The core rules

The obligations every Data Fiduciary carries: a ground for processing, the notice, valid consent and its withdrawal, legitimate uses, security safeguards, breach intimation, and how long personal data may be kept.

Module 2 of 6, 13 minutes, 7 lessons

Questions this module answers

  • How long can companies store personal data under the DPDP Act?
  • What must be included in a consent notice under the DPDP Act and Rules 2025?
  • What is a Consent Manager under the DPDP Act?
  • What are the breach notification timelines under the DPDP Act and Rules 2025?
  • Does the DPDP Act apply to small businesses and various sectors like MSMEs, law firms, fintechs, and educational institutions?

Figures use one colour per role, throughout the course:

  • Data Principal
  • Data Fiduciary
  • Data Processor
  • Consent Manager
  • Government and Board

This module covers the rules every Data Fiduciary lives with day to day: the ground for processing, the notice, consent, the legitimate uses, the general duties, breaches and retention. Rules 3applies from 13 May 2027, 6applies from 13 May 2027, 7applies from 13 May 2027 and 8applies from 13 May 2027, and the Third Scheduleapplies from 13 May 2027, apply from 13 May 2027; the Act's sections start on the dates the Central Government notifies.

Two grounds, and nothing else

Section 4 lets you process personal data only for a lawful purpose, meaning one that no law expressly forbids, and only on one of two grounds. Either the Data Principal has given her consent, or the processing is for one of the legitimate uses that Section 7 lists.

Section 4: two grounds, and no third

Ground 1: consent

  • The Data Principal has given her consent for the purpose. Section 4(1)(a)
  • A notice must accompany or precede the request for consent. Section 5(1)
  • She may withdraw at any time, as easily as she gave it. Section 6(4)
  • If it is questioned in a proceeding, you must prove the notice and the consent. Section 6(10)

Ground 2: a legitimate use

  • The processing is for “certain legitimate uses”. Section 4(1)(b)
  • It must fit one of the uses Section 7 lists, read as written. Section 7
  • Processing that fits none of them has only consent left as its ground. Section 4(1)

Both grounds need a lawful purpose, “any purpose which is not expressly forbidden by law”. Whichever ground you rely on, the general obligations in Section 8 apply in full.

Read the full lesson, with every provision it rests on (2 min)

Section 4 is the gate every piece of processing must pass. A person may process the personal data of a Data Principal only in accordance with the Act and for a lawful purpose, and only on one of two grounds: the Data Principal has given her consent (Section 4(1)(a)), or the processing is for "certain legitimate uses" (Section 4(1)(b)). Section 7 lists those uses, and a later lesson walks through them.

"Lawful purpose" has a short definition: "any purpose which is not expressly forbidden by law" (Section 4(2)). That is a low bar, but it is only half the test. A purpose that no law forbids still needs one of the two grounds. There is no third ground in Section 4. "It helps the business", "we have always done it" and "it is in our terms of service" are not grounds of their own; a clause in your terms counts only if it meets the consent standard in Section 6(1).

The choice of ground matters because it decides which other duties attach. If you rely on consent, you must give a notice first (Section 5(1)), the Data Principal may withdraw at any time (Section 6(4)), and if a question arises in a proceeding, you must prove that the notice was given and consent was obtained (Section 6(10)). If you rely on a legitimate use, you must fit the processing within one of the clauses of Section 7, read as written.

Whichever ground you use, the general obligations in Section 8 apply in full: accuracy, security, breach intimation, erasure and the rest. And Section 8(1) makes the Data Fiduciary responsible for complying with the Act "irrespective of any agreement to the contrary", including for processing a Data Processor does on its behalf.

The practical step is simple. For every purpose in your data inventory, write down which ground you rely on and why. If you cannot name one, stop that processing until you can.

The notice: what to tell people before you ask

When you ask for consent, Section 5(1) requires a notice with or before the request, telling her the data, the purpose, and how to withdraw, seek redress and complain to the Board. From 13 May 2027, Rule 3applies from 13 May 2027 requires the notice to stand on its own, itemise the data and give her a link to act.

What a notice must contain
  • It stands on its own

    It must be “presented and be understandable independently” of any other information you make available.

    Rule 3(a)
  • It is in clear and plain language

    A fair account of what she needs to give specific and informed consent.

    Rule 3(b)
  • An itemised description of the personal data

    Section 5(1) asks for the personal data; Rule 3 asks for it item by item.

    Rule 3(b)
  • The purpose, and what the processing enables

    The specified purpose, with a specific description of the goods or services to be provided or the uses to be enabled.

