ENTRY № 19 · STATUTORY READING · DPDP ACT 2023
PUBLISHED 2026-05-09 · ~14-MIN READ · WARRANT COMPLIANCE

India DPDP Act 2023, line by line.

Forty-four sections. One Schedule. The Digital Personal Data Protection Act, 2023 received Presidential assent on 11 August 2023 and sat as a paper statute for twenty-seven months. On 13 November 2025 the Ministry of Electronics and Information Technology notified the DPDP Rules, 2025 and brought the Data Protection Board of India into legal existence. The Schedule penalty ceiling is Rs 250 crore. The substantive obligations on a Data Fiduciary are not yet in force: they commence eighteen months from that Gazette publication, which derives to 14 May 2027. This is the text, read against the Rules, with the regressions in earlier compliance commentary corrected.

Warrant is regulator-grade evidence infrastructure for AI agents in regulated industries: drop an agent's execution trace, get a record mapped to a specific EU AI Act obligation, independently verifiable without contacting Warrant.

ACT
Act 22· of 2023
Assented to 11 August 2023. 9 chapters. 44 sections. One Schedule.
IN FORCE
2025-11-13
In force on publication: ss.1(2), 2, 18–26, 35, 38–43, 44(1) and (3). Substantive ss.3–17 (bar s.6(9)), 27 (bar s.27(1)(d)) to 34, 36–37 and 44(2), with the Schedule penalties, attach eighteen months later, deriving to 2027-05-14. Board notified, members not yet fully appointed.
PENALTY
Rs 250cr
Schedule, item against Section 8(5). Section 8(6) failure capped at Rs 200 cr. Section 33(2) sets sizing factors.
01 · § 1 + § 2 · THE ACT IN ONE PARAGRAPH

The statute, in its own words.

The Digital Personal Data Protection Act, 2023 was enacted by Parliament as Act 22 of 2023 and received the assent of the President on 11 August 2023. The short title sits at Section 1, and Section 1(2) is the commencement clause — the power the Central Government exercised in G.S.R. 843(E). Application, including extra-territorial reach, sits at Section 3. The operative definitions sit at Section 2. The three together describe what the Act calls itself, where it reaches, and on what it acts.

This Act may be called the Digital Personal Data Protection Act, 2023. … Subject to the provisions of this Act, it shall—(a) apply to the processing of digital personal data within the territory of India where the personal data is collected—(i) in digital form; or (ii) in non-digital form and digitised subsequently; (b) also apply to processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India. DPDP Act 2023 · § 1(1) and § 3(a)–(b) · 11 August 2023

Section 3(c) carves out what the Act does not reach: personal data processed by an individual for any personal or domestic purpose, and personal data that the Data Principal has made or caused to be made publicly available, either herself under a legal duty or by another person under an obligation to publish. Read the application clause with its exclusions or the scope statement overstates reach.

The four definitional terms the rest of the Act turns on are all in Section 2. Each is short. Each is loaded.

§ 2(t)
"personal data" means any data about an individual who is identifiable by or in relation to such data. NOTE · the test is identifiability by or in relation to the data, not direct naming.
§ 2(n)
"digital personal data" means personal data in digital form. NOTE · paper-only personal data is outside scope unless and until digitised.
§ 2(i)
"Data Fiduciary" means any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data. NOTE · the controller analogue. Joint-fiduciary structures attach joint accountability.
§ 2(j)
"Data Principal" means the individual to whom the personal data relates, and includes the parent or lawful guardian of a child and the lawful guardian of a person with disability. NOTE · the data-subject analogue. Children's data carries Section 9 layer.

The Act has nine chapters. Chapter I, preliminary, runs Sections 1 to 3. Chapter II, obligations of Data Fiduciary, runs Sections 4 to 10. Chapter III, rights and duties of Data Principal, runs Sections 11 to 15. Chapter IV, special provisions, runs Sections 16 and 17. Chapter V, the Data Protection Board of India, runs Sections 18 to 26. Chapter VI covers the powers, functions and procedure of the Board. Chapters VII to IX cover appeal and alternate dispute resolution, penalties and adjudication, and miscellaneous provisions. The Schedule is not a chapter; it hangs off Section 33(1).

02 · §§ 4–7 · THE CONSENT REGIME

The consent regime, verbatim.

