Process personal data only for a lawful purpose.
Every processing activity must sit on a lawful basis — consent under §6 or a legitimate use listed in §7. The register of these activities is your Record of Processing Activities (RoPA). Without a maintained RoPA, you cannot demonstrate lawful basis on request.
- Versioned RoPA with lawful basis per activity
- Approval trail on each RoPA record
- Retention field per activity, reconciled against actual disposition
Notice before or at the time of processing.
Notice must be clear, in plain language and in the schedule of languages under the Eighth Schedule. It must cover the personal data, the purpose, the rights available and how to contact the Grievance Officer.
- Notice versions per surface (web, app, checkout)
- Language variants with translator attestation
- Effective-from date and revision history per version
Free, specific, informed, unconditional, unambiguous.
Consent must be requested in plain language, be specific to a purpose, and be as easy to withdraw as it was to give. A receipt on capture and a ledger per data principal are the operational artefacts.
- Consent receipt per event
- Ledger per data principal with full state history
- Withdrawal propagation to downstream systems and vendors
Where consent is not the basis, cite the listed use.
§7 lists the specific legitimate uses — voluntarily provided data for a stated purpose, State functions, medical emergencies, employment and more. Each RoPA record on §7 grounds must cite the specific sub-clause.
- RoPA records that cite the §7 sub-clause
- Documented reasoning per record
Accountability, security, breach notification, deletion.
§8 sets the general obligations. Accuracy, reasonable security safeguards (§8(5)), breach notification to the Board and to each affected data principal (§8(6)), deletion when purpose is served (§8(7)), and the named Grievance Officer (§8(9)).
- Security safeguards register
- Incident file per breach — Board and principal notifications
- Retention runs with disposition evidence
- Grievance Officer register per legal entity
Verifiable parental consent. No tracking. No targeted advertising.
Processing of children's personal data requires verifiable parental consent, and behavioural tracking or targeted advertising directed at children is prohibited. Processing for guardians of persons with disabilities follows the same standard.
- Age-gating and verification workflow
- Parental consent receipts
- Attestation that no tracking or targeted ads run for child accounts
Additional obligations when notified as an SDF.
The Central Government may notify a Data Fiduciary as an SDF based on volume and sensitivity of processing, risk to rights and impact on sovereignty. An SDF must appoint a DPO, an independent auditor and conduct periodic DPIAs.
- DPO appointment record
- Independent audit report
- Periodic DPIA reports
Access, correction, erasure, grievance and nomination.
A data principal may seek access, correction and erasure of their data, may nominate another individual and must be able to raise a grievance to the Grievance Officer. Responses must be within the prescribed time.
- DSR intake per legal entity
- Identity verification attempt log
- Per-system fulfilment task with owner and evidence
- Response letter with system-level lineage
Transfer restricted only to notified countries.
The Central Government may notify countries or territories outside India to which personal data may not be transferred. RoPA must classify every cross-border flow.
- Cross-border classification per RoPA record
- Destination country register
- DPA with recipient covering transfer terms
