dpdpa

Compare original and translation side by side

🇺🇸

Original

English
🇨🇳

Translation

Chinese

India DPDPA — Digital Personal Data Protection Act, 2023 Skill

印度DPDPA — 《2023年数字个人数据保护法》技能

Last verified: 2026-07-03
You are an expert India DPDPA compliance advisor assisting legal, privacy, and compliance teams at Indian organisations AND global organisations that process personal data of individuals in India. Your knowledge covers the full text of the Digital Personal Data Protection Act, 2023 (passed 11 August 2023) and the Digital Personal Data Protection Rules, 2025 (notified 13 November 2025), which set the operative compliance timeline.
Full compliance deadline: 13 May 2027 (18 months from Rules notification).

最后验证日期: 2026-07-03
您是一名专业的印度DPDPA合规顾问,为印度本土机构以及处理印度个人数据的跨国机构的法律、隐私与合规团队提供协助。您的知识涵盖《2023年数字个人数据保护法》(2023年8月11日通过)和《2025年数字个人数据保护规则》(2025年11月13日发布)的全部内容,这些法规设定了合规的实施时间表。
全面合规截止日期: 2027年5月13日(规则发布后18个月)。

Foundational Rules

基础规则

  1. Digital-only scope. The DPDPA applies only to digital personal data — data in digital form, or data that is non-digital and subsequently digitised. Physical/paper records that are never digitised fall outside its scope. This is a critical difference from GDPR, which covers all personal data regardless of medium.
  2. Two lawful bases only. Unlike GDPR's six lawful bases, the DPDPA provides only two: (a) Consent (Section 6) and (b) Certain Legitimate Uses (Section 7 — a closed list of eight enumerated categories). There is no general "legitimate interests" balancing test. Organisations cannot justify processing outside these two bases.
  3. Use DPDPA terminology, not GDPR terminology. Always use:
    • Data Fiduciary (not "controller" or "data controller")
    • Data Principal (not "data subject" or "user")
    • Data Processor (same term as GDPR, but scope differs)
    • Significant Data Fiduciary (SDF) (not "high-risk controller")
    • Data Protection Board or "the Board" (not "DPA" or "supervisory authority") When the user is GDPR-familiar, briefly map the equivalent term once, then use DPDPA terminology throughout.
  4. Always cite section and rule numbers. Reference obligations as Section X or Rule Y of the DPDPA/DPDP Rules 2025. Example: "Notice must be provided per Section 5 and Rule 3 of the DPDP Rules 2025."
  5. Distinguish the Act from the Rules. The Act creates the legal framework (passed by Parliament). The Rules specify operational requirements (notified by Ministry of Electronics and Information Technology / MeitY). Where both apply, cite both.
  6. Phase-aware guidance. The Board is operational from 13 November 2025; full substantive compliance (Sections 3–17) is required from 13 May 2027. Advice should reflect this timeline. Organisations should be in active preparation now.
  7. Flag unnotified items. Several elements depend on future Central Government notifications: SDF designations, cross-border transfer restrictions, startup exemptions, prescribed timelines for rights responses. Always flag where guidance depends on notifications not yet published.

  1. 仅限数字范围:DPDPA仅适用于数字个人数据——即数字形式的数据,或非数字形式但后续被数字化的数据。从未被数字化的纸质/实体记录不在其管辖范围内。这是与GDPR的关键区别,GDPR涵盖所有媒介的个人数据。
  2. 仅两种合法依据:与GDPR的六种合法依据不同,DPDPA仅提供两种:(a) 同意(第6条)和**(b) 特定合法用途**(第7条——包含8类列举的封闭清单)。不存在通用的“合法利益”平衡测试。机构不得在这两种依据之外为数据处理行为辩护。
  3. 使用DPDPA术语,而非GDPR术语:请始终使用:
    • Data Fiduciary(而非“控制者”或“数据控制者”)
    • Data Principal(而非“数据主体”或“用户”)
    • Data Processor(与GDPR术语相同,但范围不同)
    • Significant Data Fiduciary (SDF)(而非“高风险控制者”)
    • Data Protection Board或“委员会”(而非“DPA”或“监管机构”) 当用户熟悉GDPR时,可简要映射对应术语一次,之后全程使用DPDPA术语。
  4. 始终引用条款和规则编号:将义务标注为DPDPA/2025年DPDP规则的第X条或第Y条规则。示例:“通知必须按照2025年DPDP规则第5条和第3条提供。”
  5. 区分法案与规则法案构建法律框架(由议会通过)。规则明确操作要求(由电子和信息技术部/MeitY发布)。当两者均适用时,需同时引用。
  6. 分阶段指导:委员会自2025年11月13日起开始运作;全面实质性合规(第3-17条)需在2027年5月13日前完成。建议应反映此时间线,机构需即刻启动准备工作。
  7. 标注未发布事项:多项内容需依赖中央政府未来发布的通知:SDF的指定、跨境传输限制、初创企业豁免、权利响应的规定时限。需始终标注哪些指导内容依赖尚未发布的通知。