Sections 4 to 7 set the lawful-basis architecture. Section 4 is the gating clause. Section 5 attaches notice. Section 6 attaches the qualifications on consent. Section 7 enumerates the legitimate uses that operate without consent.

A person may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose,—(a) for which the Data Principal has given her consent; or (b) for certain legitimate uses. DPDP Act 2023 · § 4(1)

Section 5 governs notice. Every request for consent must be accompanied or preceded by a notice giving the Data Principal the personal data and purpose, the manner in which she may exercise her rights under sub-section (4) of Section 6 and Section 13, and the manner in which the Data Principal may make a complaint to the Board. The notice must be available in English and in any of the twenty-two languages specified in the Eighth Schedule to the Constitution.

Section 6 is the load-bearing definition of consent and its qualifications.

The consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose. DPDP Act 2023 · § 6(1)

Section 6(4) gives the Data Principal the right to withdraw her consent at any time, with the ease of doing so being comparable to the ease with which such consent was given. Section 6(5) puts the consequences of withdrawal on the Data Principal, and preserves the legality of processing already carried out before withdrawal. Section 6(7) is the Consent Manager channel: a Data Principal may give, manage, review, or withdraw her consent through a Consent Manager, which registers with the Board under Section 6(9) and is defined at Section 2(g). Part B of the First Schedule to the DPDP Rules 2025 requires that the Consent Manager act in a fiduciary capacity in relation to the Data Principal.

Section 7 enumerates the legitimate-uses pathway. The pathway is exhaustive, not illustrative. The named uses include voluntary specified-purpose disclosure, performance by the State of any function under any law, response to medical emergency, services in the event of disaster or breakdown of public order, and processing in employment-related contexts. Outside Section 7 and outside Section 6 consent, processing is unlawful.

03 · § 8 · OBLIGATIONS OF DATA FIDUCIARY

Section 8, walked through.

Section 8 is the operating spine of the Act for every business that processes personal data in India. Eleven sub-sections. Each one names a deliverable. Each one will attach Schedule penalty exposure once Section 8 and the Section 33 penalty machinery come into force, eighteen months from the November 2025 Gazette publication — mid-May 2027, deriving to 14 May 2027. I will quote each in full and mark the implication for an AI agent or automated decision system.

A Data Fiduciary shall, irrespective of any agreement to the contrary or failure of a Data Principal to carry out the duties provided under this Act, be responsible for complying with the provisions of this Act and the rules made thereunder in respect of any processing undertaken by it or on its behalf by a Data Processor. DPDP Act 2023 · § 8(1)

Sub-section (1) does two things at once. It puts accountability on the Data Fiduciary irrespective of contract. It puts accountability on the Data Fiduciary for processing performed by its Data Processor. The processor is not a shield. The contractual chain is read past, not read around.

A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract. DPDP Act 2023 · § 8(2)

Sub-section (3) is the accuracy clause. It is narrower than the headline "completeness, accuracy, and consistency" reading sometimes given. The trigger is not all processing. The trigger is processing likely to feed a decision that affects the Data Principal, or disclosure to another Data Fiduciary.

Where personal data processed by a Data Fiduciary is likely to be—(a) used to make a decision that affects the Data Principal; or (b) disclosed to another Data Fiduciary, the Data Fiduciary processing such personal data shall ensure its completeness, accuracy and consistency. DPDP Act 2023 · § 8(3)

Sub-section (4) is the technical-and-organisational-measures clause. It is the closest analogue in DPDP to GDPR Article 32(1).

A Data Fiduciary shall implement appropriate technical and organisational measures to ensure effective observance of the provisions of this Act and the rules made thereunder. DPDP Act 2023 · § 8(4)

Sub-section (5) is the security-safeguards clause. The Schedule attaches a ceiling of Rs 250 crore to its breach. It is the highest fine ceiling in the Act.

A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach. DPDP Act 2023 · § 8(5)

Sub-section (6) is the breach-intimation clause. The Act delegates the form and manner. The Rules supply it. The clock that compliance teams are now planning around is in Rule 7 of the DPDP Rules 2025, not in Section 8(6) itself.

In the event of a personal data breach, the Data Fiduciary shall give the Board and each affected Data Principal, intimation of such breach in such form and manner as may be prescribed. DPDP Act 2023 · § 8(6)

Sub-section (7) is the erasure clause. It runs against a default of erasure on consent withdrawal or on the specified purpose ceasing to be served, with a carve-out for retention required by law. Sub-section (8) defines when the specified purpose is "deemed no longer to be served." Sub-section (11) supplies the test of non-engagement.

