Skip to content
TruPriv
Explainer

The DPDP Act, section by section

Plain English, in the order the obligations actually bite. This is a reading aid for compliance owners, not a substitute for the statute. Where a section is commonly misread, the misreading is named.

Sec 3

Territorial scope

The Act applies to personal data processed within India in digital form, and to digitised non-digital records. It also reaches processing outside India where that processing relates to offering goods or services to Data Principals in India. Being incorporated elsewhere does not put you outside it.

Sec 5(1)

Notice

Before or at the time consent is requested, the Data Fiduciary must give an itemised notice: what personal data, for what purpose, how to exercise rights, and how to complain to the Board. The notice must be available in English and in the languages of the Eighth Schedule, because a notice in a language the reader does not have does not discharge the obligation.

Sec 6(1)–(4)

Consent, and what makes it valid

Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the personal data necessary for the specified purpose. Withdrawal must be as easy as giving. On withdrawal, processing must cease within a reasonable time, and so must processing by every processor acting on your behalf.

Sec 6(7)–(9)

Consent Managers

A Consent Manager is a specific intermediary registered with the Data Protection Board, through which a Data Principal may give, manage, review and withdraw consent. Registration conditions sit in Rule 4. This is a defined, registered role, not a description of any consent software. TruPriv is not a Consent Manager.

Sec 6(10)

The burden of proof

Where a question arises whether notice was given and consent was validly obtained, the Data Fiduciary must prove it. Not the Data Principal, not the Board. This single sub-section is why evidence, rather than intention, is the compliance asset, and why an audit trail is not an optional feature.

Sec 8(5)–(6)

Security safeguards and breach notification

Reasonable security safeguards must be taken to prevent a personal data breach. Penalties of up to ₹250 crore attach to failing this. A breach must be notified to the Board and to each affected Data Principal, with penalties of up to ₹200 crore for failing to do so. Note the second obligation runs to individuals, not only to the regulator.

Sec 9

Children and persons with disabilities

Processing a child's personal data requires verifiable consent from a parent or lawful guardian. Tracking, behavioural monitoring and targeted advertising directed at children are prohibited. Penalties of up to ₹200 crore attach. If you cannot tell whether a user is a child, you have a design problem before you have a legal one.

Sec 10

Significant Data Fiduciaries

The Central Government may notify a Data Fiduciary, or a class of them, as significant, based on volume and sensitivity of data, risk to Data Principals, risk to electoral democracy, and the security of the State. Additional obligations follow: a Data Protection Officer based in India, an independent data auditor, and periodic Data Protection Impact Assessments and audits. Penalties of up to ₹150 crore attach.

Sec 11(1)(a)–(b)

Right to access information

A Data Principal may require a summary of the personal data being processed and the processing activities undertaken, plus the identities of all other Data Fiduciaries and processors with whom that data has been shared and a description of what was shared. This is answerable only if you maintain a record of where data goes.

Sec 14

Right of grievance redressal

Data Principals have a right to a readily available means of grievance redressal provided by the Data Fiduciary or its Consent Manager, and must exhaust it before approaching the Board. In practice that means a named owner, an acknowledgement and a response time.

Sec 17

Exemptions

Certain processing is exempted, including processing necessary to enforce a legal right or claim, by courts and tribunals, for prevention and investigation of offences, and for certain corporate reorganisation approved by law. Exemptions are narrow and specific. Assuming one applies to your business is an expensive way to find out it does not.

This is informational and is not legal advice. Liability under the DPDP Act, 2023 remains with the Data Fiduciary.