records consent; must not read the personal data itself.
Audit Interoperable and logged Machine-readable records kept at least seven years; the consent trail portable; Board oversight.
Exhibit 19 · Design S.6(1) read with S.5

Dark patterns are a consent defect, not a design preference

Every pattern below converts a valid consent into a contested one. The cost is not the fine; it is that the purpose becomes unusable retrospectively.

If the interface had to argue for itself before the Board, would you send it alone?S.6(1) read with S.5
Asymmetric effort
Accept all in one tap, refuse in four. Fails the free and unconditional test.
Pre-ticked and nudged defaults
Fails clear affirmative action; the log records a click, not a decision.
Consequence framing
Threatening loss of unrelated features conditions access on unnecessary consent.
Buried withdrawal
Breaches the S.6(4) ease-parity requirement on its face.
Exhibit 20 · Migration S.6(1) · Transitional practice

Legacy consent: keep, re-paper, or stop

Do the triage once, in writing, before May 2027. The register you produce is itself an exhibit.

What you hold Test Action
Granular opt-in with stored text and timestamp Purpose unchanged and notice reconstructable? Keep. Attach the notice version to the consent row.
Tick against a privacy policy Was the purpose itemised and separately refusable? Re-paper with a fresh itemised notice and a new affirmative act.
Implied consent from continued use Any affirmative act at all? Stop the purpose. Re-consent before restarting.
Consent obtained by a partner or reseller Chain documented to your named purpose? Obtain the artefact or re-consent directly. Contract is not evidence of consent.
Employee data on consent Is consent even the right basis? Move to the S.7 employment limb; consent from an employee is rarely free.
Exhibit 21 · Evidence S.6 · S.8(4)

The consent record: eight fields, or it is not a record

This is the schema we implement. If your ledger is missing a column, that is the column counsel will be asked about.

01 Principal identifier Stable, pseudonymous where possible.
02 Purpose code One row per purpose. Never a composite.
03 Notice version Immutable pointer to the exact text served.
04 Consent text hash Proof of what was on screen at that moment.
05 Timestamp and channel App, web, IVR, in-store — with locale.
06 Affirmative act What the user did, not merely that a flag turned true.
07 Withdrawal state Current state plus full history, never overwritten.
08 Downstream propagation Which processors were told, and when.
Part three · Data Principal rights

Rights are a service level. Publish it, staff it, and prove you met it.

Six exhibits on Sections 11 to 15 and Rule 14 — the access summary, correction and erasure, grievance redressal, nomination, requester verification, and the narrow grounds on which a request may lawfully be refused.

Exhibit 22 · Rights S.11 · S.12 · S.13 · S.14 · S.15

Four rights, one set of duties, and what each one costs to serve

Every right has an engineering dependency. Discover them now, not on the first request.

Right or duty What must be delivered Engineering dependency
S.11 Access Summary of personal data held and of processing activities, plus identities of Fiduciaries data was shared with. Cross-system export and a maintained processor register.
S.12 Correction and erasure Correction, completion, updating; erasure unless retention is legally required. Write-back paths and a cascade to downstream stores, caches and backups.
S.13 Grievance redressal A readily available mechanism with a published response period of not more than ninety days — Rule 14(3). Ticketing with a statutory clock, exhaustion before a Board complaint.
S.14 Nomination Nominee to exercise rights on death or incapacity. Nominee capture, verification, and a documented succession path.
S.15 Duties Principal must not impersonate, suppress material information, or raise false grievances. Verification records that let you rely on this if a request is abusive.
Exhibit 23 · Workflow S.11–13 · Rule 14

The rights request, from intake to closure

Six stages, each timestamped. The clock you publish is the clock you are held to.

1
Intake
Single published channel; log the arrival time, not the triage time.
2
Verify
Confirm identity using data already held. Do not over-collect.
3
Scope
Identify the right invoked and the systems in play.
4
Execute
Access summary, correction write-back, or erasure cascade.
5
Respond
Plain-language outcome inside the published period, with reasons if refused.
6
Retain
Keep the request record even after the data is erased.
Exhibit 24 · Verification S.15 · Rule 14(1)

Verifying a requester without building a new risk

Over-collection at verification is the most common self-inflicted wound in a rights programme.

Do Use data you hold Authenticate in-session or against the account of record.
Do Escalate proportionately Ask for more only where the request unlocks materially more data.
Avoid New identity documents Collecting an ID to answer an access request creates fresh exposure.
Log The reasoning Record why the verification standard applied was proportionate.
Exhibit 25 · Grievance S.13 · Rule 14 · S.28

From internal grievance to a Board complaint: the escalation ladder

The Board expects internal exhaustion. A grievance mechanism that is hard to find becomes the complainant's best point.