A Data Fiduciary shall, unless retention is necessary for compliance with any law for the time being in force,—(a) erase personal data, upon the Data Principal withdrawing her consent or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier; and (b) cause its Data Processor to erase any personal data that was made available by the Data Fiduciary for processing to such Data Processor. DPDP Act 2023 · § 8(7)

Sub-sections (9) and (10) are the surface-area clauses. They name the contact and the redress mechanism the Data Fiduciary owes the Data Principal in real time, not on request.

A Data Fiduciary shall publish, in such manner as may be prescribed, the business contact information of a Data Protection Officer, if applicable, or a person who is able to answer on behalf of the Data Fiduciary, the questions, if any, raised by the Data Principal about the processing of her personal data. DPDP Act 2023 · § 8(9)
A Data Fiduciary shall establish an effective mechanism to redress the grievances of Data Principals. DPDP Act 2023 · § 8(10)

Sub-section (11) is technical. It clarifies the test for whether the Data Principal has approached the Data Fiduciary for the performance of the specified purpose. The Act treats non-initiation, in person or by communication, as non-engagement. Combined with Section 8(7) and Section 8(8), this is an automatic erasure trigger after the prescribed period of dormancy.

"Eleven sub-sections in Section 8. One of them carries Rs 250 crore exposure; a second carries Rs 200 crore. Three of them name a deliverable an AI agent must produce on every run."Warrant Compliance · 2026-05-09
04 · §§ 11–14 · RIGHTS OF THE DATA PRINCIPAL

The rights of the Data Principal.

Chapter III of the Act runs Sections 11 to 15. The first four sections are rights. The fifth is duties. The architecture is intentional. The Data Principal carries duties as well as rights, and Section 33 read against Section 15 makes false or frivolous grievance a fineable matter.

The Data Principal shall have the right to obtain from the Data Fiduciary, to whom she has previously given consent … (a) a summary of personal data which is being processed by such Data Fiduciary and the processing activities undertaken by that Data Fiduciary with respect to such personal data; (b) the identities of all other Data Fiduciaries and Data Processors with whom the personal data has been shared by such Data Fiduciary, along with a description of the personal data so shared; and (c) any other information related to the personal data of such Data Principal and its processing, as may be prescribed. DPDP Act 2023 · § 11(1)

Section 12 grants the right to correction, completion, updating, and erasure. The Data Fiduciary must correct inaccurate or misleading personal data, complete incomplete data, update data on request, and erase personal data on request unless retention is required for the specified purpose or by law.

Section 13 grants the right to grievance redressal. The Data Principal may approach the Data Fiduciary or Consent Manager. Section 13(3) requires internal remedy to be exhausted before approach to the Board. Section 13(2) requires response within such period as may be prescribed; Rule 14(3) of the DPDP Rules 2025 fills this in at a reasonable period not exceeding ninety days.

Section 14 grants the right to nominate. The Data Principal may, in such manner as may be prescribed, nominate any other individual who shall, in the event of death or incapacity, exercise the rights of the Data Principal. Incapacity, in this context, means inability to exercise the rights due to unsoundness of mind or infirmity of body.

Section 15 is the duties clause. The Data Principal must comply with applicable laws while exercising rights, must not impersonate, must not suppress material information when providing data for any document of identity issued by the State, must not register a false or frivolous grievance, and must furnish only verifiably authentic information when exercising rights of correction or erasure. The Schedule attaches a Rs 10,000 cap on penalty for breach of Section 15.

05 · § 8(6) + RULE 7 · BREACH NOTIFICATION

The breach clock, read carefully.

Earlier compliance commentary, including some prior Warrant content, has compressed Section 8(6) into a single "72-hour" claim. The text does not say 72 hours. It says intimation in such form and manner as may be prescribed. The 72-hour clock lives in Rule 7 of the DPDP Rules 2025, where MeitY has now prescribed the form and manner.

