← Frameworks / India DPDPA / Coverage Analysis

Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 โ€” SP 800-53 Coverage

How well do NIST SP 800-53 Rev 5 controls address each India DPDPA requirement? This analysis maps from framework clauses back to SP 800-53, with expert coverage weightings and gap identification.

Coverage Distribution
Full (85-100%): 10 Substantial (65-84%): 17 Partial (40-64%): 25 Weak (1-39%): 7 None (0%): 6

Clause-by-Clause Analysis

Sorted by clause
Act.4 Grounds for processing personal data

Rationale

PT-02 has the organisation determine and document the authority that permits processing and restrict processing to what is authorised. PT-03 restricts processing to the documented purposes. PT-04 provides the means for individuals to consent before collection.

Gaps

Whether a purpose is lawful, and whether a use falls within the legitimate uses of section 7, is a legal judgement that no control makes.

Mapped Controls

Act.5(1) Notice with or before a request for consent

Rationale

PT-05 requires a notice in plain language that states the purposes of processing, and its just-in-time notice enhancement presents it when the data is asked for. PT-03 requires the purposes to be described in notices. PT-04 provides the consent mechanism the notice accompanies.

Gaps

The notice must also say how to withdraw consent, how to use the grievance mechanism and how to complain to the Board. SP 800-53 does not prescribe that content.

Mapped Controls

Act.5(2) Notice where consent was given before commencement

Rationale

PT-05 requires notice when an individual first interacts with the organisation and again at a defined frequency, and PT-03 requires the purposes to be described. Together they support a notice to people whose consent predates the Act.

Gaps

No control requires a one-off notice to existing Data Principals after a change in the law, or sets when it is due.

Mapped Controls

Act.5(3) Notice available in English or a scheduled language

Rationale

PT-05 requires the notice to be clear, easy to understand and in plain language.

Gaps

The choice of English or a language in the Eighth Schedule to the Constitution is not addressed.

Mapped Controls

Act.6(1) Consent: free, specific, informed, limited to necessary data

Rationale

PT-04 requires consent mechanisms that support an informed decision, and its tailored consent enhancement lets an individual limit consent to selected data. PT-03 ties processing to stated purposes. SA-08 (minimization) and SI-12 (limit personally identifiable information elements) keep the data to what the purpose needs.

Gaps

That consent is free, unconditional and unambiguous with a clear affirmative action is a legal standard for the design of the consent request. SP 800-53 does not set it.

Act.6(3) Request for consent in clear and plain language

Rationale

PT-04 and PT-05 require consent requests and notices that support an informed decision in plain language. PM-20 gives the public a way to reach the senior official for privacy.

Gaps

The language options, and stating the contact details of the Data Protection Officer or authorised person in the request itself, are not addressed.

Mapped Controls

Act.6(4) Right to withdraw consent with comparable ease

Rationale

PT-04 (revocation) requires tools or mechanisms for individuals to revoke consent.

Gaps

That withdrawal must be as easy as giving consent is not stated.

Mapped Controls

Act.6(6) Cease processing on withdrawal of consent, including by processors

Rationale

PT-04 (revocation) provides the means to withdraw. PT-02 restricts processing to what is authorised, which ends when consent does. SA-09 requires external providers to comply with the organisation's privacy requirements, which carries the instruction to processors.

Gaps

No control sets a time within which processing must stop, or requires proof that processors have stopped.

Mapped Controls

Act.6(7)-(9) Consent through a registered Consent Manager

Rationale

PT-04 requires tools or mechanisms for consent, which a Consent Manager's platform can be.

Gaps

Accepting consent through a registered Consent Manager, and that body's accountability and registration, are outside SP 800-53.

Mapped Controls

Act.6(10) Proof that notice was given and consent obtained

Rationale

AU-10 requires irrefutable evidence that an individual performed a defined action, which can cover giving consent and being shown the notice.

Gaps

The actions covered by AU-10 are chosen by the organisation. No control requires a record of each notice and consent kept so that it can be produced in a proceeding.

Mapped Controls

Act.7 Certain legitimate uses without consent

Rationale

PT-02 requires the authority for each kind of processing to be determined and documented, which is where a legitimate use is recorded. PT-03 restricts processing to the purpose the use allows.