Stage Obligation What we build
Publication Grievance route readily available in the notice and on the site. One canonical page, linked from every notice version.
Acknowledge Confirm receipt and set expectations. Auto-acknowledgement carrying the reference and the published period.
Decide Respond within the period you have published under Rule 14(3) — which may not exceed ninety days. Clock in the tooling, escalation at seventy percent elapsed.
Exhaustion Principal must ordinarily exhaust internal redressal first. Closure letter that states the outcome and the Board route plainly.
Board inquiry Complaint to the Board; inquiry under S.27–28. Case file assembled from the standing evidence, not built from scratch.
Exhibit 26 · Nomination S.14

Nomination: the right nobody has built, and the one families will use

Section 14 has no GDPR analogue, which is exactly why no platform is ready for it. Health, insurance, banking and legacy accounts will see it first.

The first Section 14 request will arrive as a bereavement, not a ticket.S.14
Capture
Nominee designation at onboarding and in account settings, with consent recorded.
Verification
Documented standard for death or incapacity — and who inside the firm may accept it.
Scope of exercise
Which rights the nominee may exercise, and what remains closed to them.
Dignity of process
A route that does not require a grieving family to argue with a chatbot.
Exhibit 27 · Refusal S.12(3) · S.15 · S.17

When a request may lawfully be refused — and how to say so

Refusal is legitimate on narrow grounds and indefensible on convenience. Say which ground, in the response.

01 Legal retention duty Erasure declined where another law requires retention. Cite the law, not the policy.
02 Verification failure Identity not established after a proportionate attempt, and the attempt is logged.
03 False or frivolous request S.15 duty breached — refuse and record the basis, do not merely ignore.
04 Statutory exemption S.17 exemption applies to that processing. Scope the refusal to that data only.
05 Third-party rights Redact another Principal's data rather than refuse the whole request.
06 Never Cost, inconvenience, or a vendor who cannot export. Not grounds. Ever.
Part four · Breach and the clock

The clock does not start when legal is told. It starts when you become aware.

Six exhibits on Section 8(6) and Rule 7 — detection triggers, the hour-by-hour sequence, what goes to the Data Principal versus the Board, and the drill that turns a runbook into a reflex.

Exhibit 28 · Runbook S.8(6) · Rule 7

The Rule 7 sequence, hour by hour

Written to be executed by whoever is awake, not by the person who wrote it. Every step names an artefact.

0
Hour zero · Awareness
Any trigger in Exhibit 30 fires. Log the timestamp and the person. This timestamp is the single most examined fact in any inquiry.
1
Hour 0–2 · Convene and preserve
Incident lead, CISO, counsel, comms. Preserve logs and images before remediation destroys them.
2
Hour 0–6 · Intimate Data Principals
Without delay: nature, extent, timing, likely consequences, mitigation taken, safety steps, and contact details.
3
Hour 0–6 · Initial intimation to the Board
Nature and extent as then known. Filed under uncertainty, not withheld until certainty.
4
Hour 6–72 · Investigate
Sequence of events, root cause, scope of data, processors involved, remediation in flight.
5
Hour 72 · Detailed report
Full Rule 7(2) report to the Board, including the intimations already given and the measures taken to prevent recurrence.
6
After · Close the loop
Control changes, contract changes, board note, and an updated runbook with what actually went wrong.
Exhibit 29 · Clock Rule 7 · Rule 6

Four deadlines you cannot renegotiate

There is no materiality filter. Rule 7(2)(b) lets the Board allow a longer period for the detailed report, but only on a written request — silence is never an extension.

Intimation to Data Principals Without delay
Each affected individual, in plain language, on your own channels.
Initial intimation to the Board Without delay
Nature and extent as known. Silence is the failure, not incompleteness.
Detailed report to the Board 72 hours
Rule 7(2) content in full, from awareness — not from confirmation.
Log retention 1 year minimum
Rule 6 logs and access records, so the sequence can be reconstructed.
Exhibit 30 · Detection S.2(u) · Rule 7(1)

Six triggers that start the clock, whatever the ticket says

Define these in advance and in writing. Deciding at 2 a.m. whether you are aware is how the seventy-two hours are lost.

01 Confirmed unauthorised access Any access, disclosure or loss affecting personal data.
02 Credible third-party report Researcher, customer or journalist with specifics you can verify.
03 Processor notification A vendor tells you. Their clock and yours are not the same clock.
04 Data seen in the wild Sample matching your schema on a forum or paste site.
05 Availability loss Ransomware or destructive failure — loss of access counts.
06 Insider misuse Exfiltration or unauthorised use by staff, including well-intentioned copies.
Exhibit 31 · Content Rule 7(1) v Rule 7(2)

What goes to the Data Principal, and what goes to the Board

Two audiences, two documents, one set of facts. Divergence between them is what an inquiry finds first.

