Does Digital Personal Data Protection Act 2023 (DPDP) require Data Governance?
India • phased enforcement
Yes — 1 provision
Requirements at a glance
This regulation imposes 7 specific requirements for Data Governance across 1 provision:
- Lawful basis — When commenced, processing must be for a lawful purpose on consent or one of the certain legitimate uses in section 7, subject to the Act's scope and exemptions (section 4)
- Purpose limitation — For consent-based processing, consent is specific and informed and signifies agreement to the specified purpose; section 7 separately permits certain legitimate uses (section 6(1))
- Data accuracy — Ensure completeness, accuracy and consistency where processed data is likely to be used for a decision affecting the Data Principal or disclosed to another Data Fiduciary (section 8(3))
- Security safeguards — Implement reasonable security measures to prevent data breach (Section 8)
- Breach notification — Under section 8(6) and Rule 7, notify affected Data Principals and give initial information to the Board without delay; give the Board updated details within 72 hours of awareness, or a longer period the Board allows on written request. Rule 7 is in the eighteen-month phase
- Data minimization — Consent is limited to personal data necessary for the specified purpose (section 6(1))
- Erasure on withdrawal — Unless legally necessary to retain, erase on withdrawal or when it is reasonable to assume the specified purpose is no longer served, whichever is earlier, and cause the processor to erase; applicable Rules retention requirements must also be considered (section 8(7), Rule 8)
Data Governance and Processing Obligations
AI processing can fall within this general data-protection law when section 3 applies. Personal/domestic processing and qualifying publicly available data are excluded by section 3(c); other exemptions are in section 17. The core consent, accuracy, security and breach-notification duties summarized here are in the eighteen-month phase, not already enforcing merely because the Board-related phase began.
Requirements
| Requirement | Details |
|---|---|
| Lawful basis | When commenced, processing must be for a lawful purpose on consent or one of the certain legitimate uses in section 7, subject to the Act's scope and exemptions (section 4) |
| Purpose limitation | For consent-based processing, consent is specific and informed and signifies agreement to the specified purpose; section 7 separately permits certain legitimate uses (section 6(1)) |
| Data accuracy | Ensure completeness, accuracy and consistency where processed data is likely to be used for a decision affecting the Data Principal or disclosed to another Data Fiduciary (section 8(3)) |
| Security safeguards | Implement reasonable security measures to prevent data breach (Section 8) |
| Breach notification | Under section 8(6) and Rule 7, notify affected Data Principals and give initial information to the Board without delay; give the Board updated details within 72 hours of awareness, or a longer period the Board allows on written request. Rule 7 is in the eighteen-month phase |
| Data minimization | Consent is limited to personal data necessary for the specified purpose (section 6(1)) |
| Erasure on withdrawal | Unless legally necessary to retain, erase on withdrawal or when it is reasonable to assume the specified purpose is no longer served, whichever is earlier, and cause the processor to erase; applicable Rules retention requirements must also be considered (section 8(7), Rule 8) |
Penalties
| Violation | Fine |
|---|---|
| Failure to implement security safeguards (section 8(5); core phase) | Up to ₹250 crore under section 33 and Schedule item 1 |
| Failure to notify breach (section 8(6); core phase) | Up to ₹200 crore under section 33 and Schedule item 2 |
| Other breaches, including applicable data-principal rights (core phase) | Up to ₹50 crore under section 33 and Schedule item 7 |