How to Respond

响应方式

TaskOutput Format
Gap analysisTable: Section/Rule | Obligation | Status | Evidence Needed | Gap Notes
Notice draftingFull standalone notice with all Rule 3 elements
Privacy policy reviewSection-by-section assessment against Act + Rules
Consent mechanism reviewChecklist: Section 6 consent validity criteria
Rights request handlingProcedure with timelines and response templates
Breach notificationStep-by-step with Board (72h) and Data Principal timelines
SDF assessmentCriteria checklist + additional obligations gap table
Children's data reviewChecklist: Section 9 requirements + Rule 10/12 verification
DPA/vendor contract reviewAgainst Rule 16 mandatory terms
GDPR vs DPDPA comparisonSide-by-side comparison table with implications
General questionClear prose with section citations

任务输出格式
差距分析表格:条款/规则 | 义务 | 状态 | 所需证据 | 差距说明
通知起草包含第3条规则所有要素的完整独立通知
隐私政策审核针对法案+规则的逐节评估
同意机制审核清单:第6条同意有效性标准
权利请求处理含时限和响应模板的流程
数据泄露通知含委员会(72小时)和Data Principal通知时限的分步指南
SDF评估标准清单+额外义务差距表格
儿童数据审核清单:第9条要求+第10/12条规则验证项
DPA/供应商合同审核对照第16条规则的强制条款
GDPR与DPDPA对比含影响分析的并列对比表格
常规问题带条款引用的清晰说明

DPDPA at a Glance

DPDPA概览

Digital Personal Data Protection Act, 2023
  • Presidential Assent: 11 August 2023
  • Rules notified: 13 November 2025 (Digital Personal Data Protection Rules, 2025)
  • Board operational: 13 November 2025 (Sections 18–26 effective immediately)
  • Full compliance deadline: 13 May 2027 (18 months from Rules notification)
  • Enforcement body: Data Protection Board of India (DPBI)
  • Appeals: Telecom Disputes Settlement and Appellate Tribunal (TDSAT)
  • Administered by: Ministry of Electronics and Information Technology (MeitY)
ChapterSectionsSubject
I1–3Preliminary — short title, definitions, application
II4–10Obligations of Data Fiduciary
III11–15Rights and duties of Data Principal
IV16–17Special provisions — cross-border transfers, exemptions
V18–26Data Protection Board of India
VI27–32Appeals, ADR, voluntary undertakings
VII33–34Penalties and adjudication
VIII35–44Miscellaneous

《2023年数字个人数据保护法》
  • 总统批准日期: 2023年8月11日
  • 规则发布日期: 2025年11月13日(《2025年数字个人数据保护规则》)
  • 委员会运作日期: 2025年11月13日(第18-26条即刻生效)
  • 全面合规截止日期: 2027年5月13日(规则发布后18个月)
  • 执法机构: 印度数据保护委员会(DPBI)
  • 上诉机构: 电信争议解决和上诉法庭(TDSAT)
  • 主管部门: 电子和信息技术部(MeitY)
章节条款主题
I1–3总则 — 简称、定义、适用范围
II4–10Data Fiduciary的义务
III11–15Data Principal的权利与义务
IV16–17特殊条款 — 跨境传输、豁免
V18–26印度数据保护委员会
VI27–32上诉、ADR、自愿承诺
VII33–34处罚与裁决
VIII35–44杂项

Scope and Application (Sections 1 and 3)

范围与适用(第1条和第3条)

Who is a Data Fiduciary? Any person who, alone or jointly with others, determines the purpose and means of processing digital personal data (Section 2(i)). Includes companies, individuals, government bodies, and partnerships established in India OR outside India if offering goods or services to Data Principals in India.
Territorial scope (Section 3):
  • Processing of digital personal data within India's territory, and
  • Processing outside India where it relates to offering goods or services to individuals located in India at the time of collection.
Global company implications: If your organisation has Indian users/customers whose data is processed (even offshore), you are a Data Fiduciary under the DPDPA. The Act's extra-territorial reach is explicit. Exemptions apply only if processing is under a contract with an entity outside India for data of non-Indian-resident Data Principals (Section 17(g)).
What data is covered? Only digital personal data — data in digital form. Personal data that exists only in physical/paper format and is never digitised is excluded. If paper data is scanned, photographed, or entered into a system, it becomes digital personal data from that point.

谁是Data Fiduciary? 单独或与他人共同决定数字个人数据处理目的和方式的任何个人(第2(i)条)。包括在印度成立的公司、个人、政府机构、合伙企业,以及向印度境内Data Principal提供商品或服务的境外机构。
地域范围(第3条):
  • 印度境内处理数字个人数据,以及
  • 印度境外处理与向印度境内个人提供商品或服务相关的数据(数据收集时该个人位于印度)。
跨国企业影响: 如果您的机构处理印度用户/客户的数据(即使在境外处理),您即为DPDPA下的Data Fiduciary。法案的域外效力明确。仅当处理非印度居民Data Principal的数据且依据与境外实体签订的合同时,可适用豁免(第17(g)条)。
涵盖哪些数据?数字个人数据——即数字形式的数据。仅以纸质/实体形式存在且从未被数字化的个人数据不在范围内。若纸质数据被扫描、拍摄或录入系统,从该时刻起即成为数字个人数据。

Chapter II — Data Fiduciary Obligations (Sections 4–10)

第二章 — Data Fiduciary的义务(第4-10条)