Element To the Data Principal To the Data Protection Board
Description Nature, extent and timing, in plain language. Same facts, with technical specificity and affected record counts.
Consequences Likely consequences for that individual. Assessment of risk across the affected population.
Mitigation What you have done, and what they should do now. Measures implemented, plus remedial measures to prevent recurrence.
Sequence Not required. Broad facts, events, circumstances and reasons leading to the breach, timestamped from awareness.
Attribution Not required. Any findings regarding the person who caused the breach — Rule 7(2)(b)(iv).
Contact A named human who can answer questions. The person responsible for responding on behalf of the Fiduciary.
Proof of intimation Not applicable. Evidence of the intimations given to Data Principals and the channels used.
Exhibit 32 · Exposure Schedule, entries 1 and 2

One incident, two penalty heads

The safeguards failure and the reporting failure are separately penalised. The second is entirely within your control after the fact — which is why late reporting is the costliest choice available.

You may not be able to prevent the breach. You can always prevent the second penalty.Schedule, entries 1 and 2
₹250 crore
Failure to take reasonable security safeguards under S.8(5).
₹200 crore
Failure to intimate the Board or affected Data Principals of a breach.
S.33(2) mitigation
Prompt, complete reporting and remediation are the factors that move quantum down.
The compounding risk
An inquiry into reporting opens the whole file — safeguards, consent, retention.
Exhibit 33 · Rehearsal Practice standard

Six drills, because a runbook nobody has run is a document, not a control

We run these with the actual on-call staff, unannounced, on a working day. Each produces a dated artefact for the file.

1
Awareness drill
Can any of six triggers reach the incident lead inside thirty minutes, at 2 a.m.?
2
Processor drill
A vendor reports at hour 40 of their own investigation. What is your remaining clock?
3
Scope drill
Establish which Principals are affected when logs are partial and backups are stale.
4
Drafting drill
Produce both documents from a live template in ninety minutes, under counsel review.
5
Notification drill
Reach 100,000 Principals on channels you control, and prove you did.
6
Board-facing drill
Answer a follow-up under S.36 without contradicting the 72-hour report.
Part five · Children and guardians

Under eighteen is a child. That single line rewrites Indian product design.

Four exhibits on Section 9, Rule 10 and Rule 12 — the three prohibitions, verifiable parental consent, the Fourth Schedule exemptions, and age assurance that does not become a surveillance programme of its own.

Exhibit 34 · Prohibitions S.9(1)–(3)

Section 9: three prohibitions, one penalty head

₹200 crore under the Schedule. The prohibitions apply to every general-audience product with under-eighteen users, not only to children's apps.

01 No processing without verifiable consent Parent or lawful guardian, verifiably, before processing begins.
02 No detrimental processing Nothing likely to cause any detrimental effect on the wellbeing of the child.
03 No tracking or targeted advertising No behavioural monitoring and no targeted advertising directed at children.
Also Persons with disability Same regime where a lawful guardian acts for a person with disability.
Exhibit 35 · Verification Rule 10

Verifiable parental consent, without a document-collection habit

Rule 10 requires due diligence that the adult is identifiable and is in fact an adult. Design for the minimum that achieves it.

1
Signal that a child is present
Declared age, school context, product surface, or reliable inference.
2
Route to an adult
Separate flow; never let the child self-certify a parent.
3
Verify the adult
Reliable identity details already held, or a virtual token from an authorised issuer.
4
Bind and record
Link guardian to child record; store the verification method, not the document.
5
Re-verify on change
New purpose, or the child attaining eighteen, both require a fresh act.
Exhibit 36 · Exemptions Rule 12 · Fourth Schedule

Where the children's regime relaxes — and exactly how far

The exemptions are purpose-bound. They lift specific obligations for specific classes of Fiduciary, and nothing else.

Class Purpose covered What is still required
Healthcare professionals and facilities Health services to the child. Limited to what the health service needs; safeguards and breach duties unchanged.
Educational institutions Education, and safety on premises and transport. No behavioural advertising; tracking confined to the stated safety purpose.
Childcare providers Care and supervision of the child. Purpose limitation and retention discipline still apply in full.
Transport safety operators Tracking or monitoring for the child's safety in transit. Confined to safety. Not a route to product analytics or marketing.
Allied healthcare professionals Supporting a treatment or referral plan for the child. Limited to what the plan needs for the protection of her health.
Part B purposes — any Fiduciary Legal duties in the child's interest, State benefits, an email-only account, real-time location for safety, blocking detrimental content, and age confirmation under Rule 10. Restricted to the extent necessary for that purpose. Everything else: verifiable parental consent, no tracking, no targeted advertising.
Exhibit 37 · Design S.9 · Rule 10

Age assurance without building a surveillance system

The failure mode is over-correction: collecting identity documents from every user to solve a problem that affects a minority of accounts.