Gaps

Whether a case falls within one of the nine legitimate uses is a legal judgement. The conditions on processing by the State are not addressed.

Mapped Controls

Act.8(1) Responsibility for compliance, including processing by a Data Processor

Rationale

PM-18 and PM-19 establish a privacy programme and an accountable senior official. SA-09 requires external providers to comply with the organisation's privacy requirements, and requires the organisation to define its oversight of them and monitor their compliance.

Gaps

The Act makes the Data Fiduciary answerable for a Data Processor's acts whatever the contract says. Controls support that responsibility and do not create it.

Mapped Controls

Act.8(2) Data Processor engaged for offering goods or services only under a valid contract

Rationale

SA-04 requires security and privacy requirements in the acquisition contract. SA-09 requires external service providers to comply with them.

Gaps

That processing may take place only under a valid contract is a legal condition. SP 800-53 assumes a contract and governs its content.

Mapped Controls

Act.8(3) Completeness, accuracy and consistency of personal data

Rationale

SI-18 requires the accuracy, relevance, timeliness and completeness of personal data to be checked across its life cycle and inaccurate data corrected or deleted. PM-22 requires organisation-wide policies and procedures for the same.

Gaps

Consistency is not named in SI-18 or PM-22, which speak of accuracy, relevance, timeliness and completeness. The duty arises only where the data is likely to be used to make a decision that affects the Data Principal or to be disclosed to another Data Fiduciary.

Mapped Controls

Act.8(4) Technical and organisational measures to observe the Act

Rationale

PM-18 and PM-19 establish the privacy programme and its leadership, and PT-01 the policy and procedures for processing personal data. SA-08 applies privacy engineering principles to systems. CA-02, CA-07 and PM-14 assess and monitor whether the measures work.

Gaps

The measures are those the organisation selects. No control tests them against each provision of the Act and the Rules.

Act.8(5) Reasonable security safeguards to prevent personal data breach

Rationale

RA-03 and RA-05 identify risk and vulnerabilities. AC-03, AC-06 and IA-02 control access. SC-07, SC-08, SC-12, SC-13 and SC-28 protect data at boundaries, in transit and at rest. SI-02, SI-03, SI-04 and SI-07 keep systems patched, free of malicious code, monitored and intact. AU-06 and IR-04 detect and handle incidents, CP-09 keeps backups, and SA-09 extends the requirements to processors.

Gaps

What is reasonable is for the Board to judge after a breach. Rule 6 sets the minimum, mapped clause by clause as Rules.6(1)(a) to (g).

Act.8(6) Intimation of a personal data breach to the Board and Data Principals

Rationale

IR-06 requires incidents to be reported to defined authorities. IR-08 (breaches) requires the incident response plan to include a process for deciding whether notice to individuals and oversight bodies is needed.

Gaps

The Act requires intimation of every personal data breach to the Board and to each affected Data Principal, with no threshold of harm. The form and timing are in rule 7.

Mapped Controls

Act.8(7) Erasure when consent is withdrawn or the purpose is served

Rationale

SI-12 (information disposal) requires information to be erased after its retention period or when no longer needed, and MP-06 sanitises the media. SA-09 carries the requirement to processors.

Gaps

Erasure triggered by withdrawal of consent, and causing a processor to erase, are not stated as such.

Mapped Controls

Act.8(9) Publish contact information of a person who answers questions

Rationale

PM-19 appoints a senior official for privacy. PM-20 requires a public page through which people can reach that official, and PM-26 a process for answering questions from individuals.

Gaps

Publishing the business contact information in the manner the Rules prescribe is not addressed.

Mapped Controls

Act.8(10) Effective mechanism to redress grievances

Rationale

PM-26 requires a process for receiving and responding to complaints, concerns and questions from individuals, with mechanisms that are easy to use, tracking of each complaint and a response within a defined period.

Gaps

Mapped Controls

Act.9(1) Verifiable consent of parent or lawful guardian

Rationale

PT-04 requires consent mechanisms, and PT-07 lets the organisation set conditions for a specific category of personal data such as that of children. IA-12 requires identity evidence to be collected, validated and verified for users who need accounts. That can establish who a parent or guardian is, but not their age or their relationship to the child.

