A generic AI checklist will default to GDPR and miss what's actually different here. Answer a few real questions about how your product handles user data and get a status check against India's actual Digital Personal Data Protection Act, 2023 and Rules, 2025.
This tool is free. Prefer we just handle it for you?
Legal basis
DPDP Security Safeguards & Breach Notification
Rule 6 requires encryption, access controls, masking, monitoring, incident-response plans, and processor security clauses. Rule 7 requires breach notification to the Board and every affected Data Principal without undue delay, with a detailed report within 72 hours and no internal 'materiality' filter.
Significant Data Fiduciary (SDF)
A Data Fiduciary specifically notified by the Central Government (S.10) — not a self-assessment by size or user count — that carries added obligations: an India-based DPO, annual DPIA and independent audit, and algorithmic-risk review.
DPDP Notice & Consent Standard
Notice must be standalone and precede consent (S.5, Rule 3); consent must be free, specific, informed, unconditional, and unambiguous via clear affirmative action (S.6) — DPDP has no GDPR-style 'legitimate interest' basis, and withdrawal must be as easy as giving consent.
Digital Personal Data Protection Rules, 2025
Operational rules under the DPDP Act, notified 13 November 2025. Translate the Act's principles into concrete detail: notice format, consent-manager registration, security controls, breach timelines, retention defaults, children's-data verification, and cross-border transfer conditions.
DPDP Retention & Erasure Rules
Personal data must be erased once its specified purpose is no longer served (S.8(7)) — purpose-tied, not 'as long as necessary.' Rule 8 layers a 48-hour pre-erasure notice, a one-year minimum log-retention floor, and a 3-year default erasure window for entities above defined scale thresholds.
DPDP Children's & Disability Data Rules
DPDP sets the 'child' threshold at under 18 (not COPPA's 13 or GDPR's 16), requires verifiable parental/guardian consent via an actual verification method, and absolutely bars tracking or targeted advertising directed at anyone flagged under 18 — a prohibition that cannot be unlocked even with parental consent.
Digital Personal Data Protection Act, 2023
India's cross-sector data protection statute — 44 sections across 9 chapters, Presidential assent 11 August 2023. Governs how Data Fiduciaries handle the digital personal data of Data Principals; phased commencement runs through 13 May 2027.
DPDP Section 17(3) Startup Exemption — Not Yet Notified
S.17(3) lets the Central Government exempt DPIIT-recognised startups from notice, accuracy, erasure, and Significant Data Fiduciary obligations — but as of the last verification for BuildWright's internal DPDP checklist, that notification has not been issued. DPIIT recognition alone changes nothing under DPDP today.
Data Principal (DPDP Act)
The individual to whom the personal data relates — the DPDP Act's term for the person holding rights under the Act (consent, access, correction, erasure, grievance, nomination).
Data Fiduciary (DPDP Act)
Any entity that, alone or with others, determines the purpose and means of processing personal data — the DPDP Act's term for the party bearing compliance obligations (S.2(i)).
DPDP Penalty Framework (Section 33)
All DPDP penalties are purely monetary, imposed by the Data Protection Board after inquiry — no criminal sanctions. Range: ₹10,000 (Data Principal duty breach) up to ₹250 crore (security-safeguard failure leading to a breach), with up to a 2x enhancement for serious/repeat violations.
Learn the details
Guides that walk through every step.
Prefer to skip the paperwork?
Buildwright can take this off your plate — done properly, the first time.