Each section or rule is checked against the Act (Act No. 22 of 2023) and the DPDP Rules 2025 (G.S.R. 846(E)). Plain-language summary. Get legal advice for your situation. The toolkit's Reality Check workbook adds a status for every duty, its penalty category, the Significant Data Fiduciary rating and a dashboard of your gaps, and feeds the Compliance Timeline.
When do these apply?
The Act and the Rules start in stages, and both notifications are dated 13 November 2025 (G.S.R. 843(E) for the Act, G.S.R. 846(E) for the Rules). In force from that date: Rules 1, 2 and 17 to 21, and Sections 1(2), 2, 18 to 26, 35, 38 to 43 and 44(1) and (3) of the Act. One year after publication, on 13 November 2026: Rule 4 (Consent Managers), and Sections 6(9) and 27(1)(d) of the Act. Eighteen months after publication, on 13 May 2027: Rules 3, 5 to 16, 22 and 23, and Sections 3 to 5, 6(1) to (8) and (10), 7 to 10, 11 to 17, 27 (except 27(1)(d)), 28 to 34, 36, 37 and 44(2) of the Act. Every duty listed below is in that last group.
Notice given to Data Principal before/at consent
Before or when you ask for consent, give a notice that makes sense on its own and lists, item by item, the personal data you want and what you will use it for. It must give a link to your website or app and the ways to withdraw consent, use their rights and complain to the Board, and give the option to read it in English or any language in the Eighth Schedule to the Constitution. People who consented before the Act took effect must get a notice as soon as reasonably practicable.
Source: Act S.5(1)-(3); Rule 3
Consent is free, specific, informed, unconditional and unambiguous
Where you rely on consent, it must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the personal data needed for the purpose stated in your notice. Any part of a consent that breaks the Act or another law is invalid.
Source: Act S.6(1)-(2)
Reasonable security safeguards (technical + organisational)
Protect personal data in your possession or under your control, including processing a Data Processor does on your behalf, with reasonable security safeguards to prevent a breach. Rule 6 sets seven minimums: data security measures (encryption, masking and tokens are given as examples), access control, logs with monitoring and review, backups or other ways to keep processing going, keeping those logs and personal data for a period of one year, security terms in your contracts with Data Processors, and measures that make the safeguards work in practice.
Source: Act S.8(5); Rule 6(1)
Breach intimation to the Board
On becoming aware of any personal data breach (the law sets no size or harm threshold), tell the Board without delay what happened, its extent, timing and location, and the likely impact. Within 72 hours of becoming aware, send the Board a detailed report: updated facts and causes, steps to reduce risk, any findings on who caused it, steps to prevent a repeat, and a report on the notices sent to affected people. If you need more time, ask the Board in writing; it may allow a longer period.
Source: Act S.8(6); Rule 7(2)
Breach intimation to affected Data Principals
On becoming aware of any personal data breach, tell each affected person without delay, briefly and in plain words, through their user account or a contact method they registered with you. Say what happened and when, what it may mean for them, what you are doing about it, what they can do to protect themselves, and who to contact.
Source: Act S.8(6); Rule 7(1)
Erasure when the purpose ends or consent is withdrawn (a written retention schedule is good practice)
Erase personal data, and make your Data Processor erase any it was given, as soon as consent is withdrawn or the purpose is no longer served, unless a law requires you to keep it. Personal data and logs covered by Rule 8(3) must still be kept for at least one year from processing (see duty 17). E-commerce and social media platforms with 2 crore or more registered users in India, and online gaming platforms with 50 lakh or more, must, for most purposes (access to the user account and to stored virtual tokens is excluded), erase three years after the person last made contact or the Rules commenced, whichever is later, unless a law requires keeping it, and warn the person at least 48 hours before.
Source: Act S.8(7)-(8); Rule 8; Third Schedule
Published DPO/contact-person details
Prominently publish on your website or app the business contact details of your Data Protection Officer, if the law requires you to have one, or of a person who can answer questions about how you process personal data. Repeat them in every reply to a rights request.
Source: Act S.8(9); Rule 9
Grievance redressal mechanism (incl. response period)
Set up an effective, readily available way for people to raise grievances about how you handle their personal data or their rights. Prominently publish on your website or app the period in which you will respond, which must be reasonable and no more than 90 days, then respond within it, with technical and organisational measures in place so you can. People must use your process before they can complain to the Board.
Source: Act S.8(10), S.13; Rule 14(3)
Children's data: verifiable parental consent
A child is anyone under 18. Before processing a child's personal data, get verifiable consent from a parent or lawful guardian, and check that the person is an identifiable adult, using reliable identity and age details you already hold, or identity and age details they provide voluntarily, directly or through a virtual token issued by an authorised entity (this includes details made available and verified by a Digital Locker service provider). The Rules exempt some types of business and some purposes.
Source: Act S.9(1), S.9(4); Rules 10, 12
Children's data: no tracking, behavioural monitoring or targeted advertising
Do not track or monitor the behaviour of anyone under 18, and do not aim targeted advertising at them. The Rules exempt some types of business, such as health providers, schools and crèches, and some purposes, each only within stated conditions. Separately, Act S.9(2) bars any processing of a child's personal data that is likely to harm the child's well-being, and the Rules do not exempt that.
