Live 17 practitioner certifications live · First lesson free on every course Back to main site →

Why you can trust this course

We don't ask you to take our word for it. Every claim in every lesson is anchored to a Section, Rule, or judgment. This page is the master register of every authority we cite.

Legal basis snapshot: DPDP Act 2023 (No. 22 of 2023, assented 11 August 2023). DPDP Rules 2025 notified 13 November 2025 via Gazette Notifications G.S.R. 843(E), 844(E), 845(E) and 846(E). Sectoral overlays as in force on 5 October 2026: CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); RBI Draft Data Governance Framework (15 July 2026, consultation closed 17 August 2026); SEBI CSCRF (20 August 2024, SEBI AI Vulnerability Detection Advisory 5 May 2026); IRDAI Information and Cyber Security Guidelines 2026 (6 April 2026); Telecom Cyber Security Rules 2024 (21 November 2024); Aadhaar Data Security Regulations 2016. Constitutional context: Puttaswamy v. Union of India (2017) 10 SCC 1.

How this DPDP Implementation Practitioner — 90 Days to Audit-Ready register is built

This trust page is the citation register for the DPDP Implementation Practitioner — 90 Days to Audit-Ready course. It cites 38 authorities across 7 statutory instruments, drawn from the legal basis snapshot above (DPDP Act 2023 (No. 22 of 2023, assented 11 August 2023). DPDP Rules 2025 notified 13 November 2025 via Gazette Notifications G.S.R. 843(E), 844(E), 845(E) and 846(E). Sectoral overlays as in force on 5 October 2026: CERT-In Directions No. 20(3)/2022-CERT-In (28 April 2022); RBI Draft Data Governance Framework (15 July 2026, consultation closed 17 August 2026); SEBI CSCRF (20 August 2024, SEBI AI Vulnerability Detection Advisory 5 May 2026); IRDAI Information and Cyber Security Guidelines 2026 (6 April 2026); Telecom Cyber Security Rules 2024 (21 November 2024); Aadhaar Data Security Regulations 2016. Constitutional context: Puttaswamy v. Union of India (2017) 10 SCC 1.).

Primary sources: DPDP Act 2023 (21 entries), DPDP Rules 2025 (10 entries), CERT-In Directions 2022 (2 entries).

Every claim in every DPDP Implementation Practitioner — 90 Days to Audit-Ready lesson traces back to a Section, Rule, or judgment listed below. If a lesson references a specific obligation, click the [Lx-Cy] marker in that lesson to jump to the verbatim text in the register.

Our verification promise

  1. Every factual claim has a source. If we say "Section 9 allows a three-month limitation period", you can click the [Lx-Cy] marker next to it and read the verbatim text of Section 9 of the Sexual Harassment of Women at Workplace Act, 2013.
  2. Every source is on this page. Below you will find every Section, Rule and judgment we have relied on, grouped by category, with the verbatim text we hold in our register.
  3. Every source has a public link. Wherever an authoritative public link exists (India Code, the official court website, a reputable law-reports portal), we link to it.
  4. Bug bounty for errors. If you find a factual error in any lesson, write to [email protected] with the lesson, the claim and the corrected source. We will credit your account ₹1,000 for the first report of any verifiable error, ₹5,000 for a substantial error.
12
modules
63
lessons
38
cited authorities
recent
last reviewed

The full citation register

Every authority used in any lesson appears below. Click a row to expand the verbatim text.

CERT-In 6-hour Rule , CERT-In Directions 2022 six-hour incident reporting 28 Apr 2022
Plain summary: CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022, effective 27 June 2022. Direction (ii): every service provider, intermediary, data centre, body corporate and Government organisation must mandatorily report cyber incidents of the type specified in Annexure I to CERT-In within six hours of noticing or being brought to notice about such incidents. For an Indian entity handling EU personal data, the 6-hour CERT-In clock runs from detection in parallel with the 72-hour DPDP Rule 7 clock and the 72-hour GDPR Art 33 clock. All three are separate obligations; the incident-response runbook fires all three from a single incident record.
CERT-In Directions No. 20(3)/2022-CERT-In dated 28 April 2022. Direction (ii): Any service provider, intermediary, data centre, body corporate and Government organisation shall mandatorily report cyber incidents as mentioned in Annexure I to CERT-In within six hours of noticing such incidents or being brought to notice about such incidents. Direction (iii): Enable logs of all their ICT systems and maintain them securely for a rolling period of 180 days within the Indian jurisdiction.
Direction (ii) , CERT-In 6-hour cyber incident reporting (parallel to CSCRF) 28 Apr 2022
Plain summary: CERT-In Directions of 28 April 2022, Direction (ii): any service provider, intermediary, data centre, body corporate or Government organisation must mandatorily report cyber incidents listed in Annexure I to CERT-In within 6 hours of noticing. Runs in parallel with SEBI CSCRF 6-hour clock. Filing to one regulator does not satisfy the obligation to the other.
Any service provider, intermediary, data centre, body corporate and Government organisation shall mandatorily report cyber incidents as mentioned in Annexure I to CERT-In within 6 hours of noticing such incidents or being brought to notice about such incidents.

