Compliance Register
Every operative obligation in the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, with the organisation's assessed position against each. This register is the denominator of the readiness score.
DischargesS.28
Compliant
16
Partially compliant
9
In progress
1
Gap
9
Not assessed
0
Not applicable
3
By instrument
Weighted score and assessment coverage.
DPDP Act, 2023
56%
23 of 23 assessed
DPDP Rules, 2025
50%
14 of 14 assessed
Schedule
100%
1 of 1 assessed
By obligation area
Sorted weakest first — this is the work queue.
Cross-border transfer
0%
Children's data
0%
Retention & erasure
25%
Governance
36%
Security safeguards
50%
Data Principal rights
63%
Accountability
71%
Consent
83%
Lawful basis
83%
Notice
100%
Breach response
100%
38 obligations
Click any clause to see what it requires, which module discharges it, and the evidence behind its status.
| Section 4 | Grounds for processing personal data Process personal data only for a lawful purpose, and only either with the Data Principal's consent or for a certain legitimate use. Every processing activity must be traceable to one of those two grounds. | Partially compliant | 2 | Medium | — | Meera Iyer | |
| Section 5 | Notice Serve an itemised notice — before or at the time of seeking consent — describing the personal data sought, the purpose, how rights may be exercised, and how to complain to the Board. Offer it in English or any Eighth Schedule language, at the Data Principal's option. | Compliant | 2 | Low | — | Priya Nair | |
| Section 6 | Consent Consent must be free, specific, informed, unconditional and unambiguous, given by clear affirmative action, and limited to data necessary for the specified purpose. Withdrawal must be as easy as giving it, and must stop processing within a reasonable time. | Partially compliant | 2 | Medium | — | Vikram Saxena | |
| Section 6(7)–(9) | Consent Managers Where a Data Principal gives, manages, reviews or withdraws consent through a registered Consent Manager, the platform must interoperate with it and remain accountable to the Data Principal. | Compliant | — | Low | — | Meera Iyer | |
| Section 7 | Certain legitimate uses Where processing rests on legitimate use rather than consent — voluntary provision, State subsidy or service, legal obligation, medical emergency, employment purposes — record which limb is relied on and why it fits. | Compliant | — | Low | — | Priya Nair | |
| Section 8(1)–(2) | Accountability, including through a Processor The Data Fiduciary remains responsible for compliance even where processing is carried out by a Data Processor on its behalf, and may engage one only under a valid contract. | Gap | 1 | High | — | Vikram Saxena | |
| Section 8(3) | Accuracy and completeness Ensure personal data is complete, accurate and consistent where it is used to make a decision affecting the Data Principal, or is disclosed to another Data Fiduciary. | Compliant | — | Low | — | Meera Iyer | |
| Section 8(4)–(5) | Reasonable security safeguards Implement appropriate technical and organisational measures, and reasonable security safeguards to prevent a personal data breach. Failure here carries the highest penalty in the Schedule. | Partially compliant | 3 | Medium | ₹250 Cr | Priya Nair | |
| Section 8(6) | Breach intimation On becoming aware of a personal data breach, intimate the Board and each affected Data Principal, in the form and manner prescribed. | Compliant | — | Low | ₹200 Cr | Vikram Saxena | |
| Section 8(7)–(8) | Erasure on withdrawal or purpose fulfilment Erase personal data — and cause your Processor to erase it — once the Data Principal withdraws consent or the specified purpose is no longer being served, unless retention is required by law. | Partially compliant | 2 | Medium | — | Meera Iyer | |
| Section 8(9) | Publish contact for the DPO or responsible person Publish the business contact information of the Data Protection Officer, or of a person able to answer questions about processing on the Data Fiduciary's behalf. | Compliant | 1 | Low | — | Priya Nair | |
| Section 8(10) | Grievance redressal mechanism Establish an effective mechanism to redress the grievances of Data Principals, and make it readily available. | Partially compliant | 1 | Medium | ₹50 Cr | Vikram Saxena | |
| Section 9 | Personal data of children Obtain verifiable consent of a parent or lawful guardian before processing a child's personal data. Do not undertake tracking, behavioural monitoring or targeted advertising directed at children, or any processing likely to cause detrimental effect on a child's well-being. | Gap | 1 | Critical | ₹200 Cr | Meera Iyer | |
| Section 10 | Additional obligations of a Significant Data Fiduciary If notified as an SDF: appoint a Data Protection Officer based in India who reports to the board, appoint an independent data auditor, and undertake periodic Data Protection Impact Assessment, periodic audit, and other prescribed measures including algorithmic due diligence. | Gap | 2 | Critical | ₹150 Cr | Priya Nair | |
| Section 11 | Right to access information about personal data On request, provide a summary of the personal data being processed and the processing activities, plus the identities of other Data Fiduciaries with whom it has been shared and what was shared. | Compliant | — | Low | — | Vikram Saxena | |
| Section 12 | Right to correction, completion, updating and erasure Correct inaccurate or misleading data, complete incomplete data, update it, and erase it on request unless retention is necessary for the specified purpose or required by law. | Compliant | — | Low | — | Meera Iyer | |
| Section 13 | Right of grievance redressal Provide a readily available means of grievance redressal in respect of any act or omission regarding performance of obligations, and respond within the prescribed period. The Data Principal must exhaust this before approaching the Board. | Partially compliant | 1 | Medium | — | Priya Nair | |
| Section 14 | Right to nominate Allow a Data Principal to nominate another individual to exercise their rights in the event of death or incapacity. | Gap | 1 | High | — | Vikram Saxena | |
| Section 15 | Duties of the Data Principal Data Principals must not impersonate another person, suppress material information, register false or frivolous grievances, or furnish anything but verifiably authentic information. Surface these duties and flag abusive requests rather than silently rejecting them. | Compliant | — | Low | — | Meera Iyer | |
