RSD Bajaj Global
Public legal-awareness note
RSD Bajaj Global

Follow your data
through the Act.

The Digital Personal Data Protection Act, 2023 governs personal data at every stage of its life. Walk the stages below and tick a duty only where you can point to an owner, policy, workflow or log — the spine fills in as you go. Nothing you enter leaves your browser.

0of 7 stages
0 of 13 duties addressed across the data lifecycle
Start here
A self-assessment indicator — not a compliance certification. Answers stay in your browser; nothing is sent or stored.

0 of 13 duties addressed. 0 of 7 stages complete.

The data lifecycle

Seven stages, thirteen duties

Each duty a Data Fiduciary owes, placed where it bites in the life of a person’s data, and linked to its provision.

Collect

When personal data is taken in.

Consent

The lawful basis to process it.

Use

While the data is worked with.

Secure

Guarding it throughout its life.

Keep, then erase

How long the data may live.

Answer to people

The rights a person holds throughout.

Account for it

When data scales, moves or a breach occurs.
Where to focus

Areas still to address 13

The duties you haven’t recorded yet — the gaps to close. Each links to its provision.

The statutory clock

When the stages take effect

In force · Nov 2025
Board & definitions
Rules 1, 2 and 17–21 — the Data Protection Board of India.
One year on · ~Nov 2026
Consent Managers
Rule 4 — India-based consent platforms.
Eighteen months on · ~May 2027
Core duties
Rules 3, 5–16, 22, 23 — the operational core.

Commencement is staged under G.S.R. 846(E); the operational core falls due about eighteen months after notification.

The stakes

Penalties under the Schedule

FailureProvisionMaximum
Failure to take reasonable security safeguards, leading to a breachs.8(5)₹250 cr
Failure to notify a personal-data breachs.8(6)₹200 cr
Breach of children’s-data obligationss.9₹200 cr
Breach of Significant Data Fiduciary dutiess.10₹150 cr
Breach of any other provision of the Act or Rules₹50 cr
Breach of a Data Principal’s own duties₹10,000
Public legal-awareness noteDPDP Act 2023 · Rules 2025 · G.S.R. 846(E)

DPDP Readiness Self-Check Record

A self-check against the Act, along the life of a person’s data. General information, not legal advice.
Recorded below, against each duty, is whether the organisation discharges it.
EntryDuty of a Data FiduciaryProvision
1Collect
01Give a clear privacy notices.5
02Children — verifiable parental consents.9
2Consent
03Obtain valid consents.6
04Bind use to the purposes.6
3Use
05Keep it accurates.8(3)
4Secure
06Reasonable safeguardss.8(5)
5Keep, then erase
07Retain, then erases.8(7)
6Answer to people
08Access, correction, erasuress.11–12
09Grievance redressals.8(10)
10Nominations.14
7Account for it
11Report breachess.8(6)
12Significant Data Fiduciarys.10
13Cross-border transfers.16
0 of 13 entries satisfied — No entries
A self-assessment indicator — not a certification of compliance, a score or a legal opinion.

Areas still to address

Commencement — G.S.R. 846(E)

In force, Nov 2025: Rules 1, 2 and 17–21 — the Data Protection Board of India. One year on (~Nov 2026): Rule 4 — Consent Managers. Eighteen months on (~May 2027): Rules 3, 5–16, 22, 23 — the operational core.

Schedule — penalties under the Act

FailureProvisionMaximum
Failure to take reasonable security safeguards, leading to a breachs.8(5)₹250 cr
Failure to notify a personal-data breachs.8(6)₹200 cr
Breach of children’s-data obligationss.9₹200 cr
Breach of Significant Data Fiduciary dutiess.10₹150 cr
Breach of any other provision of the Act or Rules₹50 cr
Breach of a Data Principal’s own duties₹10,000