Got Questions?

Everything You Need to Know, Simplified

From compliance basics to complex clauses, we've broken down the DPDP Act into straightforward answers — so you spend less time searching and more time doing.

Stay Updated — Join Our WhatsApp Channel
Knowledge index 200 published answers across 10 categories
Select by topic

DPDP ACT BASICS 15 questions

What is the Digital Personal Data Protection Act, 2023?
The DPDP Act, 2023 is India's principal law governing the processing of digital personal data. It establishes obligations for organisations processing personal data and rights for Data Principals.
Who is a Data Principal under the DPDP Act?
A Data Principal is the individual to whom the personal data relates. For a child, the term refers to the child's parent or lawful guardian in the circumstances specified by the Act.
Who is a Data Fiduciary?
A Data Fiduciary is the person or organisation that determines the purpose and means of processing personal data. Businesses generally become Data Fiduciaries when they decide why and how customer or employee data is processed.
What is a Data Processor under DPDP?
A Data Processor processes personal data on behalf of a Data Fiduciary. Examples can include cloud providers, payroll providers, CRM platforms and outsourced service providers.
What is personal data under DPDP?
Personal data means any data about an individual who is identifiable by or in relation to that data. The Act focuses on digital personal data and certain data that is digitised subsequently.
Does the DPDP Act apply only to Indian companies?
No. The Act can apply to processing outside India where such processing is connected with offering goods or services to Data Principals in India, subject to the Act's scope and conditions.
Does DPDP apply to employee data?
Employee-related processing can fall within the Act depending on the circumstances and applicable provisions. Organisations should assess the purpose, nature and legal basis of each processing activity rather than assuming employee data is automatically excluded.
Does DPDP apply to customer data?
Yes. Customer information that qualifies as digital personal data can fall within the DPDP framework. Businesses should identify what customer data they collect, why they process it, where it is stored and who receives it.
Does DPDP apply to offline data?
The DPDP Act primarily concerns digital personal data. Offline data that is not digitised is generally outside its immediate scope, although digitisation can bring the resulting data within the framework.
What is processing of personal data under DPDP?
Processing broadly covers operations performed on digital personal data, including collection, storage, use, sharing, disclosure and other handling activities.
What is a Significant Data Fiduciary?
A Significant Data Fiduciary is a Data Fiduciary notified by the Central Government based on specified factors. Such entities have additional obligations under the Act.
Does every business need a Data Protection Officer?
Not necessarily. Additional DPO-related obligations apply to Significant Data Fiduciaries. Other organisations should nevertheless establish appropriate responsibility and accountability for privacy compliance.
What is a Consent Manager?
A Consent Manager is a registered entity that enables Data Principals to give, manage, review and withdraw consent through an interoperable platform, subject to the applicable Rules.
What is the Data Protection Board of India?
The Data Protection Board is the statutory body established under the DPDP framework to perform functions including dealing with certain breaches and exercising powers assigned under the Act.
What are the penalties under DPDP?
The Act provides for significant financial penalties for specified breaches. The amount depends on the nature of the breach and the relevant provision in the Schedule.

DPDP RULES 2025 11 questions

What are the DPDP Rules 2025?
The DPDP Rules, 2025 provide detailed operational requirements for implementing the Digital Personal Data Protection Act, 2023. They were notified by MeitY on 14 November 2025.
Are the DPDP Rules 2025 final?
Yes. The Rules notified on 14 November 2025 are the final Rules. Earlier draft Rules should not be treated as the current legal position.
When do the DPDP Rules 2025 take effect?
The Rules have a phased commencement structure. Certain provisions take effect on publication, while specified provisions take effect after the prescribed transition period. Organisations should therefore check the applicable commencement provision before assessing a current obligation.
What does the DPDP Rules say about privacy notices?
The Rules require notices to be clear, standalone and understandable, including information about the personal data being processed, purpose and mechanisms for exercising rights and withdrawing consent.
What do the Rules require for consent withdrawal?
The framework requires mechanisms that allow Data Principals to withdraw consent through accessible means. The Rules also require notices to explain how consent can be withdrawn and rights exercised.
What do the DPDP Rules say about security safeguards?
The Rules prescribe reasonable security safeguards and organisational and technical measures intended to protect personal data from specified risks.
What do the Rules say about personal data breaches?
The Rules establish requirements concerning intimation of personal-data breaches, including communications to affected Data Principals and the Board in specified circumstances.
Do the Rules apply differently to children?
Yes. The Rules provide additional requirements concerning processing of children's personal data and verification of consent from parents or lawful guardians in applicable circumstances.
What do the Rules say about Consent Managers?
The Rules establish requirements for registration, operation, security, interoperability, record keeping and governance of Consent Managers.
Can organisations still rely on the draft DPDP Rules?
No. The final Rules should be the primary reference for current compliance planning. Draft Rules may be useful for understanding the consultation history but should not be presented as the operative framework.
Where can businesses find the official DPDP Rules?
The official Rules are available through MeitY's website and India Code. Businesses should rely on the notified text rather than unofficial summaries.