Gaps

No control requires a parent's or guardian's consent, or defines a child as a person under eighteen. Rules 10 and 11 set how the consent is verified. Section 9(4) and rule 12 (Fourth Schedule) disapply sections 9(1) and 9(3) to the classes of Data Fiduciary and the purposes listed there, and section 9(5) lets the Central Government notify an age above which a Data Fiduciary is exempt from them.

Mapped Controls

Act.9(2) No processing detrimental to the well-being of a child

Rationale

RA-03 and RA-08 assess the likelihood and impact of adverse effects on individuals from processing their personal data. PT-07 applies conditions to specific categories of personal data.

Gaps

No control sets a test of detriment to a child's well-being or forbids processing that fails it.

Mapped Controls

Act.9(3) No tracking, behavioural monitoring or targeted advertising directed at children

Rationale

PT-02 restricts processing to what is authorised and PT-07 applies conditions to specific categories of personal data. An organisation can use them to bar tracking, behavioural monitoring and targeted advertising for children's data.

Gaps

The prohibition itself is not in SP 800-53. The controls enforce a rule the organisation must write. Section 9(4) and rule 12 (Fourth Schedule) disapply the prohibition to the classes and purposes listed there, and section 9(5) lets the Central Government notify an age above which a Data Fiduciary is exempt.

Mapped Controls

Act.10(2)(a) Significant Data Fiduciary: Data Protection Officer

Rationale

PM-19 requires a senior official for privacy with the authority, accountability and resources to run the privacy programme.

Gaps

That the officer is based in India, answers to the board of directors and is the point of contact for grievances is not addressed.

Mapped Controls

Act.10(2)(b) Significant Data Fiduciary: independent data auditor

Rationale

CA-02 requires control assessments by a selected assessor, and its independent assessors enhancement requires independence.

Gaps

A data audit evaluates compliance with the Act, which is wider than an assessment of selected controls. The appointment of an auditor is not addressed.

Mapped Controls

Act.10(2)(c) Significant Data Fiduciary: periodic impact assessment and audit

Rationale

RA-08 requires privacy impact assessments and RA-03 a risk assessment that includes adverse effects on individuals. CA-02 and CA-07 provide the periodic assessment and continuing monitoring.

Gaps

RA-08 is triggered by new systems and new collections, where the Act requires the assessment periodically. The description of Data Principals' rights that the assessment must contain is not addressed.

Act.11 Right to access information about personal data

Rationale

AC-03 (individual access) requires mechanisms for individuals to see their personal data. PM-21 requires an accounting of disclosures with the recipient of each, available to the individual on request. CM-13 and PM-05 (inventory of personally identifiable information) record the processing from which a summary is drawn.

Gaps

A summary of processing activities, and naming every Data Processor the data was shared with, go beyond what the controls require to be given to the individual.

Act.12(2) Right to correction, completion and updating

Rationale

SI-18 (individual requests) requires personal data to be corrected or deleted on request by the individual. PM-22 requires procedures for correcting inaccurate or outdated data.

Gaps

Completing incomplete data on request is not named.

Mapped Controls

Act.12(3) Right to erasure

Rationale

SI-18 (individual requests) requires deletion on request. SI-12 (information disposal) requires erasure after the retention period.

Gaps

The exceptions, where retention is necessary for the specified purpose or for compliance with a law, are legal judgements.

Mapped Controls

Act.13 Right of grievance redressal

Rationale

PM-26 requires a complaint process with mechanisms that are readily accessible, tracking, acknowledgement and a response within a defined period.

Gaps

The right and the duty bind a Consent Manager as well as a Data Fiduciary. The period for responding is set by rule 14(3).

Mapped Controls

Act.14 Right to nominate
0%

Rationale

No control addresses nomination of another individual to exercise a Data Principal's rights on death or incapacity.

Gaps

The whole clause. It needs a process for recording nominations and for verifying a nominee who later makes a request.

Act.16 Transfer of personal data outside India

Rationale

CM-12 records where personal data is processed and stored. AC-04 enforces rules on the flow of information between systems. SA-09 (processing, storage and service location) restricts the locations a provider may use.

