All 44 Articles

All Articles

India DPDPA: Article 1 – Short Title and Commencement

1. Short Title and Commencement (1) This Act may be called the Digital Personal Data Protection Act, 2023 (2) It shall come into force on such date as the Central Government may, by notification in the Official Gazette, appoint and different dates may be appointed for different provisions of this Act and any reference in any such provision to the commencement of this Act shall be construed as a reference to the coming into force of that provision.

What Article 1 Means for Your Business

Article 1 establishes the official name of the law, the Digital Personal Data Protection Act, 2023, and gives the Central Government the power to bring different provisions into force on different dates by notification in the Official Gazette. This phased commencement mechanism was used to operationalise the Act through the DPDP Rules 2025, notified on 13 November 2025.
  • The Act does not have a single commencement date, different sections came into force at different times, so compliance obligations must be tracked against official gazette notifications rather than a single fixed date.
  • As of November 2025, the DPDP Rules 2025 are in force in a phased manner, some provisions apply immediately, others after 12 months, and the remainder after 18 months from notification.
  • Businesses should monitor MeitY notifications to know exactly which obligations are currently enforceable versus those that are pending.
  • The Act applies to digital personal data only, non-digitised records are outside scope unless subsequently digitised.

Frequently Asked Questions about Article 1

+ What is the purpose of Article 1 in the DPDP Act?
Article 1 establishes the official name of the law and explains how and when different provisions of the Act will come into force.
+ Does the DPDP Act apply immediately to all businesses?
No. The Act will be implemented in phases, and different provisions will become applicable on dates notified by the Central Government.
+ How will businesses know when to comply with specific provisions?
Businesses must monitor official notifications published in the Official Gazette, which will specify when each provision becomes effective.
+ What does “commencement” mean under this article?
Commencement refers to the date from which a provision of the DPDP Act becomes legally enforceable.
+ What should businesses do before the Act becomes effective?
Businesses should start preparing compliance frameworks, review data handling practices, and implement systems for consent, data security, and user rights before enforcement begins.

View Article
India DPDPA: Article 2 – Definitions

2. Definitions
In this Act, unless the context otherwise requires,— (a) “Appellate Tribunal” means the Telecom Disputes Settlement and Appellate Tribunal established under section 14 of the Telecom Regulatory Authority of India Act, 1997; (b) “automated” means any digital process capable of operating automatically in response to instructions given or otherwise for the purpose of processing data; (c) “Board” means the Data Protection Board of India established by the Central Government under section 18; (d) “certain legitimate uses” means the uses referred to in section 7; (e) “Chairperson” means the Chairperson of the Board; (f) “child” means an individual who has not completed the age of eighteen years; (g) “Consent Manager” means a person registered with the Board, who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw her consent through an accessible, transparent and interoperable platform; (h) “data” means a representation of information, facts, concepts, opinions or instructions in a manner suitable for communication, interpretation or processing by human beings or by automated means; (i) “Data Fiduciary” means any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data; (j) “Data Principal” means the individual to whom the personal data relates and where such individual is— (i) a child, includes the parents or lawful guardian of such a child;(ii) a person with disability, includes her lawful guardian, acting on her behalf; (k) “Data Processor” means any person who processes personal data on behalf of a Data Fiduciary; (l) “Data Protection Officer” means an individual appointed by the Significant Data Fiduciary under clause (a) of sub-section (2) of section 10; (m) “digital office” means an office that adopts an online mechanism wherein the proceedings, from receipt of intimation or complaint or reference or directions or appeal, as the case may be, to the disposal thereof, are conducted in online or digital mode; (n) “digital personal data” means personal data in digital form; (o) “gain” means— (i) a gain in property or supply of services, whether temporary or permanent; or(ii) an opportunity to earn remuneration or greater remuneration or to gain a financial advantage otherwise than by way of legitimate remuneration; (p) “loss” means— (i) a loss in property or interruption in supply of services, whether temporary or permanent; or(ii) a loss of opportunity to earn remuneration or greater remuneration or to gain a financial advantage otherwise than by way of legitimate remuneration; (q) “Member” means a Member of the Board and includes the Chairperson; (r) “notification” means a notification published in the Official Gazette and the expressions “notify” and “notified” shall be construed accordingly; (s) “person” includes— (i) an individual;(ii) a Hindu undivided family; (iii) a company;(iv) a firm;(v) an association of persons or a body of individuals, whether incorporated or not;(vi) the State; and(vii) every artificial juristic person, not falling within any of the preceding sub-clauses; (t) “personal data” means any data about an individual who is identifiable by or in relation to such data; (u) “personal data breach” means any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data; (v) “prescribed” means prescribed by rules made under this Act; (w) “proceeding” means any action taken by the Board under the provisions of this Act; (x) “processing” in relation to personal data, means a wholly or partly automated operation or set of operations performed on digital personal data, and includes operations such as collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission, dissemination or otherwise making available, restriction, erasure or destruction; (y) “she” in relation to an individual includes the reference to such individual irrespective of gender; (z) “Significant Data Fiduciary” means any Data Fiduciary or class of Data Fiduciaries as may be notified by the Central Government under section 10; (za) “specified purpose” means the purpose mentioned in the notice given by the Data Fiduciary to the Data Principal in accordance with the provisions of this Act and the rules made thereunder; and (zb) “State” means the State as defined under article 12 of the Constitution.

What Article 2 Means for Your Business

Article 2 contains the definitions that underpin every other provision of the DPDPA. Getting these definitions right is essential because they determine whether the Act applies to a particular activity, who bears obligations, and what rights individuals hold. Several key terms differ meaningfully from their equivalents under the GDPR, making direct translation of GDPR compliance programmes insufficient.

  • Data Fiduciary (equivalent to GDPR's Data Controller), any person who determines the purpose and means of processing personal data. If your business decides why and how personal data is used, you are a Data Fiduciary and bear the primary compliance obligations.
  • Data Principal (equivalent to GDPR's Data Subject), the individual whose personal data is being processed. For children, the parent or lawful guardian is treated as the Data Principal.
  • Data Processor, any person who processes personal data on behalf of a Data Fiduciary. Processors are not directly liable under the Act but must be engaged under a valid contract.
  • Personal data is defined broadly as any data about an individual who is identifiable, there is no separate category for sensitive personal data under the DPDPA, unlike under the GDPR.
  • Consent Manager, a new concept under DPDPA, a registered intermediary that allows Data Principals to give, manage, review, and withdraw consent across multiple Data Fiduciaries.
  • Review all existing GDPR-based compliance documentation to ensure definitions are updated to DPDPA terminology before applying them to Indian operations.

Frequently Asked Questions about Article 2

+ What is the purpose of Article 2 in the DPDP Act?
Article 2 defines key terms used across the Act, which are essential for understanding legal obligations and compliance requirements.
+ Who is a Data Fiduciary under the DPDP Act?
A Data Fiduciary is any person or organization that determines the purpose and means of processing personal data.
+ Who is a Data Principal?
A Data Principal is the individual to whom the personal data relates, including children and persons with lawful guardians.
+ What is a Consent Manager?
A Consent Manager is a registered entity that helps individuals give, manage, review, and withdraw consent through a transparent and accessible platform.
+ Why are definitions important for businesses?
These definitions determine how the law applies to your organization and guide how you handle personal data, making them critical for proper compliance.

View Article
India DPDPA: Article 3 – Application of the Act

3. Application of the Act Subject to the provisions of this Act, it shall— (a) apply to the processing of digital personal data within the territory of India where the personal data is collected–– (i) in digital form; or (ii) in non-digital form and digitised subsequently; (b) also apply to processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering ofgoods or services to Data Principals within the territory of India; (c) not apply to— (i) personal data processed by an individual for any personal or domestic purpose; and (ii) personal data that is made or caused to be made publicly available by— (A) the Data Principal to whom such personal data relates; or (B) any other person who is under an obligation under any law for the time being in force in India to make such personal data publicly available. X, an individual, while blogging her views, has publicly made available her personal data on social media. In such case, the provisions of this Act shall not apply.

What Article 3 Means for Your Business

Article 3 defines the territorial scope of the DPDPA. It applies to digital personal data processed within India, and, critically, to data processed outside India if the processing is connected to offering goods or services to individuals in India. This extraterritorial reach means that foreign businesses serving Indian customers are caught by the Act even if they have no physical presence in India.
  • If your business collects data from Indian users, whether through a website, app, or service, you are likely within scope regardless of where your servers or headquarters are located.
  • The Act does not apply to personal data processed by individuals for personal or domestic purposes.
  • There is a specific exemption for Indian companies that process personal data collected outside India under an outsourcing contract, this is designed to protect India's IT/BPO sector.
  • Foreign companies must appoint a representative or Data Protection Officer and establish compliance mechanisms even without a local office in India.
  • Conduct a territorial scope assessment to confirm whether your organisation's activities fall within the Act before determining which obligations apply.

Frequently Asked Questions about Article 3

+ When does the DPDP Act apply to a business?
The Act applies when digital personal data is processed within India or when businesses outside India process data related to offering goods or services to individuals in India.
+ Does the DPDP Act apply to foreign companies?
Yes. Foreign companies must comply if they process personal data in connection with offering goods or services to individuals located in India.
+ Does the Act apply to non-digital data?
It applies to non-digital personal data only if it is digitized later. Purely offline data that is never digitized is not covered.
+ Are there any exemptions under this article?
Yes. The Act does not apply to personal data processed for personal or domestic purposes, or data that is made publicly available by the individual or under legal obligation.
+ Why is Article 3 important for compliance?
It helps businesses determine whether they fall under the scope of the DPDP Act, which is the first step in understanding and implementing compliance requirements.

View Article
India DPDPA: Article 4 – Grounds for processing digital personal data

4. Grounds for processing digital personal data (1) A person may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose,— (a) for which the Data Principal has given her consent; or (b) for certain legitimate uses. (2) For the purposes of this section, the expression “lawful purpose” means any purpose which is not expressly forbidden by law.

What Article 4 Means for Your Business

Article 4 establishes that personal data may only be processed for a lawful purpose, either with the consent of the Data Principal, or for certain legitimate uses specified in Article 7. Unlike the GDPR's six legal bases, the DPDPA uses a narrower framework built primarily around consent, making it one of the most consent-centric data protection laws in the world.

  • Before processing any personal data, your business must have either a valid consent from the individual or a recognised legitimate use under Article 7, there is no general "legitimate interests" ground as exists under GDPR.
  • Data must only be processed for the specific purpose for which consent was obtained, purpose limitation is strictly enforced.
  • Personal data must be accurate and kept only for as long as necessary to fulfil the stated purpose.
  • Data Fiduciaries must implement reasonable security safeguards to protect data at all stages of processing.
  • Map all data processing activities in your organisation against these grounds before the Act's enforcement provisions become active.

Frequently Asked Questions about Article 4

+ What are the legal grounds for processing personal data under DPDP?
Personal data can be processed only for a lawful purpose, either with the consent of the Data Principal or under certain legitimate uses defined in the Act.
+ Is consent always required for processing data?
No. While consent is a primary requirement, data can also be processed under specific legitimate uses as allowed by the DPDP Act.
+ What does “lawful purpose” mean?
A lawful purpose means any purpose that is not explicitly prohibited by law and complies with the provisions of the DPDP Act.
+ Can a business process data without a valid reason?
No. Processing personal data without a lawful purpose or valid consent can result in non-compliance and potential penalties.
+ Why is Article 4 important for businesses?
It defines the legal basis for all data processing activities, making it essential for businesses to ensure compliance before collecting or using personal data.

View Article
India DPDPA: Article 5 – Notice

5. Notice (1) Every request made to a Data Principal under section 6 for consent shall be accompanied or preceded by a notice given by the Data Fiduciary to the Data Principal, informing her,— (i) the personal data and the purpose for which the same is proposed to be processed; (ii) the manner in which she may exercise her rights under sub-section (4) of section 6 and section 13; and (iii) the manner in which the Data Principal may make a complaint to the Board, in such manner and as may be prescribed. Illustration. X, an individual, opens a bank account using the mobile app or website of Y, a bank. To complete the Know-Your-Customer requirements under law for opening of bank account, X opts for processing of her personal data by Y in a live, video-based customer identification process. Y shall accompany or precede the request for the personal data with notice to X, describing the personal data and the purpose of its processing. (2) Where a Data Principal has given her consent for the processing of her personal data before the date of commencement of this Act,— (a) the Data Fiduciary shall, as soon as it is reasonably practicable, give to the Data Principal a notice informing her,–– (i) the personal data and the purpose for which the same has been processed; (ii) the manner in which she may exercise her rights under sub-section (4) of section 6 and section 13; and (iii) the manner in which the Data Principal may make a complaint to the Board, in such manner and as may be prescribed. (b) the Data Fiduciary may continue to process the personal data until and unless the Data Principal withdraws her consent. Illustration. X, an individual, gave her consent to the processing of her personal data for an online shopping app or website operated by Y, an e-commerce service provider, before the commencement of this Act. Upon commencement of the Act, Y shall, as soon as practicable, give through email, in-app notification or other effective method information to X, describing the personal data and the purpose of its processing. (3) The Data Fiduciary shall give the Data Principal the option to access the contents of the notice referred to in sub-sections (1) and (2) in English or any language specified in the Eighth Schedule to the Constitution.

What Article 5 Means for Your Business

Article 5 requires every request for consent to be accompanied or preceded by a clear notice to the Data Principal. The notice must tell the individual what personal data will be collected, the purpose for which it will be processed, and how they can exercise their rights and make complaints. This notice obligation applies both to new data collections and, retrospectively, to existing data collected before the Act commenced.
  • Every consent request must be paired with a notice, you cannot seek consent without first informing the individual what they are consenting to.
  • The notice must be written in clear and plain language, available in English and any language in the Eighth Schedule to the Constitution of India.
  • For data collected before the Act commenced, you must provide retrospective notices to existing users as soon as reasonably practicable.
  • The notice must include contact details of your Data Protection Officer (if applicable) or another authorised person who can respond to Data Principal queries.
  • Review all existing privacy notices, consent banners, and onboarding flows to ensure they meet Article 5 requirements before enforcement begins.
  • Notices must explain how the individual can withdraw consent and how they can lodge a complaint with the Data Protection Board of India.

