Loading Vaultize
Skip to main content

Compliance/India/DPDP Act and Rules

Forty-four sections: eight provisions leave evidence in the file.

The Act makes the Data Fiduciary responsible for personal data wherever it is processed. Vaultize adds records that stay with the data.

  • Act No. 22 of 2023
  • Rules notified 14 Nov 2025
  • Phased commencement
  • Capability mapping, not legal advice

8(2)Obligations of Data Fiduciary

A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract.

Vaultize Share · Vaultize Seal

  1. I

    Preliminary

    0 of 3

    • 1
    • 2
    • 3
  2. II

    Obligations of Data Fiduciary

    2 of 7

    • 4
    • 5
    • 6
    • 7
    • 8
    • 9
    • 10
  3. III

    Rights and duties of Data Principal

    2 of 5

    • 11
    • 12
    • 13
    • 14
    • 15
  4. IV

    Special provisions

    1 of 2

    • 16
    • 17
  5. V

    Data Protection Board of India

    0 of 9

    • 18
    • 19
    • 20
    • 21
    • 22
    • 23
    • 24
    • 25
    • 26
  6. VI

    Powers and procedure of Board

    0 of 2

    • 27
    • 28
  7. VII

    Appeal and dispute resolution

    0 of 4

    • 29
    • 30
    • 31
    • 32
  8. VIII

    Penalties and adjudication

    0 of 2

    • 33
    • 34
  9. IX

    Miscellaneous

    0 of 10

    • 35
    • 36
    • 37
    • 38
    • 39
    • 40
    • 41
    • 42
    • 43
    • 44
Read againstThe Digital Personal Data Protection Act, 2023Act No. 22 of 2023 · Assented 11 August 2023
8provisions across 5 of 44 sections

The answer in 30 seconds

Vaultize adds file-level records to eight provisions in five sections of the Act, under the Data Fiduciary’s obligations, the Data Principal’s rights and transfers outside India. Consent, notice, the Board, appeals and penalties belong to the organisation and its counsel.

The Act in one view

Nine chapters. Forty-four sections. Where file evidence lands.

The Act runs in nine chapters. Select a chapter to see which of its sections a governed file can evidence.

IIIIIIIVVVIVIIVIIIIX

I

Preliminary

Sections 1 to 3. Title, commencement, definitions and application.

Outcomes the file can evidence

None on this page.

    How Vaultize contributes
    Definitions and application are matters for counsel. A governed file adds no evidence here.
    Evidence to retain
    None from Vaultize.

    Section by section

    What each section asks. What the file can answer.

    Section wording is quoted from the Act as published in the Gazette of India; longer sections are excerpted. Each row is a capability mapping, not legal advice. Read the Act and the Rules, and take advice on applicability and commencement.

    Using this page

    Where these rows fit in a DPDP programme.

    The Act commences in phases under the notification of 13 November 2025, and the Rules were notified on 14 November 2025. The rows above are evidence for the obligations that touch documents.

    1. 1

      Confirm applicability

      Which processing, which role, and which sections apply and from when.

    2. 2

      Find the personal data

      Where it sits in documents, who holds copies, and which processors received it.

    3. 3

      Apply safeguards

      Section 8(5). Seal rights and encryption into the documents. These rows belong here.

      Bring the eight rows above as evidence of reasonable security safeguards and of how requests are served.

    4. 4

      Serve the rights

      Sections 11 and 12. Answer access and erasure requests from the records. The Rules give ninety days.

    5. 5

      Keep the evidence

      For the Board, the data auditor and the Data Principal.

    Responsibility boundary

    Controls support compliance. They are not legal advice.

    Vaultize contributes technical safeguards and evidence for personal data held in documents. It does not decide whether the Act applies, what a reasonable safeguard is in a given case, or how the Rules prescribe form and manner. Read the Act, the Rules and the commencement notification, and take qualified advice before relying on this page.

    “A Data Fiduciary shall protect personal data in its possession or under its control, including in respect of any processing undertaken by it or on its behalf by a Data Processor, by taking reasonable security safeguards to prevent personal data breach.”

    Section 8(5), Digital Personal Data Protection Act, 2023

    A practical next step

    Bring one document that carries personal data.

    We will show which sections the governed document can evidence today. We will name the owner responsible for the rest.

    Request a compliance mapping session