01 Tier by risk Match assurance strength to what the surface exposes a child to.
02 Prefer tokens to documents A virtual token from an authorised issuer beats storing an ID scan.
03 Store the decision Retain the verification outcome and method; discard the underlying evidence.
04 Kill the ad path in code A flag that suppresses targeting, enforced at the ad-call layer, not in policy.
05 Handle the eighteenth birthday Transition from guardian consent to the Principal's own consent, on a schedule.
06 Document what you rejected Record why a heavier method was disproportionate. That memo is the defence.
Part six · Significant Data Fiduciary

Designation is not a badge. It is five additional obligations with an audit attached.

Five exhibits on Section 10 and Rule 13 — the designation factors, the DPIA that survives audit, the India-based DPO, algorithmic due diligence, and how to prepare before a notification arrives rather than after.

Exhibit 38 · Duties S.10(2) · Rule 13

The five additional duties, and the artefact each one produces

Designation adds no new principles. It adds proof obligations with named deliverables and an annual cadence.

Duty What it means in practice Artefact for the file
Data Protection Officer Based in India, representing the Fiduciary, reporting to the board or governing body. Appointment letter, reporting line, published contact details.
Independent data auditor Appoint an auditor to evaluate compliance; audit at the prescribed periodicity. Audit engagement, report, and a management response with dates.
Data Protection Impact Assessment DPIA and audit once in every twelve months from designation; significant observations reported to the Board — Rule 13(1)–(2). DPIA with a risk register and a named owner per mitigation.
Algorithmic due diligence Verify that algorithmic software does not pose a risk to the rights of Data Principals. Model inventory, test methodology, findings, and remediation log.
Transfer restrictions Observe any restriction the Government specifies on transferring specified personal data outside India. Transfer register mapped to data classes and hosting locations.
Exhibit 39 · DPIA S.10(2)(c) · Rule 13

A DPIA that survives an auditor, in six moves

Most DPIAs fail because they describe a system instead of assessing a risk to a person.

1
State the processing
Purpose, data, volumes, Principals affected, retention.
2
Name the risk to the person
Not the risk to the company. Harms, not incidents.
3
Test necessity
Would a lesser data set achieve the purpose? Record the alternative you rejected.
4
Assign mitigations
Owner, control, date. Unowned mitigations are findings.
5
Record residual risk
Accepted by a named person with authority to accept it.
6
Schedule review
Triggered by change, and periodically regardless of change.
Exhibit 40 · DPO S.10(2)(a) · Rule 9

The DPO: a statutory posture, not a job title upgrade

Getting this wrong is visible from outside the company, which makes it a cheap finding for the Board.

Where Based in India Physically in India and representing the Fiduciary.
Who to Reports to the board To the board of directors or equivalent governing body.
Public Contactable Business contact information published under Rule 9 and in every notice.
Risk Conflict of interest Cannot own the processing they must challenge. Document the independence.
Exhibit 41 · Algorithms S.10(2)(c) · Rule 13(3)

Algorithmic due diligence: what to actually test

The duty is to verify that algorithmic software does not pose a risk to Data Principals' rights. That is testable, and the test is the artefact.

System class Risk to the Principal Test that produces evidence
Credit and eligibility scoring Wrongful exclusion; opaque adverse outcomes. Outcome distribution across cohorts; reason-code coverage; appeal path.
Fraud and risk engines False positives that lock a person out of a service. False-positive rate, human-review latency, reversal audit trail.
Recommendation and ranking Behavioural profiling; children exposed to targeting. Feature audit for prohibited signals; under-eighteen suppression test.
LLM features on customer data Purpose creep from support data into training. Data-lineage proof, purpose binding, retention limits, opt-out efficacy.
Biometric and vision systems Misidentification with physical consequences. Error rates by cohort, fallback process, retention of raw captures.
Exhibit 42 · Designation S.10(1)

You cannot self-designate. You can be ready before the notification

The Government notifies on volume and sensitivity of data, risk to Principals, effect on the sovereignty and integrity of India, risk to electoral democracy, and security of the State and public order. None of those are secrets about your own business.