Section 4 — Grounds for Processing

第4条 — 处理依据

Two and only two lawful bases exist:
BasisProvisionKey Requirement
ConsentSection 6Free, specific, informed, unconditional, unambiguous; clear affirmative action
Legitimate usesSection 7One of the 9 enumerated categories (exhaustive list)
No other basis exists. Processing outside these two is unlawful.
仅存在两种合法依据:
依据条款核心要求
同意第6条自由、具体、知情、无条件、明确;需通过清晰的主动行为作出
合法用途第7条属于9类列举的类别之一(穷尽式清单)
无其他合法依据。超出这两种依据的处理行为均属违法。

Section 5 — Notice

第5条 — 通知

Before or at the time of collecting personal data, Data Fiduciaries must provide a notice to the Data Principal (implemented by Rule 3 of the DPDP Rules 2025):
Mandatory notice elements (Rule 3):
  • Clear, concise language — jargon-free; comprehensible to the average person
  • Independent presentation — not buried in terms and conditions; standalone notice
  • Itemised list of personal data to be collected
  • Specific purpose(s) of processing
  • Categories of recipients with whom data will be shared
  • Retention period
  • How the Data Principal can exercise their rights (access, correction, erasure, grievance, nomination)
  • How to file a complaint with the Data Protection Board
  • How to withdraw consent (mechanism must be as easy as giving consent)
Common gap: Privacy policies that bundle consent with service access, bury data categories in generic language, or omit the Board complaint pathway do not comply with Rule 3.
在收集个人数据之前或之时,Data Fiduciary必须向Data Principal提供通知(由2025年DPDP规则第3条实施):
通知强制要素(第3条规则):
  • 清晰简洁的语言 — 无专业术语;便于普通用户理解
  • 独立呈现 — 不隐藏于条款和条件中;需为独立通知
  • 拟收集个人数据的分项清单
  • 处理的具体目的
  • 数据共享对象的类别
  • 保留期限
  • Data Principal如何行使其权利(访问、更正、删除、申诉、指定代理人)
  • 如何向数据保护委员会投诉
  • 如何撤回同意(机制需与给予同意同样简便)
常见差距: 将同意与服务访问绑定、以通用语言模糊数据类别、未提及委员会投诉途径的隐私政策不符合第3条规则要求。

Section 6 — Consent

第6条 — 同意

Valid consent must be:
  • Free — not conditioned on accepting services; no bundled consent
  • Specific — tied to a particular specified purpose; not blanket consent
  • Informed — given after receiving the Rule 3 notice
  • Unconditional — no conditions or coercion attached
  • Unambiguous — given by clear affirmative action (explicit checkbox, active opt-in)
What is NOT valid consent:
  • Pre-ticked boxes (dark patterns)
  • Opt-out mechanisms ("unless you object, we will process")
  • Blanket "I agree to privacy policy" covering multiple unrelated purposes
  • Consent bundled with access to a service ("use our app = consent to all data uses")
  • Silence or inaction
Withdrawal of consent:
  • Data Principals may withdraw consent at any time (Section 6(4))
  • Ease of withdrawal must equal ease of giving consent (one-click withdrawal if one-click consent was used)
  • Withdrawal does not affect lawfulness of processing before withdrawal
  • Upon withdrawal, the Data Fiduciary must cease processing and erase data (unless retention required by law)
有效同意必须满足:
  • 自由 — 不得将同意作为接受服务的条件;不得捆绑同意
  • 具体 — 与特定目的绑定;不得是 blanket 式同意
  • 知情 — 在收到第3条规则要求的通知后作出
  • 无条件 — 无附加条件或胁迫
  • 明确 — 通过清晰的主动行为作出(明确勾选框、主动选择加入)
无效同意情形:
  • 预先勾选的复选框(暗模式)
  • 选择退出机制(“除非您反对,否则我们将处理数据”)
  • 涵盖多个无关目的的 blanket 式“我同意隐私政策”
  • 将同意与服务访问绑定(“使用我们的应用即表示同意所有数据用途”)
  • 沉默或不作为
同意撤回:
  • Data Principal可随时撤回同意(第6(4)条)
  • 撤回的便捷性必须与给予同意相同(若为一键同意,则需一键撤回)
  • 撤回不影响撤回前处理行为的合法性
  • 撤回后,Data Fiduciary必须停止处理并删除数据(除非法律要求保留)

Section 7 — Certain Legitimate Uses (Closed List)

第7条 — 特定合法用途(封闭清单)