Section 17 , Exemptions
Plain summary: Sections 4 to 10 (except Section 8(1) accountability and Section 8(5) security) do not apply to processing necessary for legal rights, judicial functions, offence prevention/investigation, and certain other specified categories. Central Government may exempt notified State instrumentalities on grounds of sovereignty, security, foreign relations, public order or incitement to any cognisable offence.
17. (1) The provisions of Chapter II [Sections 4-10], except sub-sections (1) and (5) of section 8, and those of Chapter III [Sections 11-15] and section 16 shall not apply where (a) processing is necessary for enforcing any legal right or claim; (b) processing by any court or tribunal or any body performing judicial or quasi-judicial functions; (c) processing necessary for prevention, detection, investigation or prosecution of any offence or contravention of any law; ... (2) The Central Government may, by notification, exempt from the application of provisions of this Act (a) any instrumentality of the State on such grounds as sovereignty and integrity of India, security of the State, friendly relations with foreign States, maintenance of public order or preventing incitement to the commission of any cognisable offence relating to any of these; (b) processing for research, archiving or statistical purposes subject to standards.
Section 2(u) , Definition of personal data breach
Plain summary: Personal data breach means any unauthorised processing of personal data, or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data.
"personal data breach" means any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data.
Section 27 , Functions of Data Protection Board
Plain summary: On receipt of an intimation of personal data breach, the Board shall direct the Data Fiduciary to take urgent remedial or mitigation measures. On a complaint or reference, the Board shall inquire and impose penalty or direct any other measure. The Board acts as a digital office by default.
27. On and from the date of commencement of this Act, the Board shall, (a) on receipt of an intimation of personal data breach, direct any urgent remedial or mitigation measures in the event of a personal data breach, and inquire into such personal data breach and impose penalty as provided in this Act; (b) on a complaint made by a Data Principal or on a reference made to it by the Central Government or any State Government or in compliance of the directions of any court, inquire into such breach of the provisions of this Act by a Data Fiduciary or Consent Manager and impose penalty as provided in this Act.
Section 29 , Appeal to Appellate Tribunal
Plain summary: Any person aggrieved by an order or direction of the Board may prefer an appeal to the Telecom Disputes Settlement and Appellate Tribunal (designated as the Appellate Tribunal). Appeal must be filed within 60 days from the receipt of the Board order.
29. (1) Any person aggrieved by an order or direction made by the Board under this Act may prefer an appeal before the Appellate Tribunal. (2) Every appeal under sub-section (1) shall be filed within a period of sixty days from the date of receipt of the order or direction appealed against and it shall be in such form and manner and shall be accompanied by such fee as may be prescribed.
Section 36 , Power to call for information
Plain summary: Central Government may, for specified purposes, direct the Board or any Data Fiduciary or intermediary to furnish information. Purposes enumerated in the Seventh Schedule of the Rules. Central to constitutional challenge on transparency and state access.
36. The Central Government may, for the purposes of this Act, require the Board and any Data Fiduciary or intermediary to furnish such information as it may call for.
Schedule , Penalty ceilings 11 Aug 2023
Plain summary: Item 1: Failure to take reasonable security safeguards under Section 8(5) — up to two hundred and fifty crore rupees. Item 2: Failure to give breach intimation under Section 8(6) — up to two hundred crore rupees. Item 3: Failure of children's data obligations under Section 9 — up to two hundred crore rupees. Item 4: Failure of SDF obligations under Section 10 — up to one hundred and fifty crore rupees. Item 5: Data Principal duty breach under Section 15 — up to ten thousand rupees. Item 7: Residual — any other breach of Act or Rules — up to fifty crore rupees.
Schedule (Section 33): Item 1 (Section 8(5) reasonable security safeguards): may extend to two hundred and fifty crore rupees. Item 2 (Section 8(6) breach intimation to Board and affected Data Principals): may extend to two hundred crore rupees. Item 3 (Section 9 additional obligations for children's personal data): may extend to two hundred crore rupees. Item 4 (Section 10 additional obligations for Significant Data Fiduciary): may extend to one hundred and fifty crore rupees. Item 5 (Section 15 duties of Data Principal): may extend to ten thousand rupees. Item 6 (breach of any term of voluntary undertaking accepted by Board under Section 32): may extend to the extent applicable for the relevant Item. Item 7 (any other breach of the provisions of this Act or rules): may extend to fifty crore rupees.
Section 10 , Additional obligations of Significant Data Fiduciary 11 Aug 2023
Plain summary: Central Government may notify any Data Fiduciary or class as Significant Data Fiduciary based on volume and sensitivity of personal data, risk to rights of Data Principals, potential impact on sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order. Every SDF must appoint an India-resident Data Protection Officer responsible to the Board of Directors, an independent Data Auditor, and undertake periodic DPIAs and audits.
10. (1) The Central Government may notify any Data Fiduciary or class of Data Fiduciaries as Significant Data Fiduciary, on the basis of an assessment of such relevant factors as it may determine, including (a) the volume and sensitivity of personal data processed; (b) risk to the rights of Data Principal; (c) potential impact on the sovereignty and integrity of India; (d) risk to electoral democracy; (e) security of the State; and (f) public order. (2) Every Significant Data Fiduciary shall (a) appoint a Data Protection Officer who shall (i) represent the Significant Data Fiduciary under the provisions of this Act; (ii) be based in India; (iii) be an individual responsible to the Board of Directors or similar governing body of the Significant Data Fiduciary; (iv) be the point of contact for the grievance redressal mechanism under the provisions of this Act; (b) appoint an independent data auditor to carry out data audit; and (c) undertake (i) periodic Data Protection Impact Assessment; (ii) periodic audit; and (iii) such other measures as may be prescribed.
Section 11 , Right of Data Principal to access information 11 Aug 2023
Plain summary: Data Principal has the right to obtain from the Data Fiduciary a summary of personal data being processed and the processing activities undertaken with respect to it, identities of Fiduciaries and Processors with whom data has been shared, and any other prescribed information. Excludes disclosure to other Fiduciaries authorised by law to obtain the data for prevention, detection, investigation, prosecution or punishment of offences or cyber incidents.