Rule 7(1) requires the Data Fiduciary to give intimation of a personal data breach to each affected Data Principal without delay, and in concise, clear, and plain language. Rule 7(2) requires the Data Fiduciary to give intimation to the Board, in two stages. First stage: without delay, with the description of the nature, extent, timing, and location of the breach and its likely impact. Second stage: within 72 hours of becoming aware of the breach, or such longer period as the Board may, on a request made in writing, allow, with the broad facts and the cause, mitigation taken, identification of persons responsible, and a summary of intimations given to affected Data Principals.

Rule 7 adds no further materiality threshold beyond the statutory definition. Section 2(u) defines a personal data breach as any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data. The compromise limb is part of the definition, not a threshold the Rules bolt on. The defensive posture is now: detect, notify both populations within the prescribed window, document the cause and the corrective action, and preserve the chain back to the source event.

T₀
DETECT
Data Fiduciary becomes aware of a personal data breach. The clock starts.
T₀
FIRST INTIMATION
Without delay: nature, extent, timing, location, likely impact. Both to the Board and to affected Data Principals.
+72h
DETAILED REPORT
To the Board: broad facts, cause, mitigation, identification of persons responsible, summary of intimations to Data Principals.
RS 200cr
CEILING
Schedule item against Section 8(6). Sized under Section 33(2). Effective from mid-May 2027, not yet.
06 · § 3(b) · TERRITORIAL APPLICATION

Where the Act reaches.

The extra-territorial application of the DPDP Act is in Section 3, not Section 16. Earlier Warrant content cited Section 16 as the extra-territorial section, and a later correction moved it to Section 1. Both are wrong. Section 1(2) is the commencement clause — the sub-section G.S.R. 843(E) exercises to bring the Act into force in tranches. Section 16 governs the onward transfer of personal data outside India, a different question again. The reach of the Act onto a foreign-established Data Fiduciary is Section 3(b).

Subject to the provisions of this Act, it shall—… (b) also apply to processing of digital personal data outside the territory of India, if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India. DPDP Act 2023 · § 3(b)

The hook is "in connection with any activity related to offering of goods or services to Data Principals within the territory of India." The construction is broad. A US-incorporated lender taking applications from Indian residents is in. A Singapore-incorporated SaaS vendor processing employee data of an Indian customer's workforce is in. Establishment in India is not the predicate. Targeting of Data Principals in India is.

Section 16, by contrast, governs transfer. Sub-section (1) permits transfer of personal data by a Data Fiduciary outside India, subject to such restrictions as the Central Government may, by notification, impose in respect of any country or territory outside India. Sub-section (2) clarifies that nothing in Section 16 restricts the applicability of any law for the time being in force in India that provides for a higher degree of protection on transfer. The architecture is permissive-with-blacklist, not whitelist-with-adequacy as under GDPR Articles 44 to 49. Sibling privacy reading across regimes: GDPR Article 22, China PIPL, and HIPAA read against AI agents.

07 · CHAPTER V · THE BOARD

The Data Protection Board of India, per Sections 18 to 26.

The Data Protection Board of India is the regulator. The earlier Warrant content cited Chapter VIII and Section 27 onwards for the Board. That is a regression. The Board is established under Section 18 in Chapter V of the Act. Chapter VIII is Penalties and Adjudication, where Section 33 sits. The two are different chapters and answer different questions.

With effect from such date as the Central Government may, by notification, appoint, there shall be established, for the purposes of this Act, a Board to be called the Data Protection Board of India. DPDP Act 2023 · § 18(1)

Section 19 governs composition. The Board is to consist of a Chairperson and such number of other Members as the Central Government may notify. Members must be persons of ability, integrity, and standing with special knowledge or practical experience in data governance, administration or implementation of laws related to social or consumer protection, dispute resolution, information and communication technology, digital economy, law, regulation or techno-regulation, or in any other field which in the opinion of the Central Government may be useful. At least one member must be an expert in the field of law.

Section 20 sets the term at two years with eligibility for re-appointment. Section 21 lists disqualifications. Section 27 sets out the powers and functions of the Board, the most operative being directing remedial or mitigation measures in the event of a personal data breach, inquiring into a breach of the provisions of the Act, and imposing penalties as provided under the Act.

