India DPDP Act
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
DPDP Act Scope + Sections 1-3 + Definitions
Digital Personal Data Protection Act 2023 (DPDP Act) Act No. 22 of 2023 was passed by the Indian Parliament + received the assent of President Droupadi Murmu on 11 August 2023 + published in the Gazette of India Extraordinary Part II Section 1 on 12 August 2023. India first comprehensive personal data protection law providing a statutory framework for processing digital personal data within India. Constitutional basis: 9-judge Supreme Court Constitution Bench unanimous judgement in Justice K.S. Puttaswamy (Retd.) v. Union of India + Anr. (2017) 10 SCC 1 declaring Right to Privacy as a fundamental right under Article 21 of the Constitution. The Act repeals Section 43A of Information Technology Act 2000 and IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 (SPDI Rules) which previously governed personal data. Section 1 Short Title + Ext
- DPDP applicability assessment + in-India processing + extraterritorial + goods/services + records
- Section 43A IT Act + SPDI Rules 2011 migration + DPDP compliance program transition
- Constitutional privacy awareness + Puttaswamy + privacy by design + records
- DPDP Rules 2025 compliance + manner of notice + consent + CM registration + records
- Roles mapping + Data Fiduciary + Processor + Principal + Child + SDF + Consent Manager + records
- DPDP applicability not assessed for extraterritorial activities
- Still operating per SPDI Rules 2011 (Act 43A repealed but compliance program unchanged)
- Constitutional privacy basis not understood (treating as compliance overhead)
- DPDP Rules 2025 not integrated (operating per Act alone)
- Roles unclear (Data Fiduciary vs Processor vs Principal not mapped)
DPDP Children + PwD (Sec 9)
Section 9 of DPDP Act 2023 establishes special protections for children and persons with disability. Section 9(1) Children: Data Fiduciary shall before processing any personal data of a child or a person with disability who has a lawful guardian obtain verifiable consent of the parent of such child or the lawful guardian. The Data Fiduciary shall obtain consent in such manner as may be prescribed. Section 9(2) Prohibition Children: Data Fiduciary shall not undertake such processing of personal data that is likely to cause any detrimental effect on the well-being of a child. Section 9(3) Prohibition Tracking + Targeted Ads: Data Fiduciary shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children. Section 9(4) Exemption: Central Government may by notification exempt the processing of personal data by certain classes of Data Fiduciaries
- Age verification + parental consent + verifiable + Aadhaar eKYC + records + audit
- Safety by design + child-friendly UX + content moderation + records + DPIA child impact
- No tracking + no targeted ads + content moderation + records + audit + verification
- Notified exemption monitoring + conditions compliance + records
- PwD lawful guardian consent + mature minor exception + best interest + records
- Age verification token-only (no real verifiable parental consent)
- Safety by design not assessed (children using adult-targeted features)
- Tracking + targeted ads still applied to children (privacy violation)
- Exemptions claimed without notification or compliance with conditions
- PwD guardian consent not obtained (treats all adults uniformly)
DPDP Cross-Border + Breach (Sec 16-17)
Sections 16-17 of DPDP Act 2023 address cross-border transfer + breach notification. Section 16 Processing of Personal Data Outside India: Central Government may by notification restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be notified - effectively a negative list approach where transfers are permitted by default to all countries except those that the Government specifies as blacklisted/restricted. This is a SOFTER approach than GDPR Chapter V (which requires adequacy decisions or appropriate safeguards) + reflects India India-Stack-driven approach to global digital commerce. Sub-section (2): Where any other law for the time being in force in India provides for a higher degree of protection or restriction on the transfer of personal data by a Data Fiduciary outside India + the provisions of such law shall prev
- Cross-border transfer assessment + negative list monitoring + records + per-territory
- Sectoral overlay + RBI data localisation + payment data + AA + records + compliance map
- Breach notification procedure + 72h DPBI + content items per DPDP Rules 2025 + records
