← Frameworks / Privacy Regulation

Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025

India's law on the processing of digital personal data. It sets the grounds for processing (consent and certain legitimate uses), what a notice and a request for consent must contain, and the obligations of a Data Fiduciary: reasonable security safeguards, intimation of a breach to the Data Protection Board of India and to each affected Data Principal, erasure, and a grievance mechanism. Data Principals have rights of access, correction, erasure and nomination. Significant Data Fiduciaries and Consent Managers carry further obligations. The 2025 Rules set the minimum safeguards, a detailed breach report within seventy-two hours, retention and erasure periods, and how consent for a child is verified.

When it applies

Rule 1(2) to (4) of the Rules and G.S.R. 843(E), 13 November 2025, which brings the Act into force.

From 13 November 2025

Section 1(2), section 2, sections 18 to 26, sections 35 and 38 to 43, and section 44(1) and (3).

Rules 1, 2 and 17 to 21.

From 13 November 2026

Section 6(9) and section 27(1)(d).

Rule 4.

From 13 May 2027

Sections 3 to 5, section 6(1) to (8) and (10), sections 7 to 17, section 27 except (1)(d), sections 28 to 34, 36 and 37, and section 44(2).

Rules 3, 5 to 16, 22 and 23.

Rule 4(3) gives the Consent Manager the obligations in Part B of the First Schedule from 13 November 2026, while section 6(8), which says the Consent Manager acts on the Data Principal's behalf subject to the prescribed obligations, comes into force on 13 May 2027. This mapping does not settle which date governs Rules.Sch1.B.

How this mapping was made

OSA's own analysis. No published crosswalk between the DPDPA and SP 800-53 was found in NIST's catalogue of registered crosswalks. Each clause was rated three times, independently, against the control statements, by AI models, and reviewed by a human subject matter expert where practical. A control is listed for a clause where at least two of the three ratings named it. The coverage figure is the median of the three estimates of how much of the clause an organisation would meet by implementing the listed controls. The contributor who asked for the mapping then reviewed it against the Act, the Rules and NIST's control text. As a result the controls of four clauses were changed by hand, and those changes are listed in hand_edits.

Texts

  • The Digital Personal Data Protection Act, 2023 (No. 22 of 2023) (Gazette of India Extraordinary, Part II Section 1, No. 25, 11 August 2023)
  • Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), 13 November 2025, Gazette of India Extraordinary, Part II Section 3(i), English text)

Changed by hand after review

  • Rules.8(2): PM-22 and SI-18 removed and coverage set to 0, because both act after erasure and the rule requires notice at least forty-eight hours before.
  • Rules.8(3): SA-09 added, because the rule also covers a Data Processor holding the data and logs on the Data Fiduciary's behalf. Coverage unchanged.
  • Act.8(7) and Rules.8(1): SI-21 removed. It refreshes information or generates it on demand and deletes it when no longer needed, and SI-12 already covers disposal. Coverage unchanged.
Clause Title SP 800-53 Controls
Act.4 Grounds for processing personal data
Act.5(1) Notice with or before a request for consent
Act.5(2) Notice where consent was given before commencement
Act.5(3) Notice available in English or a scheduled language
Act.6(1) Consent: free, specific, informed, limited to necessary data
Act.6(3) Request for consent in clear and plain language
Act.6(4) Right to withdraw consent with comparable ease
Act.6(6) Cease processing on withdrawal of consent, including by processors
Act.6(7)-(9) Consent through a registered Consent Manager
Act.6(10) Proof that notice was given and consent obtained
Act.7 Certain legitimate uses without consent
Act.8(1) Responsibility for compliance, including processing by a Data Processor
Act.8(2) Data Processor engaged for offering goods or services only under a valid contract
Act.8(3) Completeness, accuracy and consistency of personal data
Act.8(4) Technical and organisational measures to observe the Act
Act.8(5) Reasonable security safeguards to prevent personal data breach
Act.8(6) Intimation of a personal data breach to the Board and Data Principals
Act.8(7) Erasure when consent is withdrawn or the purpose is served
Act.8(9) Publish contact information of a person who answers questions
Act.8(10) Effective mechanism to redress grievances
Act.9(1) Verifiable consent of parent or lawful guardian
Act.9(2) No processing detrimental to the well-being of a child
Act.9(3) No tracking, behavioural monitoring or targeted advertising directed at children
Act.10(2)(a) Significant Data Fiduciary: Data Protection Officer
Act.10(2)(b) Significant Data Fiduciary: independent data auditor
Act.10(2)(c) Significant Data Fiduciary: periodic impact assessment and audit
Act.11 Right to access information about personal data
Act.12(2) Right to correction, completion and updating
Act.12(3) Right to erasure
Act.13 Right of grievance redressal
Act.14 Right to nominate
Act.16 Transfer of personal data outside India
Act.27-33 Inquiry by the Board, directions, appeals, undertakings and penalties
Act.36 Furnishing information called for by the Central Government
Rules.3 Content of the notice
Rules.4 Consent Manager: registration, conditions and governance obligations
Rules.6(1)(a) Security safeguards: encryption, obfuscation, masking or virtual tokens
Rules.6(1)(b) Security safeguards: control of access to computer resources
Rules.6(1)(c) Security safeguards: logs, monitoring and review of access
Rules.6(1)(d) Security safeguards: continued processing, such as data backups
Rules.6(1)(e) Security safeguards: logs and personal data retained for one year
Rules.6(1)(f) Security safeguards: provision in the contract with a Data Processor
Rules.6(1)(g) Security safeguards: measures to ensure the safeguards are observed
Rules.7(1) Intimation of a breach to each affected Data Principal
Rules.7(2) Intimation of a breach to the Board, with detail within seventy-two hours
Rules.8(1) Erasure after the period in the Third Schedule
Rules.8(2) Inform the Data Principal forty-eight hours before erasure
Rules.8(3) Personal data, traffic data and logs retained for at least one year
Rules.9 Contact information published on the website or app and in responses
Rules.10 Verifiable consent for a child: the parent is an identifiable adult
Rules.11 Verifiable consent for a person with disability: the guardian's appointment
Rules.13(1)-(2) Significant Data Fiduciary: impact assessment and audit every twelve months, reported to the Board
Rules.13(3) Significant Data Fiduciary: due diligence on technical measures and algorithmic software
Rules.13(4) Significant Data Fiduciary: specified personal data kept within India
Rules.14(1)-(2) Means of exercising rights published on the website or app
Rules.14(3) Grievances answered within a published period of not more than ninety days
Rules.14(4) Means of nominating another individual
Rules.15 Transfer outside India subject to requirements set by the Central Government
Rules.23 Furnishing information to the Central Government, without disclosure where required
Rules.Sch1.A.9 Consent Manager: independent certification of the platform and its measures
Rules.Sch1.B.2 Consent Manager: shared personal data not readable by it
Rules.Sch1.B.3-4 Consent Manager: record of consents, notices and sharing, kept for at least seven years
Rules.Sch1.B.7 Consent Manager: reasonable security safeguards
Rules.Sch1.B.12 Consent Manager: audit mechanisms, with the outcome reported to the Board
Rules.Sch2 Standards for processing by the State and for research, archiving or statistics