Browse by workflow
People do not think in sections of an Act, they think in tasks. Pick what you need to do and this page routes you straight to the governing provision, the terms that explain it, and the tool for the job. Every task is a step toward the Consent Manager framework on 14 November 2026 and full DPDP compliance by 13 May 2027.
Get lawful consent and notice in place before you process anything.
Before asking for consent, a Data Fiduciary must give a standalone notice stating the personal data collected, the specified purpose, how to exercise rights, and how to complain to the Board. Write it in clear, itemised language, in English or any Eighth Schedule language.
Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the data the purpose needs. Where a listed situation applies, you may instead rely on a certain legitimate use without fresh consent.
Before processing anyone under 18, obtain verifiable parental or guardian consent, and never track, behaviourally monitor, or serve targeted advertising to children. Breaching this carries a penalty up to two hundred crore rupees.
Serve the requests people are entitled to make, and retire data on time.
On request you must give a summary of the personal data you process and who it was shared with, and correct, complete, update or erase it, within the timelines the Rules set.
A person can withdraw consent at any time, and it must be as easy to withdraw as it was to give. On withdrawal, stop processing and make your processors stop, unless another lawful basis applies.
Erase personal data once consent is withdrawn or the specified purpose is no longer served, whichever is earlier, and make your processors erase it too, unless a law requires you to keep it.
Protect the data you hold, and disclose fast when something goes wrong.
Protect all personal data you hold or control, including data handled by your processors, with reasonable security safeguards to prevent a breach. Weak security carries the highest penalty on the Schedule, up to two hundred and fifty crore rupees.
After any personal data breach, notify both the Data Protection Board and every affected individual in the prescribed form and manner. Accidental disclosure and loss of access both count as breaches.
Stand up the roles and evidence the Act expects of higher-risk fiduciaries.
A Significant Data Fiduciary must appoint an India-based Data Protection Officer, answerable to its governing body, as the contact point for the grievance mechanism.
A Significant Data Fiduciary must appoint an independent data auditor and run periodic Data Protection Impact Assessments that assess and manage the risks to data principals' rights.
You may engage a processor only under a valid contract, and you stay responsible for its compliance, so vet its security and instructions before you sign. The duty cannot be contracted away.
Know your exposure and what happens if the Board comes knocking.
Map where you stand against every obligation, consent, notice, rights, security, breach, retention and governance, ahead of the Consent Manager framework on 14 November 2026 and full compliance by 13 May 2027.
Penalties are set by the Schedule and imposed by the Board for significant breaches, up to two hundred and fifty crore rupees for weak security and two hundred crore for breach or children's failings.
The Board inquires into breaches and complaints and can impose penalties after a hearing. You can also offer a voluntary undertaking to resolve a matter before it proceeds.
You may transfer personal data outside India unless the government notifies a country or territory as restricted, and any stricter sector law continues to apply.
The regulated intermediary role, and how to qualify for it.
A Consent Manager must be a company incorporated in India, registered with the Data Protection Board, running an accessible, interoperable platform where people give, manage, review and withdraw consent. The framework becomes operational on 14 November 2026.