DPDP COMPLIANCE & IMPLEMENTATION 10 questions

How can a company start DPDP compliance?
Start by identifying personal data, processing activities, purposes, Data Fiduciaries, processors, systems and data flows. Then assess gaps against applicable obligations and create a prioritised remediation plan.
Does every business need a DPDP compliance policy?
A written privacy and data-governance framework is a practical way to establish accountability and consistent processes. The exact documents required should depend on the organisation's processing activities and applicable obligations.
Is having a privacy policy enough for DPDP compliance?
No. A privacy notice is only one component. Compliance also involves governance, consent or other applicable processing grounds, security, rights handling, processor management, retention and evidence.
How long does DPDP compliance take?
There is no universal timeline. Complexity depends on data volume, systems, vendors, industry, processing activities and existing controls. A structured gap assessment can establish a realistic implementation roadmap.
Does a small business need DPDP compliance?
Businesses should assess whether and how the Act applies to their processing. Small size does not automatically mean that personal-data obligations can be ignored.
What documents should a business maintain for DPDP compliance?
Depending on the organisation, documentation can include privacy notices, consent records, data inventories, processing records, contracts, retention policies, breach procedures, rights-request records and security evidence.
What is a DPDP compliance gap assessment?
It is a structured review comparing an organisation's current data practices, controls and documentation against applicable DPDP requirements.
Can DPDP compliance be automated?
Some activities can be supported by technology, including data discovery, consent management, cookie scanning, rights requests and compliance monitoring. Technology does not replace governance or accountability.
How often should DPDP compliance be reviewed?
Organisations should establish periodic reviews and reassess compliance when there are material changes to products, systems, vendors, regulations or processing activities.
Should DPDP compliance be integrated with cybersecurity?
Yes. Privacy and cybersecurity are different disciplines but overlap significantly in areas such as access control, data security, incident response and protection of personal data.

DATA GOVERNANCE 10 questions

What is a DPDP data inventory?
A data inventory identifies what personal data an organisation processes, where it resides, why it is processed, who accesses it and which third parties receive it.
Why is data mapping important for DPDP?
Data mapping helps organisations understand how personal data moves across applications, departments, vendors and locations. Without visibility, organisations may struggle to implement retention, security and rights processes effectively.
Should Excel files be included in a data inventory?
Yes, if they contain digital personal data. Spreadsheets are often overlooked repositories and should be considered during data discovery and classification.
Should email systems be included in data discovery?
Yes. Emails and attachments can contain substantial amounts of personal data. Organisations should consider appropriate discovery, retention and access controls.
How should businesses identify unnecessary personal data?
Review each category of data against its purpose, business need, legal requirements and retention requirements. Data without a continuing legitimate purpose should be evaluated for deletion or appropriate handling.
What is data minimisation under DPDP?
Data minimisation means avoiding unnecessary collection or processing of personal data. Organisations should assess whether every data field collected is genuinely necessary for the stated purpose.
How should businesses handle duplicate personal data?
Identify where duplicate records exist, determine the authoritative source and establish appropriate synchronisation, correction and deletion processes.
What should happen to personal data in legacy systems?
Legacy data should be identified, assessed for ongoing necessity and handled according to applicable retention, security and deletion requirements.
Should personal data in backups be deleted?
Backup handling requires a risk-based and technically informed approach. Organisations should establish retention, restoration and deletion procedures that address personal data contained in backup environments.
Who should own the company's data inventory?
Ownership should be clearly assigned. Depending on the organisation, responsibility may sit with privacy, compliance, security, IT, data governance or a coordinated cross-functional team.

