The Digital Personal Data Protection Act, 2023 governs personal data at every stage of its life. Walk the stages below and tick a duty only where you can point to an owner, policy, workflow or log — the spine fills in as you go. Nothing you enter leaves your browser.
0 of 13 duties addressed. 0 of 7 stages complete.
Each duty a Data Fiduciary owes, placed where it bites in the life of a person’s data, and linked to its provision.
The duties you haven’t recorded yet — the gaps to close. Each links to its provision.
Commencement is staged under G.S.R. 846(E); the operational core falls due about eighteen months after notification.
| Failure | Provision | Maximum |
|---|---|---|
| Failure to take reasonable security safeguards, leading to a breach | s.8(5) | ₹250 cr |
| Failure to notify a personal-data breach | s.8(6) | ₹200 cr |
| Breach of children’s-data obligations | s.9 | ₹200 cr |
| Breach of Significant Data Fiduciary duties | s.10 | ₹150 cr |
| Breach of any other provision of the Act or Rules | — | ₹50 cr |
| Breach of a Data Principal’s own duties | — | ₹10,000 |
This DPDP Readiness Self-Check is provided for general information and legal awareness only. It is not legal advice, a legal opinion, or a certification of compliance, and using it does not create a lawyer–client relationship. It is based on the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.
Your actual obligations depend on your role (Data Fiduciary or Significant Data Fiduciary), your sector, your data flows, children’s data, cross-border transfers, vendor arrangements and the staggered commencement dates. This page does not determine your legal compliance. Outcomes are not guaranteed; they depend on the facts, the law, the forum and the evidence. Please seek independent professional advice on your own facts.
No data is collected. Your answers are processed entirely in your browser and are never sent, stored, logged or tracked. No AI-generated or synthetic imagery, and no depiction of any court, judge or proceeding, is used on this page.
| Entry | Duty of a Data Fiduciary | Provision | ✓ |
|---|---|---|---|
| 1 | Collect | ||
| 01 | Give a clear privacy notice | s.5 | |
| 02 | Children — verifiable parental consent | s.9 | |
| 2 | Consent | ||
| 03 | Obtain valid consent | s.6 | |
| 04 | Bind use to the purpose | s.6 | |
| 3 | Use | ||
| 05 | Keep it accurate | s.8(3) | |
| 4 | Secure | ||
| 06 | Reasonable safeguards | s.8(5) | |
| 5 | Keep, then erase | ||
| 07 | Retain, then erase | s.8(7) | |
| 6 | Answer to people | ||
| 08 | Access, correction, erasure | ss.11–12 | |
| 09 | Grievance redressal | s.8(10) | |
| 10 | Nomination | s.14 | |
| 7 | Account for it | ||
| 11 | Report breaches | s.8(6) | |
| 12 | Significant Data Fiduciary | s.10 | |
| 13 | Cross-border transfer | s.16 | |
| Failure | Provision | Maximum |
|---|---|---|
| Failure to take reasonable security safeguards, leading to a breach | s.8(5) | ₹250 cr |
| Failure to notify a personal-data breach | s.8(6) | ₹200 cr |
| Breach of children’s-data obligations | s.9 | ₹200 cr |
| Breach of Significant Data Fiduciary duties | s.10 | ₹150 cr |
| Breach of any other provision of the Act or Rules | — | ₹50 cr |
| Breach of a Data Principal’s own duties | — | ₹10,000 |