4

Compliance Register

Every operative obligation in the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, with the organisation's assessed position against each. This register is the denominator of the readiness score.

DischargesS.28
Compliant
16
Partially compliant
9
In progress
1
Gap
9
Not assessed
0
Not applicable
3
By instrument

Weighted score and assessment coverage.

DPDP Act, 2023
56%

23 of 23 assessed

DPDP Rules, 2025
50%

14 of 14 assessed

Schedule
100%

1 of 1 assessed

By obligation area

Sorted weakest first — this is the work queue.

Cross-border transfer
0%
Children's data
0%
Retention & erasure
25%
Governance
36%
Security safeguards
50%
Data Principal rights
63%
Accountability
71%
Consent
83%
Lawful basis
83%
Notice
100%
Breach response
100%

38 obligations

Click any clause to see what it requires, which module discharges it, and the evidence behind its status.

Section 4
Grounds for processing personal data
Process personal data only for a lawful purpose, and only either with the Data Principal's consent or for a certain legitimate use. Every processing activity must be traceable to one of those two grounds.
Partially compliant2MediumMeera Iyer
Section 5
Notice
Serve an itemised notice — before or at the time of seeking consent — describing the personal data sought, the purpose, how rights may be exercised, and how to complain to the Board. Offer it in English or any Eighth Schedule language, at the Data Principal's option.
Compliant2LowPriya Nair
Section 6
Consent
Consent must be free, specific, informed, unconditional and unambiguous, given by clear affirmative action, and limited to data necessary for the specified purpose. Withdrawal must be as easy as giving it, and must stop processing within a reasonable time.
Partially compliant2MediumVikram Saxena
Section 6(7)–(9)
Consent Managers
Where a Data Principal gives, manages, reviews or withdraws consent through a registered Consent Manager, the platform must interoperate with it and remain accountable to the Data Principal.
CompliantLowMeera Iyer
Section 7
Certain legitimate uses
Where processing rests on legitimate use rather than consent — voluntary provision, State subsidy or service, legal obligation, medical emergency, employment purposes — record which limb is relied on and why it fits.
CompliantLowPriya Nair
Section 8(1)–(2)
Accountability, including through a Processor
The Data Fiduciary remains responsible for compliance even where processing is carried out by a Data Processor on its behalf, and may engage one only under a valid contract.
Gap1HighVikram Saxena
Section 8(3)
Accuracy and completeness
Ensure personal data is complete, accurate and consistent where it is used to make a decision affecting the Data Principal, or is disclosed to another Data Fiduciary.
CompliantLowMeera Iyer
Section 8(4)–(5)
Reasonable security safeguards
Implement appropriate technical and organisational measures, and reasonable security safeguards to prevent a personal data breach. Failure here carries the highest penalty in the Schedule.
Partially compliant3Medium₹250 CrPriya Nair
Section 8(6)
Breach intimation
On becoming aware of a personal data breach, intimate the Board and each affected Data Principal, in the form and manner prescribed.
CompliantLow₹200 CrVikram Saxena
Section 8(7)–(8)
Erasure on withdrawal or purpose fulfilment
Erase personal data — and cause your Processor to erase it — once the Data Principal withdraws consent or the specified purpose is no longer being served, unless retention is required by law.
Partially compliant2MediumMeera Iyer
Section 8(9)
Publish contact for the DPO or responsible person
Publish the business contact information of the Data Protection Officer, or of a person able to answer questions about processing on the Data Fiduciary's behalf.
Compliant1LowPriya Nair
Section 8(10)
Grievance redressal mechanism
Establish an effective mechanism to redress the grievances of Data Principals, and make it readily available.
Partially compliant1Medium₹50 CrVikram Saxena
Section 9
Personal data of children
Obtain verifiable consent of a parent or lawful guardian before processing a child's personal data. Do not undertake tracking, behavioural monitoring or targeted advertising directed at children, or any processing likely to cause detrimental effect on a child's well-being.
Gap1Critical₹200 CrMeera Iyer
Section 10
Additional obligations of a Significant Data Fiduciary
If notified as an SDF: appoint a Data Protection Officer based in India who reports to the board, appoint an independent data auditor, and undertake periodic Data Protection Impact Assessment, periodic audit, and other prescribed measures including algorithmic due diligence.
Gap2Critical₹150 CrPriya Nair
Section 11
Right to access information about personal data
On request, provide a summary of the personal data being processed and the processing activities, plus the identities of other Data Fiduciaries with whom it has been shared and what was shared.
CompliantLowVikram Saxena
Section 12
Right to correction, completion, updating and erasure
Correct inaccurate or misleading data, complete incomplete data, update it, and erase it on request unless retention is necessary for the specified purpose or required by law.
CompliantLowMeera Iyer
Section 13
Right of grievance redressal
Provide a readily available means of grievance redressal in respect of any act or omission regarding performance of obligations, and respond within the prescribed period. The Data Principal must exhaust this before approaching the Board.
Partially compliant1MediumPriya Nair
Section 14
Right to nominate
Allow a Data Principal to nominate another individual to exercise their rights in the event of death or incapacity.
Gap1HighVikram Saxena
Section 15
Duties of the Data Principal
Data Principals must not impersonate another person, suppress material information, register false or frivolous grievances, or furnish anything but verifiably authentic information. Surface these duties and flag abusive requests rather than silently rejecting them.
CompliantLowMeera Iyer
Section 16
Processing of personal data outside India
