Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment
SaaS & Technology · Developer tools

The DPDP Act for Developer Tools

SDKs, APIs and analytics quietly collect telemetry and end-user data inside your customers apps.

In short

Developer tools, SDKs, APIs and analytics collect telemetry and end-user data inside other apps, which usually makes you a Processor with real exposure. Penalties reach ₹250 crore.

Core impacts

What changes for this sub-sector.

Telemetry is personal data

Device IDs, IPs and usage events can identify people and count as personal data.

Processor for embedded data

Inside a customer app you are a processor; act only on instructions under contract.

Consent pass-through

Make it clear what your SDK collects so the host app can obtain and document consent.

Minimise SDK data

Default to collecting the minimum; give developers switches to reduce it further.

Security of collected data

Protect the telemetry and events you gather in transit and at rest.

Onward transfer

Disclose where SDK data goes and who else processes it.

Check your SDK and API data.

The readiness check flags telemetry, consent-passthrough and transfer gaps.

Take the readiness check →