| Section 16 | Processing of personal data outside India Transfer of personal data outside India is permitted except to a country restricted by Central Government notification. Sectoral laws providing higher protection continue to apply. | Gap | 2 | High | — | Priya Nair | |
| Section 17 | Exemptions Record and justify reliance on any exemption — enforcement of legal rights, judicial or regulatory functions, prevention and investigation of offences, approved corporate schemes, research and statistics — rather than assuming it. | Not applicable | — | Informational | — | Vikram Saxena | |
| Section 27 | Powers and functions of the Board On a breach intimation or complaint, the Board may inquire and impose penalties, direct remedial or mitigation measures, and issue directions binding on the Data Fiduciary. | Compliant | — | Low | — | Meera Iyer | |
| Section 28 | Procedure to be followed by the Board Be able to produce a complete, coherent evidence package on demand during an inquiry — the Board functions as a digital office and expects documentary responsiveness. | In progress | — | Medium | — | Priya Nair | |
| The Schedule | Monetary penalties Understand and track exposure: ₹250 crore for security safeguard failure, ₹200 crore for breach notification failure and for children's data obligations, ₹150 crore for SDF obligations, ₹50 crore for other breaches, ₹10,000 for Data Principal duty breaches. | Compliant | — | Low | ₹250 Cr | Vikram Saxena | |
| Rule 3 | Notice given by the Data Fiduciary The notice must be presented independently of any other information, in clear and plain language, and give a fair account of the data and purposes, the means to withdraw consent and exercise rights, and how to complain to the Board. | Compliant | 2 | Low | — | Meera Iyer | |
| Rule 4 | Registration and obligations of Consent Managers Where a Consent Manager is used, it must be registered with the Board and meet the prescribed conditions. Consent records must be maintained and made available to the Data Principal. | Compliant | — | Low | — | Priya Nair | |
| Rule 5 | Processing for State subsidy, benefit, service, certificate, licence or permit Where the State or its instrumentality processes personal data to provide a subsidy, benefit, service, certificate, licence or permit, follow the prescribed standards for lawful, transparent and accountable processing and data minimisation. | Compliant | — | Low | — | Vikram Saxena | |
| Rule 6 | Reasonable security safeguards At minimum: encryption, obfuscation, masking or virtual tokens; access control; logs and monitoring retained for the prescribed period to detect unauthorised access; measures for continued processing after a compromise; and contractual security obligations on Data Processors. | Partially compliant | 4 | Medium | — | Meera Iyer | |
| Rule 7 | Intimation of a personal data breach Notify each affected Data Principal without delay, in plain language, with the nature, extent and timing of the breach, the likely consequences, mitigation measures and contact details. Notify the Board without delay, and give a detailed report within 72 hours of becoming aware. | Compliant | — | Low | ₹200 Cr | Priya Nair | |
| Rule 8 | Erasure and retention periods Specified classes of Data Fiduciary must erase personal data once the prescribed period elapses without the Data Principal approaching them, and must give advance intimation before erasure. Maintain logs of personal data and processing for the prescribed period. | Gap | 1 | High | — | Vikram Saxena | |
| Rule 9 | Contact information for questions about processing Prominently display, on the website or app and in every notice, the contact details of the Data Protection Officer or the person able to answer questions about processing. | Partially compliant | 1 | Medium | — | Meera Iyer | |
| Rule 10 | Verifiable consent for children and persons with disability Adopt appropriate technical and organisational measures to verify that the person giving consent is an identifiable adult who is the parent or lawful guardian — including reliance on reliable identity details already held, or a virtual token mapped to a verified identity issued by an entitled entity. | Gap | 1 | Critical | ₹200 Cr | Priya Nair | |
| Rule 11 | Exemptions for certain classes processing children's data Where relying on an exemption from the children's data obligations — healthcare, educational institutions, childcare, and processing restricted to specified purposes — record the class relied on and keep processing within the permitted limits. | Not applicable | — | Informational | — | Vikram Saxena | |
| Rule 12 | Additional obligations of a Significant Data Fiduciary Undertake a Data Protection Impact Assessment and an audit at least once every twelve months and report the significant observations to the Board. Verify that algorithmic software used for processing does not pose a risk to Data Principals' rights. Observe restrictions on transferring specified personal data outside India. | Gap | 2 | Critical | ₹150 Cr | Meera Iyer | |
| Rule 13 | Rights of Data Principals Publish on the website or app the means by which a Data Principal may make a request, and the particulars required to identify them. Publish the period within which a grievance will be responded to, and implement technical and organisational measures to meet it. | Partially compliant | 1 | Medium | — | Priya Nair | |
| Rule 14 | Processing of personal data outside India Where personal data is processed within India, or outside India in connection with offering goods or services to Data Principals in India, comply with any requirements the Central Government specifies for making that data available to a foreign State or its instrumentality. | Gap | 1 | High | — | Vikram Saxena | |
| Rule 15 | Research, archiving and statistical purposes Processing for research, archiving or statistical purposes is exempt only where carried out in accordance with the prescribed standards. Record the standards applied. | Not applicable | — | Informational | — | Meera Iyer | |
| Rule 22 | Calling for information The Central Government may require a Data Fiduciary or intermediary to furnish specified information for the purposes set out in the Rules. Be able to respond completely and within time. | Compliant | — | Low | — | Priya Nair |
The register is data, not code. Where the numbering of a Rule is contested, the clause record carries a note and can be corrected without any change to the product. Verify citations against the published Gazette before relying on this register in a regulatory submission.