LAW JOURNAL
Law Firm
Awards.
Recognised in Arbitration & ADR, Corporate, and Technology.
Celebrating excellence & dedication.

Anandaday Misshra
Founder & Managing Partner, AMLEGALS
Privacy touches every part of an organisation. We bring legal interpretation, governance and implementation into one conversation.
Understand your position. Map the gaps. Put notices, consent, contracts and operating procedures into place.
Explore DPDPA advisoryCoordinate Indian requirements with the privacy frameworks that govern your international operations.
Explore global privacyConnect AI use cases with legal review, human oversight, vendor terms and evidence of responsible operation.
Explore AI advisoryFind guidance for the decisions on your desk.
A patient record, a payment journey and an AI training dataset raise different questions. Start with the context of your business.
Compliance is a file, not a claim. Fifty-six exhibits. Every obligation, mapped to a control, an owner and an artefact.
Open The DPDPA FileOnce notified an SDF, Section 10 read with Rule 13 adds an India-based DPO, an independent auditor, DPIAs and algorithmic due diligence. The exhibit lists each duty and its artefact.
A governance framework built from the DPDPA statutory text — not translated from the GDPR. It measures your compliance stance against all 44 Sections and 23 Rules, and resolves to one Board-ready number.
A single Board-ready index, assessed against the Act and the Rules — reported the way a finance committee reads a metric.
The systematic conversion of legal, regulatory, contractual and governance obligations into continuously operating business systems that can be measured, monitored and independently verified — organised across ten engineering disciplines.
Section 3(b) extends India's data protection regime to every organisation offering goods or services to Data Principals in India — regardless of where it is incorporated.
A GDPR programme cannot be transplanted to the DPDPA. The Board examines Indian law. Not your global framework.
Read the analysis
Section 16 permits transfers today. It can restrict them by executive notification tomorrow. The architecture must exist before that day.
Read the analysis
The gap discovered in the legal memo is the one that kills the transaction. The investors who find it have already decided.
Read the analysisThe Schedule prescribes the maximum. The Board determines the quantum under Section 33.
The only variable is your evidence — and when you begin building it.
Choose your role and priority to find relevant guidance across the practice.
Articles, compliance analyses, working resources and answers from the AMLEGALS privacy practice.
Consent obtained minus consent understood equals zero legal defence. The gap between collection and validity is where the penalties live.
Read ↗
Companies that invest in trust outperform those that invest in damage control. Here is the model and the maths behind it.
Read ↗
Fifty organisations from BFSI and pharma to IT services and manufacturing. The gap between awareness and action is staggering.
Read ↗Each analysis maps a specific obligation to its operational reality — statutory text, regulatory overlap, implementation architecture and evidence requirements.
44 Sections. 23 Rules. One knowledge architecture — from statutory analysis to sector-specific compliance, from Board governance to operational implementation.
Twenty-eight answers, each grounded in the statutory text rather than in a vendor's framework.
All DPDPA FAQs ↗Tell us what you are working on. The practitioner with the relevant statutory expertise will respond directly. Confidential. Counsel-led. Statutory basis from the first engagement.
The Digital Personal Data Protection Act, 2023 (DPDPA) is India's comprehensive data privacy legislation. It applies to all entities processing digital personal data in India, and to foreign entities processing personal data in connection with offering goods or services to Data Principals within India under Section 3. There is no revenue or size threshold. every Data Fiduciary processing digital personal data is within scope.
DPDPA prescribes penalties up to ₹250 Crore under Section 33 read with the Schedule. The penalty for failure to protect children's data is up to ₹200 Crore. The Data Protection Board of India determines penalties based on the nature, gravity, and duration of the breach.
Vibe Data Privacy™ is AMLEGALS' proprietary governance framework built from the DPDPA 2023 statutory text. It measures compliance across five operational layers. Signal (privacy frequency across consent records and data flows), Pulse (governance stance against all 44 Sections and 23 Rules), Drift (compliance entropy and deviations from baseline), Dividend (privacy ROI through trust metrics and audit readiness), and Culture (organisational privacy maturity). producing a single Board ready Vibe Pulse Score (VPS) from 0 to 100.
DPDPA received Presidential Assent on 11 August 2023. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)). Commencement is phased: the institutional provisions, including the Data Protection Board, commenced on 13 November 2025; the Consent Manager framework (Rule 4) commences on 13 November 2026; and the substantive obligations on notice, consent, breach reporting, children data, Significant Data Fiduciaries, rights and cross-border transfers commence on 13 May 2027. Organisations should treat the current period as the build window.
DPDPA and GDPR are structurally independent frameworks. Key differences: (1) DPDPA uses a negative list approach for cross border transfers under Section 16 versus GDPR's adequacy model; (2) No right to data portability under DPDPA; (3) Centralised Data Protection Board versus multiple supervisory authorities; (4) Fixed penalty amounts versus revenue percentages; (5) DPDPA applies only to digital personal data, not paper records.