    Rule 3(b)
  • How to withdraw consent, as easily as she gave it

    The particular link to your website or app, and any other means.

    Rule 3(c)
  • How to exercise her rights, including grievance redressal

    Section 5(1)
  • How to complain to the Board

    Section 5(1)
  • In English or an Eighth Schedule language, at her option

    Any language specified in the Eighth Schedule to the Constitution.

    Section 5(3)

Section 5 sets what the notice covers; Rule 3 sets the standard it must meet, from 13 May 2027. The notice goes with a request for consent.

Read the full lesson, with every provision it rests on (2 min)

Section 5(1) requires every request for consent to be "accompanied or preceded by a notice". The notice tells the Data Principal three things: the personal data and the purpose for which it is to be processed; how she can withdraw consent under Section 6(4) and use her right of grievance redressal; and how she can complain to the Board. The Act's illustration is a bank customer opening an account through an app and choosing a video-based identity check; the bank must describe the personal data and the purpose before it asks.

Section 5(2) deals with consent given before the Act commenced. The Data Fiduciary must give the same kind of notice "as soon as it is reasonably practicable", and may continue processing until the Data Principal withdraws her consent. The illustration suggests email, an in-app notification or another effective method.

Section 5(3) requires the option to read the notice in English or in any language specified in the Eighth Schedule to the Constitution.

Rule 3 sets the standard the notice must meet. It must be "presented and be understandable independently" of any other information the Data Fiduciary makes available (Rule 3(a)); a paragraph buried in a long policy does not meet that. It must give, in clear and plain language, a fair account of what the Data Principal needs to give specific and informed consent, including at the minimum an itemised description of the personal data, and the specified purposes with a specific description of the goods, services or uses the processing enables (Rule 3(b)). And it must give the particular link to the website or app, and describe any other means, through which she can withdraw consent as easily as she gave it, exercise her rights under the Act, and complain to the Board (Rule 3(c)).

Rule 3 applies from 13 May 2027. Section 5 ties the notice to consent: where you rely on a legitimate use rather than consent, Section 5(1) does not require one, though telling people what you do is rarely a mistake.

Under Section 6(1), consent counts only if it is free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the data the purpose needs. She may withdraw it at any time, as easily as she gave it, and you must then stop processing within a reasonable time.

Valid consent: every test must hold
  • Free and unconditional

    Section 6(1)
  • Specific and informed

    For the specified purpose, after a notice that accompanies or precedes the request (Section 5(1)).

    Section 6(1)
  • Unambiguous, with a clear affirmative action

    It must “signify an agreement” to the processing for the specified purpose.

    Section 6(1)
  • Limited to the data the purpose needs

    In the Act's telemedicine illustration, the phone contact list is not necessary, so consent covers the telemedicine service only.

    Section 6(1)
  • Asked in clear and plain language

    In English or an Eighth Schedule language at her option, with the contact details of a Data Protection Officer, where applicable, or another authorised person.

    Section 6(3)
  • Withdrawable at any time, as easily as it was given

    Section 6(4)
  • After withdrawal, processing stops

    Within a reasonable time, you cease and make your Data Processors cease, unless the Act, the Rules or another law requires or authorises processing without her consent.

    Section 6(6)

Any part of a consent that infringes the Act, the Rules or any other law is invalid to that extent, and the rest stands (Section 6(2)). Withdrawal ends consent for the future; processing before it stays lawful (Section 6(5)).

Read the full lesson, with every provision it rests on (2 min)

Section 6(1) sets the standard. Consent must be "free, specific, informed, unconditional and unambiguous with a clear affirmative action". It must signify agreement to processing for the specified purpose and be limited to the personal data necessary for that purpose. The Act's illustration is a telemedicine app that asks for consent to provide its service and to read the user's phone contact list. The contact list is not necessary for telemedicine, so the consent is limited to the telemedicine service.

Section 6(2) makes any part of a consent that infringes the Act, the Rules or any other law invalid to that extent. The illustration is an insurance customer who "consents" to waive her right to complain to the Board; that part of the consent is invalid, and the rest stands.

Section 6(3) requires every request for consent to be in clear and plain language, available in English or any language in the Eighth Schedule to the Constitution, and to give the contact details of a Data Protection Officer, where applicable, or another person authorised to respond to the Data Principal about her rights.

