Guide

DPDP Readiness Guide — what each section actually asks of you.

A section-by-section walkthrough of the DPDP Act 2023, translated into the operational artefacts a Data Fiduciary must maintain.

§4 — Grounds for processing

Process personal data only for a lawful purpose.

Every processing activity must sit on a lawful basis — consent under §6 or a legitimate use listed in §7. The register of these activities is your Record of Processing Activities (RoPA). Without a maintained RoPA, you cannot demonstrate lawful basis on request.

Evidence expected
  • Versioned RoPA with lawful basis per activity
  • Approval trail on each RoPA record
  • Retention field per activity, reconciled against actual disposition
§5 — Notice

Notice before or at the time of processing.

Notice must be clear, in plain language and in the schedule of languages under the Eighth Schedule. It must cover the personal data, the purpose, the rights available and how to contact the Grievance Officer.

Evidence expected
  • Notice versions per surface (web, app, checkout)
  • Language variants with translator attestation
  • Effective-from date and revision history per version
§6 — Consent

Free, specific, informed, unconditional, unambiguous.

Consent must be requested in plain language, be specific to a purpose, and be as easy to withdraw as it was to give. A receipt on capture and a ledger per data principal are the operational artefacts.

Evidence expected
  • Consent receipt per event
  • Ledger per data principal with full state history
  • Withdrawal propagation to downstream systems and vendors
§7 — Legitimate uses

Where consent is not the basis, cite the listed use.

§7 lists the specific legitimate uses — voluntarily provided data for a stated purpose, State functions, medical emergencies, employment and more. Each RoPA record on §7 grounds must cite the specific sub-clause.

Evidence expected
  • RoPA records that cite the §7 sub-clause
  • Documented reasoning per record
§8 — Obligations of the Data Fiduciary

Accountability, security, breach notification, deletion.

§8 sets the general obligations. Accuracy, reasonable security safeguards (§8(5)), breach notification to the Board and to each affected data principal (§8(6)), deletion when purpose is served (§8(7)), and the named Grievance Officer (§8(9)).

Evidence expected
  • Security safeguards register
  • Incident file per breach — Board and principal notifications
  • Retention runs with disposition evidence
  • Grievance Officer register per legal entity
§9 — Children and persons with disabilities

Verifiable parental consent. No tracking. No targeted advertising.

Processing of children's personal data requires verifiable parental consent, and behavioural tracking or targeted advertising directed at children is prohibited. Processing for guardians of persons with disabilities follows the same standard.

Evidence expected
  • Age-gating and verification workflow
  • Parental consent receipts
  • Attestation that no tracking or targeted ads run for child accounts
§10 — Significant Data Fiduciary

Additional obligations when notified as an SDF.

The Central Government may notify a Data Fiduciary as an SDF based on volume and sensitivity of processing, risk to rights and impact on sovereignty. An SDF must appoint a DPO, an independent auditor and conduct periodic DPIAs.

Evidence expected
  • DPO appointment record
  • Independent audit report
  • Periodic DPIA reports
§§11–14 — Rights and grievance

Access, correction, erasure, grievance and nomination.

A data principal may seek access, correction and erasure of their data, may nominate another individual and must be able to raise a grievance to the Grievance Officer. Responses must be within the prescribed time.

Evidence expected
  • DSR intake per legal entity
  • Identity verification attempt log
  • Per-system fulfilment task with owner and evidence
  • Response letter with system-level lineage
§16 — Cross-border transfer

Transfer restricted only to notified countries.

The Central Government may notify countries or territories outside India to which personal data may not be transferred. RoPA must classify every cross-border flow.

Evidence expected
  • Cross-border classification per RoPA record
  • Destination country register
  • DPA with recipient covering transfer terms
Next

Baseline against every section — with evidence per gap.

The Binary AIQ Readiness Assessment turns this guide into a scored register per legal entity.