11. (1) The Data Principal shall have the right to obtain from the Data Fiduciary to whom she has previously given consent, (a) a summary of personal data which is being processed by such Data Fiduciary and the processing activities undertaken by that Data Fiduciary with respect to such personal data; (b) the identities of all other Data Fiduciaries and Data Processors with whom the personal data has been shared by such Data Fiduciary, along with a description of the personal data so shared; and (c) any other information related to the personal data of such Data Principal and its processing, as may be prescribed.
Section 12 , Right to correction, completion, updating and erasure 11 Aug 2023
Plain summary: Data Principal has the right to correction, completion, updating and erasure of personal data for the processing of which she has previously given consent. Erasure must be honoured unless retention is required by law or for the specified purpose.
12. (1) A Data Principal shall have the right to correction, completion, updating and erasure of her personal data for the processing of which she has previously given consent. (2) A Data Fiduciary shall, upon receiving a request for such correction, completion or updating from a Data Principal, (a) correct the inaccurate or misleading personal data; (b) complete the incomplete personal data; and (c) update the personal data. (3) A Data Principal shall make a request in such manner as may be prescribed to the Data Fiduciary for erasure of her personal data, and upon receipt of such a request, the Data Fiduciary shall erase her personal data unless retention of the same is necessary for the specified purpose or for compliance with any law for the time being in force.
Section 13 , Right of grievance redressal 11 Aug 2023
Plain summary: Data Principal has the right to a readily available means of grievance redressal from the Data Fiduciary or Consent Manager. The Fiduciary or CM must respond to grievance within the prescribed period. The Data Principal must exhaust the internal grievance mechanism before approaching the Board.
13. (1) A Data Principal shall have the right to have readily available means of grievance redressal provided by a Data Fiduciary or Consent Manager in respect of any act or omission regarding the performance of its obligations. (2) The Data Fiduciary or Consent Manager shall respond to any grievances referred to in sub-section (1) within such period as may be prescribed. (3) The Data Principal shall exhaust the opportunity of redressing her grievance under this section before approaching the Board.
Section 15 , Duties of Data Principal 11 Aug 2023
Plain summary: Data Principal must comply with applicable law while exercising rights; must not impersonate another person while providing personal data; must not suppress material information; must not register a false or frivolous grievance or complaint with a Data Fiduciary or the Board; and must furnish only authentic information when exercising the right to correction or erasure. Breach attracts penalty up to ten thousand rupees under the Schedule.
15. A Data Principal shall (a) comply with the provisions of all applicable laws while exercising rights under the provisions of this Act; (b) ensure not to impersonate another person while providing her personal data; (c) ensure not to suppress any material information; (d) ensure not to register a false or frivolous grievance or complaint with a Data Fiduciary or the Board; and (e) furnish only such information as is verifiably authentic while exercising the right to correction or erasure.
Section 16 , Processing of personal data outside India 11 Aug 2023
Plain summary: The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary to countries or territories outside India. Nothing in this section shall restrict the applicability of any law for the time being in force in India that provides for a higher degree of protection or restriction on transfer.
16. (1) The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified. (2) Nothing contained in sub-section (1) shall restrict the applicability of any law for the time being in force in India that provides for a higher degree of protection for or restriction on transfer of personal data by a Data Fiduciary outside India in relation to any personal data or Data Fiduciary or class thereof.
Section 2 , Definitions 11 Aug 2023
Plain summary: Defines key terms including Data Principal, Data Fiduciary, Data Processor, personal data, personal data breach, processing, Significant Data Fiduciary, Consent Manager, child, and Board.
2. In this Act, unless the context otherwise requires (selected clauses): (f) "child" means an individual who has not completed the age of eighteen years; (i) "Data Fiduciary" means any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data; (j) "Data Principal" means the individual to whom the personal data relates, and where such individual is (i) a child, includes the parents or lawful guardian; (ii) a person with disability, includes her lawful guardian; (k) "Data Processor" means any person who processes personal data on behalf of a Data Fiduciary; (t) "personal data" means any data about an individual who is identifiable by or in relation to such data; (u) "personal data breach" means any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data; (x) "processing" means a wholly or partly automated operation or set of operations performed on digital personal data; (z) "Significant Data Fiduciary" means any Data Fiduciary or class of Data Fiduciaries as may be notified by the Central Government under section 10.
Section 3 , Application of the Act 11 Aug 2023
Plain summary: The Act applies to processing of digital personal data within India collected in digital form or digitised subsequently; and to processing outside India if in connection with offering goods or services to Data Principals in India. It does not apply to personal or domestic use, or to data made publicly available by the Data Principal or under law.
3. Subject to the provisions of this Act, it shall (a) apply to the processing of digital personal data within the territory of India where the personal data is collected (i) in digital form; or (ii) in non-digital form and digitised subsequently; (b) also apply to processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India; (c) not apply to (i) personal data processed by an individual for any personal or domestic purpose; and (ii) personal data that is made or caused to be made publicly available by (A) the Data Principal to whom such personal data relates; or (B) any other person under an obligation under any law for the time being in force in India to make such personal data publicly available.
Section 33 , Penalties for breach 11 Aug 2023
Plain summary: The Board may impose penalty as specified in the Schedule. Factors to consider include nature/gravity/duration of breach, type of data affected, repetitive nature, gain avoided or loss suffered, mitigation, proportionality and impact. Penalty is credited to the Consolidated Fund of India.
