Digital Personal Data Protection Act 2023
DPDP Act compliance for Data Fiduciaries, as work you can track.
The obligations that apply to you, referenced to the sections of the Act; the register of what you process and why; the requests people make of you; and the deadlines a breach starts. In one place, with the trail an assessor asks for.
14-day trial · No card required · Priced per workspace, never per seat
- Data Fiduciary obligations
- 17
- Apply to every Data Fiduciary
- 14
- Data principal request types
- 5
- Grievance limit, Rule 14(3)
- 90 days
01The obligations
17 obligations, each referenced to the Act.
The control set every workspace is seeded with. Each obligation comes with what the Act requires in plain words, what to do about it, and what an assessor will ask to see.
Obligations of a Data Fiduciary
Ch. II · 12 obligations- S.4Lawful ground for every processing purposePersonal data may be processed only for a lawful purpose, and only with consent or under a listed legitimate use.
- S.5Notice to the Data PrincipalA notice must accompany or precede a request for consent, stating what is collected, the purpose, how to withdraw, and how to complain.
- S.6Consent that is free, specific, informed and unambiguousConsent must be a clear affirmative action, limited to the data necessary for the stated purpose, and as easy to withdraw as it was to give.
- S.7Legitimate uses relied on are recordedProcessing without consent is permitted only for the specific legitimate uses the Act lists.
- S.8(1)–(2)Accountability for processorsThe Data Fiduciary remains responsible for compliance even where processing is carried out by a Data Processor on its behalf.
- S.8(4)–(5)Reasonable security safeguardsAppropriate technical and organisational measures, and reasonable security safeguards to prevent a personal data breach, must be in place.
- S.8(3)Accuracy where data drives a decisionPersonal data used to make a decision affecting a Data Principal, or disclosed to another Data Fiduciary, must be complete, accurate and consistent.
- S.8(6)Breach intimation to the Board and to those affectedA personal data breach must be intimated to the Data Protection Board and to each affected Data Principal.
- S.8(7)Erasure once consent is withdrawn or the purpose is servedPersonal data must be erased when consent is withdrawn or the purpose is no longer being served, unless retention is required by law.
- S.8(9)Published contact for questions about processingThe contact details of a Data Protection Officer, or of a person able to answer questions about processing, must be published.
- S.9Children: verifiable parental consent, and no trackingProcessing a child’s personal data requires verifiable consent from a parent or lawful guardian, and behavioural tracking or targeted advertising directed at children is not permitted.Children’s data
- S.10Significant Data Fiduciary: DPO, audit, DPIA and due diligenceAn organisation designated a Significant Data Fiduciary must appoint a Data Protection Officer based in India, engage an independent data auditor, and carry out a Data Protection Impact Assessment and periodic audit.Significant Data Fiduciary
Rights of a Data Principal
Ch. III · 4 obligations- S.11Right to access information about processingA Data Principal may obtain a summary of the personal data being processed and the processing activities undertaken.
- S.12Right to correction, completion, updating and erasureA Data Principal may require correction of inaccurate data, completion of incomplete data, and erasure where retention is no longer required.
- S.14Right to nominateA Data Principal may nominate another individual to exercise their rights in the event of death or incapacity.
- S.8(10), S.13Grievance redressalThe Data Fiduciary must establish an effective mechanism to redress grievances (s.8(10)), and a Data Principal has the right to use it (s.13). Grievances are answered within the period the Data Fiduciary publishes; Rule 14(3) sets 90 days as the outer limit.
Processing outside India
Ch. IV · 1 obligation- S.16Transfers to countries outside IndiaPersonal data may be transferred outside India except to a territory the Government restricts by notification.Transfers outside India
Section references follow the numbering of the Act as enacted. Descriptions are plain-language summaries, not the Act’s text.
02Scope
Only what applies to you counts against you.
14 obligations apply to every Data Fiduciary. Three switches decide the rest. An obligation outside your scope is shown, but it leaves the figures: a business that processes no children’s data has not failed the children’s section.
- Significant Data FiduciaryOnly if the Government notifies you as one1 obligation
- Children’s dataOnly if you process children’s personal data1 obligation
- Transfers outside IndiaOnly if personal data leaves India1 obligation
03Register and requests
What you process and why, and what people ask of you.
