← Frameworks / India DPDPA / Control Mappings

Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025

India's law on the processing of digital personal data. It sets the grounds for processing (consent and certain legitimate uses), what a notice and a request for consent must contain, and the obligations of a Data Fiduciary: reasonable security safeguards, intimation of a breach to the Data Protection Board of India and to each affected Data Principal, erasure, and a grievance mechanism. Data Principals have rights of access, correction, erasure and nomination. Significant Data Fiduciaries and Consent Managers carry further obligations. The 2025 Rules set the minimum safeguards, a detailed breach report within seventy-two hours, retention and erasure periods, and how consent for a child is verified.

AC Access Control

Control Name India DPDPA References
AC-02 Account Management
Rules.6(1)(b)
AC-03 Access Enforcement
Act.8(5)Act.11Rules.6(1)(b)Rules.Sch1.B.3-4Rules.Sch1.B.7Rules.Sch2
AC-04 Information Flow Enforcement
Act.16Rules.13(4)Rules.15
AC-06 Least Privilege
Act.8(5)Rules.6(1)(b)Rules.Sch1.B.7
AC-17 Remote Access
Rules.6(1)(b)
AC-21 Information Sharing
Rules.15

AU Audit and Accountability

Control Name India DPDPA References
AU-02 Event Logging
Rules.6(1)(c)
AU-03 Content of Audit Records
Rules.6(1)(c)
AU-06 Audit Record Review, Analysis, and Reporting
Act.8(5)Rules.6(1)(c)Rules.Sch1.B.7
AU-07 Audit Record Reduction and Report Generation
Rules.6(1)(c)
AU-10 Non-repudiation
Act.6(10)
AU-11 Audit Record Retention
Rules.6(1)(e)Rules.8(3)Rules.Sch1.B.3-4
AU-12 Audit Record Generation
Rules.6(1)(c)

CA Security Assessment and Authorization

Control Name India DPDPA References
CA-02 Control Assessments
Act.8(4)Act.10(2)(b)Act.10(2)(c)Rules.6(1)(g)Rules.13(1)-(2)Rules.Sch1.A.9Rules.Sch1.B.12
CA-07 Continuous Monitoring
Act.8(4)Act.10(2)(c)Rules.6(1)(g)Rules.13(1)-(2)Rules.Sch1.B.12

CM Configuration Management

Control Name India DPDPA References
CM-04 Impact Analyses
Rules.13(3)
CM-12 Information Location
Act.16Rules.13(4)Rules.15
CM-13 Data Action Mapping
Act.11

CP Contingency Planning

Control Name India DPDPA References
CP-02 Contingency Plan
Rules.6(1)(d)
CP-06 Alternate Storage Site
Rules.6(1)(d)
CP-07 Alternate Processing Site
Rules.6(1)(d)
CP-09 System Backup
Act.8(5)Rules.6(1)(d)Rules.Sch1.B.7
CP-10 System Recovery and Reconstitution
Rules.6(1)(d)

IA Identification and Authentication

Control Name India DPDPA References
IA-02 Identification and Authentication (Organizational Users)
Act.8(5)Rules.6(1)(b)Rules.Sch1.B.7
IA-05 Authenticator Management
Rules.6(1)(b)
IA-12 Identity Proofing
Act.9(1)Rules.10Rules.11

IR Incident Response

Control Name India DPDPA References
IR-04 Incident Handling
Act.8(5)Rules.6(1)(c)Rules.7(1)Rules.7(2)Rules.Sch1.B.7
IR-05 Incident Monitoring
Rules.7(2)
IR-06 Incident Reporting
Act.8(6)Rules.7(2)
IR-08 Incident Response Plan
Act.8(6)Rules.7(1)Rules.7(2)

MP Media Protection

Control Name India DPDPA References
MP-06 Media Sanitization
Act.8(7)Rules.8(1)

PE Physical and Environmental Protection

Control Name India DPDPA References
PE-03 Physical Access Control
Rules.6(1)(b)

