Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025
India's law on the processing of digital personal data. It sets the grounds for processing (consent and certain legitimate uses), what a notice and a request for consent must contain, and the obligations of a Data Fiduciary: reasonable security safeguards, intimation of a breach to the Data Protection Board of India and to each affected Data Principal, erasure, and a grievance mechanism. Data Principals have rights of access, correction, erasure and nomination. Significant Data Fiduciaries and Consent Managers carry further obligations. The 2025 Rules set the minimum safeguards, a detailed breach report within seventy-two hours, retention and erasure periods, and how consent for a child is verified.
When it applies
Rule 1(2) to (4) of the Rules and G.S.R. 843(E), 13 November 2025, which brings the Act into force.
- From 13 November 2025
-
Section 1(2), section 2, sections 18 to 26, sections 35 and 38 to 43, and section 44(1) and (3).
Rules 1, 2 and 17 to 21.
- From 13 November 2026
-
Section 6(9) and section 27(1)(d).
Rule 4.
- From 13 May 2027
-
Sections 3 to 5, section 6(1) to (8) and (10), sections 7 to 17, section 27 except (1)(d), sections 28 to 34, 36 and 37, and section 44(2).
Rules 3, 5 to 16, 22 and 23.
Rule 4(3) gives the Consent Manager the obligations in Part B of the First Schedule from 13 November 2026, while section 6(8), which says the Consent Manager acts on the Data Principal's behalf subject to the prescribed obligations, comes into force on 13 May 2027. This mapping does not settle which date governs Rules.Sch1.B.
How this mapping was made
OSA's own analysis. No published crosswalk between the DPDPA and SP 800-53 was found in NIST's catalogue of registered crosswalks. Each clause was rated three times, independently, against the control statements, by AI models, and reviewed by a human subject matter expert where practical. A control is listed for a clause where at least two of the three ratings named it. The coverage figure is the median of the three estimates of how much of the clause an organisation would meet by implementing the listed controls. The contributor who asked for the mapping then reviewed it against the Act, the Rules and NIST's control text. As a result the controls of four clauses were changed by hand, and those changes are listed in hand_edits.
Texts
- The Digital Personal Data Protection Act, 2023 (No. 22 of 2023) (Gazette of India Extraordinary, Part II Section 1, No. 25, 11 August 2023)
- Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), 13 November 2025, Gazette of India Extraordinary, Part II Section 3(i), English text)
Changed by hand after review
- Rules.8(2): PM-22 and SI-18 removed and coverage set to 0, because both act after erasure and the rule requires notice at least forty-eight hours before.
- Rules.8(3): SA-09 added, because the rule also covers a Data Processor holding the data and logs on the Data Fiduciary's behalf. Coverage unchanged.
- Act.8(7) and Rules.8(1): SI-21 removed. It refreshes information or generates it on demand and deletes it when no longer needed, and SI-12 already covers disposal. Coverage unchanged.