Frequently Asked Questions about Article 5

+ What is a “notice” under the DPDP Act?
A notice is information provided by a Data Fiduciary to a Data Principal explaining what personal data is being collected, why it is being processed, and how the individual can exercise their rights.
+ When must a business provide a notice?
A notice must be provided before or at the time of requesting consent for processing personal data.
+ What information should be included in the notice?
The notice should include details about the personal data being collected, the purpose of processing, how users can exercise their rights, and how they can file complaints.
+ Is notice required for data collected before the Act?
Yes. If personal data was collected before the Act came into force, businesses must provide notice as soon as reasonably practicable.
+ Why is Article 5 important for compliance?
It ensures transparency and helps users make informed decisions about their personal data, which is a key requirement under the DPDP Act.

View Article
India DPDPA: Article 6 – Consent

6. Consent (1) The consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose. Illustration. X, an individual, downloads Y, a telemedicine app. Y requests the consent of X for (i) the processing of her personal data for making available telemedicine services, and (ii) accessing her mobile phone contact list, and X signifies her consent to both. Since phone contact list is not necessary for making available telemedicine services, her consent shall be limited to the processing of her personal data for making available telemedicine services. (2) Any part of consent referred in sub-section (1) which constitutes an infringement of the provisions of this Act or the rules made thereunder or any other law for the time being in force shall be invalid to the extent of such infringement. Illustration. X, an individual, buys an insurance policy using the mobile app or website of Y, an insurer. She gives to Y her consent for (i) the processing of her personal data by Y for the purpose of issuing the policy, and (ii) waiving her right to file a complaint to the Data Protection Board of India. Part (ii) of the consent, relating to waiver of her right to file a complaint, shall be invalid. (3) Every request for consent under the provisions of this Act or the rules made thereunder shall be presented to the Data Principal in a clear and plain language, giving her the option to access such request in English or any language specified in the Eighth Schedule to the Constitution and providing the contact details of a Data Protection Officer, where applicable, or of any other person authorised by the Data Fiduciary to respond to any communication from the Data Principal for the purpose of exercise of her rights under the provisions of this Act. (4) Where consent given by the Data Principal is the basis of processing of personal data, such Data Principal shall have the right to withdraw her consent at any time, with the ease of doing so being comparable to the ease with which such consent was given. (5) The consequences of the withdrawal referred to in sub-section (4) shall be borne by the Data Principal, and such withdrawal shall not affect the legality of processing of the personal data based on consent before its withdrawal. Illustration. X, an individual, is the user of an online shopping app or website operated by Y, an e-commerce service provider. X consents to the processing of her personal data by Y for the purpose of fulfilling her supply order and places an order for supply of a good while making payment for the same. If X withdraws her consent, Y may stop enabling X to use the app or website for placing orders, but may not stop the processing for supply of the goods already ordered and paid for by X. (6) If a Data Principal withdraws her consent to the processing of personal data under sub-section (5), the Data Fiduciary shall, within a reasonable time, cease and cause its Data Processors to cease processing the personal data of such Data Principal unless such processing without her consent is required or authorised under the provisions of this Act or the rules made thereunder or any other law for the time being in force in India. Consent. Illustration. X, a telecom service provider, enters into a contract with Y, a Data Processor, for emailing telephone bills to the customers of X. Z, a customer of X, who had earlier given her consent to X for the processing of her personal data for emailing of bills, downloads the mobile app of X and opts to receive bills only on the app. X shall itself cease, and shall cause Y to cease, the processing of the personal data of Z for emailing bills. (7) The Data Principal may give, manage, review or withdraw her consent to the Data Fiduciary through a Consent Manager. (8) The Consent Manager shall be accountable to the Data Principal and shall act on her behalf in such manner and subject to such obligations as may be prescribed. (9) Every Consent Manager shall be registered with the Board in such manner and subject to such technical, operational, financial and other conditions as may be prescribed. (10) Where a consent given by the Data Principal is the basis of processing of personal data and a question arises in this regard in a proceeding, the Data Fiduciary shall be obliged to prove that a notice was given by her to the Data Principal and consent was given by such Data Principal to the Data Fiduciary in accordance with the provisions of this Act and the rules made thereunder.

What Article 6 Means for Your Business

Article 6 sets the standard for valid consent under the DPDPA. Consent must be free, specific, informed, unconditional, and unambiguous, given through a clear affirmative action. This is a stricter standard than many businesses currently meet, and it has significant implications for how consent is collected, managed, and evidenced across digital products and services.
  • Pre-ticked checkboxes, silence, and inactivity do not constitute valid consent, the user must actively take an affirmative action such as ticking an unticked box or clicking an explicit agree button.
  • Bundled consent, asking users to agree to multiple unrelated purposes in a single action, is non-compliant. Each distinct purpose requires a separate, specific consent.
  • You may only collect the personal data that is strictly necessary for the purpose for which consent was obtained, collecting additional data because it "might be useful" is not permitted.
  • Users have the right to withdraw consent at any time, and the withdrawal mechanism must be as easy to use as the original consent mechanism.
  • Once consent is withdrawn, you must stop processing the individual's data and instruct any data processors you have engaged to do the same, within a reasonable time.
  • Where a consent dispute arises, the burden of proof is on the Data Fiduciary to demonstrate that valid notice was given and consent was properly obtained.
  • Consent Managers registered with the Data Protection Board may be used to manage consent on behalf of Data Principals, using an unregistered platform may undermine the validity of consent.

Frequently Asked Questions about Article 6

+ What is valid consent under the DPDP Act?
Valid consent must be free, specific, informed, unconditional, and unambiguous, and it must be given through a clear affirmative action.
+ Are pre-ticked checkboxes allowed for consent?
No. Pre-ticked checkboxes or passive actions do not qualify as valid consent under the DPDP Act.
+ Can users withdraw their consent?
Yes. Users have the right to withdraw their consent at any time, and businesses must stop processing their data as soon as practicable after withdrawal.
+ What happens if consent is invalid?
Any processing based on invalid consent may be considered non-compliant and can lead to penalties under the DPDP Act.
+ Why is Article 6 important for businesses?
It defines how businesses must legally obtain and manage consent, making it essential for compliance and avoiding regulatory penalties.

View Article
India DPDPA: Article 7 – Certain Legitimate Uses

7. Certain Legitimate Uses A Data Fiduciary may process personal data of a Data Principal for any of following uses, namely:— (a) for the specified purpose for which the Data Principal has voluntarily provided her personal data to the Data Fiduciary, and in respect of which she has not indicated to the Data Fiduciary that she does not consent to the use of her personal data. Illustrations. (I) X, an individual, makes a purchase at Y, a pharmacy. She voluntarily provides Y her personal data and requests Y to acknowledge receipt of the payment made for the purchase by sending a message to her mobile phone. Y may process the personal data of X for the purpose of sending the receipt. (II) X, an individual, electronically messages Y, a real estate broker, requesting Y to help identify a suitable rented accommodation for her and shares her personal data for this purpose. Y may process her personal data to identify and intimate to her the details of accommodation available on rent. Subsequently, X informs Y that X no longer needs help from Y. Y shall cease to process the personal data of X. (b) for the State and any of its instrumentalities to provide or issue to the Data Principal such subsidy, benefit, service, certificate, licence or permit as may be prescribed, where–– (i) she has previously consented to the processing of her personal data by the State or any of its instrumentalities for any subsidy, benefit, service, certificate, licence or permit; or (ii) such personal data is available in digital form in, or in non-digital form and digitised subsequently from, any database, register, book or other document which is maintained by the State or any of its instrumentalities and is notified by the Central Government, subject to standards followed for processing being in accordance with the policy issued by the Central Government or any law for the time being in force for governance of personal data. Illustration. X. a pregnant woman, enrols herself on an app or website to avail of government’s maternity benefits programme, while consenting to provide her personal data for the purpose of availing of such benefits. Government may process the personal data of X processing to determine her eligibility to receive any other prescribed benefit from the government. (c) for the performance by the State or any of its instrumentalities of any function under any law for the time being in force in India or in the interest of sovereignty and integrity of India or security of the State; (d) for fulfilling any obligation under any law for the time being in force in India on any person to disclose any information to the State or any of its instrumentalities, subject to such processing being in accordance with the provisions regarding disclosure of such information in any other law for the time being in force; (e) for compliance with any judgment or decree or order issued under any law for the time being in force in India, or any judgment or order relating to claims of a contractual or civil nature under any law for the time being in force outside India; (f) for responding to a medical emergency involving a threat to the life or immediate threat to the health of the Data Principal or any other individual; (g) for taking measures to provide medical treatment or health services to any individual during an epidemic, outbreak of disease, or any other threat to public health; (h) for taking measures to ensure safety of, or provide assistance or services to, any individual during any disaster, or any breakdown of public order. Explanation.—For the purposes of this clause, the expression “disaster” shall have the same meaning as assigned to it in clause (d) of section 2 of the Disaster Management Act, 2005; or (i) for the purposes of employment or those related to safeguarding the employer from loss or liability, such as prevention of corporate espionage, maintenance of confidentiality of trade secrets, intellectual property, classified information or provision of any service or benefit sought by a Data Principal who is an employee.

What Article 7 Means for Your Business

Article 7 provides a limited set of grounds under which personal data may be processed without consent. These are the DPDPA's equivalent of GDPR's non-consent legal bases, but the list is significantly narrower. There is no general legitimate interests ground, businesses cannot rely on a balancing test to justify processing without consent.
  • Personal data may be processed without consent where the individual has voluntarily provided it for a specific purpose and has not objected to its use for that purpose.
  • The State and its instrumentalities may process data for subsidies, benefits, licences, and other state functions without consent, subject to the standards in Schedule II.
  • Processing is permitted for compliance with a legal obligation or court order, this covers regulatory reporting, tax compliance, and similar requirements.
  • Medical emergencies and healthcare delivery are recognised as legitimate uses, hospitals, clinics, and health platforms may process data to protect life without first seeking consent.
  • Employment-related processing, such as payroll, performance management, and workplace safety, is permitted under this Article without requiring employee consent for each processing activity.
  • Do not assume that a GDPR legitimate interests assessment will translate to a valid ground under Article 7, the two frameworks are not equivalent.

Frequently Asked Questions about Article 7

+ What are “legitimate uses” under the DPDP Act?
Legitimate uses are specific situations where personal data can be processed without consent, such as when the data is voluntarily provided by the individual or required for legal or public purposes.
+ Can businesses always skip consent under legitimate use?
No. Businesses can only skip consent in limited scenarios defined under Article 7 and must not misuse this provision to bypass consent requirements.
+ What is an example of legitimate use?
If a user voluntarily provides personal data to receive a service, such as requesting a receipt or inquiry, the business can process that data for that specific purpose.
+ When must a business stop processing data under legitimate use?
Processing must stop once the intended purpose is fulfilled or when the user indicates that they no longer require the service.
+ Why is Article 7 important for businesses?
It provides flexibility to process data in specific cases without consent while ensuring that businesses still follow strict legal boundaries.

View Article
India DPDPA: Article 8 – General Obligations of Data Fiduciary

8. General Obligations of Data Fiduciary (1) A Data Fiduciary shall, irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties provided under this Act, be responsible for complying with the provisions of this Act and the rules made thereunder in respect of any processing undertaken by it or on its behalf by a Data Processor. (2) A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract. (3) Where personal data processed by a Data Fiduciary is likely to be— (a) used to make a decision that affects the Data Principal; or (b) disclosed to another Data Fiduciary, the Data Fiduciary processing such personal data shall ensure its completeness, accuracy and consistency. (4) A Data Fiduciary shall implement appropriate technical and organisational measures to ensure effective observance of the provisions of this Act and the rules made thereunder. (5) A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach. (6) In the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed. (7) A Data Fiduciary shall, unless retention is necessary for compliance with any law for the time being in force,— (a) erase personal data, upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier; and (b) cause its Data Processor to erase any personal data that was made available by the Data Fiduciary for processing to such Data Processor. Illustrations. (I) X, an individual, registers herself on an online marketplace operated by Y, an e-commerce service provider. X gives her consent to Y for the processing of her personal data for selling her used car. The online marketplace helps conclude the sale. Y shall no longer retain her personal data. (II) X, an individual, decides to close her savings account with Y, a bank. Y is required by law applicable to banks to maintain the record of the identity of its clients for a period of ten years beyond closing of accounts. Since retention is necessary for compliance with law, Y shall retain X’s personal data for the said period. (8) The purpose referred to in clause (a) of sub-section (7) shall be deemed to no longer be served, if the Data Principal does not–– (a) approach the Data Fiduciary for the performance of the specified purpose; and (b) exercise any of her rights in relation to such processing, for such time period as may be prescribed, and different time periods may be prescribed for different classes of Data Fiduciaries and for different purposes. (9) A Data Fiduciary shall publish, in such manner as may be prescribed, the business contact information of a Data Protection Officer, if applicable, or a person who is able to answer on behalf of the Data Fiduciary, the questions, if any, raised by the Data Principal about the processing of her personal data. (10) A Data Fiduciary shall establish an effective mechanism to redress the grievances of Data Principals. (11) For the purposes of this section, it is hereby clarified that a Data Principal shall be considered as not having approached the Data Fiduciary for the performance of the specified purpose, in any period during which she has not initiated contact with the Data Fiduciary for such performance, in person or by way of communication in electronic or physical form.