Transfer of personal data outside India is permitted except to a country restricted by Central Government notification. Sectoral laws providing higher protection continue to apply.
Gap2HighPriya Nair
Section 17
Exemptions
Record and justify reliance on any exemption — enforcement of legal rights, judicial or regulatory functions, prevention and investigation of offences, approved corporate schemes, research and statistics — rather than assuming it.
Not applicableInformationalVikram Saxena
Section 27
Powers and functions of the Board
On a breach intimation or complaint, the Board may inquire and impose penalties, direct remedial or mitigation measures, and issue directions binding on the Data Fiduciary.
CompliantLowMeera Iyer
Section 28
Procedure to be followed by the Board
Be able to produce a complete, coherent evidence package on demand during an inquiry — the Board functions as a digital office and expects documentary responsiveness.
In progressMediumPriya Nair
The Schedule
Monetary penalties
Understand and track exposure: ₹250 crore for security safeguard failure, ₹200 crore for breach notification failure and for children's data obligations, ₹150 crore for SDF obligations, ₹50 crore for other breaches, ₹10,000 for Data Principal duty breaches.
CompliantLow₹250 CrVikram Saxena
Rule 3
Notice given by the Data Fiduciary
The notice must be presented independently of any other information, in clear and plain language, and give a fair account of the data and purposes, the means to withdraw consent and exercise rights, and how to complain to the Board.
Compliant2LowMeera Iyer
Rule 4
Registration and obligations of Consent Managers
Where a Consent Manager is used, it must be registered with the Board and meet the prescribed conditions. Consent records must be maintained and made available to the Data Principal.
CompliantLowPriya Nair
Rule 5
Processing for State subsidy, benefit, service, certificate, licence or permit
Where the State or its instrumentality processes personal data to provide a subsidy, benefit, service, certificate, licence or permit, follow the prescribed standards for lawful, transparent and accountable processing and data minimisation.
CompliantLowVikram Saxena
Rule 6
Reasonable security safeguards
At minimum: encryption, obfuscation, masking or virtual tokens; access control; logs and monitoring retained for the prescribed period to detect unauthorised access; measures for continued processing after a compromise; and contractual security obligations on Data Processors.
Partially compliant4MediumMeera Iyer
Rule 7
Intimation of a personal data breach
Notify each affected Data Principal without delay, in plain language, with the nature, extent and timing of the breach, the likely consequences, mitigation measures and contact details. Notify the Board without delay, and give a detailed report within 72 hours of becoming aware.
CompliantLow₹200 CrPriya Nair
Rule 8
Erasure and retention periods
Specified classes of Data Fiduciary must erase personal data once the prescribed period elapses without the Data Principal approaching them, and must give advance intimation before erasure. Maintain logs of personal data and processing for the prescribed period.
Gap1HighVikram Saxena
Rule 9
Contact information for questions about processing
Prominently display, on the website or app and in every notice, the contact details of the Data Protection Officer or the person able to answer questions about processing.
Partially compliant1MediumMeera Iyer
Rule 10
Verifiable consent for children and persons with disability
Adopt appropriate technical and organisational measures to verify that the person giving consent is an identifiable adult who is the parent or lawful guardian — including reliance on reliable identity details already held, or a virtual token mapped to a verified identity issued by an entitled entity.
Gap1Critical₹200 CrPriya Nair
Rule 11
Exemptions for certain classes processing children's data
Where relying on an exemption from the children's data obligations — healthcare, educational institutions, childcare, and processing restricted to specified purposes — record the class relied on and keep processing within the permitted limits.
Not applicableInformationalVikram Saxena
Rule 12
Additional obligations of a Significant Data Fiduciary
Undertake a Data Protection Impact Assessment and an audit at least once every twelve months and report the significant observations to the Board. Verify that algorithmic software used for processing does not pose a risk to Data Principals' rights. Observe restrictions on transferring specified personal data outside India.
Gap2Critical₹150 CrMeera Iyer
Rule 13
Rights of Data Principals
Publish on the website or app the means by which a Data Principal may make a request, and the particulars required to identify them. Publish the period within which a grievance will be responded to, and implement technical and organisational measures to meet it.
Partially compliant1MediumPriya Nair
Rule 14
Processing of personal data outside India
Where personal data is processed within India, or outside India in connection with offering goods or services to Data Principals in India, comply with any requirements the Central Government specifies for making that data available to a foreign State or its instrumentality.
Gap1HighVikram Saxena
Rule 15
Research, archiving and statistical purposes
Processing for research, archiving or statistical purposes is exempt only where carried out in accordance with the prescribed standards. Record the standards applied.
Not applicableInformationalMeera Iyer
Rule 22
Calling for information
The Central Government may require a Data Fiduciary or intermediary to furnish specified information for the purposes set out in the Rules. Be able to respond completely and within time.
CompliantLowPriya Nair

The register is data, not code. Where the numbering of a Rule is contested, the clause record carries a note and can be corrected without any change to the product. Verify citations against the published Gazette before relying on this register in a regulatory submission.