Source: Act S.9(2), S.9(3), S.9(4); Rule 12; Fourth Schedule
SDF: India-based DPO appointed (if notified as SDF)
If the Government notifies you, or a class of businesses you belong to, as a Significant Data Fiduciary, appoint a Data Protection Officer: an individual based in India who represents you under the Act, is responsible to your board of directors or similar governing body, and is the point of contact for your grievance redressal mechanism.
Source: Act S.10(1), S.10(2)(a)
SDF: independent data audit (if notified as SDF)
If notified as a Significant Data Fiduciary, appoint an independent data auditor to evaluate your compliance with the Act. The Rules also require an audit once in every 12 months, counted from the date you were notified, and you must have the person who carries it out send the Board a report of significant observations.
Source: Act S.10(2)(b), S.10(2)(c)(ii); Rule 13(1)-(2)
SDF: periodic DPIA (if notified as SDF)
If notified as a Significant Data Fiduciary, carry out a periodic Data Protection Impact Assessment: describe people's rights and the purpose of processing their personal data, and assess and manage the risk to those rights. The Rules require one once in every 12 months from the date you were notified, and you must have the person who carries it out send the Board a report of significant observations.
Source: Act S.10(2)(c)(i); Rule 13(1)-(2)
Data Principal rights process (access/correction/erasure)
Where a person gave you consent, or voluntarily gave you their data for a specified purpose (Act S.7(a)), let them ask for a summary of their personal data and your processing of it, and the identities of the other Data Fiduciaries and Data Processors you shared it with. Let them ask you to correct, complete, update or erase it; you may keep data that is needed for the specified purpose or to comply with a law. Publish how to make a request and what identifier you need to find them.
Source: Act S.11, S.12; Rule 14(1)-(2)
Nomination mechanism
Let a person nominate one or more individuals to exercise their rights if they die, or become unable to exercise those rights because of unsoundness of mind or infirmity of body. Publish the means for making a nomination.
Source: Act S.14; Rule 14(1)(a), 14(4)
Cross-border transfer compliance (notified-country check)
You may transfer personal data outside India, except to a country or territory the Government has restricted by notification. Any other Indian law that gives higher protection or restricts transfers further still applies. If the Government sets requirements by order for making personal data available to a foreign State, or to an entity under its control or one of its agencies, you must meet them.
Source: Act S.16(1)-(2); Rule 15
Log/traffic-data retention (>=1 year)
Two separate one-year rules. Rule 6(1)(e), part of your security safeguards: keep the access logs and the personal data for a period of one year, so that unauthorised access can be detected, investigated and fixed and processing can continue after a compromise, unless a law requires otherwise. Rule 8(3): keep personal data, associated traffic data and other logs of each processing, including processing a Data Processor does on your behalf, for a minimum of one year from the date of that processing, for the Government purposes in the Seventh Schedule (security of the State, functions and disclosures under law, and assessing Significant Data Fiduciaries). Then erase them, unless another law or a Government notification requires longer.
Source: Rule 6(1)(e); Rule 8(3); Seventh Schedule
Data Processor contracts in place
You remain responsible under the Act for processing a Data Processor does on your behalf, whatever your contract says. Engage a Data Processor for activities related to offering goods or services to people only under a valid contract, and where applicable that contract must provide for reasonable security safeguards. When you must stop processing or erase data, you must also make your Data Processor do so.
Source: Act S.6(6), S.8(1), S.8(2), S.8(7)(b); Rule 6(1)(f)
Good practice, not a legal duty
Data map / record of processing (good practice, not a legal duty)
Not a legal duty: neither the Act nor the Rules require a Data Fiduciary to keep a record of processing. The toolkit keeps it as good practice, because a person can ask for a summary of their data and the identities of everyone you shared it with (Act S.11(1)), and you must prove notice and consent if challenged in a proceeding (Act S.6(10)).
Source: No named provision (good practice). Supports Act S.6(10), S.8(4), S.11(1)(a)-(b)
Consent withdrawal mechanism and proof of consent
Where consent is your basis for processing, let people withdraw it as easily as they gave it, and give the means in your notice. After withdrawal, stop processing, and make your Data Processors stop, within a reasonable time, unless the Act or another law requires or authorises the processing. If consent is questioned in a proceeding, you must prove that notice was given and consent obtained (Act S.6(10)).
Source: Act S.6(4), S.6(6), S.6(10); Rule 3(c)(i)
The Significant Data Fiduciary duties above are not the full set. Rule 13(3) adds due diligence that the algorithmic software it uses is not likely to pose a risk to people's rights. Rule 13(4) adds measures so that personal data the Government specifies, and its traffic data, is not transferred outside India. Act S.10(2)(c)(iii) allows further measures to be prescribed.
A drafting aid. Get legal advice for your situation.
To check these against your own business, start with step 1 of the toolkit.