Under Section 10, the Central Government may notify a Data Fiduciary as Significant based on volume and sensitivity of data processed, risk to Data Principals, and other prescribed factors. SDFs have enhanced obligations including mandatory DPO appointment (based in India), periodic audits by independent auditors, and Data Protection Impact Assessments.
Yes. Section 3 of DPDPA extends its applicability to processing of digital personal data outside India if such processing is in connection with offering goods or services to Data Principals within India. This extraterritorial scope means foreign companies offering goods or services to Data Principals within India must comply regardless of their physical location.
The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025 (G.S.R. 846(E)) under Section 40 of DPDPA. They contain 23 Rules and 7 Schedules covering notice requirements (Rule 3), Consent Manager registration and obligations (Rule 4), breach notification form and manner (Rule 7), children's data processing safeguards (Rule 10), Significant Data Fiduciary obligations including DPIA, audit and algorithmic due diligence (Rule 13), Data Principal rights (Rule 14), cross-border transfer requirements (Rule 15), and the Data Protection Board (Rules 17 to 22). Commencement is phased, with the substantive obligations commencing on 13 May 2027.
Section 6 of DPDPA requires consent that is free, specific, informed, unconditional, and unambiguous with clear affirmative action. Section 5 mandates an itemised notice before or at the time of data collection specifying the personal data to be processed and the purpose. Consent must be as easy to withdraw as to give under Section 6(6). Section 7 provides certain legitimate uses (historically termed deemed consent) including employment purposes, public interest, and medical emergencies.
Section 8(6) of DPDPA requires every Data Fiduciary to inform both the Data Protection Board of India and each affected Data Principal of a personal data breach. Rule 7 of DPDP Rules 2025 prescribes a staged model: affected Data Principals must be intimated without delay; the Data Protection Board must receive an initial intimation without delay; and a detailed report must follow within 72 hours, or such longer period as the Board may allow on request. Failure to implement reasonable security safeguards attracting a breach carries penalties up to Rs 250 Crore under the Schedule.
Section 9 of DPDPA requires verifiable parental consent before processing any child's data (below 18 years). Data Fiduciaries must not undertake tracking, behavioural monitoring, or targeted advertising directed at children. Rule 10 of DPDP Rules 2025 prescribes the manner of obtaining verifiable parental consent. Processing children's data that may cause detrimental effect is prohibited. Penalty for non-compliance is up to Rs 200 Crore under the Schedule.
Yes. Section 3 of DPDPA applies extraterritorially to the processing of digital personal data outside India if such processing is in connection with offering goods or services to Data Principals within India. US SaaS companies collecting personal data from Indian users through sign-ups, analytics, payment processing, or support are Data Fiduciaries under DPDPA. Compliance obligations include Section 5 notice, Section 6 consent, Section 8 breach notification, and appointing a representative under the DPDP Rules 2025.
Non-compliance exposes the entity to penalties up to Rs 250 Crore per instance under Section 33 read with the Schedule. The Data Protection Board can issue directions, impose penalties, and require remedial measures. Beyond monetary penalties, non-compliance risks reputational damage, contract termination by Indian partners, and potential blocking of services. The Data Protection Board can issue directions and impose remedial measures. Non-compliance with Board directions attracts further penalties under the Act.
DPDPA differs from Singapore PDPA and Brazil LGPD in several structural ways. DPDPA applies exclusively to digital personal data (not paper records), uses a negative-list approach for cross-border transfers (unlike PDPA accountability model and LGPD adequacy model), prescribes fixed penalty amounts rather than revenue percentages, does not include a right to data portability, and centralises enforcement in a single Data Protection Board. All three share a consent-centric architecture, but DPDPA Section 7 on certain legitimate uses is narrower than the legitimate interests bases in LGPD and PDPA exceptions.
Rule 13 of the DPDP Rules 2025 introduces algorithmic due diligence as an obligation for Significant Data Fiduciaries. It requires SDFs to verify that algorithmic systems processing personal data do not pose a risk to the rights of Data Principals. This includes ensuring algorithms used for profiling, automated decision-making, or content recommendation do not produce outcomes that are detrimental. This is one of the first statutory algorithmic accountability requirements in Indian law.
Banks, insurers, NBFCs, and payment aggregators face overlapping compliance obligations. Under DPDPA: Section 5 notice, Section 6 consent, Section 8 breach notification, and Section 10 SDF obligations (if notified). Additionally, RBI data localisation circulars mandate payment system data be stored exclusively in India. IRDAI requires health and claims data retention. SEBI mandates KYC data governance. The BFSI sector must reconcile these sectoral mandates with DPDPA to avoid regulatory conflict.
