Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment

Obligation

Data Protection Impact Assessment

A Data Protection Impact Assessment (DPIA) is a periodic risk process that Significant Data Fiduciaries must run to assess and manage risks to Data Principals' rights.

Defined inSection 10(2)(c)
CategoryData Lifecycle & Security
Applies toSignificant Data Fiduciaries

TL;DR

A Data Protection Impact Assessment, or DPIA (Section 10(2)(c)), is a periodic, structured risk process that Significant Data Fiduciaries must run to assess and manage risks to Data Principals' rights. It sits alongside the independent audit obligation.

What Does the DPDP Act Say About Data Protection Impact Assessments?

DPDP Act 2023, Section 10(2)(c)

periodic Data Protection Impact Assessment, which shall be a process comprising a description of the rights of Data Principals and the purpose of processing of their personal data, assessment and management of the risk to the rights of the Data Principals, and such other matters as may be prescribed.

What is a Data Protection Impact Assessment in Simple Words?

A DPIA is a structured look at what could go wrong. It describes the rights involved and the purpose of processing, then assesses and manages the risks to those rights.

It is a periodic obligation for Significant Data Fiduciaries, sitting alongside independent audits under Section 10(2).

Data Protection Impact Assessment: Example

Before launching a large new data-driven feature, a notified SDF runs a DPIA to map and mitigate the risks to users.

Related terms

Related sections of the Act

Related Rules

Data Protection Impact Assessment: Frequently Asked Questions

Who must run a DPIA?

Significant Data Fiduciaries, periodically, under Section 10(2)(c).

What does a DPIA cover?

The rights involved, the purpose of processing, and assessment and management of risks to those rights.

Continue learning