India Digital Personal Data Protection Act 2023
India comprehensive data protection law governing processing of digital personal data. Applies to organizations processing data of individuals in India with penalties up to ₹250 crore.
What DPDP Act draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Security Safeguards
Data Fiduciaries MUST implement appropriate technical and organizational measures to protect personal data.
Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.
Breach Notification
Personal data breaches MUST be reported to the Board and affected individuals without delay.
Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.
Data Principal Rights
Organizations MUST provide data principals with access to their personal data and processing information.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
Retention Limitation
Personal data MUST be erased when purpose is achieved or upon data principal request. Logs retained for 180 days minimum.
Retention obligations are easy to state and expensive to meet, because the cost is in keeping the record queryable rather than merely stored. Audit events land in columnar storage on immutable object storage, so a multi-year window costs object-storage prices and is still searchable in seconds when an examiner asks for a sample. Each record carries a verification hash, so what you produce years later is demonstrably what was written at the time.
What DPDP Act covers
s. 2(n) and s. 3
Digital personal data — data about an identifiable individual, in digital form or digitised afterwards.
In scope
- Any data about an individual identifiable by or in relation to it
- Non-digital data subsequently digitised
What falls outside
Personal data made publicly available by the individual, or by anyone under a legal obligation to publish it.
The Act defines NO sensitive or critical category at all. That is a deliberate departure from the 2011 SPDI Rules it replaces, and it is the single most useful fact about its scope: obligations attach uniformly, so a programme cannot be tiered by data class the way an Indian programme built before 2023 will have been.
Ministry of Electronics and IT — DPDP · as at 2026-08
How DPDP Act is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The Data Protection Board of India, with appeal to the Appellate Tribunal.
| Published maximum | Charged | As at |
|---|---|---|
| INR 250 crore | for failing to maintain reasonable security safeguards | 2026-08 |
| INR 200 crore | for failing to notify a breach, and separately for the children provisions | 2026-08 |
| INR 150 crore | for the additional obligations on a significant data fiduciary | 2026-08 |
The Schedule to the Act sets a distinct maximum per obligation: INR 250 crore for security safeguards, INR 200 crore for failing to notify a breach, INR 200 crore for the children provisions, and INR 150 crore for the additional obligations on significant data fiduciaries. Notably, the Act carries no imprisonment at all — the design is civil penalties only.
The Rules were notified in November 2025, but the substantive compliance obligations take effect on 13 May 2027, and enforcement begins then with no grace period.
Uncapped exposure that sits outside this instrument
These come from company law rather than from DPDP Act, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Duty of oversight
Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.
Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.
Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.
This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.
In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for DPDP Act,
not configured for it afterwards
India Personal Data Monitoring
Track access to Aadhaar, PAN, and Indian personal data
DPDP Compliance Report
180-day minimum retention with security safeguard evidence
Indian PII Patterns
Detect Aadhaar numbers, PAN, and Indian identifiers
Breach Detection for DPDP
Real-time detection for rapid breach notification
Other Data Privacy frameworks
Walk into the DPDP Act audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.