The DPDP Act 2023,
section by section.
All 44 sections across 9 chapters — official text, plain-English commentary, and the platform modules that operationalise each one.
Preliminary
Short title and commencement
Establishes the name and staged commencement. Companies should track government notifications because different sections can switch on at different times.
ReadDefinitions
Foundational vocabulary. Every role in the platform — tenants, principals, vendors, consent managers — maps directly to a definition here.
ReadApplication of the Act
Extra-territorial reach. Even India-targeting foreign businesses must comply. Onboarding wizard checks this for each tenant.
ReadObligations of Data Fiduciary
Grounds for processing personal data
Two-track lawful basis: consent (§6) OR legitimate use (§7). Drives the lawful_basis dropdown on every consent purpose.
ReadNotice
Drives the Notices module: each notice must satisfy a §5 checklist (purpose, data list, rights, grievance route, DPB complaint route, language coverage).
ReadConsent
Core of the Consent Management module and SDK. §6(4) parity test ensures withdrawal UX matches the grant UX.
ReadCertain legitimate uses
When a purpose uses §7, the consent widget is bypassed but the lawful_basis must be recorded and the Notice still applies. Reflected in lawful_basis dropdown.
ReadGeneral obligations of Data Fiduciary
Cross-cuts almost every module: Vendor contracts, Incident response (breach notification), Retention/erasure jobs, Grievance Officer in Settings.
ReadProcessing of personal data of children
Adds a "Children's Data" toggle per consent purpose, triggers parental-consent flow in the widget, and a hard-block on tracking purposes when enabled.
ReadAdditional obligations of Significant Data Fiduciary
Tenant flag is_sdf unlocks the SDF dashboard tab: DPO directory, annual DPIA cadence, audit export.
ReadRights and Duties of Data Principal
Right to access information about personal data
DSAR type = ACCESS. SLA tracked under §13 grievance redressal.
ReadRight to correction and erasure of personal data
DSAR types = CORRECTION, UPDATION, ERASURE.
ReadRight of grievance redressal
DSAR module SLA timer (typically 30 days). Escalation path: Fiduciary → Board.
ReadRight to nominate
Adds a nominee_contact field to consent records and to the DSAR submission form.
ReadDuties of Data Principal
Surfaced as disclaimer on the public DSAR portal and on the consent widget.
ReadSpecial Provisions
Data Protection Board of India
Establishment of Board
Reference. Drives the "Escalate to DPB" action in Incidents and DSARs.
ReadComposition and qualifications
Reference content for Act Explorer.
ReadSalary, allowances and conditions
Reference content for Act Explorer.
ReadDisqualifications, resignation, removal
Reference content for Act Explorer.
ReadOfficers and employees of Board
Reference content for Act Explorer.
ReadMeetings of Board
Reference content.
ReadAuthentication of orders
Reference content.
ReadMembers and officers to be public servants
Reference content.
ReadFunctions of Chairperson
Reference content.
ReadPowers, Functions, and Procedure of Board
Appeal and Alternate Dispute Resolution
Appeal to Appellate Tribunal
Captured as escalation path in incident timeline.
ReadOrders passed in appeal
Reference content.
ReadAlternate Dispute Resolution
"Initiate mediation" action on DSAR and Incident records.
ReadVoluntary undertaking
Reference content; informs Incident remediation flow.
ReadPenalties and Adjudication
Miscellaneous
Action by Central Government to be confidential
Drives the "Regulatory Notifications" feed surfacing on the dashboard.
ReadPower to call for information
Reference; tenants should be ready with audit-grade records.
ReadPower to block access to information
Reference.
ReadConsistency with other laws
Reference; the AI Assistant cross-checks for IT Act, RBI, SEBI overlap.
ReadBar of jurisdiction of civil courts
Reference content.
ReadPower of Central Government to make rules
The "Rules Tracker" — the DPDP Rules 2025 are the operational substance the platform monitors and applies.
ReadPower of Board to make regulations
Reference content.
ReadLaying of rules and regulations before Parliament
Reference content.
ReadPower to amend the Schedule
Penalty Calculator must update when Schedule is amended.
ReadPower to remove difficulties; consequential amendments
Important: RTI amendment narrows personal-information disclosure exemptions; AI Assistant flags any tenant flow that touches RTI requests.
Read