Section 6(4) gives the Data Principal the right to withdraw consent at any time, and withdrawal must be as easy as giving consent was. Under Section 6(5), she bears the consequences of withdrawing, and withdrawal does not make earlier processing unlawful. The illustration: a shopper who withdraws consent can be stopped from placing new orders, but the store may not stop processing needed to supply goods she has already paid for.

Once she withdraws, Section 6(6) requires the Data Fiduciary, within a reasonable time, to cease processing and to cause its Data Processors to cease, unless processing without her consent is required or authorised by the Act, the Rules or another law.

Finally, Section 6(10) puts the burden of proof on the Data Fiduciary: if consent is questioned in a proceeding, it must prove the notice and the consent. Keep a record of both. Consent Managers, under Section 6(7) to 6(9), are covered in module 4.

Section 7 lists nine uses for which you may process personal data without relying on consent. Most businesses meet three kinds: data a person voluntarily gave for a purpose, legal duties and court orders, and employment; the rest concern the State, medical emergencies, epidemics and disasters.

Section 7: the nine legitimate uses, in two groups

The uses most businesses meet

  • Personal data she voluntarily provided for a specified purpose, while she has not said she does not consent to that use Section 7(a)
  • A legal duty under Indian law to disclose information to the State or its instrumentalities Section 7(d)
  • Complying with a judgment, decree or order under Indian law, or a judgment or order on contractual or civil claims under a law outside India Section 7(e)
  • Employment, or safeguarding the employer from loss or liability Section 7(i)

The narrower uses

  • The State providing a prescribed subsidy, benefit, service, certificate, licence or permit, on the conditions set Section 7(b)
  • The State performing a function under Indian law, or in the interest of the sovereignty and integrity of India or the security of the State Section 7(c)
  • Responding to a medical emergency that threatens anyone's life or immediately threatens anyone's health Section 7(f)
  • Medical treatment or health services during an epidemic, outbreak of disease or other threat to public health Section 7(g)
  • Safety of, or assistance or services to, anyone during a disaster or a breakdown of public order Section 7(h)

Processing that fits one of these clauses, read as written, needs no consent. If it fits none, the ground is consent.

Read the full lesson, with every provision it rests on (2 min)

Section 7 lists the uses for which a Data Fiduciary may process personal data without relying on consent. Most businesses meet three of them.

Section 7(a) covers a specified purpose for which the Data Principal voluntarily provided her personal data, so long as she has not said she does not consent to that use. The Act gives two illustrations. A pharmacy customer who gives her phone number and asks for a payment receipt by SMS may be sent the receipt. A woman who messages a property broker for help finding a rented flat may be sent listings, but once she tells him she no longer needs help, he must stop processing her personal data. The clause covers the purpose she provided the data for; it says nothing about other purposes, so a new purpose needs its own ground.

Section 7(d) covers fulfilling a legal obligation to disclose information to the State or its instrumentalities, and Section 7(e) covers compliance with a judgment, decree or order under Indian law, or a judgment or order on contractual or civil claims under a law outside India.

Section 7(i) covers processing "for the purposes of employment" or to safeguard the employer from loss or liability. The Act's examples are preventing corporate espionage, keeping trade secrets, intellectual property and classified information confidential, and providing a service or benefit an employee asks for.

The remaining clauses are narrower. Section 7(b) and 7(c) concern the State: subsidies, benefits, services, certificates, licences and permits, and the State's functions under law or in the interest of sovereignty, integrity and security. Section 7(f) covers a medical emergency involving a threat to anyone's life or an immediate threat to health. Section 7(g) covers medical treatment or health services during an epidemic, outbreak or other threat to public health. Section 7(h) covers safety, assistance or services during a disaster or a breakdown of public order.

Read each clause as written. If your processing does not fit one, the ground is consent, with everything that brings.

What every Data Fiduciary must do

Section 8 lists duties that apply whichever ground you use: answer for your processors, keep data accurate, protect it, report breaches, erase it on time, and publish a contact and a grievance route. From 13 May 2027, Rule 6applies from 13 May 2027 sets the minimum security safeguards.

The standing duties of every Data Fiduciary
  • Answer for your Data Processors

    You are responsible for processing done by you or on your behalf, whatever any agreement says.

    Section 8(1)
  • Engage a Data Processor only under a valid contract

    Section 8(2)
  • Keep data complete, accurate and consistent

    Where it is likely to be used for a decision that affects her, or disclosed to another Data Fiduciary.