What Article 8 Means for Your Business

Article 8 contains the core ongoing obligations of every Data Fiduciary. These are not one-time setup requirements, they are continuous duties that must be embedded into operational processes. Article 8 is one of the most practically significant provisions of the Act for compliance teams.
  • You are responsible for compliance with the Act regardless of whether your data processor or a contractual counterparty fails, the obligation sits with the Data Fiduciary irrespective of fault or agreement to the contrary.
  • Data Processors must be engaged under a valid written contract, verbal or informal arrangements are not sufficient.
  • You must implement appropriate technical and organisational measures to ensure compliance, documented policies, access controls, encryption, and regular reviews are expected.
  • Reasonable security safeguards must be maintained at all times to prevent personal data breaches, this includes data held by your processors on your behalf.
  • In the event of a personal data breach, you must notify both the Data Protection Board of India and each affected Data Principal in the prescribed form and manner, there is no materiality threshold, all breaches must be reported.
  • Personal data must be erased once the specified purpose is no longer being served, or upon consent withdrawal, whichever comes earlier, unless retention is legally required.
  • You must publish contact details of your Data Protection Officer or a designated person capable of answering Data Principal queries about processing.

Frequently Asked Questions about Article 8

+ Who is responsible for personal data under the DPDP Act?
The Data Fiduciary is fully responsible for complying with the DPDP Act, even when processing is carried out by a third-party Data Processor.
+ What are the key obligations of a Data Fiduciary?
Key obligations include ensuring data accuracy, implementing security safeguards, preventing breaches, and complying with all provisions of the Act.
+ What should a business do in case of a data breach?
The business must notify the Data Protection Board and affected individuals in the prescribed manner as soon as a breach occurs.
+ Can businesses use third-party data processors?
Yes, but only under a valid contract, and the Data Fiduciary remains responsible for compliance and data protection.
+ When should personal data be deleted?
Personal data must be deleted when it is no longer necessary for the purpose or when consent is withdrawn, unless retention is required by law.

View Article
India DPDPA: Article 9 – Processing of Personal Data of Children

9. Processing of Personal Data of Children (1) The Data Fiduciary shall, before processing any personal data of a child or a person with disability who has a lawful guardian obtain verifiable consent of the parent of such child or the lawful guardian, as the case may be, in such manner as may be prescribed. Explanation.—For the purpose of this sub-section, the expression “consent of the parent” includes the consent of lawful guardian, wherever applicable. (2) A Data Fiduciary shall not undertake such processing of personal data that is likely to cause any detrimental effect on the well-being of a child. (3) A Data Fiduciary shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children. (4) The provisions of sub-sections (1) and (3) shall not be applicable to processing of personal data of a child by such classes of Data Fiduciaries or for such purposes, and subject to such conditions, as may be prescribed. (5) The Central Government may, if satisfied that a Data Fiduciary has ensured that its processing of personal data of children is done in a manner that is verifiably safe, notify for such processing by such Data Fiduciary the age above which that Data Fiduciary shall be exempt from the applicability of all or any of the obligations under sub-sections (1) and (3) in respect of processing by that Data Fiduciary as the notification may specify.

What Article 9 Means for Your Business

Article 9 imposes strict additional requirements before a Data Fiduciary may process personal data of a child (anyone under 18). These requirements go beyond the standard consent framework and reflect the legislature's view that children's data deserves heightened protection. For any business whose product or service is accessible to or directed at minors, Article 9 compliance is non-negotiable.
  • Verifiable parental consent must be obtained before processing any personal data relating to a child, it is not sufficient to rely on the child's own consent regardless of their age.
  • The mechanism for verifying parental consent is prescribed under DPDP Rule 10, which requires identity and age verification of the parent or guardian through approved means.
  • Behavioural monitoring of children and targeted advertising directed at children are expressly prohibited, these activities cannot be made lawful even with parental consent.
  • Significant Data Fiduciaries and platforms likely to be accessed by children must design age-gating mechanisms before data collection begins.
  • Certain exemptions apply under Schedule IV, for example, processing for child protection purposes or by educational institutions in connection with a child's welfare.
  • Review your product design, onboarding flows, and advertising targeting to identify any exposure to Article 9 obligations and implement technical controls accordingly.

Frequently Asked Questions about Article 9

+ Can businesses process children’s personal data under the DPDP Act?
Yes, but only after obtaining verifiable consent from the child’s parent or lawful guardian.
+ What is “verifiable parental consent”?
It means businesses must take reasonable steps to confirm that consent is genuinely given by the parent or lawful guardian.
+ Is targeted advertising allowed for children?
No. Businesses are not allowed to track, monitor, or target children with behavioral advertising.
+ Can businesses process data that may harm children?
No. Any processing likely to cause harm or detrimental effects on a child’s well-being is strictly prohibited.
+ Are there any exemptions under Article 9?
Yes. The Central Government may exempt certain Data Fiduciaries or processing activities if they meet specific safety conditions.

View Article
India DPDPA: Article 10 – Additional obligations of Significant Data Fiduciary

10. Additional obligations of Significant Data Fiduciary (1) The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciary, on the basis of an assessment of such relevant factors as it may determine, including (a) the volume and sensitivity of personal data processed; (b) risk to the rights of Data Principal; (c) potential impact on the sovereignty and integrity of India; (d) risk to electoral democracy; (e) security of the State; and (f) public order. (2) The Significant Data Fiduciary shall— (a) appoint a Data Protection Officer who shall— (i) represent the Significant Data Fiduciary under the provisions of this Act; (ii) be based in India; (iii) be an individual responsible to the Board of Directors or similar governing body of the Significant Data Fiduciary; and (iv) be the point of contact for the grievance redressal mechanism under the provisions of this Act; (b) appoint an independent data auditor to carry out data audit, who shall evaluate the compliance of the Significant Data Fiduciary in accordance with the provisions of this Act; and (c) undertake the following other measures, namely:— (i) periodic Data Protection Impact Assessment, which shall be a process comprising a description of the rights of Data Principals and the purpose of processing of their personal data, assessment and management of the risk to the rights of the Data Principals, and such other matters regarding such process as may be prescribed; (ii) periodic audit; and (iii) such other measures, consistent with the provisions of this Act, as may be prescribed.

What Article 10 Means for Your Business

Article 10 creates a higher tier of compliance obligations for organisations designated as Significant Data Fiduciaries (SDFs) by the Central Government. The designation is based on factors including the volume and sensitivity of data processed, national security risk, impact on democratic rights, and risk to children. If your organisation is or might be designated an SDF, Article 10 obligations require substantial additional investment in governance infrastructure.
  • SDFs must appoint a Data Protection Officer (DPO) based in India, the DPO must be a senior employee, not an outsourced third party, and must report directly to the board.
  • SDFs must appoint an independent data auditor to conduct periodic audits of compliance with the Act.
  • Data Protection Impact Assessments (DPIAs) are mandatory for SDFs for any processing that poses a high risk to individuals' rights.
  • SDFs must undertake periodic algorithmic impact assessments to evaluate the risk of bias, discrimination, or harm from automated decision-making systems.
  • The Central Government may impose data localisation requirements on SDFs, requiring certain categories of data to be stored or processed only within India.
  • Even if your organisation is not yet designated an SDF, monitoring the Central Government's criteria and preparing for potential designation is advisable for large-scale data processors.

Frequently Asked Questions about Article 10

+ What is a Significant Data Fiduciary?
A Significant Data Fiduciary is a business classified by the government based on factors like the volume and sensitivity of data processed and the risk to individuals or the state.
+ Who decides whether a business is a Significant Data Fiduciary?
The Central Government determines and notifies which businesses qualify as Significant Data Fiduciaries.
+ Is appointing a Data Protection Officer mandatory?
Yes. Significant Data Fiduciaries must appoint a Data Protection Officer who is based in India and responsible for compliance.
+ What additional compliance is required under this article?
Businesses must conduct data audits, perform impact assessments, and implement enhanced governance and security measures.
+ Does Article 10 apply to all businesses?
No. It only applies to businesses specifically classified as Significant Data Fiduciaries by the government.

View Article
India DPDPA: Article 11 – Right to access information about personal data

11. Right to access information about personal data (1) The Data Principal shall have the right to obtain from the Data Fiduciary to whom she has previously given consent, including consent as referred to in clause (a) of section 7 (hereinafter referred to as the said Data Fiduciary), for processing of personal data, upon making to it a request in such manner as may be prescribed,— (a) a summary of personal data which is being processed by such Data Fiduciary and the processing activities undertaken by that Data Fiduciary with respect to suchpersonal data; (b) the identities of all other Data Fiduciaries and Data Processors with whom the personal data has been shared by such Data Fiduciary, along with a description of the personal data so shared; and (c) any other information related to the personal data of such Data Principal and its processing, as may be prescribed. (2) Nothing contained in clause (b) or clause (c) of sub-section (1) shall apply in respect of the sharing of any personal data by the said Data Fiduciary with any other Data Fiduciary authorised by law to obtain such personal data, where such sharing is pursuant to a request made in writing by such other Data Fiduciary for the purpose of prevention or detection or investigation of offences or cyber incidents, or for prosecution or punishment of offences.

What Article 11 Means for Your Business

Article 11 gives Data Principals the right to obtain information about their personal data from any Data Fiduciary that holds it. This is the DPDPA's equivalent of the GDPR's right of access, but with some specific requirements about the form and content of the response. Businesses must have processes in place to handle these requests promptly and accurately.
  • Data Principals may request a summary of what personal data you hold about them and the processing activities undertaken on that data.
  • Data Principals may request a list of all other Data Fiduciaries and processors with whom their personal data has been shared.
  • Any grievance redressal mechanism you provide must be responsive, the Data Principal can escalate to the Data Protection Board if their complaint is not resolved satisfactorily.
  • Build a structured Subject Access Request (SAR) handling process that can produce accurate responses within a reasonable timeframe, the rules prescribe specific response timelines.
  • Ensure your data inventory and records of processing activities are sufficiently detailed to support accurate responses to access requests.

Frequently Asked Questions about Article 11

+ What rights do individuals have under Article 11?
Individuals have the right to request and obtain information about their personal data, including how it is processed and shared.
+ What information must a business provide?
Businesses must provide a summary of personal data processed, the purpose of processing, and details of any third parties with whom the data has been shared.
+ Are there any exceptions to this right?
Yes. Certain information may not be disclosed if it is required for legal investigations, law enforcement, or other authorized purposes under the law.
+ How should businesses handle access requests?
Businesses should have clear processes in place to verify requests and provide accurate information within a reasonable timeframe.
+ Why is Article 11 important for compliance?
It promotes transparency and accountability by ensuring individuals can understand and verify how their personal data is being used.

View Article
India DPDPA: Article 12 – Right to correction and erasure of personal data

12. Right to correction and erasure of personal data (1) A Data Principal shall have the right to correction, completion, updating and erasure of her personal data for the processing of which she has previously given consent, including consent as referred to in clause (a) of section 7, in accordance with any requirement or procedure under any law for the time being in force. (2) A Data Fiduciary shall, upon receiving a request for correction, completion or updating from a Data Principal,— (a) correct the inaccurate or misleading personal data; (b) complete the incomplete personal data; and (c) update the personal data. (3) A Data Principal shall make a request in such manner as may be prescribed to the Data Fiduciary for erasure of her personal data, and upon receipt of such a request, the Data Fiduciary shall erase her personal data unless retention of the same is necessary for the specified purpose or for compliance with any law for the time being in force.

What Article 12 Means for Your Business

Article 12 gives Data Principals the right to have inaccurate or incomplete personal data corrected and to request erasure of data that is no longer needed or for which consent has been withdrawn. These rights impose operational obligations on businesses to maintain accurate data and to have processes capable of actioning correction and erasure requests.

  • Upon receiving a correction request, you must correct inaccurate or misleading data, complete incomplete data, and update outdated data.
  • Erasure requests must be honoured unless retention is legally required or necessary for the specified purpose, you cannot simply refuse erasure requests without a valid ground.
  • Where data is likely to be used to make decisions affecting the individual, or will be shared with other Data Fiduciaries, accuracy is especially critical, ensure processes exist to maintain data quality throughout its lifecycle.
  • Implement a documented request handling workflow covering receipt, verification, actioning, and confirmation of correction and erasure requests.
  • Ensure that erasure from your systems extends to any data you have shared with processors, they must also delete the data upon your instruction.

Frequently Asked Questions about Article 12

+ What rights do individuals have under Article 12?
Individuals have the right to correct, update, complete, and erase their personal data held by a business.
+ When must a business correct personal data?
Businesses must correct personal data when it is inaccurate, misleading, or incomplete upon receiving a valid request.
+ Can a user request deletion of their data?
Yes. Users can request erasure of their personal data, and businesses must comply unless retention is required by law.
+ Are there any exceptions to data deletion?
Yes. Data may be retained if it is necessary for legal compliance or for fulfilling the original purpose under applicable laws.
+ Why is Article 12 important for businesses?
It ensures data accuracy and gives users control over their information, which helps businesses maintain trust and comply with legal requirements.

View Article
India DPDPA: Article 13 – Right of grievance redressal

13. Right of grievance redressal (1) A Data Principal shall have the right to have readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager in respect of any act or omission of such Data Fiduciary or Consent Manager regarding the performance of its obligations in relation to the personal data of such Data Principal or the exercise of her rights under the provisions of this Act and the rules made thereunder. (2) The Data Fiduciary or Consent Manager shall respond to any grievances referred to in sub-section (1) within such period as may be prescribed from the date of its receipt for all or any class of Data Fiduciaries. (3) The Data Principal shall exhaust the opportunity of redressing her grievance under this section before approaching the Board.

What Article 13 Means for Your Business

Article 13 requires every Data Fiduciary to establish an accessible grievance redressal mechanism for Data Principals. This is not optional, it is a mandatory operational requirement. The Article also creates a two-tier escalation path: first to the Data Fiduciary, then to the Data Protection Board of India if the individual is unsatisfied.
  • You must establish and publish a clear grievance redressal mechanism, a named contact, email address, or online form is the minimum requirement.
  • Grievances must be addressed within the time period prescribed under the DPDP Rules, failing to respond within the prescribed timeframe entitles the Data Principal to escalate directly to the Board.
  • The grievance mechanism must be accessible and not require the individual to navigate complex processes to reach it, burying it in a lengthy privacy policy is insufficient.
  • Maintain a log of all grievances received, responses given, and timelines, this forms part of your compliance record and may be reviewed by the Board.
  • Train customer-facing and compliance staff to identify and properly route data protection grievances so they are handled under Article 13 requirements rather than general customer service processes.

