Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment
Manufacturing · IoT

The DPDP Act for IoT & Connected Products

Connected products stream usage, location and sometimes household data back from the field.

In short

If it identifies a person, the Act applies: consent in the product, minimization by design, and security across the device fleet. Penalties reach ₹250 crore.

Core impacts

What changes for this sub-sector.

Device data is personal data

Usage, location and identifiers from connected products can identify people.

Consent in the product

Build notice and consent into device setup, not buried in a portal.

Minimization by design

Collect the least the product needs; avoid always-on capture you cannot justify.

Firmware and security

Secure devices and update paths; unpatched fleets are a breach risk.

Rights at scale

Support access and erasure for data tied to devices and accounts.

Processors

Cloud, analytics and connectivity partners are processors.

Check your device fleet.

The readiness check surfaces consent, minimization and firmware gaps.

Take the readiness check →