- Affected Data Principal intimation + form + channel + records + statistics
- Multi-regulator reporting matrix + CERT-In 6h + DPDP 72h + RBI + records
- Cross-border transfer without negative list monitoring (transfer to blacklisted territory)
- Sectoral higher protection ignored (RBI/AA data localised but DPDP-only mindset)
- Breach 72h missed (treating as informational rather than mandatory)
- Affected Data Principal intimation skipped (only DPBI notified)
- Multi-regulator reporting fragmented (CERT-In 6h + DPDP 72h not coordinated)
DPDP DPBI + Enforcement + Penalties (Sec 18-42)
Sections 18-42 of DPDP Act 2023 establish the regulatory architecture for enforcement. Section 18 Establishment of Data Protection Board of India (DPBI): a Board to be called the Data Protection Board of India + body corporate + perpetual succession + common seal + power to acquire/hold/dispose of property + contract + sue and be sued. DPBI headquartered in Delhi-NCR + may have other offices + as the Government may decide. Section 19-22 Composition + Service Conditions: DPBI consists of Chairperson + other Members (number prescribed by Government); appointed by Central Government from candidates with specialised knowledge of data governance + economics + privacy + technology + administration + law + or related disciplines; Chairperson + Members hold office for 2 years (eligible for reappointment); salary + allowances prescribed by Government. Section 23-26 Functions of DPBI: shall be a d
- DPBI engagement capability + cooperation playbook + procedures + records
- Penalty risk assessment + INR 250cr exposure + per-category + mitigation + Board awareness
- Voluntary undertaking strategy + DPBI negotiation + records + Board approval
- TDSAT appeals capability + 60-day window + counsel retained + records + procedure
- Schedule penalties coverage analysis + Children/SDF/Consent/Notice + records
- No DPBI engagement capability (would not respond to inquiry)
- Penalty risk not Board-level (INR 250cr exposure unmanaged)
- Voluntary undertaking strategy absent (no negotiation framework)
- TDSAT appeals unprepared (no counsel + 60-day window not understood)
- Schedule penalties not mapped to operations (categories untracked)
DPDP Data Fiduciary General Obligations (Sec 8)
Section 8 of DPDP Act 2023 establishes general obligations of every Data Fiduciary regardless of size or significance. Section 8(1): A Data Fiduciary shall be responsible for complying with the provisions of this Act and the rules made thereunder in respect of any processing undertaken by it or on its behalf by a Data Processor. Section 8(2) Engagement of Processor: A Data Fiduciary may engage + appoint + use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals + only under a valid contract (Data Processing Agreement DPA covering scope + purpose + duration + technical and organisational measures + confidentiality + sub-processor approval + assistance + audit rights + breach notification + return/deletion at end). Section 8(3) Accuracy + Completeness + Consistency: where Personal Data proc
- DPA with each processor + scope + duration + TOMs + sub-processor + audit + records
- Accuracy + completeness + consistency procedures + records + automated decision impact assessment
- TOMs assessment + encryption + access control + ISO 27001 alignment + ROPA + records
- Breach notification procedure + 72h DPBI + Data Principal intimation + records + drills
- Erasure procedure + withdrawal trigger + processor cascade + audit + records
- Processor engagement without DPA (Section 8(2) violation)
- Accuracy not procedurally enforced (legacy/stale data used in decisions)
- Reasonable security pro forma (no TOMs assessment or encryption audit)
- Breach notification untested (would miss 72h DPBI window)
- Erasure on withdrawal absent or partial (processors continue processing)
DPDP Data Principal Rights (Sec 11-14)
Sections 11-14 of DPDP Act 2023 establish the rights granted to Data Principals and Data Principal duties. Section 11 Right to Information: Data Principal shall have the right to obtain from the Data Fiduciary to whom she has previously given consent + including consent as referred to in Section 7 (Legitimate Uses): (a) a summary of personal data which is being processed by such Data Fiduciary and the processing activities undertaken; (b) the identities of all other Data Fiduciaries and Data Processors with whom the personal data has been shared + along with a description of the personal data so shared; (c) any other information related to the personal data of such Data Principal and its processing as may be prescribed. Section 12 Right to Correction + Completion + Updation + Erasure: Data Principal shall have the right to correction + completion + updating and erasure of her personal da