Ask one question: if our data set led the evening news, would the Government be comfortable that nobody was watching it?S.10(1)
Score yourself annually
Volume, sensitivity, cohort exposure, criticality — minuted at board level.
Pre-build the two long-lead items
The DPIA and the audit relationship take quarters, not weeks.
Contract for the auditor early
Independence and capacity both become scarce after a notification wave.
Treat readiness as commercial
Enterprise buyers now ask for SDF-grade artefacts irrespective of designation.
Part seven · Transfers and the supply chain

Section 16 is permissive. Your sectoral regulator may not be.

Four exhibits on cross-border transfer, the transfer register, processor contracting under Rule 6, and the sectoral localisation stack that survives the Act untouched.

Exhibit 43 · Transfers S.16 · Rule 15 · S.17(2)

The negative-list model, and the three conditions layered on it

DPDPA liberalised transfer relative to the 2019 drafts. The constraints that remain are the ones people forget to check.

Layer Rule What to do about it
The Act S.16(1): transfer permitted except to countries restricted by notification. Maintain a register keyed to country, so a notification is a config change.
Sectoral law S.16(2): stricter localisation under other law continues to apply. Map RBI, IRDAI, telecom and government-procurement conditions per data class.
Rule 15 Requirements the Government may specify on making data available to a foreign State. Document lawful-access exposure of each hosting jurisdiction and vendor.
SDF overlay Rule 13(4): specified personal data and its traffic data may be barred from leaving India. Classify data so a class-level restriction can be enforced without a rebuild.
Contract Rule 6(2): security duties flow to processors by contract. One addendum, one standard, applied to every processor including affiliates.
Exhibit 44 · Register S.16 · Rule 13(4)

The transfer register: five fields and nothing else

Five columns, one row per flow. This is the artefact that makes a future restriction survivable.

01 Data class What leaves — mapped to your classification, not to vendor marketing terms.
02 Destination Country, region and legal entity. Sub-processors named.
03 Purpose and basis Why it leaves, and under which lawful basis.
04 Sectoral overlay Any RBI, IRDAI or other localisation condition that bites on this flow.
05 Reversibility Time and cost to repatriate. The number your board will ask for.
Exhibit 45 · Contracts S.8(2) · Rule 6(2)

The processor addendum, in five clauses that matter

Liability does not transfer, so the contract is a control rather than a shield. Write it to be enforced.

1
Purpose lock
Processing only on documented instruction, for the named purpose.
2
Safeguards flow-down
Rule 6 measures specified, not merely appropriate technical measures.
3
Breach clock
Notify you within hours, not within the vendor's own reporting window.
4
Rights assistance
Access, correction and erasure executable inside your published timeline.
5
Exit and erasure
Deletion certificate on termination, including backups, with a deadline.
Exhibit 46 · Sectoral S.16(2) · Sectoral regulation

The localisation stack that DPDPA does not disturb

Where sectoral law is stricter, it governs. A DPDPA programme that ignores the regulator on the other side of the building is only half a programme.

Regulator or regime Constraint Interaction with DPDPA
RBI — payment system data Payment data to be stored in India, with conditions on processing abroad. Survives S.16(2). Stricter standard prevails on that data class.
RBI — outsourcing and IT governance Access, audit and incident-reporting rights over service providers. Align incident timelines so one incident does not produce inconsistent filings.
IRDAI Policyholder records maintained in India. Read together with S.16(2); localisation binds independently of the Act.
Telecom and CERT-In directions Log retention and incident reporting on their own clocks. Two clocks, one incident. Sequence filings so facts cannot diverge.
Government procurement Data-residency conditions in contract, often stricter than statute. Contractual, not statutory — but a breach is a termination event.
Part eight · Exposure and the Board

₹250 crore is the headline. The file is what decides where in the range you land.

Six exhibits on the Schedule, the Section 33(2) quantum factors, Board procedure and appeal, the voluntary undertaking, the non-monetary consequences, and what privilege does and does not protect.

Exhibit 47 · Penalties S.33 read with the Schedule

The Schedule, drawn to scale

Ceilings, not tariffs. The Board determines quantum after inquiry, and per instance — a single programme failure can produce several instances.

Failure to take reasonable security safeguards — S.8(5) Up to ₹250 cr
The largest single head. Attaches to the control failure, whether or not data was misused.
Failure to intimate a personal data breach Up to ₹200 cr
Board or Data Principals. Independent of the safeguards head on the same incident.
Breach of obligations concerning children — S.9 Up to ₹200 cr
Verifiable parental consent, tracking, targeted advertising, detrimental processing.
Breach of additional SDF obligations — S.10 Up to ₹150 cr
DPO, audit, DPIA, algorithmic due diligence, transfer restrictions.
Breach of any other provision or rule Up to ₹50 cr
The residual head. Notice, consent, rights and retention failures land here.
Breach of Data Principal duties — S.15 Up to ₹10,000
Aimed at false and frivolous complaints. Small, but it exists.
Exhibit 48 · Quantum S.33(2)

The six factors that decide where in the range you land

Five of the six are fixed by the time an inquiry opens. The sixth is built in the twelve months before it.