Frequently Asked Questions about Article 13

+ What is grievance redressal under Article 13?
It is the process that allows individuals to raise complaints with a business regarding how their personal data is handled.
+ Are businesses required to provide a grievance system?
Yes. Businesses must provide accessible mechanisms for users to submit complaints about data processing.
+ How quickly must businesses respond to complaints?
Businesses must respond within a prescribed or reasonable timeframe from the date the complaint is received.
+ Can users go directly to the Data Protection Board?
No. Users must first attempt to resolve their grievance with the business before approaching the Data Protection Board.
+ Why is grievance handling important for businesses?
It helps resolve user issues early, ensures compliance, and reduces the risk of regulatory escalation or penalties.

View Article
India DPDPA: Article 14 – Right to nominate

14. Right to nominate (1) A Data Principal shall have the right to nominate, in such manner as may be prescribed, any other individual, who shall, in the event of death or incapacity of the Data Principal, exercise the rights of the Data Principal in accordance with the provisions of this Act and the rules made thereunder. (2) For the purposes of this section, the expression “incapacity” means inability to exercise the rights of the Data Principal under the provisions of this Act or the rules made thereunder due to unsoundness of mind or infirmity of body.

What Article 14 Means for Your Business

Article 14 introduces a right unique to the DPDPA, the right of a Data Principal to nominate another individual to exercise their data rights in the event of their death or incapacity. This forward-looking provision reflects the increasing importance of digital assets and personal data in estate and welfare planning.
  • Data Principals may nominate any individual to act on their behalf regarding their personal data after death or in the event they become incapacitated.
  • Businesses must be prepared to recognise and act on requests from validly nominated individuals, the rules prescribe the manner in which nominations are made and verified.
  • Update your Subject Access Request and data rights processes to include a pathway for nominated representatives to submit requests and receive responses.
  • This right has particular relevance for platforms that hold significant personal or financial data, social media, financial services, healthcare, and similar sectors should prioritise implementation.

Frequently Asked Questions about Article 14

+ What is the right to nominate under Article 14?
It allows an individual to appoint another person to exercise their data rights in case of death or incapacity.
+ Who can be a nominee?
Any individual chosen by the user can be nominated to act on their behalf.
+ When can a nominee exercise these rights?
A nominee can exercise the rights only when the original user is deceased or unable to act due to incapacity.
+ What must businesses do when a nominee makes a request?
Businesses must verify the nominee’s identity and authority before processing any request.
+ Why is this important for businesses?
It ensures continuity of user rights and helps businesses handle sensitive situations legally and securely.

View Article
India DPDPA: Article 15 – Duties of Data Principal

15. Duties of Data Principal A Data Principal shall perform the following duties, namely:— (a) comply with the provisions of all applicable laws for the time being in force while exercising rights under the provisions of this Act; (b) to ensure not to impersonate another person while providing her personal data for a specified purpose; (c) to ensure not to suppress any material information while providing her personal data for any document, unique identifier, proof of identity or proof of address issued by the State or any of its instrumentalities; (d) to ensure not to register a false or frivolous grievance or complaint with a Data Fiduciary or the Board; and (e) to furnish only such information as is verifiably authentic, while exercising the right to correction or erasure under the provisions of this Act or the rules made thereunder.

What Article 15 Means for Your Business

Article 15 is unusual in data protection law, it places positive duties on the individuals whose data is being protected, not just the organisations processing it. Data Principals must not impersonate others, provide false information, make frivolous complaints, or suppress material information when exercising their rights. Breaches can result in penalties against the individual.
  • Data Principals must comply with applicable laws when exercising rights under the DPDPA, they cannot use data rights as a mechanism to harass organisations or suppress legitimate processing.
  • Providing false information to obtain access or correction of another person's data is prohibited and carries a penalty of up to ₹10,000 on the Data Principal.
  • For businesses, this provision provides some protection against bad-faith Subject Access Requests and frivolous complaints, document your legitimate grounds for declining such requests.
  • This Article does not reduce your obligations as a Data Fiduciary, the existence of Data Principal duties does not allow you to refuse valid, good-faith rights requests.

Frequently Asked Questions about Article 15

+ What are the duties of a Data Principal?
A Data Principal must provide accurate information, avoid impersonation, and follow applicable laws when exercising their rights.
+ Can a user provide false information?
No. Users must ensure that the information they provide is authentic and not misleading.
+ Are users allowed to file any complaint?
Users should not file false or frivolous complaints, as this may violate the provisions of the Act.
+ Why is this important for businesses?
It ensures businesses can rely on accurate user data and reduces misuse of grievance or data rights mechanisms.
+ Does this article impose obligations on businesses?
No. This article primarily defines responsibilities of users, not businesses.

View Article
India DPDPA: Article 16 – Processing of personal data outside India

16. Processing of personal data outside India (1) The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified. (2) Nothing contained in this section shall restrict the applicability of any law for the time being in force in India that provides for a higher degree of protection for or restriction on transfer of personal data by a Data Fiduciary outside India in relation to any personal data or Data Fiduciary or class thereof.

What Article 16 Means for Your Business

Article 16 governs cross-border transfers of personal data from India to other countries. The DPDPA adopts a "negative list" approach, transfers are permitted by default to all countries except those specifically restricted by the Central Government. This is the opposite of the GDPR's adequacy-based framework and means that most international data transfers from India are currently unrestricted.
  • Cross-border transfers of personal data are permitted unless the destination country has been placed on a restricted list notified by the Central Government, no such list has yet been published as of early 2026.
  • Businesses must monitor Central Government notifications, as restrictions on specific countries or data categories could be introduced at any time without advance notice.
  • Unlike GDPR, there is no requirement for adequacy decisions, Standard Contractual Clauses, or Binding Corporate Rules to transfer data internationally, though contractual safeguards remain good practice.
  • The Central Government retains the power to impose data localisation on specific categories of data, particularly for Significant Data Fiduciaries, build flexibility into your data architecture to accommodate this.
  • Review all international data transfer flows and document the legal basis on which data leaves India so you can demonstrate compliance if restrictions are later introduced.

Frequently Asked Questions about Article 16

+ Can businesses transfer personal data outside India?
Yes. Businesses can transfer personal data outside India unless the government restricts transfers to specific countries or territories.
+ Who decides which countries are restricted?
The Central Government of India determines and notifies any restrictions on cross-border data transfers.
+ Do businesses need to monitor government updates?
Yes. Businesses must stay updated on government notifications to ensure compliance with transfer restrictions.
+ Are there additional laws that may apply?
Yes. Other laws in India may impose stricter conditions on data transfers, and businesses must comply with them as well.
+ Why is this important for businesses?
It ensures lawful international data transfers and helps avoid penalties or compliance risks.

View Article
India DPDPA: Article 17 – Exemptions

17. Exemptions (1) The provisions of Chapter II, except sub-sections (1) and (5) of section 8, and those of Chapter III and section 16 shall not apply where— (a) the processing of personal data is necessary for enforcing any legal right or claim; (b) the processing of personal data by any court or tribunal or any other body in India which is entrusted by law with the performance of any judicial or quasi-judicial or regulatory or supervisory function, where such processing is necessary for the performance of such function; (c) personal data is processed in the interest of prevention, detection, investigation or prosecution of any offence or contravention of any law for the time being in force in India; (d) personal data of Data Principals not within the territory of India is processed pursuant to any contract entered into with any person outside the territory of India by any person based in India; (e) the processing is necessary for a scheme of compromise or arrangement or merger or amalgamation of two or more companies or a reconstruction by way of demerger or otherwise of a company, or transfer of undertaking of one or more company to another company, or involving division of one or more companies, approved by a court or tribunal or other authority competent to do so by any law for the time being in force; and (f) the processing is for the purpose of ascertaining the financial information and assets and liabilities of any person who has defaulted in payment due on account of a loan or advance taken from a financial institution, subject to such processing being in accordance with the provisions regarding disclosure of information or data in any other law for the time being in force. Explanation.—For the purposes of this clause, the expressions “default” and “financial institution” shall have the meanings respectively assigned to them in sub-sections (12) and (14) of section 3 of the Insolvency and Bankruptcy Code, 2016. Illustration. X, an individual, takes a loan from Y, a bank. X defaults in paying her monthly loan repayment instalment on the date on which it falls due. Y may process the personal data of X for ascertaining her financial information and assets and liabilities. (2) The provisions of this Act shall not apply in respect of the processing of personal data— (a) by such instrumentality of the State as the Central Government may notify,in the interests of sovereignty and integrity of India, security of the State, friendly relations with foreign States, maintenance of public order or preventing incitement to any cognizable offence relating to any of these, and the processing by the Central Government of any personal data that such instrumentality may furnish to it; and(b) necessary for research, archiving or statistical purposes if the personal data is not to be used to take any decision specific to a Data Principal and such processing is carried on in accordance with such standards as may be prescribed. (3) The Central Government may, having regard to the volume and nature of personal data processed, notify certain Data Fiduciaries or class of Data Fiduciaries, including startups, as Data Fiduciaries to whom the provisions of section 5, sub-sections (3) and (7) of section 8 and sections 10 and 11 shall not apply. Explanation.—For the purposes of this sub-section, the term “startup” means a private limited company or a partnership firm or a limited liability partnership incorporated in India, which is eligible to be and is recognised as such in accordance with the criteria and process notified by the department to which matters relating to startups are allocated in the Central Government. (4) In respect of processing by the State or any instrumentality of the State, the provisions of sub-section (7) of section 8 and sub-section (3) of section 12 and, where such processing is for a purpose that does not include making of a decision that affects the Data Principal, sub-section (2) of section 12 shall not apply. (5) The Central Government may, before expiry of five years from the date of commencement of this Act, by notification, declare that any provision of this Act shall not apply to such Data Fiduciary or classes of Data Fiduciaries for such period as may be specified in the notification. P.S: 17(1) to be read with Section 8(1): (1) A Data Fiduciary shall, irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties provided under this Act, be responsible for complying with the provisions of this Act and the rules made thereunder in respect of any processing undertaken by it or on its behalf by a Data Processor....Not Exempted Section 8(5):(5) A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach....Not Exempted Chapter II: Obligations, Chapter III: Rights, Section 16: Cross Border transfer...Exempted 17(2) (a) to be read with Section 8(7): A Data Fiduciary shall, unless retention is necessary for compliance with any law for the time being in force,—(a) erase personal data, upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier; and(b) cause its Data Processor to erase any personal data that was made available by the Data Fiduciary for processing to such Data Processor. Section 12(3): A Data Principal shall make a request in such manner as may be prescribed to the Data Fiduciary for erasure of her personal data, and upon receipt of such a request, the Data Fiduciary shall erase her personal data unless retention of the same is necessary for the specified purpose or for compliance with any law for the time being in force. Section 12(2) (2) A Data Fiduciary shall, upon receiving a request for correction, completion or updating from a Data Principal,—(a) correct the inaccurate or misleading personal data;(b) complete the incomplete personal data; and(c) update the personal data. 17(3) to be read with Section 5: Notice Section 8(3) (3) Where personal data processed by a Data Fiduciary is likely to be—(a) used to make a decision that affects the Data Principal; or (b) disclosed to another Data Fiduciary, the Data Fiduciary processing such personal data shall ensure its completeness, accuracy and consistency. Section 8(7) A Data Fiduciary shall, unless retention is necessary for compliance with any law for the time being in force,—(a) erase personal data, upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier; and(b) cause its Data Processor to erase any personal data that was made available by the Data Fiduciary for processing to such Data Processor. Section 10: Significant Data Fiduciary Section 11: Right to Access

What Article 17 Means for Your Business

Article 17 sets out categories of processing and categories of organisations that are wholly or partially exempt from the DPDPA's obligations. Understanding these exemptions is important both for organisations that may qualify and for those that do not, incorrect reliance on an exemption is itself a compliance failure.
  • Processing for personal or domestic purposes is fully exempt, an individual managing their own contact list is not subject to the Act.
  • Publicly available personal data, data that the Data Principal has voluntarily made public, may be processed without the Act's consent requirements applying.
  • The Central Government and its agencies may be exempt from certain provisions in the interests of national security, public order, sovereignty, or friendly relations with foreign states.
  • Research, archiving, and statistical processing are exempt from certain provisions, subject to the standards prescribed in Schedule V.
  • If you believe your organisation or processing activity qualifies for an exemption, document the legal basis for that position, relying on an exemption that does not apply carries penalty risk.
  • Exemptions are narrowly construed, if in doubt, assume the Act applies and seek legal advice on whether a specific exemption is available.

Frequently Asked Questions about Article 17

+ What are exemptions under Article 17?
Exemptions are situations where certain provisions of the DPDP Act do not apply to specific types of data processing.
+ When can businesses rely on exemptions?
Businesses can rely on exemptions when processing is required for legal claims, regulatory functions, or public interest purposes.
+ Do exemptions apply to law enforcement activities?
Yes. Data processing for prevention, detection, investigation, or prosecution of offences may be exempt.
+ Are mergers and acquisitions covered under exemptions?
Yes. Data processing related to corporate restructuring such as mergers or acquisitions may qualify for exemptions.
+ Why are exemptions important for businesses?
They allow necessary data processing in critical situations without violating compliance requirements.

View Article
India DPDPA: Article 18 – Establishment of the Board

18. Establishment of the Board (1) With effect from such date as the Central Government may, by notification, appoint, there shall be established, for the purposes of this Act, a Board to be called the Data Protection Board of India. (2) The Board shall be a body corporate by the name aforesaid, having perpetual succession and a common seal, with power, subject to the provisions of this Act, to acquire, hold and dispose of property, both movable and immovable, and to contract and shall, by the said name, sue or be sued. (3) The headquarters of the Board shall be at such place as the Central Government may notify.

