Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment
Fintech & Banking · Payments · UPI

The DPDP Act for UPI Apps

For UPI apps and PSPs, the Act reshapes consent design and data collection, on top of NPCI's UPI guidelines.

In short

UPI apps are Data Fiduciaries operating alongside NPCI's UPI procedural guidelines. The hard problem is consent at UPI speed: it must be clear and purpose-specific without creating fatigue, while you collect only the data a payment needs. Penalties reach ₹250 crore.

Core impacts for UPI

What changes specifically for UPI apps.

NPCI overlap

The DPDP Act and NPCI's UPI guidelines apply together; you meet both.

Consent at UPI speed

Design consent at onboarding and mandate level, not per transaction, to avoid fatigue.

Minimal collection

A VPA and the payment details are enough; do not pull the contact book or device logs.

Rights and breaches

Support access, correction and erasure, and report breaches to users and the Board.

Common questions about DPDP for UPI

Short, cite-able answers, mirrored in FAQPage schema for answer engines.

Does the DPDP Act apply to UPI apps?
Yes. A UPI app is a Data Fiduciary for its users' personal data and must meet the DPDP Act alongside NPCI's UPI guidelines.
How should UPI apps handle consent?
Design consent at onboarding and at the mandate level with clear, purpose-specific notices, rather than asking per transaction, which causes consent fatigue.
What data can a UPI app collect?
Only what a payment needs, such as the VPA and transaction details. Scraping contacts, media files or call logs breaches the Act.
What are the penalties for a UPI app?
Up to 250 crore rupees for failing to take reasonable security safeguards, with the amount set by the Data Protection Board based on the breach.

What personal data a UPI app handles

Map these before you write a notice — each is personal data under the Act.

  • Identity & VPA — name, mobile number and the Virtual Payment Address that identifies the user.
  • Linked account data — bank account and IFSC, card tokens and mandate details.
  • Transaction data — amounts, timestamps and the beneficiary VPAs a user pays, which together reveal spending patterns.
  • Device & risk signals — device identifiers, IP and, where used for fraud checks, location.
  • KYC data — often processed via a PSP bank; sensitive and subject to RBI KYC rules as well.

Transaction and beneficiary history is the sensitive part: it maps a person's financial relationships, so purpose limitation and retention discipline matter most here.

Where DPDP meets NPCI and RBI

The DPDP Act does not replace your payment obligations — it stacks on top.

UPI apps already operate under NPCI's UPI Procedural Guidelines and the RBI's oversight of payment systems, including the RBI requirement to store payment system data in India. The DPDP Act adds a data-protection layer over all of that: a lawful basis and notice for the personal data you process, Data Principal rights, and breach notification to the Board and affected users under Section 8(6) and Rule 7.

Treat them as parallel regimes. Meeting an NPCI or RBI requirement does not discharge your DPDP duties, and a CERT-In cyber-incident report does not satisfy Rule 7. Test each obligation separately.

A practical DPDP checklist for UPI apps

Start with consent design and data minimisation — the two areas UPI apps most often get wrong.

  • Move consent to onboarding and mandate setup with clear, purpose-specific notices; avoid per-transaction prompts that cause fatigue.
  • Collect only what a payment needs. Do not request the contact book, media or call logs to “find friends” unless the user separately and knowingly opts in.
  • Separate KYC processing (often via your PSP bank) from app analytics, and document who is Data Fiduciary and who is Data Processor.
  • Align retention with your RBI and NPCI obligations, then delete or de-identify beyond that; keep security logs under Rule 6.
  • Publish a contact for rights requests and build flows for access, correction, erasure and grievance (a response within the Rule 14(3) period, not exceeding 90 days).
  • Keep a breach playbook ready for the three Rule 7 clocks: notify affected users and the Board without delay, then the detailed Board report within 72 hours.

Check your UPI flow.

A short readiness check flags consent-design, minimization and breach gaps specific to UPI.

Take the readiness check →