Factor What the Board weighs How the file moves it
Nature, gravity and duration How serious, and for how long. Detection and containment records shorten duration as a matter of proof.
Type of personal data affected Sensitivity in substance, though the Act has no tiers. Classification and minimisation evidence limits what was exposed at all.
Repetitive nature Whether it happened before. A closed remediation log converts a pattern into a single corrected event.
Gain or loss avoided Whether the breach yielded gain or avoided cost. Investment records rebut the inference of deliberate under-spend.
Mitigating action taken What you did, and how fast. Timestamped runbook execution. The single most persuasive exhibit.
Proportionality and effect Whether the penalty is proportionate and effective. Governance evidence: this was a failure inside a functioning system.
Exhibit 49 · Procedure S.27 · S.28 · S.29 · S.36

From complaint to appeal: the procedural spine

The Board functions as a digital office. Filings are documents, and documents are what you will be judged on.

1
Initiation
Complaint, reference or intimation. Board decides whether there are grounds to inquire.
2
Inquiry
S.28 procedure, with civil-court-like powers of summons and discovery. To be completed within six months, extendable three months at a time — Rule 19(9).
3
Information notice
S.36 power to call for information. Your answer must match your 72-hour report.
4
Order
Penalty under S.33, or closure. Reasons recorded in writing.
5
Appeal
To the Appellate Tribunal under S.29, digitally, within the prescribed period.
Exhibit 50 · Settlement S.32

The voluntary undertaking: the only settlement lever in the Act

Accepted by the Board, it bars proceedings on the same subject matter for the term of the undertaking.

When Before or during inquiry Can be offered at any stage; earlier offers read as remediation, not as tactics.
What Committed action, with dates Specific measures and a timetable the Board can monitor.
Effect Proceedings barred No proceedings on that subject matter while the undertaking is complied with.
Risk Non-compliance revives everything Breach of the undertaking is itself actionable. Do not offer what you cannot deliver.
Exhibit 51 · Consequence S.37 · S.44(2)–(3)

The consequences that are not a penalty

Boards budget for the fine and are surprised by everything else. The non-monetary consequences usually arrive first.

The penalty is a number. Losing the enterprise renewal is a business model.S.37 · S.44(2)–(3)
Blocking of access
S.37: on repeated penalty and in the public interest, the Government may direct blocking of a platform.
Enterprise diligence
Buyers now ask for the DPDPA file in security review. No file, no renewal.
Section 43A repealed
The old IT Act compensation route is gone; the Board regime replaces it.
RTI narrowed
S.44(3) amended the RTI personal-information exemption — a change public authorities must absorb.
Exhibit 52 · Privilege Practice standard

What privilege protects in a DPDPA programme, and what it never will

Sequencing matters more than labelling. A gap assessment run as a vendor project is discoverable; the same work run under counsel need not be.

Work product Position How to run it
Legal risk assessment of a gap Capable of privilege. Commissioned by counsel, addressed to counsel, kept out of the operations wiki.
Breach root-cause analysis Split. Two workstreams: a factual remediation record, and a separate privileged legal assessment.
Consent ledger and logs Never privileged. Build them to be shown. Assume every row will be read aloud.
DPIA for an SDF Statutory artefact. Designed for disclosure. Keep the contested legal analysis in a separate memorandum.
Board minutes Disclosable and decisive. Minute the decision and the reasoning. Silence in the minutes reads as absence of governance.
Part nine · Sector positions

The same statute lands differently on a hospital, a lender and a factory.

Four closing exhibits: where the first exposure sits by sector, the fiduciary nobody thinks about, DPDPA in the data room, and what an engagement with us produces.

Exhibit 53 · Sectors S.5–S.16 applied

Where the first exposure sits, sector by sector

Drawn from diagnostics, not from a survey. The first-failure column is where remediation should start.

Sector First failure we find Priority artefact
B2B SaaS Customer data used for product analytics and model training with no basis. Purpose register plus a processor-versus-fiduciary determination per data flow.
BFSI and lending Consent bundled across onboarding, credit, cross-sell and collections. Unbundled consent architecture reconciled with RBI localisation.
Healthcare and diagnostics Reports shared over consumer messaging apps with no record. Channel policy, retention schedule, and a S.7 medical-emergency memorandum.
Edtech and schools Under-eighteen users treated as adults; behavioural advertising live. Verifiable parental consent flow and an ad-suppression flag enforced in code.
D2C and retail Enrichment and lookalike audiences built from purchase history. Consent ledger with per-purpose toggles and a documented vendor list.
Manufacturing and logistics Employee, contractor and driver data held with no basis analysis at all. S.7 employment memorandum plus a CCTV and telematics position.
Public sector and PSU S.7 State-function limbs assumed to cover everything, including vendors. Limb-by-limb basis map and an exemption-scope note under S.17.
Exhibit 54 · Employer S.7 employment limb

The forgotten fiduciary: your own HR and workforce data

No customer-facing product, no privacy team, and the largest volume of sensitive records in the building.

