India · Ministry of Electronics and Information Technology, enforced by the Data Protection Board of India

India's Digital Personal Data Protection Act 2023, and the DPDP Rules 2025

India's personal data law, and the Rules that make it operable. It is consent-first, it applies to digital personal data wherever it is processed if the processing relates to offering goods or services in India, and the Board can impose penalties running to hundreds of crores.

The library does not carry this regime yet. The obligations are enumerated and the mapping to our common controls is known, but nothing is authored into ControlRegistry and no crosswalk is published. This page describes the law. It does not claim we cover it, and we are not offering an assessment against it today.

Who it applies to

Any organisation that determines the purpose and means of processing digital personal data in India, and any organisation outside India processing such data in connection with offering goods or services to people in India. The Act calls that organisation a fiduciary rather than a controller, and the duty is not delegable: it remains accountable for what its processors do. A subset are designated as significant, which adds independent audit, impact assessment and algorithmic due diligence on top of everything else. Whether an organisation falls in that subset is a determination it makes against the criteria, not one this page can make for it.

What it requires

  • A notice at or before collection, itemised and in plain language, standing on its own rather than buried in terms of service, and available in the languages the Eighth Schedule allows (Rule 3)
  • Consent that is free, specific and informed, with withdrawal made as easy as giving it was, and processing that stops across every system that received the data when it is withdrawn
  • Reasonable security safeguards, spelled out rather than left to judgement: encryption, masking or obfuscation, access control, and retention of logs and traffic data for at least one year (Rule 6)
  • Breach handling in two stages with different recipients and different clocks: affected people without delay, and the Board a preliminary intimation without delay followed by a detailed report within seventy-two hours (Rule 7)
  • Erasure once the purpose is served or consent is withdrawn, and the fiduciary must cause its processors to erase too (Rule 8)
  • Published contact details for the person who answers questions about the processing (Rule 9)
  • Verifiable parental consent for children, and no tracking or behavioural advertising directed at them (Rule 10)
  • A route for people to exercise access, correction, completion, updating and erasure, and to nominate someone to exercise those rights on their behalf (Rule 14)
  • A grievance channel that is readily available and answered, which is a separate duty from incident reporting (Rule 15)
  • For significant fiduciaries: a data protection impact assessment, an independent audit each year, and due diligence that algorithmic software does not risk people's rights (Rules 13 and 16)

What preparing for it involves

Most of the security half is work an organisation has usually started. Encryption, access control and logging are the same controls ISO 27001 and SOC 2 ask for, and evidence gathered for those carries over. What is genuinely new is the privacy-procedural half, and it is procedural rather than technical: knowing every point at which personal data is collected and what notice was in force there, being able to answer a person within the response period, and being able to run a breach as a sequence with two clocks rather than a single notification. The work that catches organisations out is not a control they lack but a record they cannot produce: which version of the notice a given consent was given against.

How it concludes

There is no certificate. DPDP is supervised rather than certified: the Board acts on complaints and breaches, and what protects an organisation is the record it can produce at that moment. That makes preparation a matter of evidence and operational routine rather than of achieving a status, and it is why we treat it as an obligations register with clocks attached rather than as a checklist.

SecureEdge Advisory prepares you and facilitates the process. The affirmation is made by an external auditor, a certification body or the regulator, never by us.

Cross-framework reuse

Control mappings for this framework are not yet published in the library. It is carried in full for assessment and preparation, and cross-framework reuse will follow as the mapping matures. We would rather state that plainly than imply reuse that does not exist.