Understand data protection

Other language: हिंदी

Read the Act

The examples and explanations below are original study material, separate from statutory text. Read the relevant provision's commencement information separately.

Which data and people does DPDP cover?

Section 3 covers digital personal data processed in India, including information collected on paper and digitised later. It also covers processing outside India connected with offering goods or services to Data Principals within India. A foreign website is not automatically outside the scheme, and a paper record is not automatically covered before digitisation. Check the relevant provision's effective date before treating this scope as operational.

A Data Principal is the individual to whom the personal data relates. A Data Fiduciary determines the purpose and means of processing; a Data Processor processes on its behalf. These describe roles, not product labels. A fictional shop choosing why and how to use customer details is different from a supplier merely processing those details for the shop.

Section 3 excludes an individual's personal or domestic processing and specified publicly available data. Public availability is qualified: the Data Principal made it public, or another person had a legal obligation to do so. A leaked file is not automatically exempt merely because it can be found online. Section 17 contains separate, conditional exemptions; do not assume that every startup, researcher or public authority is exempt.

Access, correction and privacy grievances

Section 11 describes access to a summary of personal data and processing activities, and information about specified sharing, from the Data Fiduciary to whom consent was previously given, including section 7(a). It is not an unrestricted right to every internal document. Section 11(2) limits the sharing-information provisions where its specific conditions for a lawful written request concerning offences or cyber incidents are met.

Correction and erasure are different requests. Under section 12, inaccurate or misleading data can be corrected, incomplete data completed, and data updated. Erasure is not unconditional: retention may remain necessary for the specified purpose or compliance with law. In a fictional account, correcting an old address does not mean every invoice must also disappear. Use verifiably authentic information; section 15 also prohibits impersonation and false or frivolous grievances.

Section 13 requires exhausting the opportunity for grievance redressal with the Data Fiduciary or Consent Manager before approaching the Board. It does not make Banaka a complaint portal. Section 14 separately allows nomination of another individual to exercise rights on death or defined incapacity; it is not general authority over a person's account. Sections 11–15 have a notified effective date of 13 May 2027 in the reader's commencement source. These explanations describe the statutory scheme, not a claim that those remedies are already available under these sections before that date. Check the current notification and applicable procedure before acting.

Children's data needs distinct safeguards

The Act defines a child as an individual under eighteen. Section 9(1) requires verifiable parental consent before processing a child's data, in the prescribed manner. It separately addresses a person with disability who has a lawful guardian; it does not mean every person with a disability lacks capacity. Rules 10 and 11 describe the relevant verification processes. Read their notified dates before relying on the procedure.

Parental consent does not remove every restriction. Section 9(2) prohibits processing likely to harm a child's well-being, and section 9(3) addresses tracking, behavioural monitoring and targeted advertising directed at children. A fictional learning app cannot treat a parent's consent as a blanket approval for unrelated advertising surveillance.

Exemptions are specific, not automatic. Section 9(4), Rule 12 and the Fourth Schedule identify classes, purposes and conditions; section 9(5) separately permits a notified age-related exemption for verifiably safe processing. Read the exact row and condition rather than assuming every educational or health app qualifies. The reader keeps both parts of the schedule's table intact.

Business duties, processors and breaches

Section 8 makes a Data Fiduciary responsible for processing by it or on its behalf, notwithstanding a contrary agreement or a Data Principal's failure to perform duties. Using a processor does not transfer all responsibility away. Section 8(2) requires a valid contract for the specified processor engagement; sections 8(4) and (5) address organisational measures and reasonable security safeguards.

Section 8(6) describes breach intimation to the Board and each affected Data Principal in the prescribed form and manner. Rule 7 distinguishes prompt intimation from the additional information to the Board within seventy-two hours, or a longer period the Board permits on written request. Do not simplify it to 'wait seventy-two hours before telling anyone'. These provisions have phased commencement; this is preparation guidance, not a claim that every DPDP breach procedure is already operative.

Retention and deletion require context: section 8(7) preserves retention required by law, and Rule 8 specifies relevant periods and safeguards. Significant Data Fiduciaries have additional duties under section 10 after government notification, including an India-based Data Protection Officer and independent data auditor. Not every small business automatically needs that statutory designation. Banaka offers reading material, not a compliance certificate or breach-report submission service.

Enacted does not mean every provision is in force

The November 2025 notification uses three phases: immediate provisions, specified provisions after one year, and the remainder listed for eighteen months. The reader records 13 November 2025, 13 November 2026 and 13 May 2027 for the relevant scopes. Rules have their own Rule 1 dates. Do not treat the Act's assent date as the start of all rights, duties or Rules.

Sections 6, 27 and 44 have mixed subsection dates. For example, section 6(9) is scheduled for 13 November 2026 while most of section 6 is scheduled for 13 May 2027. Section 44(3)'s RTI amendment has a different date from section 44(2)'s IT Act change. Read the exact scope and notice rather than relying on a single 'active Act' badge. A nightly static build can advance known dates; it cannot discover new notifications automatically.

English Rules include the December 2025 corrigendum. Hindi Rules reproduce the complete original Gazette text with separate February 2026 corrigendum records, because some cited pages/phrases do not match the Hindi original. In particular, Rule 23's period wording differs from corrected English; consult the linked official editions before acting. Educational Hindi explanations are not statutory translations, and neither Banaka reader is a certified consolidated edition.

Study check

Check your understanding

Choose an answer, then check it. Scoring stays in your browser and every explanation links to the statutory text.

  1. 1.Can paper-collected data enter section 3's scope after digitisation?
  2. 2.Who determines processing purposes and means?
  3. 3.Is every online leak excluded as publicly available data?
  4. 4.Must the section 5 notice describe the purpose for processing?
  5. 5.Does withdrawing consent automatically make earlier processing unlawful?
  6. 6.Can consent cover unnecessary personal data merely because permission was requested?
  7. 7.Must every record be erased whenever section 12 erasure is requested?
  8. 8.What step does section 13 require before approaching the Board?
  9. 9.When does section 14 describe a nominee exercising the Data Principal's rights?
  10. 10.What is the Act's default definition of a child?
  11. 11.Does parental consent automatically remove the child-well-being restriction?
  12. 12.Should an exemption be checked against its exact conditions?
  13. 13.Does outsourcing processing remove the Data Fiduciary's section 8 responsibility?
  14. 14.Does section 8(6) mention only the Board for breach intimation?
  15. 15.Is every business automatically a Significant Data Fiduciary?
  16. 16.Does section 1 allow different commencement dates for different provisions?
  17. 17.Should section 6(9)'s date be assumed to apply to all of section 6?
  18. 18.Do both amendments in section 44 have to share one start date?

Educational reference, not personal legal advice or a certified edition. Check official text, applicable rules and the relevant provision's commencement information before relying on a remedy.