Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment

DPDP Act by role

DPDP Act for Developers and Engineering Teams

The DPDP Act is a set of requirements you build into the product. Here is what to implement.

Understand. Check. Connect.

We match you with the right DPDP implementation partner, only when you ask.

At a glance

Developers and engineering teams turn DPDP Act obligations into product reality: consent capture and withdrawal, data minimisation, deletion and correction, secure storage and logging, data mapping across services and third-party SDKs, and breach detection. Privacy-by-design is the cheapest path, because building it in beats retrofitting.

What the DPDP Act means for you

Most DPDP Act requirements ultimately land on engineering: how consent is captured and revoked, whether a user can actually be deleted, what your logs and third-party SDKs collect, and how a breach is detected and contained. Treating privacy as a design constraint rather than a bolt-on keeps the work small and avoids expensive rework later.

Your priorities

Consent and withdrawal

Build granular consent capture and a withdrawal that is as easy as opt-in, with an audit trail.

Minimisation and mapping

Collect only what you need, and keep a live map of where personal data flows, including SDKs and APIs.

Deletion and correction

Implement real erasure and correction across your services, not just a soft flag in the UI.

Security and breach detection

Encrypt, control access, log, and be able to detect and contain a breach quickly.

Where to start

Map data flows

Document where personal data enters, lives and leaves, including third parties.

Build consent

Ship granular consent capture and an easy withdrawal with an audit trail.

Implement deletion

Make erasure and correction real across primary stores and downstream services.

Harden and monitor

Encrypt, restrict access, log, and add breach detection.

Tools and help

Move fast with ready-made resources, or get expert help where it matters:

Frequently asked questions

What does privacy-by-design mean in practice?
Building data minimisation, consent, deletion and security into the product from the start, so compliance is a property of the system rather than a manual process.
Do third-party SDKs count?
Yes. Any SDK or API that receives personal data is part of your processing, so map it, minimise it, and bind the provider contractually.
How do we handle deletion requests technically?
You need real erasure across primary stores, a backups policy and downstream services, not just hiding a record in the interface.

See where you stand

Take the free readiness assessment for a picture tailored to your organisation, then choose a tool or a partner.

Start free readiness assessmentSee the Compliance Toolkit

This page is educational and not legal advice. Confirm against the enacted Act and the DPDP Rules, or take professional advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.