01 Recruitment CVs and assessments retained indefinitely across ATS and email.
02 Background checks Vendor collects more than the role requires; you remain the Fiduciary.
03 Monitoring CCTV, telematics and device logs need their own purpose and notice.
04 Health and benefits Medical records held for insurance, retained long after the claim.
05 Contractors Gig and contract workers are Data Principals with full rights.
06 Exit Erasure on separation, subject to statutory retention. Almost never implemented.
Exhibit 55 · Transactions Diligence practice

DPDPA in the data room: five questions that move price

From May 2027 an unbuilt file is a quantified liability, not a covenant. Ask before the term sheet.

1
Show the purpose register
If it does not exist, no representation about basis can be relied on.
2
Show one consent artefact
Pick a live purpose at random. Reconstruction speed tells you everything.
3
Show the last incident
Detection-to-report timeline, with timestamps.
4
Show the transfer register
Where the data actually sits, including sub-processors.
5
Show the children position
Any under-eighteen users, and whether targeting was ever suppressed.
Exhibit 56 · Engagement AMLEGALS DPDPA practice

What an engagement produces, stated as deliverables

Counsel-led, evidence-first, privileged where privilege is available. No certificate, because none exists.

When the Board writes to you, the only question that matters is whether the file was built before the letter arrived.AMLEGALS DPDPA practice
Diagnostic against these 56 exhibits
Two weeks. Gap register with named owners and dated remediation.
The instruments
Notices, consent architecture, S.7 memoranda, processor addenda, breach runbook, rights workflow.
Rehearsal and sign-off
Breach tabletop, rights drill, board resolution, DPIA where SDF designation is plausible.
Standing representation
Quarterly evidence review, and appearance before the Board and the Appellate Tribunal.
Interactive · Exposure model

Select what failed. See which penalty heads open.

Ceilings under the Schedule, not a prediction of quantum. The Board fixes quantum after inquiry on the Section 33(2) factors.

Interactive · Rule 7 breach clock

Drag the clock. See what the Rules require at that hour.

Hour zero is awareness, not confirmation. Every position on this scrubber has a required action and a document.

00hours from awareness
Within the window
Hour zero · Awareness

The most examined fact in the whole inquiry

Awareness is when any of your defined triggers fires — not when legal is briefed and not when the finding is confirmed. Record the timestamp and the person, because every later deadline is measured from it and the Board will test it against your own logs.

Do now
Timestamp and name
Who knew, what they saw, at what minute. Written, not remembered.
Do now
Preserve before you fix
Image and export logs; remediation frequently destroys the evidence.
Artefact
Awareness record
One line that anchors the intimation and the 72-hour report.
Interactive · Data Principal requests

Walk a rights request through your own organisation

Six stages. At each one, the service level, the action, the artefact it leaves behind, and the way it usually fails.

Intake: log the arrival, not the triage

One published channel, named in every notice version. The clock starts when the request lands, including when it lands in the wrong inbox. Requests that arrive by reply to a marketing email still count.

Clock
When it runs
Starts on arrival. Weekends included.
Owner
Who is accountable
Grievance officer, with the DPO on escalation.
Artefact
What it leaves behind
Timestamped intake record with the channel and the raw text of the request.
Failure
How it usually fails
Multiple undocumented channels, so the true arrival time cannot be proved.
Answers of record

The twelve questions we are asked in every scoping call

Answered against the notified text, with the section or rule stated. If an answer here is wrong, tell us and we will correct it with a dated note.

Ask a thirteenth question →
What is DPDPA compliance?+

The ability to evidence, on any given date, that every purpose for which you process digital personal data was disclosed in an itemised notice under Section 5, rests on consent under Section 6 or a legitimate use under Section 7, is protected by reasonable safeguards under Section 8(5), can be breach-reported under Rule 7 inside the clock, and can be answered when a Data Principal exercises a right under Sections 11 to 14. It is a file, not a certificate.

When does the DPDP Act become enforceable?+

In three phases from the notification of the DPDP Rules on 13 November 2025. Institutional provisions and the Board are live now. Consent Manager registration opens 13 November 2026. The substantive obligations bite on 13 May 2027. The Board can act on conduct from the date each provision commences — not from the date you finish your programme.