Multinationals should structure their DPDPA programme across four layers: (1) Entity mapping to identify which group entities qualify as Data Fiduciaries or Data Processors, (2) Data flow mapping to trace cross-border transfers under Section 16 and Rule 15, (3) Consent architecture design reconciling DPDPA Section 6 consent with GDPR consent or legitimate interests already in place, and (4) Governance documentation including privacy notices, Data Processing Agreements, breach response protocols, and DPO appointment for SDF-designated entities.
Rule 13 of the DPDP Rules 2025 requires Significant Data Fiduciaries to conduct Data Protection Impact Assessments evaluating risk to Data Principals, mitigation measures, and safeguard adequacy. The DPIA must be reviewed periodically and shared with the Data Protection Board on request. Unlike GDPR Article 35 which requires DPIAs for all high-risk processing, DPDPA limits this obligation to notified Significant Data Fiduciaries.
Rule 15 supplements Section 16 of DPDPA. While Section 16 empowers the Central Government to restrict transfers to notified countries (negative-list approach), Rule 15 further allows requiring that personal data made available to any foreign State or its agencies meet prescribed requirements. Sectoral localisation mandates under RBI, IRDAI, and SEBI continue to apply independently. Unlike GDPR, DPDPA does not require adequacy decisions for permitted jurisdictions.
AMLEGALS provides counsel-led DPDPA compliance services from its New Delhi office at A-24, ILBS Colony, Vasant Kunj, New Delhi 110070. The firm advises on DPDP Act 2023 implementation, DPDP Rules 2025 compliance, consent architecture, breach notification, DPO services, cross-border transfers, and Significant Data Fiduciary obligations. Contact [email protected] or +91-8448548549.
AMLEGALS provides DPDPA compliance advisory from its Mumbai office. Services include DPDPA implementation, consent management, breach notification protocols, DPO advisory, cross-border transfer structuring, and the proprietary Vibe Data Privacy Framework assessment. The firm serves BFSI, pharmaceutical, e-commerce, and technology entities across Maharashtra.
AMLEGALS operates from its Ahmedabad office, providing comprehensive DPDPA compliance services to manufacturing, pharmaceutical, chemical, and technology companies in Gujarat. Services include DPDP Act implementation, DPDP Rules compliance, consent architecture, Significant Data Fiduciary advisory, and the Vibe Pulse Score assessment.
Rule 4 of the DPDP Rules 2025 establishes the Consent Manager framework. A Consent Manager is an entity registered with the Data Protection Board under the First Schedule Part A that acts as a single point of contact for Data Principals to give, manage, review, and withdraw consent. Foreign companies can engage a registered Consent Manager, but legal responsibility for lawful processing remains with the Data Fiduciary. The Consent Manager registration framework commences on 13 November 2026.
Insurance companies face DPDPA obligations overlaid with IRDAI regulatory requirements. Under DPDPA: Section 5 notice for policy data, Section 6 consent for health and claims data, Section 8 breach notification, and potential Section 10 SDF obligations. IRDAI mandates on data retention, claims processing, and policyholder data governance must be reconciled with DPDPA requirements. AMLEGALS builds sector-specific reconciliation matrices mapping each IRDAI requirement to the corresponding DPDPA provision.
E-commerce platforms processing customer data face Section 5 notice obligations at scale, Section 6 consent challenges for multiple processing purposes (marketing, analytics, personalisation, payment), Section 8 breach notification for large user bases, and potential SDF designation under Section 10 for high-volume processors. AMLEGALS advises e-commerce entities on consent architecture design, vendor data processing agreements, cross-border transfer mechanisms for international fulfilment, and children data protection under Section 9.
Yes. Online gaming platforms face acute Section 9 challenges because they cannot simply add an age gate. Verifiable parental consent under Rule 10 is required before processing any child's data. Behavioural monitoring, tracking, and targeted advertising directed at children are prohibited. Gaming companies must also address Section 6 consent for gameplay analytics, in-app purchase data, and social features, plus Section 8 breach notification obligations.
DPDPA compliance costs vary by organisation size, sector, data processing complexity, and existing governance maturity. Key cost heads include legal advisory, consent architecture implementation, privacy notice drafting, data mapping and flow analysis, breach notification infrastructure, DPO appointment (for SDFs), Data Protection Impact Assessments, vendor agreement restructuring, and ongoing compliance monitoring. AMLEGALS provides structured scope assessments to help organisations understand their specific compliance investment requirements.
No. As of 2026, no DPDPA certification body exists in India. The DPDP Act 2023 and DPDP Rules 2025 do not establish any certification framework. Any vendor claiming DPDPA certification, DPDPA-ready status, or DPDPA audit compliance is making a claim without statutory backing. Organisations should evaluate vendor compliance claims against the actual statutory text rather than relying on self-declared certifications.