- Right to Information procedure + summary + sharing list + response period + records
- Right to Correction/Completion/Updation/Erasure procedure + balance assessment + records
- Grievance redressal mechanism + means readily available + 7-30 day SLA + records + statistics
- Right to Nominate procedure + death/incapacity verification + records + statistics
- Data Principal duties + verification of identity + impersonation prevention + records
- Right to Information slow (no procedure or beyond response period)
- Right to Correction limited (only own data, not 3rd parties sharing)
- Grievance redressal channel single (only email, no portal or phone)
- Right to Nominate absent (no procedure for death/incapacity)
- Identity verification weak (impersonation risk + false grievances)
DPDP Notice + Consent + Lawful Processing (Sec 4-7)
Sections 4-7 of DPDP Act 2023 establish the foundational lawful processing framework. Section 4 Grounds for Processing Personal Data: a person may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose - (a) for which the Data Principal has given her consent; or (b) for certain legitimate uses (Section 7). Section 5 Notice: every request made to a Data Principal for consent shall be accompanied or preceded by a notice given by the Data Fiduciary to the Data Principal informing her - (i) the personal data and the purpose for which the same is proposed to be processed; (ii) the manner in which she may exercise her rights under Section 11 (Right to Information) + Section 13 (Right to Grievance Redressal) + and may make a complaint to the Board (DPBI); (iii) the manner in which the Data Principal may make a complaint to the B
- Notice templates + 22 languages + per-purpose itemised + per-context + audit + records
- Consent capture + free/specific/informed/unambiguous + itemised + records + audit
- Consent withdrawal mechanism + easy + propagated to processors + records + audit
- Consent Manager registration with DPBI + AA-DPDP CM bridge + records
- Legitimate uses + per-section assessment + government/medical/employment + records
- Notice English-only (not 8th Schedule languages)
- Consent bundled or pre-checked (violates free/specific/unambiguous)
- Withdrawal harder than giving consent (button hidden or multi-step)
- Consent Manager not registered with DPBI (operating as CM without authority)
- Legitimate uses claimed without per-section assessment (catch-all)
DPDP SDF + DPO + Audit + DPIA (Sec 10-11)
Sections 10-11 of DPDP Act 2023 establish enhanced obligations on entities designated as Significant Data Fiduciaries (SDFs). Section 10 Significant Data Fiduciary: Central Government may notify Data Fiduciary or class of Data Fiduciaries as SDF having regard to such factors as may be relevant including (a) volume and sensitivity of personal data processed; (b) risk to rights of Data Principal; (c) potential impact on sovereignty + integrity of India; (d) risk to electoral democracy; (e) security of the State; (f) public order. SDF determination criteria operationalised through DPDP Rules 2025 quantitative thresholds. Enhanced SDF obligations: (a) appoint a Data Protection Officer (DPO) who shall be an individual responsible for representing the SDF + based in India + report directly to Board of Directors or similar governing body + be the point of contact for the grievance redressal mec
- SDF determination assessment + volume + sensitivity + risk + MeitY notification monitoring
- DPO appointment + India-based + Board reporting line + contact info published + records
- Independent Data Auditor + qualification + periodic audit cadence + scope + report + records
- DPIA template + periodic + risk assessment + mitigation + records + linked to processing activities
- Algorithmic software audit + AI/ML + bias + explainability + accuracy + impact + records
- SDF determination ignored (data volume + sensitivity not assessed)
- DPO appointed but reporting to CIO instead of Board (violates Sec 10(2)(a))
- Independent Data Auditor in-house instead of independent + qualified
- DPIA done once + not periodic + no risk-based prioritisation
- Algorithmic audit absent for AI/ML SDFs (no bias assessment)
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the India DPDP Act framework page.