Is there a DPDPA certification we can obtain?+

No. The Act creates no accreditation or certification regime and empanels no certifier. A vendor certificate has no statutory standing before the Data Protection Board. What has standing is the record: notices as served, consent artefacts as captured, safeguards as tested, breach logs as timestamped, rights requests as closed.

Does the Act apply to a company outside India?+

Yes. Section 3(b) reaches processing outside India connected with offering goods or services to Data Principals in India. A Delaware SaaS company with Indian subscribers is a Data Fiduciary. There is no revenue, headcount or user threshold for the base obligations — thresholds appear only in Rule 8 retention classes and in Significant Data Fiduciary designation.

What is the penalty exposure for a breach?+

Up to ₹250 crore for failing to take reasonable security safeguards, and up to ₹200 crore for failing to intimate the Board or affected Data Principals. Two separate heads on one incident. Quantum is decided under Section 33(2) — nature, gravity and duration of the breach, the type of data affected, repetitive conduct, gain or loss, and what you did after you found out. The last factor is the only one you can still change today.

How fast must a breach be reported?+

Rule 7 requires intimation to each affected Data Principal without delay, an initial intimation to the Board without delay, and a detailed report to the Board within seventy-two hours of becoming aware. There is no materiality filter and no de minimis carve-out. The operative words are becoming aware — which is why your detection triggers, not your legal opinion, decide when the clock started.

Who becomes a Significant Data Fiduciary?+

Whoever the Central Government notifies under Section 10(1), judged on volume and sensitivity of data, risk to Data Principals, effect on the sovereignty and integrity of India, risk to electoral democracy, security of the State and public order. Designation is not self-assessed, but it is predictable. If your data set would make a national news story, budget for the SDF duties now: DPIA, annual independent audit, algorithmic due diligence, and a DPO based in India who reports to the board.

Can we keep using US and EU cloud regions?+

Under the Act, yes. Section 16 is a negative list: transfer is free except to a country the Government restricts by notification. Two caveats do the real work. Sectoral law is untouched — RBI payment data localisation still binds. And Rule 15 lets the Government attach conditions about making personal data available to a foreign State. Build a transfer register now so that a future notification is a configuration change, not a migration project.

We are GDPR compliant. How much is left to do?+

More than the vendors admit. There is no legitimate-interest basis for a private business, so every purpose you currently run on balancing tests has to move to consent or to a Section 7 legitimate use. Notice must be itemised and available in the languages of the Eighth Schedule to the Constitution. Everyone under eighteen is a child, with verifiable parental consent and a prohibition on tracking and targeted advertising. Breach reporting has no risk threshold. In our experience a mature GDPR programme covers roughly half the DPDPA file.

Do our existing consents survive?+

Only where the original collection can be shown to meet the Section 6 standard and the purpose is unchanged. A bundled tick against a privacy policy is not consent that is free, specific, informed and unambiguous. The practical answer is a triage: keep what is provable, re-paper what is salvageable with a fresh itemised notice, and stop the purposes you cannot defend. Doing that before May 2027 costs a sprint. Doing it during an inquiry costs the inquiry.

Is a privacy tool enough?+

A tool is excellent at doing the same thing a million times and useless at deciding what that thing should be. Software cannot classify a purpose, choose between Section 6 and Section 7, draft a defensible notice, decide whether an incident is a reportable breach, or appear before the Board. Buy the tool for scale. Buy counsel for the positions the tool will execute — and keep the reasoning privileged.

What does an AMLEGALS engagement look like?+

Two weeks of diagnostic against the 56 exhibits on this page, producing a gap register with named owners and a dated remediation plan. Then a build phase: notices, consent architecture, Section 7 memoranda, processor contracts, breach runbook, rights workflow, DPIA where SDF designation is plausible. Then a standing retainer for the file — quarterly evidence review, board reporting, and representation if the Board ever writes to you.

The engagement

Start with the diagnostic. Everything else follows from what it finds.

Two weeks. Fifty-six exhibits tested against your actual processing. One gap register your board can read and your engineers can execute.

Scoping calls are privileged. Nothing you tell us in one becomes a marketing case study.

WEEK 1–2
Diagnostic and gap register
Processing inventory, lawful-basis map, exposure model, owner-by-owner remediation plan.
WEEK 3–10
Build the artefacts
Notices, consent architecture, Section 7 memoranda, processor contracts, breach runbook, rights workflow.
WEEK 11–12
Rehearse and sign off
Breach tabletop, rights-request drill, board resolution, DPIA where SDF designation is plausible.
ONGOING
Hold the file
Quarterly evidence review, change control on new purposes, representation before the Board and the Appellate Tribunal.