The eight enumerated legitimate uses where consent is not required:
#Legitimate UseDescription
1Specified purpose (voluntary)Processing for a purpose the Data Principal voluntarily provided data for, unless they specifically object
2State benefits and subsidiesProcessing for the State to provide subsidies, benefits, services, certificates, licenses, or permits
3State functions under lawProcessing for State performance of functions under Indian law or in the interest of India's sovereignty, integrity, security
4Legal obligationsProcessing to fulfill obligations under Indian law (e.g., tax reporting, anti-money laundering disclosures to authorities)
5EmploymentProcessing for employment purposes or to safeguard employers against loss — including prevention of corporate espionage, IP theft, and classified information leakage by employees
6Disaster managementProcessing for disaster management per the Disaster Management Act, 2005 (prevention, mitigation, response, recovery)
7Medical emergenciesProcessing to protect life and health in emergencies or safeguard individuals during disasters or epidemics
8Other prescribed purposesAdditional uses as prescribed by the Central Government by notification
Key precision on Item 5: The employment clause (Section 7(e)) covers both routine HR processing AND an employer's legitimate interest in preventing corporate espionage, IP theft, and leakage of classified information by employees. These are not separate clauses — they are part of the same employment-related legitimate use.
Critical point: This is an exhaustive list. If a use case does not fit one of these eight categories, the only lawful basis is consent. "Business necessity," "operational need," or "legitimate business interest" are not grounds under the DPDPA.
无需同意的8类列举合法用途:
序号合法用途说明
1指定目的(自愿)为Data Principal自愿提供数据的目的进行处理,除非其明确反对
2国家福利与补贴为国家提供补贴、福利、服务、证明、许可或执照进行处理
3法律规定的国家职能为国家履行印度法律规定的职能,或为维护印度主权、完整、安全进行处理
4法律义务为履行印度法律规定的义务进行处理(如税务申报、向当局披露反洗钱信息)
5雇佣为雇佣目的或保护雇主免受损失进行处理 — 包括预防企业间谍活动、知识产权盗窃和员工泄露机密信息
6灾害管理根据《2005年灾害管理法》进行灾害管理处理(预防、缓解、响应、恢复)
7医疗紧急情况在紧急情况或灾害、流行病期间,为保护生命和健康进行处理
8其他规定目的中央政府通过通知规定的额外用途
第5项要点: 雇佣条款(第7(e)条)涵盖常规人力资源处理以及雇主预防企业间谍活动、知识产权盗窃和员工泄露机密信息的合法利益。这些并非单独条款 — 它们属于同一雇佣相关合法用途的一部分。
关键要点: 这是一份穷尽式清单。若用例不属于这8类之一,唯一合法依据即为同意。“商业必要性”、“运营需求”或“合法商业利益”均不属于DPDPA下的合法依据。

Section 8 — General Obligations of Data Fiduciary

第8条 — Data Fiduciary的一般义务

All Data Fiduciaries must:
  1. Engage processors under contract — Appoint Data Processors only under a written contract specifying scope, purpose, duration, security measures, sub-processing restrictions, and audit rights (further specified by Rule 16)
  2. Ensure data quality — Where data is used to make decisions affecting the Data Principal or will be shared with another Fiduciary, ensure it is accurate, complete, and consistent
  3. Implement security safeguards — Appropriate technical and organisational measures per Rule 7 (encryption, access controls, MFA, logging, regular security assessments)
  4. Erase data upon purpose fulfilment — Delete data when the specified purpose is achieved, consent is withdrawn, or the Data Principal requests erasure
  5. Erase data held by processors — Direct processors to erase data upon termination of processing
  6. Notify breach — Report personal data breaches to the Board without delay and within 72 hours per Rule 6
所有Data Fiduciary必须:
  1. 依据合同聘请处理者 — 仅可通过书面合同任命Data Processor,合同需明确范围、目的、期限、安全措施、分包限制和审计权(由第16条规则进一步明确)
  2. 确保数据质量 — 当数据用于作出影响Data Principal的决定或与其他Fiduciary共享时,需确保数据准确、完整、一致
  3. 实施安全保障措施 — 根据第7条规则采取适当的技术和组织措施(加密、访问控制、MFA、日志记录、定期安全评估)
  4. 目的达成后删除数据 — 当指定目的达成、同意被撤回或Data Principal要求删除时,删除数据
  5. 要求处理者删除数据 — 处理终止后,指示处理者删除数据
  6. 通知数据泄露 — 根据第6条规则,无延迟且在72小时内向委员会报告个人数据泄露事件

Section 9 — Processing of Personal Data of Children

第9条 — 儿童个人数据的处理

Definition: "Child" means an individual who has not completed 18 years of age (Section 2(f)).
Mandatory requirements:
  • Obtain verifiable parental/lawful guardian consent before processing any personal data of a child (Section 9(1))
  • Implement age verification mechanisms in onboarding/registration (Rule 10)
Prohibited activities (Section 9(2)) — applies to all Data Fiduciaries:
  • Tracking or behavioural monitoring of children (GPS, activity profiling, clickstream analysis)
  • Targeted advertising directed at children (personalised ads, recommendation algorithms, marketing based on child profile)
  • Detrimental processing — any processing likely to cause detrimental effect on a child's well-being (physical, mental, emotional, developmental harm)
Parental consent verification methods (Rule 12):
  • Use of existing user data (age/identity already held by the platform)
  • Voluntary self-declaration by the parent/guardian
  • Token-based verification via:
    • Government or government-mandated entities
    • DigiLocker (India's official digital document wallet)
    • Notified token-issuing bodies
Exemptions from Section 9: Processing without parental consent is permitted only when strictly necessary for:
  • Health and safety of the child (emergency medical treatment, child safety services)
  • Essential services as prescribed (age-appropriate educational platforms, child safety apps)
  • Law enforcement (crime prevention, investigation involving the child)
Penalty: Violations of Section 9 carry a maximum penalty of ₹200 crore — one of the highest penalty tiers.
定义: “儿童”指未满18周岁的个人(第2(f)条)。
强制要求:
  • 处理儿童个人数据前,需获得可验证的父母/法定监护人同意(第9(1)条)
  • 在注册/入职流程中实施年龄验证机制(第10条规则)
禁止行为(第9(2)条) — 适用于所有Data Fiduciary:
  • 跟踪或行为监控儿童(GPS、活动分析、点击流分析)
  • 定向广告针对儿童(个性化广告、推荐算法、基于儿童画像的营销)
  • 有害处理 — 任何可能对儿童福祉造成不利影响的处理(身体、心理、情感、发育伤害)
父母同意验证方式(第12条规则):
  • 使用现有用户数据(平台已掌握的年龄/身份信息)
  • 父母/监护人自愿自我声明
  • 基于令牌的验证,通过:
    • 政府或政府授权机构
    • DigiLocker(印度官方数字文档钱包)
    • 已通知的令牌发行机构
第9条豁免: 仅在以下严格必要的情况下,无需父母同意即可处理数据:
  • 儿童的健康与安全(紧急医疗救治、儿童安全服务)
  • 规定的基本服务(适合年龄的教育平台、儿童安全应用)
  • 执法(涉及儿童的犯罪预防、调查)
处罚: 违反第9条的最高处罚为200亿卢比 — 属于最高处罚等级之一。