What Article 18 Means for Your Business

Article 18 establishes the Data Protection Board of India (DPBI) as the statutory body responsible for enforcing the DPDPA. The Board is the regulatory authority to which Data Principals can bring complaints, and which can investigate breaches and impose penalties on Data Fiduciaries.
  • The Data Protection Board of India is now established and operational, it is the primary enforcement authority under the DPDPA.
  • The Board operates as a digital-first body, complaints, notices, and proceedings are conducted electronically where possible.
  • Businesses should familiarise themselves with the Board's procedures for receiving and handling complaints, as these affect how you must respond to Board inquiries.
  • The Board has the power to direct urgent remedial action in the event of a data breach, non-compliance with Board directions carries significant penalty risk.

Frequently Asked Questions about Article 18

+ What is the Data Protection Board of India?
It is the authority established to enforce the provisions of the DPDP Act and handle data protection-related matters.
+ What powers does the Board have?
The Board can investigate non-compliance, issue directions, and take enforcement actions against businesses.
+ Do businesses need to interact with the Board?
Yes. Businesses may need to respond to notices, provide information, or cooperate during investigations.
+ Where is the Board located?
The headquarters of the Board will be determined and notified by the Central Government.
+ Why is this important for businesses?
It establishes the regulatory authority that ensures compliance and enforces penalties under the Act.

View Article
India DPDPA: Article 19 – Composition and Qualifications for Appointment of Chairperson and Members

19. Composition and Qualifications for Appointment of Chairperson and Members (1) The Board shall consist of a Chairperson and such number of other Members as the Central Government may notify. (2) The Chairperson and other Members shall be appointed by the Central Government in such manner as may be prescribed. (3) The Chairperson and other Members shall be a person of ability, integrity and standing who possesses special knowledge or practical experience in the fields of data governance, administration or implementation of laws related to social or consumer protection, dispute resolution, information and communication technology, digital economy,law, regulation or techno-regulation, or in any other field which in the opinion of the Central Government may be useful to the Board, and at least one among them shall be an expert in the field of law.

What Article 19 Means for Your Business

Article 19 prescribes the composition of the Data Protection Board and the qualifications required for its Chairperson and Members. While primarily of structural importance, this Article reflects the legislature's intent for the Board to have expertise in law, technology, and data governance.
  • The Board is composed of a Chairperson and such number of Members as the Central Government prescribes, the size and composition may evolve as the Board's caseload grows.
  • Members must have expertise in data protection, information technology, law, or related fields, this signals that the Board is intended to apply substantive regulatory judgement rather than simply administrative process.
  • The qualification requirements for Board Members provide an indication of the standards against which compliance decisions will be assessed.

Frequently Asked Questions about Article 19

+ What does Article 19 of the DPDP Act cover?
Article 19 outlines the composition of the Data Protection Board and the qualifications required for appointing its Chairperson and Members.
+ Who appoints the Chairperson and Members of the Board?
The Central Government appoints the Chairperson and other Members of the Data Protection Board.
+ What qualifications must Board members have?
Members must have expertise in areas such as law, data governance, information technology, public administration, or related fields, along with integrity and relevant experience.
+ Is legal expertise required on the Board?
Yes. At least one member of the Board must be an expert in the field of law.
+ Why is Article 19 important for businesses?
It ensures that decisions affecting businesses will be made by qualified professionals, leading to fair, informed, and consistent enforcement of data protection rules.

View Article
India DPDPA: Article 20 – Salary, allowances payable to and term of office

20. Salary, allowances payable to and term of office (1) The salary, allowances and other terms and conditions of service of the Chairperson and other Members shall be such as may be prescribed, and shall not be varied to their disadvantage after their appointment. (2) The Chairperson and other Members shall hold office for a term of two years and shall be eligible for re-appointment.

What Article 20 Means for Your Business

Article 20 governs the terms of service of the Board's Chairperson and Members, including their salaries, allowances, and tenure. These provisions support the Board's independence and institutional stability, which in turn affects the predictability and consistency of enforcement.
  • The fixed terms and prescribed conditions of service for Board Members are designed to insulate them from undue political or commercial influence.
  • A stable, professionally remunerated Board is more likely to develop consistent and predictable enforcement practice, businesses should monitor early Board decisions to understand enforcement priorities.

Frequently Asked Questions about Article 20

+ What does Article 20 of the DPDP Act cover?
Article 20 specifies the salary, allowances, and terms of service for the Chairperson and Members of the Data Protection Board of India.
+ Who decides the salary and allowances of Board members?
The Central Government determines the salary, allowances, and other service conditions of the Chairperson and Members.
+ Can the terms of service be changed after appointment?
No. The terms and conditions cannot be changed to the disadvantage of the Chairperson or Members after their appointment.
+ What is the tenure of Board members?
The Chairperson and Members hold office for a specified term, typically two years, and may be eligible for re-appointment.
+ Why is Article 20 relevant for businesses?
It ensures stability and independence of the regulatory authority, which leads to consistent and predictable enforcement of data protection laws for businesses.

View Article
India DPDPA: Article 21 – Disqualifications for appointment and continuation as Chairperson and Members of the Board

21. Disqualifications for appointment and continuation as Chairperson and Members of the Board (1) A person shall be disqualified for being appointed and continued as the Chairperson or a Member, if she— (a) has been adjudged as an insolvent; (b) has been convicted of an offence, which in the opinion of the Central Government, involves moral turpitude; (c) has become physically or mentally incapable of acting as a Member; (d) has acquired such financial or other interest, as is likely to affect prejudicially her functions as a Member; or (e) has so abused her position as to render her continuance in office prejudicial to the public interest. (2) The Chairperson or Member shall not be removed from her office by the Central Government unless she has been given an opportunity of being heard in the matter.

What Article 21 Means for Your Business

Article 21 specifies the grounds on which a person may not be appointed to or continue to serve on the Data Protection Board. These provisions are designed to ensure the integrity and independence of the regulatory body.
  • Board Members cannot have conflicts of interest with the entities they regulate, this is relevant when assessing the likelihood of impartial treatment in enforcement proceedings involving your organisation.
  • If your organisation is ever a party to Board proceedings, you are entitled to raise legitimate questions about the impartiality of the decision-maker where a relevant disqualification ground exists.

Frequently Asked Questions about Article 21

+ What does Article 21 of the DPDP Act cover?
Article 21 specifies the conditions under which a person is disqualified from being appointed or continuing as the Chairperson or a Member of the Data Protection Board.
+ What are common grounds for disqualification?
Disqualification may occur if a person is insolvent, convicted of an offence involving moral turpitude, mentally or physically incapable, has conflicting financial interests, or abuses their position.
+ Can Board members be removed after appointment?
Yes. Members can be removed by the Central Government if they meet any disqualification criteria, but they must be given an opportunity to be heard.
+ Why are disqualification rules important?
These rules ensure that only qualified, unbiased, and capable individuals serve on the Board, maintaining trust and fairness in regulatory enforcement.
+ How does this impact businesses?
It ensures that businesses are regulated by a fair and independent authority, reducing the risk of biased or improper enforcement decisions.

View Article
India DPDPA: Article 22 – Resignation by Members and filling of vacancy

22. Resignation by Members and filling of vacancy (1) The Chairperson or any other Member may give notice in writing to the Central Government of resigning from her office, and such resignation shall be effective from the date on which the Central Government permits her to relinquish office, or upon expiry of a period of three months from the date of receipt of such notice, or upon a duly appointed successor entering upon her office, or upon the expiry of the term of her office, whichever is earliest. (2) A vacancy caused by the resignation or removal or death of the Chairperson or any other Member, or otherwise, shall be filled by fresh appointment in accordance with the provisions of this Act. (3) The Chairperson and any other Member shall not, for a period of one year from the date on which they cease to hold such office, except with the previous approval of the Central Government, accept any employment, and shall also disclose to the Central Government any subsequent acceptance of employment with any Data Fiduciary against whom proceedings were initiated by or before such Chairperson or other Member.

What Article 22 Means for Your Business

Article 22 sets out the process for Board Members to resign and for vacancies to be filled. The continuity of the Board's composition is important for ongoing enforcement proceedings.
  • Vacancies on the Board must be filled promptly, any gaps in Board composition should not affect the validity of proceedings already under way.
  • If your organisation has an active matter before the Board and a membership change occurs, understand the rules governing continuity of proceedings in such circumstances.

Frequently Asked Questions about Article 22

+ What does Article 22 of the DPDP Act cover?
Article 22 deals with the resignation of the Chairperson and Members of the Data Protection Board and how vacancies are filled.
+ How can a Board member resign?
A member can resign by submitting a written notice to the Central Government, and the resignation takes effect based on specified conditions.
+ What happens when a vacancy arises?
Any vacancy is filled through a new appointment in accordance with the provisions of the DPDP Act.
+ Are there restrictions after leaving the Board?
Yes. Former members may be restricted from accepting certain employment for a specified period without prior approval from the Central Government.
+ Why is this important for businesses?
It ensures continuity and stability in regulatory oversight, so businesses are not affected by changes in Board membership.

View Article
India DPDPA: Article 23 – Proceedings of Board

23. Proceedings of Board (1) The Board shall observe such procedure in regard to the holding of and transaction of business at its meetings, including by digital means, and authenticate its orders, directions and instruments in such manner as may be prescribed. (2) No act or proceeding of the Board shall be invalid merely by reason of (a) any vacancy in or any defect in the constitution of the Board;(b) any defect in the appointment of a person acting as the Chairperson or other Member of the Board; or(c) any irregularity in the procedure of the Board, which does not affect the merits of the case. (3) When the Chairperson is unable to discharge her functions owing to absence, illness or any other cause, the senior-most Member shall discharge the functions of the Chairperson until the date on which the Chairperson resumes her duties.

What Article 23 Means for Your Business

Article 23 governs how the Data Protection Board conducts its proceedings, including quorum requirements and decision-making procedures. Understanding these procedural rules is important if your organisation ever faces a Board inquiry or is a complainant.
  • Board decisions are made by a majority of Members present, understanding the quorum rules helps assess whether a decision or order is procedurally valid.
  • The Board must follow principles of natural justice, you have the right to be heard before any adverse order is made against your organisation.
  • Familiarise yourself with the Board's published procedural rules under the DPDP Rules 2025 before any inquiry commences.

Frequently Asked Questions about Article 23

+ What does Article 23 of the DPDP Act cover?
Article 23 outlines the procedures for how the Data Protection Board conducts its meetings, proceedings, and decision-making processes.
+ Can Board meetings be conducted digitally?
Yes. The Board may conduct its meetings and proceedings through digital means as prescribed by rules.
+ Are Board decisions invalid due to procedural defects?
No. Minor defects in the Board’s composition, appointment, or procedures do not invalidate its decisions if they do not affect the merits of the case.
+ What happens if the Chairperson is unavailable?
If the Chairperson is unable to perform duties, the senior-most Member will temporarily discharge those functions.
+ Why is Article 23 important for businesses?
It ensures that regulatory decisions are stable and enforceable, reducing the risk of delays or challenges based on procedural technicalities.

View Article
India DPDPA: Article 24 – Officers and Employees of the Board

24. Officers and Employees of the Board The Board may, with previous approval of the Central Government, appoint such officers and employees as it may deem necessary for the efficient discharge of its functions under the provisions of this Act, on such terms and conditions of appointment and service as may be prescribed.

What Article 24 Means for Your Business

Article 24 provides for the Board to appoint officers and staff necessary for carrying out its functions. The capacity and capability of the Board's secretariat affects the pace and quality of its enforcement activity.
  • The Board's operational capacity will grow over time, initial enforcement may be selective while the secretariat is established, but this should not be treated as a licence to delay compliance.
  • Communications from Board officers in the course of an inquiry carry the same weight as directions from Members, respond promptly and completely to all formal Board correspondence.

Frequently Asked Questions about Article 24

+ What does Article 24 of the DPDP Act cover?
Article 24 provides for the appointment of officers and employees to assist the Data Protection Board in performing its functions.
+ Who appoints the officers and employees of the Board?
The Board appoints its officers and employees with the prior approval of the Central Government.
+ What roles do these officers perform?
They support the Board in administrative tasks, investigations, enforcement actions, and handling compliance-related processes.
+ Will businesses interact with these officers?
Yes. Businesses may communicate with authorized officers during inquiries, investigations, or compliance processes.
+ Why is Article 24 important for businesses?
It ensures that the Board has sufficient resources to enforce the law effectively, leading to more efficient and timely regulatory actions.

View Article
India DPDPA: Article 25 – Members and Officers to be public servants

25. Members and Officers to be public servants The Chairperson, Members, officers and employees of the Board shall be deemed, when acting or purporting to act in pursuance of provisions of this Act, to be public servants within the meaning of section 21 of the Indian Penal Code.

What Article 25 Means for Your Business

Article 25 classifies Board Members and officers as public servants under the Indian Penal Code. This has practical implications for how businesses interact with the Board during proceedings.
  • Any attempt to obstruct, mislead, or improperly influence Board Members or staff constitutes an offence, ensure all interactions with the Board are conducted transparently and in good faith.
  • Documents and information submitted to the Board must be accurate, submitting false or misleading information carries criminal liability independent of any DPDPA penalty.

Frequently Asked Questions about Article 25

+ What does Article 25 of the DPDP Act cover?
Article 25 states that the Chairperson, Members, officers, and employees of the Data Protection Board are deemed to be public servants.
+ What does it mean to be a public servant?
Being a public servant means that individuals are subject to legal obligations, accountability standards, and protections under the law while performing official duties.
+ Why are Board members classified as public servants?
This classification ensures that they act with integrity, transparency, and accountability while exercising regulatory powers.
+ Can businesses challenge actions taken by the Board?
Yes. Since Board officials are public servants, their actions must comply with the law and can be challenged if they are unlawful or abusive.
+ Why is Article 25 important for businesses?
It ensures that regulatory actions are carried out responsibly and within a legal framework, protecting businesses from arbitrary or unfair decisions.