33. (1) If the Board determines on conclusion of an inquiry that non-compliance by a person is significant, it may, after giving the person a reasonable opportunity of being heard, impose such monetary penalty specified in the Schedule. (2) While determining the amount of monetary penalty, the Board shall have regard to (a) nature, gravity and duration of the non-compliance; (b) type and nature of personal data affected; (c) repetitive nature of the non-compliance; (d) whether the person, as a result of the non-compliance, has realised a gain or avoided any loss; (e) whether the person took any action to mitigate the effects and consequences and the timeliness and effectiveness of the action; (f) whether the monetary penalty is proportionate and effective; and (g) likely impact of the imposition on the person. (3) The amount so realised shall be credited to the Consolidated Fund of India.
Section 4 , Grounds for processing personal data 11 Aug 2023
Plain summary: Personal data may be processed only for a lawful purpose, either with the consent of the Data Principal, or for certain legitimate uses listed in Section 7.
4. (1) A person may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose, (a) for which the Data Principal has given her consent; or (b) for certain legitimate uses. (2) For the purposes of this section, the expression "lawful purpose" means any purpose which is not expressly forbidden by law.
Section 5 , Notice to Data Principal 11 Aug 2023
Plain summary: Every consent request must be accompanied or preceded by a notice describing the personal data, purpose of processing, how to exercise rights, and how to complain to the Board. Notice must be available in English or any language listed in the Eighth Schedule.
5. (1) Every request made to a Data Principal under section 6 for consent shall be accompanied or preceded by a notice given by the Data Fiduciary to the Data Principal, informing her (i) the personal data and the purpose for which the same is proposed to be processed; (ii) the manner in which she may exercise her rights under sub-section (4) of section 6 and section 13; and (iii) the manner in which the Data Principal may make a complaint to the Board. (3) The Data Fiduciary shall give the Data Principal the option to access the contents of the notice in English or any language specified in the Eighth Schedule to the Constitution of India.
Section 6 , Consent 11 Aug 2023
Plain summary: Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to personal data necessary for the specified purpose. Withdrawal must be as easy as giving consent. Consent may be given, managed, reviewed or withdrawn through a Consent Manager registered with the Board.
6. (1) The consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose. (4) Where consent given by the Data Principal is the basis of processing of personal data, such Data Principal shall have the right to withdraw her consent at any time, with the ease of doing so being comparable to the ease with which such consent was given. (7) The Data Principal may give, manage, review or withdraw her consent to the Data Fiduciary through a Consent Manager. (8) The Consent Manager shall be accountable to the Data Principal and shall act on her behalf. (9) Every Consent Manager shall be registered with the Board. (10) In a dispute, the burden of proving valid notice and consent lies on the Data Fiduciary.
Section 7 , Certain legitimate uses 11 Aug 2023
Plain summary: Nine specific limbs allowing processing without explicit consent: voluntarily provided data used for the specified purpose; State subsidies/benefits/services/licences; State functions under law or in the interests of sovereignty/security; disclosures required by law; compliance with judgments; medical emergency; epidemic or public health measures; disaster response; and employment purposes including safeguarding employer from loss or liability.
7. A Data Fiduciary may process personal data of a Data Principal for any of the following uses, namely: (a) for the specified purpose for which the Data Principal has voluntarily provided her personal data; (b) for the State and its instrumentalities to provide or issue any subsidy, benefit, service, certificate, licence or permit; (c) for State functions under law or in the interest of sovereignty and integrity of India or security of the State; (d) for legal disclosure obligations; (e) for compliance with any judgment or order under law; (f) for a medical emergency involving threat to life or immediate threat to health; (g) for measures during an epidemic, outbreak of disease, or other threat to public health; (h) for measures during any disaster or breakdown of public order; (i) for the purposes of employment or those related to safeguarding the employer from loss or liability.
Section 8 , General obligations of Data Fiduciary 11 Aug 2023
Plain summary: The Data Fiduciary is responsible for compliance regardless of any agreement to the contrary or Data Principal duty failure. Must engage Processors only under a valid contract. Must ensure data quality where the data will affect the Data Principal. Must implement reasonable security safeguards. Must intimate personal data breaches to the Board and affected Data Principals. Must erase personal data when consent is withdrawn or the specified purpose is no longer served, unless retention is required by law. Must publish contact details of the Data Protection Officer or a designated person to answer queries.
8. (1) A Data Fiduciary shall, irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties, be responsible for complying with the provisions of this Act and the rules made thereunder. (2) A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf only under a valid contract. (5) A Data Fiduciary shall protect personal data in its possession or under its control by taking reasonable security safeguards to prevent personal data breach. (6) In the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed. (7) A Data Fiduciary shall, unless retention is necessary for compliance with any law for the time being in force, erase personal data upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier. (9) A Data Fiduciary shall publish the business contact information of a Data Protection Officer or of such other person who is able to answer questions from the Data Principal.
Section 9 , Processing of personal data of children 11 Aug 2023
Plain summary: Before processing personal data of a child or a person with disability who has a lawful guardian, the Data Fiduciary must obtain verifiable consent of the parent or lawful guardian. Fiduciary shall not undertake processing likely to cause detrimental effect on well-being, tracking or behavioural monitoring, or targeted advertising directed at children. Central Government may notify exemptions for classes of Fiduciaries or purposes.
9. (1) The Data Fiduciary shall, before processing any personal data of a child or a person with disability who has a lawful guardian, obtain verifiable consent of the parent of such child or the lawful guardian. (2) A Data Fiduciary shall not undertake such processing of personal data that is likely to cause any detrimental effect on the well-being of a child. (3) A Data Fiduciary shall not undertake tracking or behavioural monitoring of children or targeted advertising directed at children.