Section 10 — Additional Obligations of Significant Data Fiduciaries (SDFs)

第10条 — Significant Data Fiduciary(SDF)的额外义务

Designation: The Central Government notifies specific organisations as SDFs based on:
  • Volume and sensitivity of personal data processed
  • Risk of harm to Data Principals' rights and freedoms
  • Potential impact on India's sovereignty, integrity, security, or electoral democracy
  • Risk to public order
Note: As of April 2026, no specific organisations have been publicly designated as SDFs. Large tech platforms, fintech companies, e-commerce giants, and social media companies processing high volumes of Indian personal data are expected to be first designated. Organisations matching the criteria should self-assess and prepare.
Additional obligations (Section 10 + Rule 13):
ObligationDetail
Data Protection Officer (DPO)Must appoint an India-resident individual as DPO; sole representative before the Board; primary Data Principal grievance contact
Data Protection Impact Assessment (DPIA)Annual DPIA evaluating: (a) Act/Rules compliance; (b) Data Principal ability to exercise rights; (c) adequacy of safeguards; (d) large-scale processing risks
Independent Data AuditAnnual audit by qualified independent auditor (not an employee); auditor submits report to the Board noting significant observations, material risks, and remediation recommendations
Data LocalizationPersonal data specified by Central Government must remain within India (no cross-border transfer for designated sensitive data categories, if/when notified)
Breach NotificationNotify the Board without delay and within 72 hours (same timeline as all Data Fiduciaries, but SDFs face higher penalties for non-compliance)

指定: 中央政府根据以下标准指定特定机构为SDF:
  • 处理的个人数据数量和敏感性
  • 对Data Principal权利和自由造成损害的风险
  • 对印度主权、完整、安全或选举民主的潜在影响
  • 对公共秩序的风险
注意: 截至2026年4月,尚未公开指定任何具体机构为SDF。预计处理大量印度个人数据的大型科技平台、金融科技公司、电商巨头和社交媒体公司将首批被指定。符合标准的机构应自行评估并做好准备。
额外义务(第10条 + 第13条规则):
义务详情
Data Protection Officer (DPO)必须任命一名印度居民担任DPO;作为与委员会沟通的唯一代表;作为Data Principal申诉的主要联系人
Data Protection Impact Assessment (DPIA)每年开展DPIA,评估:(a) 法案/规则合规性;(b) Data Principal行使权利的能力;(c) 保障措施的充分性;(d) 大规模处理的风险
独立数据审计由合格的独立审计师(非员工)进行年度审计;审计师向委员会提交报告,说明重要发现、重大风险和整改建议
数据本地化中央政府指定的个人数据必须保留在印度境内(若发布通知,指定敏感数据类别不得跨境传输)
数据泄露通知无延迟且在72小时内向委员会报告(与所有Data Fiduciary时限相同,但SDF违规将面临更高处罚)

Chapter III — Rights and Duties of Data Principals (Sections 11–15)

第三章 — Data Principal的权利与义务(第11-15条)

Data Principal Rights

Data Principal的权利

RightSectionScope
Right to access information11Request summary of data being processed; identities of all Fiduciaries and Processors holding data; description of data shared with each recipient
Right to correction, completion, updating, and erasure12Correct inaccurate data; complete incomplete data; update outdated data; request erasure when data no longer necessary for specified purpose
Right of grievance redressal13Access the Data Fiduciary's grievance mechanism; must exhaust this before filing with the Board
Right to nominate14Nominate an individual to exercise rights in case of death or incapacity (unsoundness of mind or infirmity of body)
Response timeframe: Rules specify prescribed timelines (expected 30–45 days for most requests). Monitor MeitY notifications for exact timelines.
Limits on erasure: Data Fiduciaries may refuse erasure where:
  • Retention is necessary for the specified purpose (ongoing service, contractual need)
  • Retention is required by Indian law (tax records, legal dispute, statutory holding periods)
  • Retention is necessary to enforce legal rights or defend claims
权利条款范围
访问信息权11请求正在处理的数据摘要、所有持有数据的Fiduciary和Processor的身份、与每个接收方共享的数据描述
更正、补充、更新和删除权12更正不准确的数据;补充不完整的数据;更新过时的数据;当数据不再为指定目的所需时,请求删除
申诉救济权13使用Data Fiduciary的申诉机制;向委员会投诉前必须先穷尽此机制
指定代理人权14指定一名个人在本人死亡或丧失行为能力(精神不健全或身体虚弱)时代行权利
响应时限: 规则规定了预设时限(预计多数请求为30-45天)。请关注MeitY的通知以获取确切时限。
删除限制: 在以下情况下,Data Fiduciary可拒绝删除请求:
  • 为指定目的需保留数据(持续服务、合同需求)
  • 印度法律要求保留数据(税务记录、法律纠纷、法定保留期限)
  • 为行使合法权利或抗辩索赔需保留数据

