Does Digital Personal Data Protection Act 2023 (DPDP) require Data Governance?

India • phased enforcement

Yes — 1 provision

Requirements at a glance

This regulation imposes 7 specific requirements for Data Governance across 1 provision:

Data Governance and Processing Obligations

Copy link to this provision

Obligation:
Data Governance
pending
Effective:
May 13, 2027
Risk tier:
all
Scope:
Data Fiduciaries processing digital personal data within India, or outside India in connection with offering goods or services to Data Principals within India, subject to section 3 exclusions and section 17 exemptions
sleepercross-domain
AI processing can fall within this general data-protection law when section 3 applies. Personal/domestic processing and qualifying publicly available data are excluded by section 3(c); other exemptions are in section 17. The core consent, accuracy, security and breach-notification duties summarized here are in the eighteen-month phase, not already enforcing merely because the Board-related phase began.

Requirements

RequirementDetails
Lawful basisWhen commenced, processing must be for a lawful purpose on consent or one of the certain legitimate uses in section 7, subject to the Act's scope and exemptions (section 4)
Purpose limitationFor consent-based processing, consent is specific and informed and signifies agreement to the specified purpose; section 7 separately permits certain legitimate uses (section 6(1))
Data accuracyEnsure completeness, accuracy and consistency where processed data is likely to be used for a decision affecting the Data Principal or disclosed to another Data Fiduciary (section 8(3))
Security safeguardsImplement reasonable security measures to prevent data breach (Section 8)
Breach notificationUnder section 8(6) and Rule 7, notify affected Data Principals and give initial information to the Board without delay; give the Board updated details within 72 hours of awareness, or a longer period the Board allows on written request. Rule 7 is in the eighteen-month phase
Data minimizationConsent is limited to personal data necessary for the specified purpose (section 6(1))
Erasure on withdrawalUnless legally necessary to retain, erase on withdrawal or when it is reasonable to assume the specified purpose is no longer served, whichever is earlier, and cause the processor to erase; applicable Rules retention requirements must also be considered (section 8(7), Rule 8)

Penalties

ViolationFine
Failure to implement security safeguards (section 8(5); core phase)Up to ₹250 crore under section 33 and Schedule item 1
Failure to notify breach (section 8(6); core phase)Up to ₹200 crore under section 33 and Schedule item 2
Other breaches, including applicable data-principal rights (core phase)Up to ₹50 crore under section 33 and Schedule item 7
View full regulation View obligation Obligation matrix