Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment
Industry

The DPDP Act for NGOs & Non-profits

Donor records, beneficiary case files and volunteer rosters are all personal data. Charitable purpose does not exempt you from the Act.

In short

An NGO that decides why and how it collects donor, beneficiary or volunteer data is a Data Fiduciary under the DPDP Act, with the same core duties as any company: lawful consent, data minimization, security and breach reporting. There is no blanket exemption for charities. Where you serve children or vulnerable groups, or receive foreign grants, extra duties apply.

What the Act asks of you

The obligations that most often bite for non-profits.

Consent for donors and beneficiaries

Fundraising lists, donation receipts and beneficiary intake all need a clear purpose and consent. A donor consenting to a receipt has not consented to years of appeal mail.

Collect only what the programme needs

Field teams often gather far more than required. Tie every field on an intake form to a stated purpose, and drop identity documents you do not truly need to keep.

Extra care for children and vulnerable groups

Programmes for children under 18 trigger verifiable parental consent and a ban on tracking or targeting. Case data on at-risk adults is high-risk and needs tighter access.

Foreign grants and cross-border donors

Sharing beneficiary or donor data with an overseas funder, HQ or platform is a cross-border transfer. It is allowed by default, but grant agreements and any sectoral rules still bind you.

A path to readiness

The same five moves, sized for a non-profit.

Step 1

Map your data

List donor, beneficiary, volunteer and staff data, and where each lives.

Step 2

Fix consent

Rework donation and intake forms so each purpose is clear and separable.

Step 3

Minimize

Stop collecting documents you do not need; set retention for what you keep.

Step 4

Secure

Limit who can open case files; encrypt exports and backups.

Step 5

Respond

Be ready to honour access and erasure requests and to report a breach.

See where you stand.

Run the free readiness check for a gap report sized to your organisation.

Understand. Check. Connect.

We match you with the right DPDP implementation partner, only when you ask.

Take the readiness check →

See the DPDP implementation framework →