    Section 8(3)
  • Put technical and organisational measures in place

    Section 8(4)
  • Take reasonable security safeguards

    At the minimum: encryption, masking or virtual tokens; access control; logs, monitoring and review; backups; keeping logs and personal data for one year unless a law requires otherwise; a safeguards clause in each processor contract; and measures to see they are observed.

    Rule 6(1)
  • Tell the Board and each affected person about a breach

    Section 8(6)
  • Erase data when consent is withdrawn or the purpose is no longer served

    Unless a law requires you to keep it, and make your Data Processor erase it too.

    Section 8(7)
  • Publish a contact for questions about processing

    A Data Protection Officer, if applicable, or a person who can answer on your behalf.

    Section 8(9)
  • Run an effective grievance mechanism

    Section 8(10)

Section 8 applies to consent and legitimate uses alike. Rule 6 sets the minimum safeguards and applies from 13 May 2027.

Read the full lesson, with every provision it rests on (2 min)

Section 8 is the list of standing duties. Section 8(1) makes the Data Fiduciary responsible for compliance for all processing done by it or on its behalf by a Data Processor, whatever any contract says and even if the Data Principal fails in her own duties. Section 8(2) allows a Data Processor to be engaged only "under a valid contract". Where personal data is likely to be used to make a decision about the Data Principal, or disclosed to another Data Fiduciary, Section 8(3) requires the Data Fiduciary to ensure its completeness, accuracy and consistency. Section 8(4) requires appropriate technical and organisational measures to observe the Act and the Rules.

Section 8(5) requires reasonable security safeguards to prevent personal data breach, covering data in the Data Fiduciary's possession or control, including processing by a Data Processor. Rule 6(1) sets the minimum those safeguards must include:

  • data security measures such as encryption, obfuscation, masking or virtual tokens mapped to the data (Rule 6(1)(a));
  • control of access to the computer resources used by the Data Fiduciary or its Data Processor (Rule 6(1)(b));
  • visibility on who accesses the data, through logs, monitoring and review, so that unauthorised access can be detected, investigated and fixed (Rule 6(1)(c));
  • measures to keep processing going if data is compromised or lost, such as backups (Rule 6(1)(d));
  • keeping those logs and personal data for one year for that purpose, unless another law requires otherwise (Rule 6(1)(e));
  • a clause on reasonable security safeguards in the contract with each Data Processor (Rule 6(1)(f));
  • technical and organisational measures to make sure the safeguards are actually observed (Rule 6(1)(g)).

Rule 6 applies from 13 May 2027.

Section 8 also requires the Data Fiduciary to publish the business contact information of a Data Protection Officer, if applicable, or a person who can answer questions about processing (Section 8(9)), and to set up an effective mechanism to redress grievances (Section 8(10)). Module 3 explains how both work. The remaining duties, breach intimation and erasure, have lessons of their own.

When a breach happens

Section 8(6) requires you to tell the Board and each affected Data Principal about a personal data breach. From 13 May 2027, Rule 7applies from 13 May 2027 requires both to be told without delay once you become aware of it, and a detailed intimation to the Board within seventy-two hours.

A personal data breach: two tracks from the moment you know
  1. On becoming aware

    The clock starts

    Both tracks run from the moment you become aware of the breach.

    Rule 7(1)
  2. Without delay

    Tell each affected Data Principal

    Through her user account or a mode of communication she registered: what happened and when, the likely consequences for her, your mitigation measures, the safety measures she can take, and a contact for her queries.

    Rule 7(1)
  3. Without delay

    Tell the Board: the first intimation

    A description of the breach: its nature, extent, timing and location of occurrence, and the likely impact.

    Rule 7(2)(a)
  4. Within seventy-two hours

    Tell the Board: the detailed intimation

    Updated details; the events, circumstances and reasons behind the breach; mitigation measures; any findings about who caused it; remedial measures; and a report on the intimations to affected Data Principals. The Board may allow longer on a written request.

    Rule 7(2)(b)

Section 8(6) requires intimation to the Board and each affected Data Principal; Rule 7 sets the form and timing, from 13 May 2027. The first intimation to the Board does not wait for the investigation to finish.

Read the full lesson, with every provision it rests on (2 min)

Section 8(6) says that in the event of a personal data breach, the Data Fiduciary must give "the Board and each affected Data Principal" intimation of the breach, in the form and manner prescribed. Rule 7 prescribes it in two tracks that run at the same time, and applies from 13 May 2027.