PM Program Management

Control Name India DPDPA References
PM-01 Information Security Program Plan
Rules.6(1)(g)
PM-05 System Inventory
Act.11
PM-14 Testing, Training, and Monitoring
Act.8(4)Rules.6(1)(g)
PM-18 Privacy Program Plan
Act.8(1)Act.8(4)
PM-19 Privacy Program Leadership Role
Act.8(1)Act.8(4)Act.8(9)Act.10(2)(a)Rules.9Rules.Sch2
PM-20 Dissemination of Privacy Program Information
Act.6(3)Act.8(9)Rules.9Rules.14(1)-(2)Rules.14(3)Rules.Sch2
PM-21 Accounting of Disclosures
Act.11Rules.Sch1.B.3-4
PM-22 Personally Identifiable Information Quality Management
Act.8(3)Act.12(2)Rules.Sch2
PM-25 Minimization of Personally Identifiable Information Used in Testing, Training, and Research
Rules.Sch2
PM-26 Complaint Management
Act.8(9)Act.8(10)Act.13Rules.9Rules.14(1)-(2)Rules.14(3)
PM-27 Privacy Reporting
Rules.13(1)-(2)Rules.Sch1.B.12

PT Personally Identifiable Information Processing and Transparency

Control Name India DPDPA References
PT-01 Policy and Procedures
Act.8(4)
PT-02 Authority to Process Personally Identifiable Information
Act.4Act.6(6)Act.7Act.9(3)Rules.Sch2
PT-03 Personally Identifiable Information Processing Purposes
Act.4Act.5(1)Act.5(2)Act.6(1)Act.7Rules.3Rules.Sch2
PT-04 Consent
Act.4Act.5(1)Act.6(1)Act.6(3)Act.6(4)Act.6(6)Act.6(7)-(9)Act.9(1)Rules.3Rules.4Rules.10Rules.11
PT-05 Privacy Notice
Act.5(1)Act.5(2)Act.5(3)Act.6(3)Rules.3Rules.Sch2
PT-07 Specific Categories of Personally Identifiable Information
Act.9(1)Act.9(2)Act.9(3)Rules.10

RA Risk Assessment

Control Name India DPDPA References
RA-03 Risk Assessment
Act.8(5)Act.9(2)Act.10(2)(c)Rules.13(1)-(2)Rules.13(3)Rules.Sch1.B.7
RA-05 Vulnerability Monitoring and Scanning
Act.8(5)Rules.Sch1.B.7
RA-08 Privacy Impact Assessments
Act.9(2)Act.10(2)(c)Rules.13(1)-(2)Rules.13(3)

SA System and Services Acquisition

Control Name India DPDPA References
SA-04 Acquisition Process
Act.8(2)Rules.6(1)(f)
SA-08 Security and Privacy Engineering Principles
Act.6(1)Act.8(4)Rules.Sch2
SA-09 External System Services
Act.6(6)Act.8(1)Act.8(2)Act.8(5)Act.8(7)Act.16Rules.6(1)(f)Rules.8(3)Rules.13(4)Rules.15Rules.Sch1.B.7
SA-11 Developer Testing and Evaluation
Rules.13(3)

SC System and Communications Protection

Control Name India DPDPA References
SC-07 Boundary Protection
Act.8(5)Rules.13(4)Rules.Sch1.B.7
SC-08 Transmission Confidentiality and Integrity
Act.8(5)Rules.6(1)(a)Rules.Sch1.B.2Rules.Sch1.B.7Rules.Sch2
SC-12 Cryptographic Key Establishment and Management
Act.8(5)Rules.6(1)(a)Rules.Sch1.B.2Rules.Sch1.B.7
SC-13 Cryptographic Protection
Act.8(5)Rules.6(1)(a)Rules.Sch1.B.2Rules.Sch1.B.7
SC-28 Protection of Information at Rest
Act.8(5)Rules.6(1)(a)Rules.Sch1.B.7Rules.Sch2

SI System and Information Integrity

Control Name India DPDPA References
SI-02 Flaw Remediation
Act.8(5)Rules.Sch1.B.7
SI-03 Malicious Code Protection
Act.8(5)Rules.Sch1.B.7
SI-04 System Monitoring
Act.8(5)Rules.6(1)(c)Rules.Sch1.B.7
SI-06 Security and Privacy Function Verification
Rules.6(1)(g)
SI-07 Software, Firmware, and Information Integrity
Act.8(5)Rules.Sch1.B.7
SI-12 Information Management and Retention
Act.6(1)Act.8(7)Act.12(3)Rules.6(1)(e)Rules.8(1)Rules.8(3)Rules.Sch1.B.3-4Rules.Sch2
SI-18 Personally Identifiable Information Quality Operations
Act.8(3)Act.12(2)Act.12(3)Rules.Sch2
SI-19 De-identification
Rules.6(1)(a)