CONSENT & DATA PRINCIPAL RIGHTS 13 questions

Can a customer withdraw consent under DPDP?
Yes, where processing is based on consent, the Data Principal has the right to withdraw consent, subject to the framework's provisions and consequences.
Does withdrawal of consent have to be as easy as giving consent?
Yes. The Act requires withdrawal to be as easy as giving consent. The Rules also require notices to explain how consent can be withdrawn.
What happens after consent is withdrawn?
Where processing depends on consent, the Data Fiduciary must cease processing within a reasonable time unless processing is otherwise authorised or required under the Act or another applicable law.
Does withdrawing consent make previous processing unlawful?
No. Withdrawal generally does not affect the legality of processing that occurred before withdrawal.
What if a customer says they never gave consent?
The organisation should review its consent records, notice, collection mechanism and evidence. Where the organisation cannot establish the relevant basis for processing, it should assess the appropriate remediation.
Can a business continue processing after consent is withdrawn?
Potentially, if another lawful basis or legal requirement permits or requires the processing. The organisation should identify and document the applicable basis rather than assuming consent is the only possible basis.
What should a business do if consent records are missing?
Investigate whether evidence exists elsewhere, assess the relevant processing basis and remediate the affected process. Consent should not simply be assumed because data was collected in the past.
Can consent records be stored in Excel?
Technically they can, but organisations should ensure that records are accurate, secure, traceable and sufficient to demonstrate the relevant consent and its history.
Can a Data Principal request correction of personal data?
Yes. The Act provides rights concerning correction and updating of personal data, subject to applicable provisions and procedures.
Can a Data Principal request deletion of personal data?
Yes, subject to the Act and applicable legal requirements. Businesses should assess the request against their continuing obligations and processing purposes.
Can someone exercise Data Principal rights through an authorised person?
The Act provides mechanisms for exercising rights through an authorised person in specified circumstances. Organisations should verify the authority and follow their documented rights-handling process.
How should a business handle a Data Principal request involving several systems?
Establish a central request-management process, identify relevant systems and processors, verify the requester and coordinate the response across responsible teams.
How quickly should a Data Principal request be handled?
Organisations should follow the applicable requirements under the Act and Rules and establish internal service timelines that allow sufficient time for verification, investigation and response.

SECURITY, BREACH & INCIDENT RESPONSE 10 questions

What is a personal data breach under DPDP?
"Personal Data Breach" means any unauthorized processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data.
What should I do if personal data is sent to the wrong person?
Contain the incident, determine what data was disclosed, identify the recipient, assess the risk and follow the organisation's breach-response and notification procedures.
What if an employee accidentally shares customer data?
Treat it as a potential security incident, investigate the scope, contain further disclosure, preserve evidence and assess whether the incident meets the applicable personal-data breach requirements.
What if a customer database is exposed online?
Immediately restrict access, preserve evidence, investigate the exposure, identify affected data and individuals, assess the incident and follow applicable breach-intimation requirements.
What if a breach is discovered several days later?
The organisation should begin response immediately upon discovery. It should document when the incident occurred, when it was detected and what actions were taken.
Is every cybersecurity incident a DPDP breach?
No. A cybersecurity incident becomes relevant to DPDP when it involves personal data and falls within the applicable breach framework. Proper incident classification is therefore important.
What if a laptop containing personal data is lost?
Assess whether personal data was stored on the device, whether it was encrypted or otherwise protected, whether remote controls are available and whether the incident triggers breach-response obligations.
What security measures should businesses implement for personal data?
Appropriate measures may include access controls, authentication, encryption where appropriate, logging, monitoring, backups, vulnerability management, secure development and incident-response processes.
Should DPDP breach response be part of the cyber incident-response plan?
Yes. Organisations should integrate privacy considerations into incident response so that personal-data exposure can be identified, assessed and escalated quickly.
What evidence should be maintained after a personal data breach?
Maintain relevant incident timelines, investigation records, affected-data analysis, containment actions, communications, remediation and decision records consistent with applicable requirements and internal policies.