Gaps

Which countries are restricted is set by notification. The controls enforce a restriction once the organisation has turned it into a flow or location rule.

Mapped Controls

Act.27-33 Inquiry by the Board, directions, appeals, undertakings and penalties
0%

Rationale

No control addresses the Board's powers of inquiry, its directions, appeals against them, mediation, voluntary undertakings or the penalties.

Gaps

The whole clause. An organisation needs to be able to produce documents and records to the Board and to act on its directions.

Act.36 Furnishing information called for by the Central Government
0%

Rationale

No control addresses a requirement to furnish information to the Central Government.

Gaps

The whole clause.

Rules.3 Content of the notice

Rationale

PT-05 requires a notice in plain language stating the purposes of processing. PT-03 requires the purposes to be described, and PT-04 requires that the individual can make an informed decision.

Gaps

An itemised description of the personal data, a notice that stands on its own, and links for withdrawing consent, exercising rights and complaining to the Board are not prescribed.

Mapped Controls

Rules.4 Consent Manager: registration, conditions and governance obligations

Rationale

PT-04 requires tools or mechanisms for individuals to consent, which is what the platform provides.

Gaps

The conditions of registration and the governance obligations, on incorporation, net worth, conflict of interest, sub-contracting and change of control, have no counterpart in SP 800-53.

Mapped Controls

Rules.6(1)(a) Security safeguards: encryption, obfuscation, masking or virtual tokens

Rationale

SC-28 protects data at rest and SC-08 data in transit, with SC-13 and SC-12 for the cryptography and its keys. SI-19 (removal, masking, encryption, hashing or replacement of direct identifiers) covers obfuscation, masking and tokens.

Gaps

Rules.6(1)(b) Security safeguards: control of access to computer resources

Rationale

AC-02, AC-03 and AC-06 manage accounts, enforce authorisations and apply least privilege. IA-02 and IA-05 identify and authenticate users and manage authenticators. AC-17 governs remote access and PE-03 physical access.

Gaps

Rules.6(1)(c) Security safeguards: logs, monitoring and review of access

Rationale

AU-02, AU-03 and AU-12 define, fill and generate audit records. AU-06 and AU-07 review and analyse them and support investigation. SI-04 monitors for unauthorised access, and IR-04 handles the incident and applies the lessons to prevent recurrence.

Gaps

Rules.6(1)(d) Security safeguards: continued processing, such as data backups

Rationale

CP-09 requires backups and CP-10 recovery to a known state. CP-02 plans for continued operation, with CP-06 and CP-07 for alternate storage and processing.

Gaps

Rules.6(1)(e) Security safeguards: logs and personal data retained for one year

Rationale

AU-11 requires audit records to be retained for a defined period to support investigation of incidents. SI-12 manages retention of information in line with applicable law.

Gaps

The period of one year is a value the organisation must set in both controls.

Mapped Controls

Rules.6(1)(f) Security safeguards: provision in the contract with a Data Processor

Rationale

SA-04 requires security and privacy requirements in the contract. SA-09 requires external providers to comply with them and to be monitored.

Gaps

Mapped Controls

Rules.6(1)(g) Security safeguards: measures to ensure the safeguards are observed

Rationale

PM-01 sets out the security programme. CA-02 and CA-07 assess and monitor the controls, PM-14 keeps testing, training and monitoring in operation, and SI-06 verifies that security and privacy functions work.

Gaps

The measures are those the organisation selects. No control checks them against rule 6 item by item.

Rules.7(1) Intimation of a breach to each affected Data Principal

Rationale

IR-08 (breaches) requires a process for deciding whether to notify individuals and for assessing the harm to them. IR-04 handles the incident and produces the facts and the measures taken.

Gaps

Notice to every affected Data Principal without delay, through her account or registered contact, with the five stated items, is not prescribed.

Mapped Controls

Rules.7(2) Intimation of a breach to the Board, with detail within seventy-two hours

Rationale

IR-06 requires incident information to be reported to defined authorities. IR-05 tracks and documents incidents, IR-04 establishes cause and remedy, and IR-08 (breaches) covers notice to oversight bodies.

Gaps

The two stages, a first intimation without delay and detail within seventy-two hours, and the six items of the detailed report, are values and content the organisation must add.