| Clause | Title | SP 800-53 Controls |
|---|---|---|
| Act.4 | Grounds for processing personal data | |
| Act.5(1) | Notice with or before a request for consent | |
| Act.5(2) | Notice where consent was given before commencement | |
| Act.5(3) | Notice available in English or a scheduled language | |
| Act.6(1) | Consent: free, specific, informed, limited to necessary data | |
| Act.6(3) | Request for consent in clear and plain language | |
| Act.6(4) | Right to withdraw consent with comparable ease | |
| Act.6(6) | Cease processing on withdrawal of consent, including by processors | |
| Act.6(7)-(9) | Consent through a registered Consent Manager | |
| Act.6(10) | Proof that notice was given and consent obtained | |
| Act.7 | Certain legitimate uses without consent | |
| Act.8(1) | Responsibility for compliance, including processing by a Data Processor | |
| Act.8(2) | Data Processor engaged for offering goods or services only under a valid contract | |
| Act.8(3) | Completeness, accuracy and consistency of personal data | |
| Act.8(4) | Technical and organisational measures to observe the Act | |
| Act.8(5) | Reasonable security safeguards to prevent personal data breach | |
| Act.8(6) | Intimation of a personal data breach to the Board and Data Principals | |
| Act.8(7) | Erasure when consent is withdrawn or the purpose is served | |
| Act.8(9) | Publish contact information of a person who answers questions | |
| Act.8(10) | Effective mechanism to redress grievances | |
| Act.9(1) | Verifiable consent of parent or lawful guardian | |
| Act.9(2) | No processing detrimental to the well-being of a child | |
| Act.9(3) | No tracking, behavioural monitoring or targeted advertising directed at children | |
| Act.10(2)(a) | Significant Data Fiduciary: Data Protection Officer | |
| Act.10(2)(b) | Significant Data Fiduciary: independent data auditor | |
| Act.10(2)(c) | Significant Data Fiduciary: periodic impact assessment and audit | |
| Act.11 | Right to access information about personal data | |
| Act.12(2) | Right to correction, completion and updating | |
| Act.12(3) | Right to erasure | |
| Act.13 | Right of grievance redressal | |
| Act.14 | Right to nominate | |
| Act.16 | Transfer of personal data outside India | |
| Act.27-33 | Inquiry by the Board, directions, appeals, undertakings and penalties | |
| Act.36 | Furnishing information called for by the Central Government | |
| Rules.3 | Content of the notice | |
| Rules.4 | Consent Manager: registration, conditions and governance obligations | |
| Rules.6(1)(a) | Security safeguards: encryption, obfuscation, masking or virtual tokens | |
| Rules.6(1)(b) | Security safeguards: control of access to computer resources | |
| Rules.6(1)(c) | Security safeguards: logs, monitoring and review of access | |
| Rules.6(1)(d) | Security safeguards: continued processing, such as data backups | |
| Rules.6(1)(e) | Security safeguards: logs and personal data retained for one year | |
| Rules.6(1)(f) | Security safeguards: provision in the contract with a Data Processor | |
| Rules.6(1)(g) | Security safeguards: measures to ensure the safeguards are observed | |
| Rules.7(1) | Intimation of a breach to each affected Data Principal | |
| Rules.7(2) | Intimation of a breach to the Board, with detail within seventy-two hours | |
| Rules.8(1) | Erasure after the period in the Third Schedule | |
| Rules.8(2) | Inform the Data Principal forty-eight hours before erasure | |
| Rules.8(3) | Personal data, traffic data and logs retained for at least one year | |
| Rules.9 | Contact information published on the website or app and in responses | |
| Rules.10 | Verifiable consent for a child: the parent is an identifiable adult | |
| Rules.11 | Verifiable consent for a person with disability: the guardian's appointment | |
| Rules.13(1)-(2) | Significant Data Fiduciary: impact assessment and audit every twelve months, reported to the Board | |
| Rules.13(3) | Significant Data Fiduciary: due diligence on technical measures and algorithmic software | |
| Rules.13(4) | Significant Data Fiduciary: specified personal data kept within India | |
| Rules.14(1)-(2) | Means of exercising rights published on the website or app | |
| Rules.14(3) | Grievances answered within a published period of not more than ninety days | |
| Rules.14(4) | Means of nominating another individual | |
| Rules.15 | Transfer outside India subject to requirements set by the Central Government | |
| Rules.23 | Furnishing information to the Central Government, without disclosure where required | |
| Rules.Sch1.A.9 | Consent Manager: independent certification of the platform and its measures | |
| Rules.Sch1.B.2 | Consent Manager: shared personal data not readable by it | |
| Rules.Sch1.B.3-4 | Consent Manager: record of consents, notices and sharing, kept for at least seven years | |
| Rules.Sch1.B.7 | Consent Manager: reasonable security safeguards | |
| Rules.Sch1.B.12 | Consent Manager: audit mechanisms, with the outcome reported to the Board | |
| Rules.Sch2 | Standards for processing by the State and for research, archiving or statistics |