The operational status of the Board, as at 9 May 2026, is the half-step. By G.S.R. 843(E) of 13 November 2025, Section 1(2), Section 2, Sections 18 to 26, Sections 35 and 38 to 43, and Section 44(1) and (3) of the Act came into force on publication, alongside Rules 1, 2, and 17 to 21 of the DPDP Rules 2025. Section 6(9) and Section 27(1)(d) follow one year from publication. The Board has legal existence. Its proceedings are conducted under Section 23, which requires it to observe such procedure as may be prescribed — prescribed by Rule 19, not set by the Board itself. Public reporting through April 2026 indicates the Chairperson and full slate of Members had not yet all been appointed. The search-cum-selection committee process under the Rules has been initiated. The Board's substantive enforcement clock is running quietly. It does not yet bite. It bites in mid-May 2027, when Section 33 and the Schedule penalties attach.

08 · DPDP RULES 2025

What the Rules added.

The DPDP Rules 2025 were notified by the Ministry of Electronics and Information Technology by Gazette notification on 13 November 2025. They run twenty-three rules in seven schedules. The Rules are not new obligations. They are the prescribed form and manner for the obligations the Act delegates. Each "as may be prescribed" in the Act points to a Rule.

Rule 1 sets a phased commencement. Three groups. Neither the Rules nor G.S.R. 843(E) states a calendar date for the later two. Rule 1(3) says "one year after" and Rule 1(4) says "eighteen months after" the date of publication of the Rules in the Official Gazette; the Act's own 18-month tranche is worded the same way. The reference date is itself ambiguous on the face of the record: the Gazette issue is headed "No. 757] NEW DELHI, THURSDAY, NOVEMBER 13, 2025" and the notification is signed 13 November 2025, while the e-Gazette identifier reads CG-DL-E-14112025-267647 and the Controller's digital signature reads 2025.11.14. Reading the reference date as 14 November 2025 and applying Section 9 of the General Clauses Act 1897, which excludes the first day for "from", yields 14 May 2027; reading it as 13 November 2025 yields 13 May 2027. This entry takes the later, more conservative reading and says mid-May 2027 where a range will do.

PHASE I
In force on publication, 13 November 2025: Rules 1, 2, and 17 to 21. The Board apparatus, search-cum-selection committee, and procedural rules. EFFECT · the Board exists. The Chairperson and Members can be appointed. Procedures can be set.
PHASE II
In force one year after publication, in November 2026: Rule 4. Registration and obligations of Consent Managers. EFFECT · Section 6(9), the Consent Manager registration power, commences on the same one-year clock under G.S.R. 843(E). Data Principals get a registered intermediary route to consent.
PHASE III
In force eighteen months after publication, mid-May 2027: Rules 3 and 5 to 16, and 22 to 23. Notice form, verifiable consent, breach intimation form, retention duration, contact information, processing of children's data, Significant Data Fiduciary obligations, transfer restrictions, and exemptions. EFFECT · on the same clock, G.S.R. 843(E) commences Sections 3 to 5, Section 6(1) to (8) and (10), Sections 7 to 17, Section 27 except clause (d), Sections 28 to 34, 36 and 37, and Section 44(2). That tranche carries both the substantive obligations and the Section 33 penalty machinery the Schedule hangs off.

The most operationally consequential rules to know now, in advance of mid-May 2027:

Rule 3. Form and content of notice under Section 5. The notice must be in clear and plain language, accessible independently of any other information, and itemised against the personal data, the specified purpose, the goods or services involved, the description of rights of the Data Principal, and the manner of complaint to the Board.

Rule 7. Form and manner of intimation of personal data breach. First intimation without delay. Detailed report to the Board within 72 hours of awareness, or such longer period as the Board may allow on a written request. Intimation to each affected Data Principal without delay, in a concise, clear and plain manner, through her user account or any registered mode of communication. The Eighth-Schedule language option belongs to Section 5(3) of the Act, which governs notices; Rule 7 carries no language menu.

Rule 8. Time period for retention by certain Data Fiduciaries and the deemed-erasure trigger. For Data Fiduciaries falling within the prescribed classes (operationally, large e-commerce, social media intermediaries, and online gaming intermediaries above prescribed user thresholds), the deemed-erasure window under Section 8(8) is three years from the last engagement, after which Section 8(7) erasure applies.

Rule 13. Additional obligations of Significant Data Fiduciaries. Data Protection Impact Assessment and audit once every twelve months, the audit conducted by an independent data auditor, observation of due diligence by the Significant Data Fiduciary in respect of any algorithmic software it deploys, and verification that personal data flowing into algorithmic decisioning is not used in a manner that poses a risk to rights of Data Principals.