View Article
India DPDPA: Article 26 – Powers of the Chairperson

26. Powers of the Chairperson 26. The Chairperson shall exercise the following powers, namely:— (a) general superintendence and giving direction in respect of all administrative matters of the Board; (b) authorise any officer of the Board to scrutinise any intimation, complaint, reference or correspondence addressed to the Board; and(c) authorise performance of any of the functions of the Board and conduct any of its proceedings, by an individual Member or groups of Members and to allocateproceedings among them.

What Article 26 Means for Your Business

Article 26 vests administrative and operational powers in the Chairperson of the Data Protection Board. These powers govern the internal management of the Board and the assignment of matters to Members.
  • The Chairperson has the power to distribute cases among Members, this may affect which Member handles a particular inquiry involving your organisation.
  • The Chairperson's administrative decisions may be subject to review, understand the available avenues if you believe a procedural irregularity has affected proceedings involving your organisation.

Frequently Asked Questions about Article 26

+ What does Article 26 of the DPDP Act cover?
Article 26 outlines the powers and responsibilities of the Chairperson of the Data Protection Board of India.
+ What powers does the Chairperson have?
The Chairperson has administrative control over the Board, can allocate cases, authorize officers, and oversee proceedings.
+ Can the Chairperson assign cases to Members?
Yes. The Chairperson can assign cases to individual Members or groups of Members for efficient handling of matters.
+ Do officers play a role under the Chairperson?
Yes. The Chairperson may authorize officers of the Board to examine complaints, communications, and related matters.
+ Why is Article 26 important for businesses?
It ensures efficient leadership and coordination within the Board, leading to faster, more organized handling of regulatory actions affecting businesses.

View Article
India DPDPA: Article 27 – Powers and functions of Board

27. Powers and functions of Board (1) The Board shall exercise and perform the following powers and functions, namely:— (a) on receipt of an intimation of personal data breach under sub-section (6) of section 8, to direct any urgent remedial or mitigation measures in the event of a personal data breach, and to inquire into such personal data breach and impose penalty as provided in this Act; (b) on a complaint made by a Data Principal in respect of a personal data breach or a breach in observance by a Data Fiduciary of its obligations in relation to her personal data or the exercise of her rights under the provisions of this Act, or on a reference made to it by the Central Government or a State Government, or in compliance of the directions of any court, to inquire into such breach and impose penalty as provided in this Act; (c) on a complaint made by a Data Principal in respect of a breach in observance by a Consent Manager of its obligations in relation to her personal data, to inquire into such breach and impose penalty as provided in this Act; (d) on receipt of an intimation of breach of any condition of registration of a Consent Manager, to inquire into such breach and impose penalty as provided in this Act; and (e) on a reference made by the Central Government in respect of the breach in observance of the provisions of sub-section (2) of section 36 (?) (ed: Should be 37)by an intermediary, to inquire into such breach and impose penalty as provided in this Act. (2) The Board may, for the effective discharge of its functions under the provisions of this Act, after giving the person concerned an opportunity of being heard and after recording reasons in writing, issue such directions as it may consider necessary to such person, who shall be bound to comply with the same. (3) The Board may, on a representation made to it by a person affected by a direction issued under sub-section (1) or sub-section (2), or on a reference made by the Central Government, modify, suspend, withdraw or cancel such direction and, while doing so, impose such conditions as it may deem fit, subject to which the modification, suspension, withdrawal or cancellation shall have effect.

What Article 27 Means for Your Business

Article 27 is one of the most operationally significant provisions of the DPDPA for compliance teams. It defines the full range of the Data Protection Board's enforcement powers, from directing urgent remedial action following a breach to conducting inquiries and imposing penalties of up to ₹250 crore.
  • The Board can act on its own initiative following a breach notification, it does not need to wait for a complaint from a Data Principal to open an inquiry.
  • In urgent situations, the Board can direct immediate remedial or mitigation measures, your incident response plan must include a Board notification and response track alongside technical containment steps.
  • The Board can summon persons, require documents, and conduct hearings, non-cooperation with a Board inquiry is itself a breach that can attract additional penalties.
  • Penalties can reach ₹250 crore for the most serious breaches, assess the potential financial exposure for your organisation across each obligation under the Act.
  • The Board also has the power to refer matters to alternate dispute resolution, understand when this pathway may be available and advantageous in any dispute.

Frequently Asked Questions about Article 27

+ What does Article 27 of the DPDP Act cover?
Article 27 outlines the powers and functions of the Data Protection Board, including investigation, enforcement, and handling of data protection complaints.
+ Can the Board investigate data breaches?
Yes. The Board can investigate personal data breaches and require businesses to take corrective or mitigation measures.
+ Can individuals file complaints against businesses?
Yes. Data Principals can file complaints regarding violations of their rights or non-compliance by businesses.
+ Does the Board have the power to impose penalties?
Yes. The Board can impose penalties on businesses and other entities for violations of the DPDP Act.
+ Why is Article 27 important for businesses?
It defines the enforcement authority of the Board, making it essential for businesses to maintain compliance and respond promptly to regulatory actions.

View Article
India DPDPA: Article 28 – Procedure to be followed by Board

28. Procedure to be followed by Board (1) The Board shall function as an independent body and shall, as far as practicable, function as a digital office, with the receipt of complaints and the allocation, hearing and pronouncement of decisions in respect of the same being digital by design, and adopt such techno-legal measures as may be prescribed. (2) The Board may, on receipt of an intimation or complaint or reference or directions as referred to in sub-section (1) of section 27, take action in accordance with the provisions of this Act and the rules made thereunder. (3) The Board shall determine whether there are sufficient grounds to proceed with an inquiry. (4) In case the Board determines that there are insufficient grounds, it may, for reasons to be recorded in writing, close the proceedings. (5) In case the Board determines that there are sufficient grounds to proceed with inquiry, it may, for reasons to be recorded in writing, inquire into the affairs of any person for ascertaining whether such person is complying with or has complied with the provisions of this Act. (6) The Board shall conduct such inquiry following the principles of natural justice and shall record reasons for its actions during the course of such inquiry. (7) For the purposes of discharging its functions under this Act, the Board shall have the same powers as are vested in a civil court under the Code of Civil Procedure, 1908, in respect of matters relating to— (a) summoning and enforcing the attendance of any person and examining her on oath;(b) receiving evidence of affidavit requiring the discovery and production of documents;(c) inspecting any data, book, document, register, books of account or any other document; and(d) such other matters as may be prescribed. (8) The Board or its officers shall not prevent access to any premises or take into custody any equipment or any item that may adversely affect the day-to-day functioning of a person. (9) The Board may require the services of any police officer or any officer of the Central Government or a State Government to assist it for the purposes of this section and it shall be the duty of every such officer to comply with such requisition. (10) During the course of the inquiry, if the Board considers it necessary, it may for reasons to be recorded in writing, issue interim orders after giving the person concerned an opportunity of being heard. (11) On completion of the inquiry and after giving the person concerned an opportunity of being heard, the Board may for reasons to be recorded in writing, either close the proceedings or proceed in accordance with section 33. (12) At any stage after receipt of a complaint, if the Board is of the opinion that the complaint is false or frivolous, it may issue a warning or impose costs on the complainant.

What Article 28 Means for Your Business

Article 28 sets out the procedural framework within which the Data Protection Board conducts its inquiries and adjudicates complaints. The procedures are designed to be accessible and efficient while ensuring fairness to all parties.
  • The Board is not bound by the Code of Civil Procedure, it has the flexibility to determine its own procedures, which may make proceedings faster than traditional courts but also less predictable.
  • Both parties, the complainant and the Data Fiduciary, must be given the opportunity to be heard before any adverse finding is made.
  • The Board conducts proceedings digitally where possible, ensure your organisation has clear lines of responsibility for receiving and responding to Board communications promptly.
  • Prepare standard operating procedures for how your legal and compliance teams will respond to a Board notice, time limits for response are strict and missing them can lead to adverse findings.

Frequently Asked Questions about Article 28

+ What does Article 28 of the DPDP Act cover?
Article 28 defines the procedures the Data Protection Board follows when handling complaints, inquiries, and enforcement actions.
+ Does the Board operate digitally?
Yes. The Board is designed to function as a digital office, handling complaints, hearings, and decisions through digital means wherever practicable.
+ Will businesses get a chance to respond during an inquiry?
Yes. The Board follows principles of natural justice, ensuring that businesses are given an opportunity to be heard before decisions are made.
+ What powers does the Board have during investigations?
The Board has powers similar to a civil court, including summoning individuals, examining evidence, and requiring production of documents.
+ Why is Article 28 important for businesses?
It defines how enforcement actions are carried out, ensuring fairness, transparency, and structured processes during regulatory proceedings.

View Article
India DPDPA: Article 29 – Appeal to Appellate Tribunal

29. Appeal to Appellate Tribunal (1) Any person aggrieved by an order or direction made by the Board under this Act may prefer an appeal before the Appellate Tribunal. (2) Every appeal under sub-section (1) shall be filed within a period of sixty days from the date of receipt of the order or direction appealed against and it shall be in such form and manner and shall be accompanied by such fee as may be prescribed. (3) The Appellate Tribunal may entertain an appeal after the expiry of the period specified in sub-section (2), if it is satisfied that there was sufficient cause for not preferring the appeal within that period. (4) On receipt of an appeal under sub-section (1), the Appellate Tribunal may, after giving the parties to the appeal, an opportunity of being heard, pass such orders thereon as it thinks fit, confirming, modifying or setting aside the order appealed against. (5) The Appellate Tribunal shall send a copy of every order made by it to the Board and to the parties to the appeal. (6) The appeal filed before the Appellate Tribunal under sub-section (1) shall be dealt with by it as expeditiously as possible and endeavour shall be made by it to dispose of the appeal finally within six months from the date on which the appeal is presented to it. (7) Where any appeal under sub-section (6) could not be disposed of within the period of six months, the Appellate Tribunal shall record its reasons in writing for not disposing of the appeal within that period. (8) Without prejudice to the provisions of section 14A and section 16 of the Telecom Regulatory Authority of India Act, 1997, the Appellate Tribunal shall deal with an appeal under this section in accordance with such procedure as may be prescribed. (9) Where an appeal is filed against the orders of the Appellate Tribunal under this Act, the provisions of section 18 of the Telecom Regulatory Authority of India Act, 1997 shall apply. (10) In respect of appeals filed under the provisions of this Act, the Appellate Tribunal shall, as far as practicable, function as a digital office, with the receipt of appeal, hearing and pronouncement of decisions in respect of the same being digital by design.

What Article 29 Means for Your Business

Article 29 provides the right to appeal a Data Protection Board decision to the Appellate Tribunal (the Telecom Disputes Settlement and Appellate Tribunal, or TDSAT, currently designated for this purpose). This creates a two-tier adjudicatory system and gives organisations a formal route to challenge Board decisions they believe are incorrect.
  • Appeals must be filed within 60 days of the Board's order, missing this deadline forfeits the right to appeal unless the Appellate Tribunal condones the delay.
  • The Appellate Tribunal can stay the execution of a Board order pending appeal, apply for a stay promptly if the order requires immediate action that you intend to contest.
  • Build appeal rights into your DPDPA incident response framework, know in advance who will make the decision to appeal and what the internal approval process looks like.
  • Legal representation before the Appellate Tribunal is advisable, retain counsel experienced in both data protection law and administrative tribunal practice.

Frequently Asked Questions about Article 29

+ What does Article 29 of the DPDP Act cover?
Article 29 allows individuals and businesses to appeal decisions made by the Data Protection Board to an Appellate Tribunal.
+ Who can file an appeal?
Any person aggrieved by an order or direction of the Data Protection Board can file an appeal before the Appellate Tribunal.
+ What is the time limit for filing an appeal?
An appeal should generally be filed within 60 days from the date of receiving the order or direction.
+ Can late appeals be accepted?
Yes. The Appellate Tribunal may accept a delayed appeal if sufficient cause for the delay is demonstrated.
+ What powers does the Appellate Tribunal have?
The Tribunal can confirm, modify, or set aside the order of the Data Protection Board after hearing the parties involved.

View Article
India DPDPA: Article 30 – Orders passed by Appellate Tribunal to be executable as decree

30. Orders passed by Appellate Tribunal to be executable as decree
(1) An order passed by the Appellate Tribunal under this Act shall be executable by it as a decree of civil court, and for this purpose, the Appellate Tribunal shall have all the powers of a civil court. (2) Notwithstanding anything contained in sub-section (1), the Appellate Tribunal may transmit any order made by it to a civil court having local jurisdiction and such civil court shall execute the order as if it were a decree made by that court.

What Article 30 Means for Your Business

Article 30 provides that orders of the Appellate Tribunal are enforceable as decrees of a civil court. This makes Appellate Tribunal decisions legally binding in the same way as court judgments, with all associated enforcement mechanisms available.
  • Appellate Tribunal orders are not merely administrative recommendations, they carry the full legal force of civil court decrees and can be enforced through court execution proceedings if not complied with voluntarily.
  • Non-compliance with an Appellate Tribunal order can result in contempt proceedings and further financial liability.
  • Factor the enforcement mechanism into your decisions about whether to comply, appeal, or seek a stay of any Board or Tribunal order.

Frequently Asked Questions about Article 30

+ What does Article 30 of the DPDP Act cover?
Article 30 states that orders passed by the Appellate Tribunal are enforceable as if they were decrees of a civil court.
+ What does “executable as a decree” mean?
It means that the Tribunal’s orders have the same legal force as a court judgment and can be enforced through legal mechanisms.
+ Can Tribunal orders be enforced through civil courts?
Yes. The Tribunal may transfer its orders to a civil court, which will execute them as if they were its own decrees.
+ What happens if a business does not comply with a Tribunal order?
Non-compliance can lead to enforcement actions through the legal system, including court proceedings.
+ Why is Article 30 important for businesses?
It ensures that appeal decisions are final and enforceable, requiring businesses to comply with Tribunal orders without delay.