G.S.R. 843(E) , Commencement of specific Sections of the DPDP Act 13 Nov 2025
Plain summary: MeitY notification dated 13 November 2025 bringing specified Sections of the DPDP Act 2023 into force. Enables the DPB constitution and the phased Rules commencement schedule.
MeitY Notification G.S.R. 843(E) dated 13 November 2025. In exercise of the powers conferred by sub-section (2) of section 1 of the Digital Personal Data Protection Act, 2023, the Central Government hereby appoints the specified sections of the said Act to come into force on the date of publication of this notification in the Official Gazette.

Fourth Schedule , Exemptions from Section 9(1)/(3) for classes of Data Fiduciary and purposes 13 Nov 2025
Plain summary: Classes of Data Fiduciary exempt from verifiable parental consent + no-tracking + no-targeted-ads: clinical and mental health establishments; healthcare professionals and allied healthcare professionals; educational institutions; creches and day-care centres. Purposes exempt: safety of the child; welfare of the child; obligation under law; transportation tracking; provision of subsidies, benefits or services. Ed-tech and consumer platforms are NOT exempt.
Fourth Schedule (See Rule 12) Classes of Data Fiduciary: (i) Clinical establishment, mental health establishment, healthcare professional, allied healthcare professional; (ii) Educational institution; (iii) Individual, entity or creche, day-care centre providing care to children. Purposes for which exemption applies: (a) Restricted to protection or physical or emotional safety of child; (b) Restricted to necessary health services; (c) Restricted to educational activities; (d) Restricted to transportation tracking for child safety; (e) Provision of subsidies, benefits or services; (f) Compliance with any law for the time being in force.
Rule 13 , Additional obligations of Significant Data Fiduciary 13 Nov 2025
Plain summary: A Significant Data Fiduciary must (a) undertake a Data Protection Impact Assessment and independent audit at least once every 12 months from the date of notification as SDF, and shall submit the results of the DPIA and audit and observations to the Board; (b) exercise due diligence to verify that algorithmic software deployed for hosting, display, uploading, modification, publishing, transmission, storage or sharing of personal data is not likely to pose a risk to the rights of the Data Principal; (c) undertake such measures as the Central Government may specify, including in relation to certain classes of personal data or traffic data that shall not be transferred outside India.
13. (1) A Significant Data Fiduciary shall (a) undertake, at least once in a period of twelve months from the date of its notification as such, (i) a Data Protection Impact Assessment; and (ii) an audit; and (b) publish and submit to the Board a report containing significant observations arising from such Data Protection Impact Assessment and audit. (2) A Significant Data Fiduciary shall exercise due diligence to verify that algorithmic software deployed by it for hosting, display, uploading, modification, publishing, transmission, storage, updating or sharing of personal data managed or processed by it is not likely to pose a risk to the rights of Data Principals. (3) A Significant Data Fiduciary shall undertake such measures as the Central Government may specify from time to time to ensure that personal data and traffic data pertaining to its flow, as may be specified, is not transferred outside India.
Rule 14 , Rights of Data Principals — publication and response 13 Nov 2025
Plain summary: Every Data Fiduciary and Consent Manager must publish on its website or app the URL/app path to lodge access, correction, erasure and grievance requests; the particulars required to identify the Data Principal (username, customer ID, email, mobile, etc.); and the contact details of the DPO or the person authorised to respond. The Fiduciary must respond within the prescribed period, subject to a hard 90-day cap. The Data Principal may nominate any individual to exercise her rights on death or incapacity.
14. (1) A Data Fiduciary and a Consent Manager shall publish on its website or app or both the means using which a Data Principal may make a request in respect of exercise of her rights, the particulars, such as a username or an email address or a mobile phone number, or any other information, that are required to identify the Data Principal, and the period within which such request will be responded to. (2) A Data Principal may nominate, in the manner published by the Data Fiduciary, any other individual to exercise her rights under section 14 in the event of death or incapacity.
Rule 15 , Cross-border transfer restrictions 13 Nov 2025
Plain summary: Data Fiduciary transferring personal data outside India shall comply with such requirements as the Central Government may, by general or special order, specify in respect of making such personal data available to any foreign State or its instrumentality. As of August 2026, no restricted-country list has been notified. India's approach is a negative list — transfers are allowed by default subject to DPDP obligations and sectoral overlays.
15. The Central Government may, by general or special order, restrict the transfer of personal data, in respect of a Data Fiduciary or class of Data Fiduciary, to such foreign State, or to any person or entity under the control of or any agency of such foreign State, as may be so notified.
Rule 3 , Notice by Data Fiduciary to Data Principal 13 Nov 2025
Plain summary: Notice under Section 5 must be presented independently of any other information or document. It must contain an itemised description of the personal data and an itemised description of the specified purpose including the goods or services enabled. Notice must set out how the Data Principal can withdraw consent, exercise rights and make a complaint to the Board. Notice must be available in English or any of the 22 Eighth Schedule languages on the Data Principal's option.
3. The notice given by a Data Fiduciary to a Data Principal under section 5 shall (a) be presented and be understandable independently of any other information that may be made available by such Data Fiduciary; (b) give in clear and plain language a fair account of the following details necessary to enable the Data Principal to give specific and informed consent for the processing of her personal data, namely: (i) an itemised description of such personal data; and (ii) the specified purpose of and an itemised description of the goods or services to be provided or uses to be enabled by such processing; (c) provide the communication link for accessing the website or app or both of the Data Fiduciary; and (d) the manner in which the Data Principal may withdraw her consent, exercise her rights and make a complaint to the Board.