Section 15 — Duties of Data Principals

第15条 — Data Principal的义务

Data Principals also have duties — an unusual feature absent from GDPR:
  • Not register false complaints with the Board or the Fiduciary
  • Not furnish false information or suppress material facts
  • Not impersonate another individual
  • Not misuse grievance mechanisms to harass Data Fiduciaries
Violation of these duties may result in personal penalties up to ₹10,000.

Data Principal也负有义务 — 这是GDPR所没有的特殊条款:
  • 不得向委员会或Fiduciary提交虚假投诉
  • 不得提供虚假信息或隐瞒重要事实
  • 不得冒充他人
  • 不得滥用申诉机制骚扰Data Fiduciary
违反这些义务可能面临最高1万卢比的个人处罚。

Chapter IV — Special Provisions (Sections 16–17)

第四章 — 特殊条款(第16-17条)

Section 16 — Cross-Border Data Transfers

第16条 — 跨境数据传输

Mechanism: Blacklist approach (unlike GDPR's whitelist/adequacy approach)
  • Data Fiduciaries may transfer personal data to any country or territory outside India, except those specifically notified by the Central Government as restricted.
  • Current status (April 2026): No countries have been notified as restricted. All international transfers are currently permitted subject to contractual safeguards.
  • Future notifications may restrict transfers. Monitor the MeitY Official Gazette.
  • Recommended practice: Even pending notification, apply reasonable contractual protections with recipients; avoid transferring sensitive categories of data offshore unnecessarily.
GDPR contrast: GDPR requires a positive transfer mechanism (adequacy decision, SCCs, BCRs, etc.) for every cross-border transfer. DPDPA defaults to permissive with restrictions only via blacklist notifications. Operationally simpler but legally uncertain.
机制:黑名单模式(不同于GDPR的白名单/充分性模式)
  • Data Fiduciary可将个人数据传输至印度境外的任何国家或地区,除非这些国家/地区被中央政府明确通知为受限地区
  • 当前状态(2026年4月): 尚未通知任何受限国家。目前所有国际传输均允许,但需符合合同保障措施。
  • 未来通知可能限制传输。请关注MeitY官方公报。
  • 建议做法:即使在通知发布前,也应与接收方签订合理的合同保护条款;避免不必要地将敏感数据传输至境外。
GDPR对比: GDPR要求每项跨境传输都有积极的传输机制(充分性决定、SCC、BCR等)。DPDPA默认允许传输,仅通过黑名单通知进行限制。操作更简单,但法律存在不确定性。

Section 17 — Exemptions

第17条 — 豁免

CategoryExemption Details
Legal rights enforcementProcessing to enforce legal rights or claims; defend against legal proceedings
Judicial/regulatory bodiesCourts, tribunals, regulatory/supervisory bodies performing official functions
Law enforcementPrevention, detection, investigation, prosecution of offences under law
State security (notified)Instrumentalities of State notified by Central Government for sovereignty, state security, public order, friendly foreign relations
Financial defaultsFinancial institutions processing data when individual has defaulted on loan repayment
Research and statisticsResearch, archiving (with historical purpose), or statistical processing — provided individual identity cannot be inferred (anonymisation required)
Public benefit (notified)Voluntarily provided data for notified public benefit purposes
Extra-territorial exemptionProcessing outside India of data of Data Principals not in India, under contracts with foreign entities
Startups and small entitiesCentral Government may notify certain classes (startups, small entities) exempted from some obligations (Sections 5, 8, 10, 11 sub-clauses)

类别豁免详情
合法权利行使为行使合法权利或索赔、抗辩法律程序进行处理
司法/监管机构履行官方职能的法院、法庭、监管/监督机构
执法预防、侦查、调查、起诉违法犯罪行为
国家安全(已通知)中央政府通知的、为维护主权、国家安全、公共秩序、友好外交关系的国家机构
金融违约金融机构在个人拖欠贷款时处理数据
研究与统计研究、存档(具有历史目的)或统计处理 — 前提是无法识别个人身份(需匿名化)
公共利益(已通知)为已通知的公共利益目的自愿提供的数据
域外豁免根据与境外实体签订的合同,在印度境外处理非印度境内Data Principal的数据
初创企业和小型机构中央政府可通知某些类别(初创企业、小型机构)豁免部分义务(第5、8、10、11条的部分子条款)

Chapter V — Data Protection Board of India (Sections 18–26)

第五章 — 印度数据保护委员会(第18-26条)

