Ch IPreliminary
S.1 Short title and commencementS.2 DefinitionsS.3 Application and scopeCh IIObligations of Data Fiduciary
S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data FiduciaryCh IIIRights and duties of Data Principal
S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data PrincipalCh IVSpecial provisions
S.16 Transfer outside IndiaS.17 ExemptionsCh VData Protection Board of India
S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the ChairpersonCh VIBoard powers and procedure
S.27 Powers and functions of the BoardS.28 Procedure followed by the BoardCh VIIAppeal and dispute resolution
S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertakingCh VIIIPenalties
S.33 Penalties and the ScheduleS.34 Penalties to Consolidated FundCh IXMiscellaneous
S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other ActsObligation
A Data Protection Impact Assessment (DPIA) is a periodic risk process that Significant Data Fiduciaries must run to assess and manage risks to Data Principals' rights.
TL;DR
A Data Protection Impact Assessment, or DPIA (Section 10(2)(c)), is a periodic, structured risk process that Significant Data Fiduciaries must run to assess and manage risks to Data Principals' rights. It sits alongside the independent audit obligation.
periodic Data Protection Impact Assessment, which shall be a process comprising a description of the rights of Data Principals and the purpose of processing of their personal data, assessment and management of the risk to the rights of the Data Principals, and such other matters as may be prescribed.
A DPIA is a structured look at what could go wrong. It describes the rights involved and the purpose of processing, then assesses and manages the risks to those rights.
It is a periodic obligation for Significant Data Fiduciaries, sitting alongside independent audits under Section 10(2).
Before launching a large new data-driven feature, a notified SDF runs a DPIA to map and mitigate the risks to users.
Who must run a DPIA?
Significant Data Fiduciaries, periodically, under Section 10(2)(c).
What does a DPIA cover?
The rights involved, the purpose of processing, and assessment and management of risks to those rights.
Consultant-led and partner-backed.