To each affected Data Principal, Rule 7(1) requires intimation "without delay", to the best of the Data Fiduciary's knowledge, in a concise, clear and plain manner, through her user account or any mode of communication she has registered. It must cover:

  • a description of the breach, including its nature, extent and when it occurred;
  • the consequences relevant to her that are likely to arise;
  • the measures the Data Fiduciary has taken or is taking to mitigate risk, if any;
  • the safety measures she can take to protect her interests;
  • business contact information of a person who can answer her queries.

To the Board, Rule 7(2) sets two steps. First, "without delay", a description of the breach, including its nature, extent, timing and location of occurrence and the likely impact (Rule 7(2)(a)). Second, within seventy-two hours of becoming aware of the breach, or a longer period the Board allows on a written request, the detailed intimation (Rule 7(2)(b)): updated and detailed information on that description; the broad facts about the events, circumstances and reasons that led to the breach; mitigation measures taken or proposed; any findings about the person who caused it; remedial measures to prevent it happening again; and a report on the intimations given to affected Data Principals.

Three points follow. The first Board intimation does not wait for the investigation to finish; the seventy-two-hour step is where the detail goes. Neither Section 8(6) nor Rule 7 sets a minimum number of affected people or a type of data below which intimation is not needed. And the clock starts when the Data Fiduciary becomes aware of the breach, so a Data Processor that finds a breach should tell you at once; write that into the contract.

How long you may keep personal data

Under Section 8(7), you must erase personal data once consent is withdrawn or the purpose is no longer served, unless a law requires you to keep it. From 13 May 2027, Rule 8applies from 13 May 2027 sets a three-year period for three classes of large platform, a forty-eight-hour warning, and a one-year minimum for data and logs.

When personal data must go
  1. The trigger

    Consent is withdrawn, or the purpose is no longer served

    Whichever is earlier. The purpose counts as no longer served if she neither approaches you for it nor exercises her rights for the prescribed period (Section 8(8)).

    Section 8(7)
  2. Three years, for large platforms

    The prescribed period for three classes

    E-commerce entities and social media intermediaries with at least two crore registered users in India, and online gaming intermediaries with at least fifty lakh: three years from her last approach or exercise of rights, or from the commencement of the Rules, whichever is latest. Access to her user account and to stored virtual tokens is excepted.

    the Third Schedule
  3. At least forty-eight hours before

    Warn her before erasure

    Tell her the data will be erased unless she logs in, makes contact for the purpose, or exercises her rights.

    Rule 8(2)
  4. Then

    Erase, and make your Data Processor erase

    Unless a law requires you to keep it.

    Section 8(7)
  5. At least one year

    But keep the minimum record

    Personal data, associated traffic data and processing logs, for at least one year from the date of processing, for the purposes the Rules list, even if she deletes her account; then erase them unless a law requires longer.

    Rule 8(3)

Rule 8 and the Third Schedule apply from 13 May 2027. Outside the three classes of large platform, the Third Schedule sets no period and the Section 8(7) test applies on its own.

Read the full lesson, with every provision it rests on (2 min)

Under Section 8(7), unless retention is necessary to comply with a law in force, the Data Fiduciary must erase personal data when the Data Principal withdraws consent, or as soon as it is reasonable to assume the specified purpose is no longer being served, whichever is earlier. It must also cause its Data Processor to erase the data it passed on. In the Act's illustrations, an online marketplace that has helped a seller sell her used car may no longer keep her data, while a bank that must by law keep identity records for ten years after closure keeps them.

Section 8(8) adds a deeming rule. The purpose is treated as no longer served if the Data Principal neither approaches the Data Fiduciary for that purpose nor exercises her rights for a prescribed period. Under Section 8(11), she has not approached it in any period when she has not initiated contact, in person or in electronic or physical form.

Rule 8(1) and the Third Scheduleapplies from 13 May 2027 prescribe that period for three classes: e-commerce entities with not less than two crore registered users in India, online gaming intermediaries with not less than fifty lakh, and social media intermediaries with not less than two crore. For all purposes except giving her access to her user account and to virtual tokens she can use for money, goods or services, the period is three years from her last approach or exercise of rights, or from the commencement of the Rules, whichever is latest. Rule 8(2) requires at least forty-eight hours' notice to her before erasure, so she can log in or make contact and stop the erasure.

Rule 8(3) sets a floor: keep personal data, traffic data and processing logs for at least one year from the date of processing, for purposes the Rules list, then erase them unless another law requires longer. The Rule's illustration applies it even where the buyer deletes her account.

Outside the three classes, the Third Schedule sets no period; the Section 8(7) test applies. Rule 8 and the Third Schedule apply from 13 May 2027.