Compliance/India/DPDP Act and Rules
Forty-four sections: eight provisions leave evidence in the file.
The Act makes the Data Fiduciary responsible for personal data wherever it is processed. Vaultize adds records that stay with the data.
- Act No. 22 of 2023
- Rules notified 14 Nov 2025
- Phased commencement
- Capability mapping, not legal advice
8(2)Obligations of Data Fiduciary
A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract.
Vaultize Share · Vaultize Seal
I
Preliminary
0 of 3
- 1
- 2
- 3
II
Obligations of Data Fiduciary
2 of 7
- 4
- 5
- 6
- 7
- 8
- 9
- 10
III
Rights and duties of Data Principal
2 of 5
- 11
- 12
- 13
- 14
- 15
IV
Special provisions
1 of 2
- 16
- 17
V
Data Protection Board of India
0 of 9
- 18
- 19
- 20
- 21
- 22
- 23
- 24
- 25
- 26
VI
Powers and procedure of Board
0 of 2
- 27
- 28
VII
Appeal and dispute resolution
0 of 4
- 29
- 30
- 31
- 32
VIII
Penalties and adjudication
0 of 2
- 33
- 34
IX
Miscellaneous
0 of 10
- 35
- 36
- 37
- 38
- 39
- 40
- 41
- 42
- 43
- 44
The answer in 30 seconds
Vaultize adds file-level records to eight provisions in five sections of the Act, under the Data Fiduciary’s obligations, the Data Principal’s rights and transfers outside India. Consent, notice, the Board, appeals and penalties belong to the organisation and its counsel.
The Act in one view
Nine chapters. Forty-four sections. Where file evidence lands.
The Act runs in nine chapters. Select a chapter to see which of its sections a governed file can evidence.
I
Preliminary
Sections 1 to 3. Title, commencement, definitions and application.
Outcomes the file can evidence
None on this page.
- How Vaultize contributes
- Definitions and application are matters for counsel. A governed file adds no evidence here.
- Evidence to retain
- None from Vaultize.
Section by section
What each section asks. What the file can answer.
Section wording is quoted from the Act as published in the Gazette of India; longer sections are excerpted. Each row is a capability mapping, not legal advice. Read the Act and the Rules, and take advice on applicability and commencement.
Using this page
Where these rows fit in a DPDP programme.
The Act commences in phases under the notification of 13 November 2025, and the Rules were notified on 14 November 2025. The rows above are evidence for the obligations that touch documents.
- 1
Confirm applicability
Which processing, which role, and which sections apply and from when.
- 2
Find the personal data
Where it sits in documents, who holds copies, and which processors received it.
- 3
Apply safeguards
Section 8(5). Seal rights and encryption into the documents. These rows belong here.
Bring the eight rows above as evidence of reasonable security safeguards and of how requests are served.
- 4
Serve the rights
Sections 11 and 12. Answer access and erasure requests from the records. The Rules give ninety days.
- 5
Keep the evidence
For the Board, the data auditor and the Data Principal.
Responsibility boundary
Controls support compliance. They are not legal advice.
Vaultize contributes technical safeguards and evidence for personal data held in documents. It does not decide whether the Act applies, what a reasonable safeguard is in a given case, or how the Rules prescribe form and manner. Read the Act, the Rules and the commencement notification, and take qualified advice before relying on this page.
“A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach.”
Section 8(5), Digital Personal Data Protection Act, 2023
Official references
Read the source before relying on the mapping.
Section wording comes from the first item. The others are the Government’s own instruments.
- The Digital Personal Data Protection Act, 2023Act No. 22 of 2023 as published in the Gazette of India. Every section quoted on this page is from it.
- Commencement notification, 13 November 2025G.S.R. 843(E). Which sections commence immediately, after one year, and after eighteen months.
- Digital Personal Data Protection Rules, 2025The Rules prescribing form and manner under the Act, on the MeitY site.
- PIB backgrounder on the Rules, 17 November 2025Government summary: breach intimation without delay, ninety days to address requests, phased commencement.
A practical next step
Bring one document that carries personal data.
We will show which sections the governed document can evidence today. We will name the owner responsible for the rest.