Rule 4 , Registration and obligations of Consent Manager 13 Nov 2025
Plain summary: A person may apply to the Board for registration as a Consent Manager if it fulfils the conditions in Part A of the First Schedule (Indian company, net worth at least two crore rupees, technical/operational/financial capability, no conflict of interest, etc.). A registered Consent Manager shall comply with the obligations in Part B (data-blind pipe, ≥7-year consent-log retention, interoperability, audit, security). Rule 4 commences 13 November 2026.
4. (1) A person seeking to be registered as a Consent Manager shall make an application to the Board fulfilling the conditions specified in Part A of the First Schedule. (2) A Consent Manager shall comply with the obligations specified in Part B of the First Schedule. (3) The Board may register a Consent Manager fulfilling the conditions and may cancel or suspend registration for non-compliance.
Rule 7 , DPDP breach notification (parallel to CSCRF for personal data) 13 Nov 2025
Plain summary: DPDP Rules 2025 Rule 7: on becoming aware of a personal data breach, the Data Fiduciary must intimate each affected Data Principal without delay and intimate the Data Protection Board without delay. Detailed report to the Board within 72 hours of awareness (extendable on written request). For a SEBI RE handling personal data, this runs in parallel with the CSCRF 6-hour clock.
DPDP Rules 2025 Rule 7. On becoming aware of any personal data breach, the Data Fiduciary shall intimate each affected Data Principal in a concise, clear and plain manner and without delay; and shall intimate the Data Protection Board without delay of the initial description, followed by an updated and detailed report within seventy-two hours of becoming aware (extendable on written request to the Board).
Seventh Schedule , Purposes for calling information under Section 36 13 Nov 2025
Plain summary: Central Government may direct the Board, Data Fiduciary or intermediary to furnish information for purposes including: sovereignty and integrity of India; security of the State; friendly relations with foreign States; maintenance of public order; preventing incitement to commission of any cognisable offence relating to any of the above; assessment or notification of a Data Fiduciary as Significant Data Fiduciary; performance of any function of the Board. Central to constitutional challenge on unchecked state access.
Seventh Schedule (See Rules 8 and 22) Purposes for which information may be called for under Section 36: (a) Sovereignty and integrity of India; (b) Security of the State; (c) Friendly relations with foreign States; (d) Maintenance of public order; (e) Preventing incitement to the commission of any cognisable offence relating to any of the above; (f) Assessment or notification of a Data Fiduciary as Significant Data Fiduciary under section 10; (g) Performance of any function of the Board under the Act.
Third Schedule , Retention default periods 13 Nov 2025
Plain summary: For e-commerce entities with two crore or more registered users, online gaming intermediaries with fifty lakh or more registered users, and social media intermediaries with two crore or more registered users: personal data of a Data Principal who has not approached the Fiduciary nor exercised her rights for a period of three years is deemed no longer needed for the specified purpose and shall be erased. Fiduciary must inform the Data Principal at least 48 hours before erasure. Government has additional Seventh Schedule retention exceptions for state functions.
Third Schedule (See Rule 8) Class of Data Fiduciary | Purpose | Time period (i) E-commerce entity with 2 crore or more registered users in India | For which the Data Principal enrolled or provided personal data | 3 years from date the Data Principal last approached the Data Fiduciary or exercised any of her rights, whichever is later (ii) Online gaming intermediary with 50 lakh or more registered users in India | Same | 3 years (iii) Social media intermediary with 2 crore or more registered users in India | Same | 3 years
Rule 8 , DPDP Rules 2025 Rule 8 (Log Retention and Third Schedule Sector Defaults) 14 Nov 2025
Plain summary: Rule 8 of the DPDP Rules 2025 establishes log-retention obligations independent of the underlying data-retention rules. Data Fiduciaries and Data Processors must retain LOGS for at least ONE YEAR, EVEN when deletion of the underlying personal data is requested by the Data Principal. The logs must capture access logs, authentication logs, modification logs, processor activity logs, consent updates, breach detection logs, deletion events and system anomalies. The Third Schedule sets default retention periods for specified sectors: e-commerce entities with 2 crore+ users (3 years from last transaction or login), social media entities with 2 crore+ users (3 years from last login), online gaming entities with 50 lakh+ users (3 years from last login). For POSH-Lead-Practitioner purposes, the Rule 8 log-retention obligation applies to the IC's case management system alongside the Section 16 confidentiality obligation. Section 16 restricts publication of content; Rule 8 requires retention of access logs. The two are compatible because access logs record who accessed what, not the substance of what they accessed.
DPDP Rules 2025 Rule 8 (Log Retention) and Third Schedule (Sector-Specific Retention Defaults). Key provisions (summary paraphrased from Mondaq + Scrut + Progressive commentary): (i) Rule 8: Data Fiduciaries and Data Processors shall retain logs of access, processing, deletion and breach-detection activities for at least one year, regardless of whether the underlying personal data is deleted at the request of the Data Principal or under retention rules. (ii) Log categories to be captured: access logs; authentication logs; modification logs; processor activity logs; consent updates; breach detection logs; deletion event logs; system anomaly logs. (iii) Where deletion is requested by the Data Principal, the personal data may be deleted or anonymised but the log entries recording the access and processing history must be retained. (iv) Third Schedule sector-specific retention defaults: e-commerce entities with 2 crore+ users — 3 years from last transaction or login; social media entities with 2 crore+ users — 3 years from last login; online gaming entities with 50 lakh+ users — 3 years from last login. (v) At the end of the retention period, personal data must be erased with 48 hours\' advance notice to the Data Principal (unless retention is otherwise required by law).