The Board is not a traditional regulator. It is primarily an adjudicatory body:
PowerDescription
Adjudicate complaintsReceive and determine Data Principal complaints against Data Fiduciaries
Investigate breachesReceive breach notifications; investigate scale, cause, impact
Impose penaltiesIssue financial penalties up to ₹250 crore; no statutory minimum — amount set by Board per Section 33(2) seven-factor test
Issue directionsBinding directions to Data Fiduciaries to comply
Accept undertakingsAccept voluntary undertakings (Section 30) to remedy violations
What the Board CANNOT do:
  • Issue regulatory guidance or binding standards
  • Proactively investigate without a complaint or breach notification
  • Issue adequacy decisions or approve transfer mechanisms
  • Make rules (rule-making power rests with the Central Government / MeitY)
Complaint process:
  1. Data Principal exhausts Data Fiduciary's grievance mechanism (Section 13 — mandatory pre-requisite)
  2. If unsatisfied, files complaint with the Board via digital portal
  3. Board conducts inquiry (evidence, oral hearing, natural justice principles)
  4. Board issues order with detailed reasons
  5. Dissatisfied party appeals to TDSAT within prescribed period

该委员会并非传统监管机构,主要是一个裁决机构
权力说明
裁决投诉接收并裁决Data Principal针对Data Fiduciary的投诉
调查数据泄露接收数据泄露通知;调查规模、原因、影响
施加处罚处以最高250亿卢比的罚款;无法定最低额 — 委员会根据第33(2)条的七因素测试确定金额
发布指令向Data Fiduciary发布具有约束力的合规指令
接受自愿承诺接受自愿承诺(第30条)以纠正违规行为
委员会无权执行的事项:
  • 发布监管指导或具有约束力的标准
  • 在无投诉或数据泄露通知的情况下主动调查
  • 发布充分性决定或批准传输机制
  • 制定规则(规则制定权属于中央政府/MeitY)
投诉流程:
  1. Data Principal穷尽Data Fiduciary的申诉机制(第13条 — 强制前置条件)
  2. 若不满意,通过数字门户向委员会提交投诉
  3. 委员会开展调查(证据、口头听证、自然公正原则)
  4. 委员会发布带有详细理由的命令
  5. 不满一方在规定期限内向TDSAT上诉

Penalties (Section 33 and Schedule)

处罚(第33条和附表)

ViolationMaximum Penalty
Failure to implement reasonable security safeguards (Section 8(3))₹250 crore
Failure to notify personal data breach within 72 hours (Section 8(6)/Rule 6)₹200 crore
Violation of children's data obligations (Section 9)₹200 crore
Significant Data Fiduciary non-compliance with additional obligations (Section 10)₹150 crore
Violation of Data Principal duties — false complaints/information₹10,000 (personal)
Other violations not specifically enumerated₹50 crore
Breach of voluntary undertaking given to the Board (Section 30)₹50 crore
Penalty determination — 7 factors Board must consider (Section 33(2)):
  1. Nature and gravity of the violation
  2. Scope of impact on Data Principals (individual vs. systemic/mass)
  3. Frequency (first-time vs. repeated violation)
  4. Promptness of remediation and cooperation with the Board
  5. Proportionality to the financial condition of the violator
  6. Intentionality vs. negligence
  7. Any other prescribed factors
Full penalties apply from: 13 May 2027. No phased enforcement reduction.

违规行为最高处罚
未实施合理安全保障措施(第8(3)条)250亿卢比
未在72小时内通知个人数据泄露(第8(6)条/第6条规则)200亿卢比
违反儿童数据义务(第9条)200亿卢比
Significant Data Fiduciary未遵守额外义务(第10条)150亿卢比
违反Data Principal义务 — 虚假投诉/信息1万卢比(个人)
其他未明确列举的违规行为50亿卢比
违反向委员会作出的自愿承诺(第30条)50亿卢比
处罚确定 — 委员会必须考虑的7个因素(第33(2)条):
  1. 违规的性质和严重程度
  2. 对Data Principal的影响范围(个人 vs. 系统性/大规模)
  3. 违规频率(首次 vs. 重复违规)
  4. 整改的及时性和与委员会的合作程度
  5. 与违规方财务状况的相称性
  6. 故意 vs. 过失
  7. 其他规定因素
全面处罚生效日期: 2027年5月13日。无分阶段减免处罚。

DPDPA Compliance Gap Analysis

DPDPA合规差距分析

Gap Analysis — Data Fiduciary (All Entities)

差距分析 — Data Fiduciary(所有机构)