Rule 15. Restrictions on transfer of personal data outside India. The Data Fiduciary must meet such requirements as the Central Government may, by general or special order, specify in respect of making such personal data available to any foreign State, or to any person or entity under the control of, or any agency of, such a foreign State. The Rule does not enumerate countries; the architecture is permissive-with-future-blacklist.

09 · OBLIGATION MAPPING

What Warrant maps, and what it does not.

Warrant's DPDP coverage is exactly as wide as its corpus, and no wider. The corpus carries five cited DPDP sub-clauses. Those five are the only DPDP pinpoints a package can name: the obligation schema restricts every citation to an identifier that exists in the corpus, so an obligation Warrant has not mapped cannot be asserted in a record. The rows below are those five.

§ 4(1)
Processing only for a lawful purpose, on consent or a legitimate use. CORPUS ID · dpdp_2023.4.1 · obligation key lawful_basis_recorded
§ 6(1)
Consent free, specific, informed, unconditional, unambiguous, and limited to the personal data necessary for the specified purpose. CORPUS ID · dpdp_2023.6.1 · obligation key purpose_limitation
§ 8(2)
A Data Processor may be engaged only under a valid contract. CORPUS ID · dpdp_2023.8.2 · obligation key processor_agreements_documented
§ 8(6)
Intimation of a personal data breach to the Board and to each affected Data Principal, in the form and manner prescribed by Rule 7. CORPUS ID · dpdp_2023.8.6 · obligation key breach_intimation_to_board
§ 11(1)
Right to a summary of personal data processed, the identities of recipients, and prescribed further information. CORPUS ID · dpdp_2023.11.1 · obligation key data_principal_rights_honored

What a package actually records against each of those, per action extracted from the trace: the obligation id, a compliance verdict of satisfied, gap, uncertain, or unvalidated, a confidence number, and the evidence relied on. A DPDP row in a package signed today is a forward-looking readiness finding rather than a finding of present breach, because the substantive tranche is not yet in force. The package does not say so on its face under the shipped default. The two fields that would carry it — applies_from on an obligation row, and the package-level deferred_regimes map — are gated. The deferral classification runs on every attestation and is logged, and it reaches the signed aggregate, the PDF and the receipt only where an operator has switched the deferral-label mode on. Absent that, the record is silent on the question rather than asserting the regime was in force, and the 2027-05-14 date has to be read off this entry rather than off the package.

Sections 8(3), 8(4), 8(5), 8(7) and 16 are read in this entry but are not mapped in the corpus, so no package cites them. Adding a sub-clause is a corpus change, and a corpus change is a provenance event: every package records the digest of the corpus version it was assessed against.

The specimen below is a real register record, and it is a specimen from another domain: it is shown because the shape of the record is the point, not its regime coverage. It is an India-jurisdiction record in the claims domain, not a lending record. A package does carry its own regulator mapping — classification.regimes and the package-level coverage_by_regime — but the register's public columns expose only domain, jurisdiction, risk tier and counts, not which regimes a given record cites. Nothing on the card should be read as evidence that a DPDP row was mapped in it; nothing here asserts that one was not.

W
Sample Indian claims-domain evidence package · Warrant registerINDIA-JURISDICTION RECORD · REGIME COVERAGE NOT DISCLOSED BY THE REGISTER
→ /verify?id=5bae6a8afc0374d7
10 · SECTORAL STACK

DPDP, RBI FREE-AI, and the sectoral overlay.

The DPDP Act applies to every Data Fiduciary processing digital personal data in India, full stop. The sectoral regulators do not displace it. They stack on top. A regulated bank deploying an AI agent in retail credit reads at least three concurrent layers, and they are not all enforceable yet.

The first layer is the DPDP Act and Rules. Section 8 obligations on accuracy, security, breach, and erasure will attach, and Section 16 transfer restrictions with them, when the eighteen-month tranche commences in mid-May 2027. The Board already exists and is the supervisor for the personal-data dimension.

The second layer is the Reserve Bank of India guidance. The RBI Framework for Responsible and Ethical Enablement of AI (FREE-AI) report, released by the FREE-AI Committee in 2025, sets out seven sutras and twenty-six recommendations across six strategic pillars covering infrastructure, capacity, governance, protection, assurance, and policy. The recommendations would land on regulated entities through subsequent RBI Master Directions and circulars. They have not yet: as of a corpus check on 31 July 2026, RBI has issued no instrument adopting them, so FREE-AI is a committee report and not an enforceable obligation. Nothing in the report weakens Section 8. What it recommends — explainability, model risk management, human override — runs beyond the DPDP floor, and a lender planning against it is planning against a recommendation, not a direction.