April 2026 Guidelines , IRDAI Information and Cyber Security Guidelines 2026 06 Apr 2026
Plain summary: IRDAI Information and Cyber Security Guidelines 2026 notified on 6 April 2026, mandating DPDP Act compliance for insurers, foreign reinsurance branches, brokers, corporate agents, web aggregators and third-party administrators. Requires grey-box / white-box VAPT every 6 months by CERT-In empanelled auditors; quarterly ISRMC meetings; post-quantum cryptography readiness planning; and revised cyber incident reporting protocols.
IRDAI Information and Cyber Security Guidelines 2026, notified 6 April 2026. Applies to all insurers, foreign reinsurance branches, insurance brokers, corporate agents, insurance web aggregators, and third-party administrators. Regulated entities shall (a) comply with the Digital Personal Data Protection Act, 2023 and rules made thereunder; (b) conduct VAPT in grey-box or white-box mode at least every six months by CERT-In empanelled auditors; (c) constitute an Information Security Risk Management Committee meeting at least quarterly; (d) plan for post-quantum cryptography readiness.

Draft July 2026 , RBI Data Governance Framework Draft (15 July 2026) 15 Jul 2026
Plain summary: Reserve Bank of India's Draft Guidance on Regulatory Expectations for Data Governance, released 15 July 2026, consultation closed 17 August 2026. Applies to banks, NBFCs, payment banks, co-operative banks, CICs and other Regulated Entities. Requires an annually-reviewed data governance framework, Board-level Data Governance Committee oversight, and data owners / data stewards / data custodians role structure. Explicitly binds compliance to the DPDP Act 2023 and Rules 2025.
RBI Draft Guidance on Regulatory Expectations for Data Governance, dated 15 July 2026. Applies to Scheduled Commercial Banks, Small Finance Banks, Payment Banks, Local Area Banks, Co-operative Banks, NBFCs, Housing Finance Companies, Credit Information Companies and All-India Financial Institutions. Requires each RE to (a) formulate a Board-approved Data Governance Framework reviewed at least annually; (b) constitute a Data Governance Committee at the Board level; (c) designate data owners, data stewards and data custodians; (d) comply with the Digital Personal Data Protection Act, 2023 and rules made thereunder.