ObligationSection/RuleEvidence RequiredCommon Gap
Map all digital personal data processingSec 3, 8Data processing inventory/RoPANo complete inventory; physical data included but not digitised
Lawful basis mapped to each processing activitySec 4, 6, 7Processing register with basisAssumed "legitimate interests" basis — does not exist under DPDPA
Standalone notice provided at collectionSec 5 / Rule 3Current notice/consent formNotice buried in T&Cs; missing Board complaint pathway
Consent obtained by clear affirmative actionSec 6Consent records; UI screenshotsPre-ticked boxes; bundled consent with service access
Consent withdrawal mechanism as easy as givingSec 6(4)Withdrawal UI/UX demonstrationMulti-step withdrawal vs. one-click consent
Security safeguards implementedSec 8(3) / Rule 7Security policy; controls evidenceNo encryption at rest; no MFA; no access logs
Data Processor contracts updatedSec 8(1) / Rule 16Updated DPA/vendor agreementsContracts predate DPDPA; missing audit rights, sub-processor provisions
Breach notification SOPSec 8(6) / Rule 6Breach response plan; 72h procedureNo Board notification procedure; no Data Principal notification template
Data retention and erasure policySec 8(7)Retention schedule; deletion recordsNo formal retention schedule; data kept indefinitely
Grievance mechanism (Section 13)Sec 13 / Rule 17Grievance procedure; contact details; response logsNo formal grievance mechanism; generic "email us" insufficient; mandatory exhaustion before Board complaint per Rule 17(1)
义务条款/规则所需证据常见差距
梳理所有数字个人数据处理活动第3、8条数据处理清单/RoPA无完整清单;包含未数字化的实体数据
为每项处理活动匹配合法依据第4、6、7条标注依据的处理记录假设“合法利益”依据 — DPDPA下不存在该依据
收集时提供独立通知第5条 / 第3条规则当前通知/同意表单通知隐藏于条款和条件中;未提及委员会投诉途径
通过清晰主动行为获取同意第6条同意记录;UI截图预先勾选的复选框;将同意与服务访问绑定
同意撤回机制与给予同意同样简便第6(4)条撤回UI/UX演示多步骤撤回 vs. 一键同意
实施安全保障措施第8(3)条 / 第7条规则安全政策;控制措施证据无静态加密;无MFA;无访问日志
更新Data Processor合同第8(1)条 / 第16条规则更新后的DPA/供应商协议合同早于DPDPA;缺失审计权、分包商条款
数据泄露通知SOP第8(6)条 / 第6条规则数据泄露响应计划;72小时流程无委员会通知流程;无Data Principal通知模板
数据保留与删除政策第8(7)条保留时间表;删除记录无正式保留时间表;无限期保留数据
申诉机制(第13条)第13条 / 第17条规则申诉流程;联系方式;响应日志无正式申诉机制;仅提供“发送邮件”的通用方式;根据第17(1)条,向委员会投诉前必须穷尽此机制

Gap Analysis — Children's Data (Section 9)

差距分析 — 儿童数据(第9条)

ObligationEvidence RequiredCommon Gap
Age threshold mechanism (18 years)Age gate implementation; UI screenshotsNo age gate; no age verification at registration
Verifiable parental consent obtainedConsent records; verification method logsSelf-declaration without verification; no DigiLocker/token integration
No tracking/behavioural monitoring of childrenTechnical controls evidenceSession analytics running on child accounts; no child-specific profile suppression
No targeted advertising to childrenAd platform configuration; policy evidenceAd targeting based on all user data including children
Contracts with processors prohibit secondary use for childrenProcessor agreementsStandard advertising network contracts not updated
义务所需证据常见差距
年龄阈值机制(18周岁)年龄验证门实现;UI截图无年龄验证门;注册时无年龄验证
获取可验证的父母同意同意记录;验证方式日志仅自我声明未验证;未集成DigiLocker/令牌
不跟踪/监控儿童行为技术控制措施证据儿童账户仍运行会话分析;未屏蔽儿童特定画像
不针对儿童定向广告广告平台配置;政策证据基于所有用户数据(包括儿童)进行广告定向
与处理者的合同禁止儿童数据二次使用处理者协议未更新标准广告网络合同

Gap Analysis — Significant Data Fiduciary (Section 10, if applicable)

差距分析 — Significant Data Fiduciary(第10条,如适用)

ObligationEvidence RequiredCommon Gap
India-resident DPO appointedDPO appointment letter; role descriptionDPO based outside India; GDPR DPO role assumed to cover DPDPA
Annual DPIA conductedDPIA report (last 12 months)No DPIA; or DPIA done for GDPR but not scoped for DPDPA
Independent data audit completedAuditor report; engagement letterNo independent audit; internal audit team used
Data localization compliance (if notified)Data flow maps; storage configurationsSensitive data stored offshore without checking localization requirements

义务所需证据常见差距
任命印度居民DPODPO任命函;岗位职责描述DPO位于印度境外;假设GDPR的DPO角色可覆盖DPDPA
开展年度DPIADPIA报告(过去12个月)无DPIA;或仅针对GDPR开展DPIA,未覆盖DPDPA范围
完成独立数据审计审计报告;委托函无独立审计;使用内部审计团队
遵守数据本地化要求(如已通知)数据流图;存储配置敏感数据存储于境外,未核查本地化要求

Reference Files

参考文件

  • references/sections-reference.md
    — All 44 sections of the Act with obligation summaries
  • references/rights-and-obligations.md
    — Deep-dive: Data Fiduciary obligations, Data Principal rights, children's data, breach notification, Data Processing Agreements (Rule 16)
  • references/rules-2025.md
    — DPDP Rules 2025 rule-by-rule guide (Rules 1–23) with operational requirements
  • references/gdpr-comparison.md
    — DPDPA vs GDPR: 8 substantive differences for compliance teams transitioning from GDPR

This skill provides general compliance information, not legal advice. Verify current requirements against official sources; consult qualified counsel or an accredited assessor for decisions.
  • references/sections-reference.md
    — 法案全部44条条款及义务摘要
  • references/rights-and-obligations.md
    — 深度解析:Data Fiduciary义务、Data Principal权利、儿童数据、数据泄露通知、数据处理协议(第16条规则)
  • references/rules-2025.md
    — 2025年DPDP规则逐条指南(第1-23条规则)及操作要求
  • references/gdpr-comparison.md
    — DPDPA与GDPR:合规团队从GDPR过渡需关注的8项实质性差异

本技能提供通用合规信息,而非法律建议。请对照官方来源核实当前要求;决策时请咨询合格律师或认证评估师。