View Article
India DPDPA: Article 31 – Alternate Dispute Resolution

31. Alternate Dispute Resolution If the Board is of the opinion that any complaint may be resolved by mediation, it may direct the parties concerned to attempt resolution of the dispute through such mediation by such mediator as the parties may mutually agree upon, or as provided for under any law for the time being in force in India.

What Article 31 Means for Your Business

Article 31 allows parties to DPDPA proceedings to resolve disputes through alternate dispute resolution (ADR) mechanisms. This provides a faster and potentially less costly pathway to resolution compared to full Board adjudication.
  • ADR may be available for certain categories of disputes, explore this option early in any Board proceedings to assess whether a negotiated resolution is achievable.
  • Settlements reached through ADR must be approved by the Board, they are not simply private agreements and must meet the Board's standards for adequacy.
  • ADR may allow for remediation commitments rather than purely financial penalties, this can be preferable for organisations that have taken genuine steps to address a breach.

Frequently Asked Questions about Article 31

+ What does Article 31 of the DPDP Act cover?
Article 31 allows disputes under the DPDP Act to be resolved through alternate dispute resolution methods such as mediation.
+ What is Alternate Dispute Resolution (ADR)?
ADR refers to resolving disputes outside formal legal proceedings, typically through mediation or negotiation.
+ Who decides if ADR will be used?
The Data Protection Board may direct parties to attempt mediation if it believes the dispute can be resolved through ADR.
+ Can businesses choose the mediator?
Yes. The parties may mutually agree on a mediator, or follow procedures prescribed under applicable laws.
+ Why is ADR beneficial for businesses?
ADR provides a faster, less costly, and more flexible way to resolve disputes while maintaining business relationships and reputation.

View Article
India DPDPA: Article 32 – Voluntary Undertaking

32. Voluntary Undertaking (1) The Board may accept a voluntary undertaking in respect of any matter related to observance of the provisions of this Act from any person at any stage of a proceeding under section 28. (2) The voluntary undertaking referred to in sub-section (1) may include an undertaking to take such action within such time as may be determined by the Board, or refrain from taking such action, and or publicising such undertaking. (3) The Board may, after accepting the voluntary undertaking and with the consent of the person who gave the voluntary undertaking vary the terms included in the voluntary undertaking. (4) The acceptance of the voluntary undertaking by the Board shall constitute a bar on proceedings under the provisions of this Act as regards the contents of the voluntary undertaking, except in cases covered by sub-section (5). (5) Where a person fails to adhere to any term of the voluntary undertaking accepted by the Board, such breach shall be deemed to be breach of the provisions of this Act and the Board may, after giving such person an opportunity of being heard, proceed in accordance with the provisions of section 33.

What Article 32 Means for Your Business

Article 32 allows a person who is the subject of Board proceedings to offer a voluntary undertaking, a commitment to take specific remedial action, cease a particular practice, or implement compliance measures. Accepted undertakings can lead to the closure or suspension of proceedings.
  • A voluntary undertaking is a proactive tool, offering one early in proceedings demonstrates good faith and may result in more favourable treatment than waiting for a penalty to be imposed.
  • The Board can accept, modify, or reject a voluntary undertaking, prepare a well-evidenced proposal that demonstrates genuine commitment to remediation.
  • If the undertaking is accepted and subsequently breached, the Board may resume proceedings and take the breach into account as an aggravating factor when determining penalties.
  • Consider a voluntary undertaking as part of your incident response toolkit, it is not an admission of liability but a pragmatic compliance mechanism.

Frequently Asked Questions about Article 32

+ What does Article 32 of the DPDP Act cover?
Article 32 allows businesses or individuals to submit a voluntary undertaking to the Data Protection Board to resolve compliance issues.
+ What is a voluntary undertaking?
It is a formal commitment made to the Board to take specific actions or refrain from certain activities to address a compliance concern.
+ When can a voluntary undertaking be submitted?
It can be submitted at any stage of proceedings under the DPDP Act.
+ What happens after the Board accepts the undertaking?
The acceptance may pause or conclude enforcement proceedings related to the matter covered by the undertaking.
+ What if a business fails to comply with the undertaking?
Failure to comply is treated as a violation of the Act, and the Board may take further enforcement action.

View Article
India DPDPA: Article 33 – Penalties

33. Penalties (1) If the Board determines on conclusion of an inquiry that breach of the provisions of this Act or the rules made thereunder by a person is significant, it may, after giving the person an opportunity of being heard, impose such monetary penalty specified in the Schedule. (2) While determining the amount of monetary penalty to be imposed under sub-section (1), the Board shall have regard to the following matters, namely:— (a) the nature, gravity and duration of the breach; (b) the type and nature of the personal data affected by the breach; (c) repetitive nature of the breach; (d) whether the person, as a result of the breach, has realised a gain or avoided any loss; (e) whether the person took any action to mitigate the effects and consequences of the breach, and the timeliness and effectiveness of such action; (f) whether the monetary penalty to be imposed is proportionate and effective, having regard to the need to secure observance of and deter breach of the provisions of this Act; and (g) the likely impact of the imposition of the monetary penalty on the person.

What Article 33 Means for Your Business

Article 33 contains the penalty framework under the DPDPA. Penalties are tiered by severity of breach and can reach ₹250 crore (approximately USD 30 million) for the most serious violations. The Board must consider multiple factors when determining the appropriate penalty, including gravity, duration, type of personal data involved, and whether the breach was repetitive.
  • Failure to implement reasonable security safeguards leading to a data breach, penalty up to ₹250 crore.
  • Failure to notify the Board and affected Data Principals of a breach, penalty up to ₹200 crore.
  • Processing children's personal data in violation of Article 9, penalty up to ₹200 crore.
  • Breach of additional obligations by Significant Data Fiduciaries, penalty up to ₹150 crore.
  • Breach of any other provision of the Act or Rules, penalty up to ₹50 crore.
  • Failure by a Data Principal to comply with their duties under Article 15, penalty up to ₹10,000.
  • When determining the penalty quantum, the Board will consider the nature, gravity and duration of the breach; the type and volume of personal data affected; repetitive breaches; and whether the breach was intentional or negligent. Proactive remediation, voluntary disclosure, and cooperation with the Board are likely to be treated as mitigating factors.

Frequently Asked Questions about Article 33

+ What does Article 33 of the DPDP Act cover?
Article 33 defines the penalty provisions for violations of the DPDP Act and how monetary penalties are determined.
+ Who can impose penalties under the DPDP Act?
The Data Protection Board of India has the authority to impose penalties after conducting an inquiry.
+ What factors influence the amount of penalty?
Factors include the nature and severity of the breach, type of data affected, duration, repetition, mitigation efforts, and impact on individuals.
+ Can businesses reduce penalties?
Yes. Taking prompt corrective action, cooperating with the Board, and demonstrating good faith can help reduce penalties.
+ Why is Article 33 important for businesses?
It directly impacts financial risk, making compliance with data protection requirements essential to avoid significant penalties.

View Article
India DPDPA: Article 34 – Crediting sums realised by way of penalties to Consolidated Fund of India

34. Crediting sums realised by way of penalties to Consolidated Fund of India All sums realised by way of penalties imposed by the Board under this Act, shall be credited to the Consolidated Fund of India.

What Article 34 Means for Your Business

Article 34 provides that all penalty amounts collected under the DPDPA are credited to the Consolidated Fund of India rather than being retained by the Data Protection Board. This is a structural safeguard against the regulator having a financial incentive to maximise penalties.

  • The Board's funding does not depend on penalty revenue, this reduces the risk of enforcement being driven by revenue considerations rather than genuine regulatory priorities.
  • Penalties paid are not recoverable, unlike civil litigation where damages flow to the aggrieved party, DPDPA penalties go to the government, not to affected Data Principals.
  • Data Principals must pursue separate civil remedies if they wish to recover compensation for harm caused by a data breach, the penalty under Article 33 does not compensate individuals directly.

Frequently Asked Questions about Article 34

+ What does Article 34 of the DPDP Act state?
Article 34 states that all penalties collected under the Act are credited to the Consolidated Fund of India.
+ Do affected individuals receive compensation from penalties?
No. The penalties are paid to the government and are not distributed to individuals affected by data breaches.
+ Why is this important for businesses?
It emphasizes that penalties are purely punitive, so businesses must focus on compliance to avoid financial loss.
+ Can businesses recover penalty amounts?
No. Once a penalty is imposed and paid, it cannot be recovered or adjusted.

View Article
India DPDPA: Article 35 – Protection of action taken in good faith

35. Protection of action taken in good faith No suit, prosecution or other legal proceedings shall lie against the Central Government, the Board, its Chairperson and any Member, officer or employee thereof for anything which is done or intended to be done in good faith under the provisions of this Act or the rules made thereunder.

What Article 35 Means for Your Business

Article 35 protects Board Members, officers, and employees from legal proceedings for actions taken in good faith in the discharge of their duties under the Act. This provision is designed to ensure the Board can act decisively without fear of personal liability.
  • This protection applies to individual Board Members, not to the Board as an institution, the institution remains accountable through the appellate and judicial review process.
  • If you believe a Board action was taken outside the scope of the Act or in bad faith, the appropriate remedy is judicial review or appeal, not personal action against the individual Member.

Frequently Asked Questions about Article 35

+ What is meant by "good faith" in Article 35?
Good faith refers to actions taken honestly, without malicious intent, and within the scope of the law.
+ Who is protected under this article?
The Central Government, the Data Protection Board, its Chairperson, members, officers, and employees are protected.
+ Can businesses take legal action against the Board?
Legal action cannot be taken for actions done in good faith under the Act, but actions outside legal authority may still be challenged.
+ Why is this important for businesses?
It means businesses must focus on compliance rather than relying on litigation to challenge enforcement actions.

View Article
India DPDPA: Article 36 – Power to call for information

36. Power to call for information The Central Government may, for the purposes of this Act, require the Board and any Data Fiduciary or intermediary to furnish such information as it may call for.

What Article 36 Means for Your Business

Article 36 gives the Central Government the power to call for information from the Data Protection Board about its performance and functioning. This oversight mechanism ensures the Board remains accountable to the executive.
  • Government oversight of the Board may result in policy-driven shifts in enforcement priorities, monitor official statements and MeitY communications for signals about areas of regulatory focus.
  • This provision reinforces that the Board operates within a broader policy framework determined by the Central Government, expect enforcement priorities to align with government digital and data strategy.

Frequently Asked Questions about Article 36

+ What is the purpose of Article 36?
Article 36 allows the Central Government to request information from relevant entities to ensure compliance with the DPDP Act.
+ Who must provide information under this article?
Data Fiduciaries, intermediaries, and the Data Protection Board may be required to provide information when requested.
+ What kind of information can be requested?
Any information relevant to data processing, compliance, or enforcement under the Act may be requested.
+ What happens if a business fails to provide information?
Failure to comply may result in penalties or further legal action under the DPDP Act.
+ Why is this important for businesses?
It highlights the need for proper documentation and readiness to respond to regulatory requests.

View Article
India DPDPA: Article 37 – Power of Central Government to issue directions

37. Power of Central Government to issue directions (1) The Central Government or any of its officers specially authorised by it in this behalf may, upon receipt of a reference in writing from the Board that— (a) intimates the imposition of monetary penalty by the Board on a Data Fiduciary in two or more instances; and(b) advises, in the interests of the general public, the blocking for access by the public to any information generated, transmitted, received, stored or hosted, in any computer resource that enables such Data Fiduciary to carry on any activity relating to offering of goods or services to Data Principals within the territory of India, after giving an opportunity of being heard to that Data Fiduciary, on being satisfied that it is necessary or expedient so to do, in the interests of the general public, for reasons to be recorded in writing, by order, direct any agency of the Central Government or any intermediary to block for access by the public or cause to be blocked for access by the public any such information. (2) Every intermediary who receives a direction issued under sub-section (1) shall be bound to comply with the same. (3) For the purposes of this section, the expressions “computer resource”, “information” and “intermediary” shall have the meanings respectively assigned to them in the Information Technology Act, 2000.

What Article 37 Means for Your Business

Article 37 allows the Central Government to issue binding directions to the Data Protection Board on matters of policy. This means the regulatory environment can shift based on government priorities without requiring amendment to the Act itself.
  • Policy directions from the Central Government are binding on the Board, this creates a channel through which enforcement focus can be shaped by executive priorities.
  • Businesses operating in sectors of strategic national interest (fintech, healthcare, AI, telecommunications) should be particularly alert to government directions that may result in heightened scrutiny.
  • Monitor MeitY and Cabinet Secretariat communications for directions that may affect how the Board exercises its powers in areas relevant to your business.

Frequently Asked Questions about Article 37

+ What powers does Article 37 give to the government?
It allows the Central Government to issue directions, including blocking access to digital platforms or services in the public interest.
+ When can such directions be issued?
Directions may be issued when there are repeated violations of the DPDP Act or when necessary in the interest of the general public.
+ Do intermediaries have to comply with these directions?
Yes. Intermediaries are legally required to comply with directions issued under this article.
+ Can a business be blocked under this provision?
Yes. In serious cases, access to a business’s digital services or platform may be blocked for users in India.
+ Why is Article 37 important for businesses?
It creates a significant compliance risk, as non-compliance can lead to operational shutdown or restricted access.

View Article
India DPDPA: Article 38 – Consistency with other laws

38. Consistency with other laws (1) The provisions of this Act shall be in addition to and not in derogation of any other law for the time being in force. (2) In the event of any conflict between a provision of this Act and a provision of any other law for the time being in force, the provision of this Act shall prevail to the extent of such conflict.