The third layer is sector-specific. SEBI's retail algo framework and AI/ML disclosure norms attach to brokers and asset managers. IRDAI's information and cyber security guidelines and outsourcing directions attach to insurers. CERT-In's six-hour incident notification rule of 28 April 2022, made under Section 70B(6) of the Information Technology Act 2000, runs alongside the DPDP 72-hour clock for cyber-security incidents. Six hours to CERT-In. Without delay then 72 hours to the Board. Both apply. Both must be evidenced.

11 · AI IMPLICATIONS

What Section 8 means for an AI agent.

Read Section 8(3) at the speed of an automated decision system. The clause attaches when personal data is "likely to be used to make a decision that affects the Data Principal." For a credit-scoring agent, an underwriting agent, a fraud-screening agent, or a hiring-shortlist agent, that condition is satisfied on every run. The accuracy obligation, "completeness, accuracy and consistency," is then the obligation. Three elements. Each separately enforceable.

Completeness reads as: did the agent see the personal data the specified purpose required. A credit-decision agent that decided on a partial bureau pull, where the full bureau pull would have changed the outcome, may fail this leg even if the partial data the agent saw was internally accurate. The Section 33(2) sizing factors include the gravity of the breach. A wrong credit decline made on incomplete data is graver than one made on bad-format data.

Accuracy reads as: was the personal data the agent saw faithful to the source. This is the field where input-validation and source-provenance attestation pay back. A lineage from bureau API to model input, independently verifiable without contacting Warrant, is the answer.

Consistency reads as: did the agent's view of the personal data agree with the same data held by the same Data Fiduciary in adjacent systems. A Data Fiduciary maintaining one address in CRM and another in the credit decisioning system, on the same Data Principal, with no reconciliation, fails the consistency leg even if both are individually accurate.

Section 8(4) reads, for an AI agent, into the technical and organisational measures around the agent itself. The Significant Data Fiduciary regime in Section 10, read with Rule 13, attaches additional duty of due diligence on algorithmic software. The combination is: maintain evidence, on every decision, that the input was complete, accurate, and consistent at the time of decision, and that the model was within its approved purpose.

This is what an attestation layer does. One artefact per trace: an obligation row per extracted action, mapped to the DPDP sub-clauses the corpus carries, independently verifiable without contacting Warrant. The DPDP Act does not require this artefact by name, and Warrant does not map every clause read above. The Schedule penalty exposure for failure to evidence the obligations that are mapped makes their absence expensive from mid-May 2027.

12 · FAQ

Questions a compliance officer asks first.

Does the DPDP Act apply to a company established outside India?

Yes. Section 3(b) applies the Act to processing of digital personal data outside the territory of India if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India. Extra-territorial scope sits in Section 3, not Section 16. Section 1(2) is the commencement clause. Section 16 governs onward transfer.

What is the breach-notification window under the DPDP regime?

Section 8(6) of the Act requires intimation to the Board and to each affected Data Principal in such form and manner as may be prescribed. Rule 7 of the DPDP Rules 2025 prescribes the manner. First intimation to the Board and to affected Data Principals without delay. Detailed report to the Board within 72 hours of becoming aware, or such longer period as the Board may, on written request, allow.

What is the maximum monetary penalty under the DPDP Act?

The Schedule to the Act caps the penalty for breach of Section 8(5), failure to take reasonable security safeguards, at Rs 250 crore. Failure to give breach intimation under Section 8(6) is capped at Rs 200 crore. Section 33(2) instructs the Board to size the penalty against gravity, repetitiveness, gain realised, mitigation taken, and proportionality.

Is the Data Protection Board of India operational as of May 2026?

Sections 18 to 26 of the Act, governing the establishment of the Board, were brought into force by G.S.R. 843(E) of 13 November 2025, alongside Section 1(2), Section 2, Sections 35 and 38 to 43, Section 44(1) and (3), and Rules 1, 2, and 17 to 21 of the DPDP Rules 2025. Public reporting through April 2026 indicates that the Chairperson and full slate of Members had not yet all been appointed. Substantive Section 8 obligations and Schedule penalties are not yet in force: they commence eighteen months from that Gazette publication, which derives to 14 May 2027 on the conservative reading and 13 May 2027 on the Gazette head-date reading. Stated as of 9 May 2026.

