Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment

DPDP Act by role

DPDP Act for Data Protection Officers (DPO)

You own the data protection programme. Here is what the DPDP Act expects you to build, run and be able to evidence.

Understand. Check. Connect.

We match you with the right DPDP implementation partner, only when you ask.

At a glance

A Data Protection Officer under the DPDP Act owns the compliance programme: the record of processing, privacy notices, consent, breach response, rights handling and, for Significant Data Fiduciaries, board reporting, independent audits and Data Protection Impact Assessments under Section 10. The DPO is the point of contact for Data Principals and the Data Protection Board.

What the DPDP Act means for you

As a DPO you are accountable for the organisation's DPDP Act programme end to end. That means building the documentation, running the operational processes, and being able to evidence compliance to leadership, to Data Principals, and, if you are a Significant Data Fiduciary, to an independent auditor and the Board.

Your priorities

Record of processing

Own an accurate, living record of processing. It drives your notice, retention and rights responses.

Breach response

Run a plan that meets the Rules: intimate the Board and affected people without delay, with a detailed report in 72 hours.

Rights and grievances

Operate a reliable process for access, correction, erasure, nomination and grievances.

Section 10 duties

If you are an SDF: a DPO reporting to the board, an independent audit, and periodic impact assessments.

Where to start

Audit current state

Take the readiness assessment to see where the gaps are.

Build the core docs

Stand up the record of processing, notice and consent records.

Operationalise

Put breach response and rights handling into live processes.

Schedule assurance

If you are an SDF, plan your DPIA and independent audit.

Tools and help

Move fast with ready-made resources, or get expert help where it matters:

Frequently asked questions

Who must appoint a DPO under the DPDP Act?
Significant Data Fiduciaries must appoint an India-based DPO who reports to the board or governing body. Other fiduciaries must still publish a point of contact, and many appoint or outsource a DPO anyway.
What does a DPO actually own?
The programme: the record of processing, notices, consent, processor contracts, breach response, rights handling and, for SDFs, audits and impact assessments.
Can the DPO role be outsourced?
Yes. A virtual DPO or DPO-as-a-service is common, especially where you need the expertise without a full-time hire.

See where you stand

Take the free readiness assessment for a picture tailored to your organisation, then choose a tool or a partner.

Start free readiness assessmentSee the Compliance Toolkit

This page is educational and not legal advice. Confirm against the enacted Act and the DPDP Rules, or take professional advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.