What Article 38 Means for Your Business

Article 38 addresses how the DPDPA interacts with other Indian laws. The Act operates alongside existing legislation such as the Information Technology Act 2000, sectoral data protection rules in banking and telecom, and professional secrecy obligations. Understanding the interaction is essential for businesses operating in regulated sectors.
  • Where the DPDPA is inconsistent with any other law, the DPDPA prevails, sector-specific rules that conflict with DPDPA obligations must yield to the Act.
  • Sectoral regulators (RBI, SEBI, TRAI, IRDAI) may issue DPDPA-consistent guidelines for their sectors, check for sector-specific guidance before relying solely on the Act.
  • The old IT (Reasonable Security Practices) Rules 2011 will remain in force until the phased implementation of DPDPA is complete, do not discontinue compliance with those rules prematurely.
  • Contracts governed by laws other than the DPDPA that involve personal data processing must be reviewed for consistency with the Act's requirements.

Frequently Asked Questions about Article 38

+ What does Article 38 of the DPDP Act state?
It states that the DPDP Act applies in addition to other laws, but will prevail in case of conflict.
+ Does the DPDP Act override all other laws?
No. It only overrides other laws to the extent of any conflict between them.
+ Do businesses still need to follow other regulations?
Yes. Businesses must comply with all applicable laws along with the DPDP Act.
+ Why is this important for businesses?
It helps businesses understand which law to follow when there is overlap or conflict between regulations.

View Article
India DPDPA: Article 39 – Bar of Jurisdiction

39. Bar of Jurisdiction No civil court shall have the jurisdiction to entertain any suit or proceeding in respect of any matter for which the Board is empowered under the provisions of this Act and no injunction shall be granted by any court or other authority in respect of any action taken or to be taken in pursuance of any power under the provisions of this Act.

What Article 39 Means for Your Business

Article 39 prevents civil courts from entertaining suits or proceedings in relation to matters that the Data Protection Board is empowered to adjudicate. This channelling provision is designed to avoid parallel proceedings and ensure the specialist regulatory body handles data protection disputes.
  • Data Principals cannot sue Data Fiduciaries in civil court for breach of the DPDPA, their remedy is through the Board's complaint mechanism.
  • If your organisation faces a civil claim related to data protection, assess whether the matter falls within the Board's exclusive jurisdiction before engaging with court proceedings.
  • This does not prevent separate civil claims for breach of contract, negligence, or other causes of action that may arise from the same factual circumstances as a DPDPA breach, seek legal advice on potential concurrent liability.

Frequently Asked Questions about Article 39

+ What does “bar of jurisdiction” mean in Article 39?
It means that civil courts do not have authority to hear cases that fall under the jurisdiction of the Data Protection Board.
+ Can businesses file cases in civil courts for DPDP matters?
No. Matters covered under the DPDP Act must be handled through the Board and the appellate mechanism provided in the Act.
+ Can courts stop actions taken by the Board?
No. Courts cannot grant injunctions against actions taken under the DPDP Act.
+ Why is this important for businesses?
It means businesses must follow the DPDP Act’s dispute resolution process rather than relying on traditional court remedies.

View Article
India DPDPA: Article 40 – Power to Make Rules

40. Power to Make Rules (1) The Central Government may, by notification, and subject to the condition of previous publication, make rules not inconsistent with the provisions of this Act, to carry out the purposes of this Act. (2) In particular and without prejudice to the generality of the foregoing power, such rules may provide for all or any of the following matters, namely:— (a) the manner in which the notice given by the Data Fiduciary to a Data Principal shall inform her, under sub-section (1) of section 5; (b) the manner in which the notice given by the Data Fiduciary to a Data Principal shall inform her, under sub-section (2) of section 5; (c) the manner of accountability and the obligations of Consent Manager under sub-section (8) of section 6; (d) the manner of registration of Consent Manager and the conditions relating thereto, under sub-section (9) of section 6; (e) the subsidy, benefit, service, certificate, licence or permit for the provision or issuance of which, personal data may be processed under clause (b) of section 7; (f) the form and manner of intimation of personal data breach to the Board under sub-section (6) of section 8; (g) the time period for the specified purpose to be deemed as no longer being served, under sub-section (8) of section 8; (h) the manner of publishing the business contact information of a Data Protection Officer under sub-section (9) of section 8; (i) the manner of obtaining verifiable consent under sub-section (1) of section 9; (j) the classes of Data Fiduciaries, the purposes of processing of personal data of a child and the conditions relating thereto, under sub-section (4) of section 9; (k) the other matters comprising the process of Data Protection Impact Assessment under sub-clause (i) of clause (c) of sub-section (2) of section 10; (l) the other measures that the Significant Data Fiduciary shall undertake under sub-clause (iii) of clause (c) of sub-section (2) of section 10; (m) the manner in which a Data Principal shall make a request to the Data Fiduciary to obtain information and any other information related to the personal data of such Data Principal and its processing, under sub-section (1) of section 11; (n) the manner in which a Data Principal shall make a request to the Data Fiduciary for erasure of her personal data under sub-section (3) of section 12; (o) the period within which the Data Fiduciary shall respond to any grievances under sub-section (2) of section 13; (p) the manner of nomination of any other individual by the Data Principal under sub-section (1) of section 14; (q) the standards for processing the personal data for exemption under clause (b) of sub-section (2) of section 17; (r) the manner of appointment of the Chairperson and other Members of the Board under sub-section (2) of section 19; (s) the salary, allowances and other terms and conditions of services of the Chairperson and other Members of the Board under sub-section (1) of section 20; (t) the manner of authentication of orders, directions and instruments under sub-section (1) of section 23; (u) the terms and conditions of appointment and service of officers and employees of the Board under section 24; (v) the techno-legal measures to be adopted by the Board under sub-section (1) of section 28; (w) the other matters under clause (d) of sub-section (7) of section 28; (x) the form, manner and fee for filing an appeal under sub-section (2) of section 29; (y) the procedure for dealing an appeal under sub-section (8) of section 29; (z) any other matter which is to be or may be prescribed or in respect of which provision is to be, or may be, made by rules.

What Article 40 Means for Your Business

Article 40 grants the Central Government the authority to make rules to carry out the provisions of the Act. This delegated legislation power produced the DPDP Rules 2025, notified in November 2025, and may produce further rules as the Act matures.
  • Compliance obligations are not fully defined by the Act alone, the DPDP Rules 2025 prescribe specific operational requirements for consent notices, breach reporting, Consent Manager registration, and more.
  • Additional rules may be made at any time, maintain a process to monitor new rule notifications from MeitY and assess their impact on your compliance programme.
  • Rules made under Article 40 must be laid before Parliament under Article 41, providing a degree of parliamentary oversight of the secondary legislation.

Frequently Asked Questions about Article 40

+ What is the purpose of Article 40?
Article 40 allows the Central Government to make rules for implementing the DPDP Act.
+ Why are these rules important?
The rules provide detailed requirements that businesses must follow to comply with the Act.
+ What areas do the rules cover?
They cover areas such as consent mechanisms, breach reporting, data processing standards, and obligations of Data Fiduciaries.
+ Do businesses need to follow these rules?
Yes. Compliance with both the Act and the rules is mandatory.
+ Can these rules change over time?
Yes. The government may update or introduce new rules as needed.

View Article
India DPDPA: Article 41 – Laying of rules and certain notifications

41. Laying of rules and certain notifications Every rule made and every notification issued under section 16 and section 42 of this Act shall be laid, as soon as may be after it is made, before each House of Parliament, while it is in session, for a total period of thirty days which may be comprised in one session or in two or more successive sessions, and if before the expiry of the session immediately following the session or the successive sessions aforesaid, both Houses agree in making any modification in the rule or notification or both Houses agree that the rule or notification should not be made or issued, the rule or notification shall thereafter have effect only in such modified form or be of no effect, as the case may be; so, however, that any such modification or annulment shall be without prejudice to the validity of anything previously done under that rule or notification.

What Article 41 Means for Your Business

Article 41 requires rules and certain notifications made under the Act to be placed before each House of Parliament. This parliamentary scrutiny mechanism provides oversight of the delegated legislation framework.
  • Rules laid before Parliament may be subject to parliamentary scrutiny and potential modification, this creates some uncertainty around finalised rules until the parliamentary process is complete.
  • Monitor parliamentary proceedings for any resolutions or debates concerning DPDPA rules that may signal amendments or clarifications to current requirements.

Frequently Asked Questions about Article 41

+ What does Article 41 of the DPDP Act cover?
It explains how rules and notifications made under the Act are reviewed by Parliament.
+ Why are rules laid before Parliament?
This ensures transparency and allows Parliament to review, modify, or reject the rules.
+ Can rules change after being issued?
Yes. Parliament may modify or annul rules after reviewing them.
+ Why is this important for businesses?
It means compliance requirements may evolve, so businesses must stay updated with regulatory changes.

View Article
India DPDPA: Article 42 – Power to amend Schedule

42. Power to amend Schedule (1) The Central Government may, by notification, amend the Schedule, subject to the restriction that no such notification shall have the effect of increasing any penalty specified therein to more than twice of what was specified in it when this Act was originally enacted. (2) Any amendment notified under sub-section (1) shall have effect as if enacted in this Act and shall come into force on the date of the notification.

What Article 42 Means for Your Business

Article 42 allows the Central Government to amend the Schedules to the DPDPA by official notification. The Schedules contain important operational provisions including model notices, standards for state processing, and exemptions from children's data rules.
  • Schedule amendments can change your compliance obligations without the Act itself being amended, the model notice in Schedule I and the exemptions in Schedule IV may be updated over time.
  • Review Schedule amendments as they are notified, update your compliance programme and documentation to reflect any changes to the standards or exemptions that apply to your operations.

Frequently Asked Questions about Article 42

+ What does Article 42 of the DPDP Act allow?
It allows the Central Government to amend the Schedule, including penalty provisions, through notifications.
+ Can penalty amounts be increased?
Yes, but increases are subject to limits specified in the Act.
+ When do these changes take effect?
Changes become effective from the date specified in the official notification.
+ Why is this important for businesses?
It means compliance risks and penalty exposure can change over time, requiring continuous monitoring.

View Article
India DPDPA: Article 43 – Power to Remove Difficulties

43. Power to Remove Difficulties (1) If any difficulty arises in giving effect to the provisions of this Act, the Central Government may, by order published in the Official Gazette, make such provisions not inconsistent with the provisions of this Act as may appear to it to be necessary or expedient for removing the difficulty. (2) No order as referred to in sub-section (1) shall be made after the expiry of three years from the date of commencement of this Act. (3) Every order made under this section shall be laid, as soon as may be after it is made, before each House of Parliament.

What Article 43 Means for Your Business

Article 43 gives the Central Government a time-limited power, valid for two years from the commencement of the Act, to make provisions to remove any difficulties in implementing the DPDPA. This transitional power allows the government to address practical gaps or inconsistencies that emerge in the early implementation phase.
  • Businesses experiencing genuine ambiguity in how the Act applies to a specific situation can flag the difficulty through industry associations, which may prompt a clarifying notification under this Article.
  • The two-year window is limited, issues that are not addressed through this mechanism during the transitional period will require formal amendment of the Act or Rules to resolve.
  • Monitor MeitY guidance and notifications during this period, as difficulty-removal orders may clarify obligations relevant to your sector or business model.

Frequently Asked Questions about Article 43

+ What is the purpose of Article 43?
It allows the government to resolve difficulties in implementing the DPDP Act by issuing appropriate orders.
+ Can the government change the law under this article?
No. Any orders must remain consistent with the provisions of the Act.
+ Is this power permanent?
No. It is available only for a limited period after the Act comes into force.
+ Why is this important for businesses?
It means businesses should stay alert to early-stage regulatory clarifications and adjustments.

View Article
India DPDPA: Article 44 – Amendments to Certain Acts

44. Amendments to Certain Acts (1) In section 14 of the Telecom Regulatory Authority of India Act, 1997, in clause (c), for sub-clauses (i) and (ii), the following sub-clauses shall be substituted,namely:—“(i) the Appellate Tribunal under the Information Technology Act, 2000; (ii) the Appellate Tribunal under the Airports Economic Regulatory Authority of India Act, 2008; and (iii) the Appellate Tribunal under the Digital Personal Data Protection Act, 2023.”. (2) The Information Technology Act, 2000 shall be amended in the following manner, namely:— (a) section 43A shall be omitted; (b) in section 81, in the proviso, after the words and figures “the Patents Act, 1970”, the words and figures “or the Digital Personal Data Protection Act, 2023” shall be inserted; and (c) in section 87, in sub-section (2), clause (ob) shall be omitted. (3) In section 8 of the Right to Information Act, 2005, in sub-section (1), for clause (j), the following clause shall be substituted, namely:— “(j) information which relates to personal information;”.

What Article 44 Means for Your Business

Article 44 amends two existing Indian laws to align them with the DPDPA framework: the Right to Information Act 2005 and the Information Technology Act 2000. These amendments remove or modify provisions that conflicted with or were superseded by the DPDPA's data protection framework.
  • The amendment to the Right to Information Act limits the disclosure of personal information under RTI requests where such disclosure would violate the DPDPA, public authorities must now apply DPDPA standards when responding to RTI requests involving personal data.
  • The IT Act 2000 amendments remove the old Section 43A framework for sensitive personal data, which is now governed by the DPDPA, businesses should replace IT Act-based data protection clauses in contracts with DPDPA-compliant provisions.
  • Review all contractual and policy references to Section 43A of the IT Act and update them to reference the DPDPA and DPDP Rules 2025 instead.
  • The interaction between the DPDPA, the IT Act, and other legislation will continue to evolve, conduct a periodic review of your legal compliance framework to ensure it reflects the current statutory landscape.

Frequently Asked Questions about Article 44

+ What does Article 44 do?
It updates existing laws to ensure they are aligned with the DPDP Act.
+ Which laws are affected?
Key laws such as the Information Technology Act, 2000 and the Right to Information Act, 2005 are amended.
+ Does this change how businesses handle data?
Yes. Businesses must ensure compliance not only with DPDP but also with updated provisions in other related laws.
+ Why is this important?
It creates a unified and consistent legal framework for data protection across India.

View Article
Scroll to Top