Cyber Audit , Cyber audit cadence and scope 20 Aug 2024
Plain summary: MIIs, Qualified REs, and Mid/Small REs with Internet-Based Trading (IBT) or Algo trading: at least twice a year. Other Mid-size / Small REs: at least once a year. Self-Certification REs: exempt from periodic audit; VAPT-only + self-certification. Audit scope must cover 100% of critical systems and at least 25% of non-critical systems on a sample basis. All audits must be performed by CERT-In empanelled Information Security auditing organisations. Auditors need at least 3 years of BFSI IT-audit experience and hold CISA/CISM/CISSP.
Cyber Audit Frequency: (a) MIIs, Qualified REs, and Mid/Small REs with IBT or Algo — at least twice a year. (b) Other Mid-size and Small-size REs — at least once a year. (c) Self-Certification REs — exempt from periodic cyber audit; must undertake VAPT and self-certify. Audit Scope: 100 percent of critical systems and 25 percent of non-critical systems on a sample basis. Auditor Empanelment: CERT-In empanelled Information Security auditing organisations only; auditors must have minimum 3 years BFSI IT audit experience and CISA/CISM/CISSP.
Master Circular 2024/113 , Cybersecurity and Cyber Resilience Framework for SEBI Regulated Entities 20 Aug 2024
Plain summary: SEBI Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated 20 August 2024. The 205-page master framework that supersedes all prior SEBI cyber circulars (2015 MIIs, 2016 depositories, 2018 stockbrokers/DPs, 2019 MFs/RTAs). Applies to all SEBI Regulated Entities across five categories: MIIs, Qualified REs, Mid-size REs, Small-size REs and Self-Certification REs. Structured around 5 cyber-resilience goals (Anticipate, Withstand, Contain, Recover, Evolve) mapped to 6 NIST CSF 2.0 functions (Governance, Identify, Protect, Detect, Respond, Recover). Cross-references NIST CSF 2.0, ISO/IEC 27001:2022, CIS Controls v8, ISO 22301.
SEBI Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 dated August 20, 2024. Subject: Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (REs). This framework is applicable to all SEBI Regulated Entities and consolidates all prior cybersecurity guidelines. The framework is structured around five cyber-resilience goals: Anticipate, Withstand, Contain, Recover and Evolve. These goals are implemented through six functional domains aligned to NIST CSF 2.0: Govern, Identify, Protect, Detect, Respond and Recover.

Found an error? We pay for it.

If you find a factual error in any lesson, write to [email protected] with the lesson title, the specific claim, and the corrected source.

  • ₹1,000 credit for the first report of any verifiable factual error.
  • ₹5,000 credit for a substantial error (e.g. a wrong section number, an obsolete ruling, a misrepresented holding).
  • Credit on your dcomply Academy account usable against any future course.

We pay because we'd rather know than not know. If the law changes (and it will), we want to be the first to fix our lessons.

On this page
  • 🟢 Our verification promise
  • 📊 Course statistics
  • 📚 Full citation register
  • 🐛 Bug bounty for errors

Maintained by the dcomply Academy editorial team. Last reviewed recently.