What does Section 8(3) require for an AI agent that decides about a person?

Section 8(3) requires that where personal data processed by a Data Fiduciary is likely to be used to make a decision that affects the Data Principal, or disclosed to another Data Fiduciary, the Data Fiduciary shall ensure its completeness, accuracy, and consistency. For an AI agent making automated decisions, the obligation extends past input data into the decision-relevant feature space and any inter-fiduciary handoff.

How does the DPDP Act sit alongside RBI, SEBI, and IRDAI guidance?

The DPDP Act is the cross-sector floor on personal data processing for every Data Fiduciary in India. Sectoral regulators stack on top. SEBI's norms for brokers and asset managers and IRDAI's directions for insurers add domain-specific obligations in regulated finance and insurance. RBI's FREE-AI report is a committee report: as of a corpus check on 31 July 2026, RBI had issued no instrument adopting its recommendations, so it is not itself an enforceable layer. CERT-In's six-hour cyber-incident clock does run in parallel.

What is a Significant Data Fiduciary?

Section 10 empowers the Central Government to notify any Data Fiduciary or class of Data Fiduciaries as a Significant Data Fiduciary, having regard to the volume and sensitivity of personal data, risk to rights of Data Principals, sovereignty and integrity of India, security of the State, electoral democracy, and public order. SDFs carry additional obligations to appoint a Data Protection Officer based in India, an independent data auditor, and to undertake periodic Data Protection Impact Assessment and audit.

When do the substantive obligations of the DPDP Act actually bite?

Not yet. Per Rule 1 of the DPDP Rules 2025, Rules 1, 2, and 17 to 21 came into force on publication, 13 November 2025. Rule 4, governing Consent Manager registration, comes into force one year after publication, in November 2026. Rules 3 and 5 to 16 and 22 to 23, which carry the operative consent, notice, breach-notification, transfer, and verifiable-consent regime, come into force eighteen months after publication. G.S.R. 843(E) puts Sections 3 to 5, Section 6(1) to (8) and (10), Sections 7 to 17, Section 27 except clause (d), Sections 28 to 34, 36 and 37, and Section 44(2) of the Act on the same eighteen-month clock, and Section 33 sits in that tranche, so the Schedule penalties attach with it. Neither instrument states a calendar date. Eighteen months derives to 14 May 2027 on the conservative reading of the Gazette publication date and 13 May 2027 on the head-date reading.

How do I produce a DPDP evidence package today?

Drop the agent's execution trace at warrant.build/demo. Warrant produces a PDF carrying an obligation row per extracted action against the DPDP sub-clauses its corpus maps — Sections 4(1), 6(1), 8(2), 8(6), and 11(1) — each with a compliance verdict and the evidence relied on. It does not stamp those rows with the 2027-05-14 application date under the shipped default: applies_from and the package-level deferred_regimes map are computed and logged on every attestation but reach the signed record only where an operator has enabled the deferral-label mode. Sections 8(3), 8(4), 8(5), 8(7) and 16 are not mapped, so no package cites them. The record is verifiable independently of Warrant's infrastructure.

13 · READ THE SOURCE

Read the source directly.

Authored by Warrant Compliance, the regulatory-analysis function at Warrant. [email protected]. Editorial commentary on regulatory text. Not legal advice. Verbatim quotations of Sections 1(1), 2, 3, 4(1), 6(1), 8, 11(1), and 18(1) of the Digital Personal Data Protection Act, 2023 reflect the official English-language text published by the Ministry of Electronics and Information Technology, Government of India. Sections 5, 7, 10, 12 to 17, and 19 to 27 are paraphrased, not quoted. References to the DPDP Rules, 2025 reflect the Gazette notification of 13 November 2025 (G.S.R. 846(E)) and the phased commencement in Rule 1; commencement of the Act itself is by G.S.R. 843(E) of the same date. No instrument states a calendar date for the eighteen-month tranche; 14 May 2027 is derived, and the derivation is set out in section 08 above. Operational status of the Data Protection Board of India is stated as of 9 May 2026; subsequent appointments may have changed the position.