GOVERNANCE, AUDIT & ACCOUNTABILITY 9 questions

Who should be responsible for DPDP compliance?
Responsibility should be formally assigned rather than left to one department by default. Privacy, legal, compliance, security, IT, HR and business teams may all have defined responsibilities.
Does an SME need a dedicated privacy team?
Not necessarily. SMEs can allocate privacy responsibilities across existing teams or appoint external expertise, provided accountability and operational ownership are clear.
What is a DPDP compliance audit?
A DPDP compliance audit evaluates whether an organisation's data practices, controls and documentation align with applicable legal and internal requirements.
How often should DPDP audits be conducted?
Frequency should depend on risk, processing volume, regulatory obligations, business changes and the organisation's governance framework.
What evidence should a company maintain for DPDP compliance?
Evidence can include consent records, notices, data inventories, contracts, security assessments, training records, rights-request logs, breach records and audit reports.
Can ISO 27001 help with DPDP compliance?
Yes. ISO 27001 can provide a structured information-security management framework that supports several DPDP security and governance objectives. It does not, however, automatically establish DPDP compliance.
Can SOC 2 compliance help with DPDP?
SOC 2 controls can support privacy and security governance, but SOC 2 and DPDP address different frameworks and should not be treated as equivalent certifications.
What should management review for DPDP compliance?
Management should review major processing activities, compliance gaps, risks, incidents, rights requests, vendor issues, audit findings and remediation progress.
What happens if a company ignores DPDP requirements?
Non-compliance can create legal, financial, operational and reputational risks, including penalties for specified breaches. Organisations should therefore assess and address applicable obligations proactively.

VENDORS, CONTRACTS & THIRD PARTIES 10 questions

Is a vendor processing customer data a Data Processor?
It may be, if it processes personal data on behalf of the Data Fiduciary. The exact relationship should be assessed based on the parties' roles and processing activities.
Should businesses have a data-processing agreement with vendors?
A suitable contractual framework is an important governance mechanism for defining responsibilities, security, processing instructions, confidentiality, incident handling and other relevant requirements.
What if a vendor refuses to sign a data-processing agreement?
Assess the vendor's role and risk. If adequate contractual safeguards cannot be established, the organisation should consider whether the processing arrangement can safely and appropriately continue.
What is a sub-processor?
A sub-processor is generally a third party engaged by a Data Processor to process personal data in connection with services provided to the Data Fiduciary.
Should businesses assess sub-processors?
Yes. Organisations should understand material third-party data flows and establish appropriate contractual and governance controls for relevant processing arrangements.
What if a vendor suffers a data breach?
The Data Fiduciary should coordinate with the vendor, establish the scope and impact, contain the incident and assess applicable notification and remediation obligations.
What if a vendor retains personal data after the contract ends?
Review the contract, purpose and applicable retention requirements, then require appropriate deletion, return or continued protection according to the applicable framework.
Should SaaS vendors be assessed for DPDP compliance?
Yes. SaaS platforms may process significant amounts of personal data, so organisations should assess data location, processing, security, subprocessors, retention and contractual protections.
Can a company use cloud providers to process personal data?
Cloud providers can process personal data, subject to the organisation's applicable legal obligations and appropriate security, governance and contractual controls.
Can vendors process personal data outside India?
Cross-border processing must be assessed against the DPDP Act, Rules and applicable restrictions or requirements. Businesses should not assume that location alone determines legality.