Rules.8(1) Erasure after the period in the Third Schedule

Rationale

SI-12 (information disposal) requires erasure after the retention period. MP-06 sanitises the media.

Gaps

The rule applies only to the classes in the Third Schedule: e-commerce entities with at least two crore registered users in India, online gaming intermediaries with at least fifty lakh and social media intermediaries with at least two crore, and not to the purposes of accessing a user account or a virtual token. The three-year period, counted from the date the Data Principal last approached the Data Fiduciary for the specified purpose or exercised her rights, or from the commencement of the Rules, whichever is latest, must be built by the organisation.

Mapped Controls

Rules.8(2) Inform the Data Principal forty-eight hours before erasure
0%

Rationale

No control addresses telling the Data Principal before erasure that the personal data is about to be erased.

Gaps

The whole clause. The Data Fiduciary must inform the Data Principal at least forty-eight hours before the period ends that the data will be erased unless she logs in, contacts it or exercises her rights. SI-18 and PM-22 tell the person only after personal data is corrected or deleted.

Rules.8(3) Personal data, traffic data and logs retained for at least one year

Rationale

AU-11 requires audit records to be retained for a defined period. SI-12 manages retention of information in line with applicable law, with disposal afterwards. SA-09 requires external providers to comply with the organisation's requirements, which reaches a Data Processor that holds the data and logs for it.

Gaps

Keeping the personal data and traffic data themselves for at least a year after processing is a value the organisation must set. The purposes of the retention are those in the Seventh Schedule. The rule also covers a Data Processor holding the data on the Data Fiduciary's behalf, and SA-09 carries the requirement to it only if the organisation sets it.

Mapped Controls

Rules.9 Contact information published on the website or app and in responses

Rationale

PM-19 appoints the official. PM-20 requires a public page through which people can reach that official, and PM-26 mechanisms for questions that are readily accessible to the public.

Gaps

Stating the contact information in every response to a rights request is not addressed.

Mapped Controls

Rules.10 Verifiable consent for a child: the parent is an identifiable adult

Rationale

IA-12 requires identity evidence to be collected, validated and verified, and its enhancement accepts identities proofed by another party, which fits a token from an authorised entity. PT-04 provides the consent mechanism and PT-07 the conditions for children's data.

Gaps

Checking that the person giving consent is an adult and is the parent, and the choice of evidence the rule allows, are not addressed.

Mapped Controls

Rules.11 Verifiable consent for a person with disability: the guardian's appointment

Rationale

IA-12 requires identity evidence to be validated and verified. PT-04 provides the consent mechanism.

Gaps

Verifying that a guardian was appointed by a court, a designated authority or a local level committee is not addressed.

Mapped Controls

Rules.13(1)-(2) Significant Data Fiduciary: impact assessment and audit every twelve months, reported to the Board

Rationale

RA-08 and RA-03 provide the impact assessment, and CA-02 and CA-07 the audit and continuing monitoring. PM-27 requires privacy reports to be sent to oversight bodies.

Gaps

The twelve-month cycle and a report of significant observations to the Board are values and content the organisation must add.

Rules.13(3) Significant Data Fiduciary: due diligence on technical measures and algorithmic software

Rationale

RA-08 requires a privacy impact assessment before technology that processes personal data is developed or procured. CM-04 analyses the privacy impact of changes, RA-03 assesses adverse effects on individuals, and SA-11 requires developers to test and evaluate.

Gaps

Algorithmic software is not named, and none of the controls is framed as a check on risk to the rights of Data Principals.

Rules.13(4) Significant Data Fiduciary: specified personal data kept within India

Rationale

CM-12 records where the data is processed and stored. AC-04 and SC-07 control the flow of data across the boundary. SA-09 (processing, storage and service location) restricts where a provider may hold it.

Gaps

Which personal data is restricted is specified by the Central Government. Traffic data about the flow is not named.

Rules.14(1)-(2) Means of exercising rights published on the website or app

Rationale

PM-20 requires a public page about the privacy programme through which people can reach the organisation. PM-26 requires mechanisms that are easy to use, with the information needed to use them.

Gaps

Publishing the means of making each kind of rights request, and the identifier a requester must give, is not prescribed. Rule 14(1) also binds a Consent Manager, where applicable.