The processing register
Every purpose for which you process personal data, with what the Act needs recorded against it. The register shows its own gaps, such as a purpose resting on a legitimate use that is not named, or one with no retention period.
- Purpose
- Lawful basis: consent or a legitimate use
- Categories of personal data
- Who receives it
- Retention period
- Why it is kept that long
Data principal requests
One queue for every request, each with a due date that says what kind of deadline it is: the statutory limit for a grievance, and for everything else an internal target your workspace sets (30 days unless you change it).
- accessTarget · 30 days
- correctionTarget · 30 days
- erasureTarget · 30 days
- nominationTarget · 30 days
- grievanceStatutory · 90 days
04Breaches
The clock runs from the moment you became aware, not from when someone remembered.
An incident recognised as a reportable breach carries a statutory clock, timed from the recorded moment of awareness, with reminders as each deadline approaches. A duty with no fixed period is shown as immediate, never given an invented hour count. On the Intelligence plan the notices are drafted from the incident record and checked against it. Nothing is sent for you.
- Intimate the Data Protection Board of IndiaDPDP Act · drafted from the recordWithout delay
- Inform each affected Data PrincipalDPDP Act · drafted from the recordWithout delay
- Send the Board the detailed breach reportDPDP ActWithin 72 hours
- Report the incident to CERT-InCERT-In Directions, where they applyWithin 6 hours
Every drafted figure is checked against the incident record. Anything the record does not say is left blank and listed.
With ISO 27001
ISO evidence is suggested, never assumed.
Where an ISO 27001:2022 control’s evidence genuinely bears on an obligation, Regulane points to it. It never marks a legal obligation met because a security control is: an implemented control is evidence towards an obligation, not proof of it.
When the rules change
MeitY is a registered source.
A change MeitY publishes reaches the same regulatory change register as everything else, banded against your records once the feed is switched on; feeds are switched on one at a time as each publisher’s terms of use are confirmed.
Regulane does not
- Give legal advice. Its assessments are decision support; confirm how the Act applies to you with your adviser.
- Send any notice, intimation or report for you. A person files it and records it.
- Mark an obligation met by itself. Each of the 17 is decided by your team.
Questions
The DPDP Act, answered plainly.
Does Regulane make us DPDP Act compliant?
No software can do that on its own. Regulane holds the Data Fiduciary obligations as work your team can assign, evidence and track, with the processing register, the request queue and the breach deadlines that go with them. Its assessments are decision support, not a legal opinion; confirm how the Act applies to you with your adviser.
Which DPDP Act obligations does Regulane track?
17 Data Fiduciary obligations across 3 chapters of the Act, each referenced to its section. 14 apply to every Data Fiduciary; the rest switch on with your scope: Significant Data Fiduciary, children’s data and transfers outside India.
How does Regulane handle data principal request deadlines?
A grievance carries the outer limit of 90 days set by Rule 14(3). Every other request runs to an internal target your workspace chooses (30 days unless you change it), and each due date says which kind it is, so a target is never mistaken for a legal deadline.
Does Regulane draft the breach intimation to the Data Protection Board?
Yes, on the Intelligence plan. It drafts the intimation to the Board, the notice to the people affected and the detailed report from the incident record only, checks every figure against that record, and leaves blank anything the record does not say. Nothing is sent for you: a person checks the draft, files it and records it on the breach clock.
Where does Regulane hold our data, given the DPDP Act?
Regulane’s application servers run in Singapore and workspace records are held in a database in the United States (AWS us-east-1). The DPDP Act permits transfers outside India except to countries the Government restricts by notification. Every processor is named in the privacy notice.
Keep reading
- ISO 27001Annex A, clauses 4–10, the Statement of Applicability and audit preparation.
- SecurityWhere your data lives, what the code enforces, and what we do not claim.
- Regulatory IntelligenceWhich regulatory changes name something you run, and why.
- PricingPer workspace, never per seat. Published, not quoted.
Regulation changes every week. Your compliance programme should know what changed, and what to do next.
14-day trial · No card required · Per workspace, never per seat