AI, TECHNOLOGY & DPDP 12 questions

Can employees upload customer data to ChatGPT?
Organisations should not permit employees to upload personal data to external AI tools without assessing the purpose, legal basis, vendor terms, security, data handling and organisational controls.
What is Shadow AI in a DPDP context?
Shadow AI refers to employees using AI tools without formal organisational approval or oversight. It can create privacy, security, data-transfer and governance risks.
Can personal data be used to train AI models?
It depends on the processing purpose, legal basis, applicable obligations and how the model and data are handled. Organisations should conduct a specific privacy assessment rather than assume training is permitted.
Can AI agents access customer personal data?
They can technically be designed to access data, but organisations should control access according to purpose, necessity, authorisation, security and applicable DPDP obligations.
What if an AI vendor cannot explain where personal data is stored?
Treat the lack of transparency as a vendor-risk issue. Obtain sufficient information to assess processing, security, data flows, retention and applicable legal requirements before approving the use case.
Can customer data be entered into AI-powered CRM tools?
Potentially, but the organisation should assess the CRM provider's processing activities, AI functionality, security, retention, third parties and applicable legal requirements.
Can production customer data be used for software testing?
Organisations should carefully assess whether production personal data is necessary. Where possible, synthetic, anonymised or appropriately de-identified test data may reduce privacy risk.
Are cookies covered under DPDP?
Cookies themselves are technology rather than automatically personal data. The relevant question is whether the information collected through them constitutes personal data and how it is processed.
Do analytics tools create DPDP obligations?
They can, depending on the data collected and how the tool processes or transfers it. Organisations should assess analytics configurations, identifiers, purposes and third-party processing.
Is a cookie banner enough for DPDP compliance?
No. A banner is only one component of a broader consent and website-data governance process. Organisations should assess notices, consent mechanisms, cookies, trackers and actual data flows.
Can website forms collect personal data before consent?
Businesses should assess the applicable processing basis and ensure their collection mechanism, notice and consent process are aligned with the DPDP framework.
Can WhatsApp be used to share customer personal data?
Organisations should assess whether the sharing is necessary, authorised, secure and consistent with their data-processing practices, contractual requirements and applicable DPDP obligations.

INDUSTRIES 100 questions

Does DPDP apply to patient personal data?
Yes. Patient information that qualifies as digital personal data can fall within the DPDP framework. Hospitals, clinics, diagnostic centres and health-tech providers should identify the personal data they process, why they process it, who can access it and which third parties receive it. Healthcare organisations should also consider other laws and professional obligations applicable to health information. DPDP compliance should therefore be integrated with existing privacy, security and medical-record management practices.
Can clinics store patient data in cloud software?
Yes. However, clinics should assess the cloud provider's role, security controls, processing activities, access arrangements, contractual protections, retention practices and applicable data-transfer requirements. The clinic should understand where the data resides, who can access it and whether additional processors or subprocessors are involved.
How should hospitals handle patient data under DPDP?
Hospitals should map patient-data flows across registration, consultation, diagnostics, billing, pharmacy, insurance and digital health systems. They should establish appropriate notices, access controls, security measures, retention practices, vendor controls and incident-response procedures. The exact requirements depend on the processing activity and applicable legal framework.
Can hospitals share patient data with diagnostic laboratories?
They may do so where the sharing is appropriately authorised or otherwise permitted under the applicable legal framework. Hospitals should establish clear data flows, define responsibilities, limit unnecessary disclosure and ensure appropriate contractual and security controls with laboratories and other service providers.
How should telemedicine platforms handle patient data under DPDP?
Telemedicine platforms should identify the personal data collected through consultations, registrations, prescriptions, payments and communications. They should establish appropriate notices, processing mechanisms, security controls, access restrictions, retention practices and vendor governance. They should also assess any other healthcare-specific requirements applicable to their operations.
Can hospitals use patient data for research?
Potentially, depending on the purpose, applicable legal provisions, consent or other permitted basis, and any sector-specific requirements. A hospital should not automatically assume that data collected for treatment can be reused for unrelated research. The proposed research purpose and data use should be assessed before processing.
How should hospitals handle patient-data breach incidents?
They should activate their incident-response process, contain the incident, determine what information was affected, assess the impact, preserve evidence and follow applicable breach-intimation requirements. Healthcare organisations should also coordinate privacy, cybersecurity, legal and operational teams during the response.
Can healthcare providers use patient data for marketing?
Marketing use should be separately assessed rather than automatically assumed to be covered by the original healthcare relationship. Organisations should identify the purpose, applicable processing basis, communication mechanism and withdrawal process before using patient information for marketing.
How should diagnostic centres manage patient data under DPDP?
Diagnostic centres should map information collected during registration, testing, reporting, billing and communication. They should control access, establish appropriate retention and deletion practices, assess third-party platforms and ensure that patient information is not unnecessarily exposed through reports, email, messaging or portals.
How should health-tech companies manage third-party healthcare platforms?
They should conduct appropriate vendor due diligence covering data processing, security, access, retention, subprocessors, incident management and contractual responsibilities. The organisation should understand which party determines the purpose and means of processing for each activity and govern the relationship accordingly.
Stay Updated — Join Our WhatsApp Channel