Mapped Controls

Rules.14(3) Grievances answered within a published period of not more than ninety days

Rationale

PM-26 requires complaints to be tracked and answered within a defined period. PM-20 makes the programme's information public.

Gaps

The limit of ninety days, and publishing the period, are values and content the organisation must add. The rule binds a Consent Manager as well as a Data Fiduciary.

Mapped Controls

Rules.14(4) Means of nominating another individual
0%

Rationale

No control addresses the means by which a Data Principal nominates another individual.

Gaps

The whole clause.

Rules.15 Transfer outside India subject to requirements set by the Central Government

Rationale

CM-12 records where personal data is held. AC-04 enforces rules on flows and AC-21 on sharing with a partner. SA-09 (processing, storage and service location) restricts the locations a provider may use.

Gaps

The requirements are whatever the Central Government specifies about making data available to a foreign State. The controls enforce them once they are turned into rules.

Rules.23 Furnishing information to the Central Government, without disclosure where required
0%

Rationale

No control addresses furnishing information to the Central Government, or keeping that furnishing from the Data Principal.

Gaps

The whole clause.

Rules.Sch1.A.9 Consent Manager: independent certification of the platform and its measures

Rationale

CA-02 (independent assessors) requires controls to be assessed by an assessor independent of the organisation.

Gaps

Certification against the data protection standards and assurance framework that the Board publishes is not addressed.

Mapped Controls

Rules.Sch1.B.2 Consent Manager: shared personal data not readable by it

Rationale

SC-08 protects the confidentiality of data in transit, with SC-13 and SC-12 for the cryptography and its keys.

Gaps

The controls protect data from others. That the Consent Manager itself cannot read what it carries depends on who holds the keys, which is a design choice the controls allow and do not require.

Mapped Controls

Rules.Sch1.B.3-4 Consent Manager: record of consents, notices and sharing, kept for at least seven years

Rationale

PM-21 requires an accounting of each disclosure of personal data, retained and available to the individual. AC-03 (individual access) gives the Data Principal access to the record. AU-11 and SI-12 govern how long it is kept.

Gaps

A record of consents given, denied and withdrawn and of the notices shown, kept for at least seven years, is not prescribed. Making the record available in machine-readable form on the Data Principal's request is not prescribed either. AU-11 retains audit records, which a record of consents is not. PM-21 retains its accounting for the longer of the life of the data or five years, which does not guarantee seven.

Rules.Sch1.B.7 Consent Manager: reasonable security safeguards

Rationale

The same obligation as Act.8(5), applied to a Consent Manager. The controls and the figure are that clause's.

Gaps

As for Act.8(5).

Rules.Sch1.B.12 Consent Manager: audit mechanisms, with the outcome reported to the Board

Rationale

CA-02 and CA-07 assess and monitor technical and organisational controls. PM-27 requires reports to oversight bodies.

Gaps

Audit of the conditions of registration and of the obligations under the Act, and reporting when the Board directs, are not addressed.

Mapped Controls

Rules.Sch2 Standards for processing by the State and for research, archiving or statistics

Rationale

PT-02 and PT-03 keep processing lawful and within its purpose. SA-08 (minimization), SI-12 (limit personally identifiable information elements) and PM-25 limit the data, PM-25 for research in particular. SI-18 and PM-22 keep it accurate and SI-12 governs retention. AC-03, SC-08 and SC-28 are among the safeguards. PT-05 and PM-20 give the notice and the contact, and PM-19 the accountable person.

Gaps

The safeguards item is as wide as Act.8(5) and only three of its controls are listed here. The standards apply to the State and to research, archiving and statistics, which the controls do not single out.

Methodology and Disclaimer

This coverage analysis maps from India DPDPA clauses/requirements back to NIST SP 800-53 Rev 5 controls, assessing how well the SP 800-53 control set addresses each framework requirement.

Coverage weighting represents an informed estimate based on control-objective alignment, not a definitive compliance determination. Weightings consider whether SP 800-53 controls address the intent of each framework requirement, even where terminology and structure differ.

This analysis should be validated by qualified assessors for use in compliance or audit activities. The authoritative source for any compliance determination is always the framework itself.