Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025
India's law on the processing of digital personal data. It sets the grounds for processing (consent and certain legitimate uses), what a notice and a request for consent must contain, and the obligations of a Data Fiduciary: reasonable security safeguards, intimation of a breach to the Data Protection Board of India and to each affected Data Principal, erasure, and a grievance mechanism. Data Principals have rights of access, correction, erasure and nomination. Significant Data Fiduciaries and Consent Managers carry further obligations. The 2025 Rules set the minimum safeguards, a detailed breach report within seventy-two hours, retention and erasure periods, and how consent for a child is verified.
Controls: 69
Total Mappings: 210
Publisher: Government of India, Ministry of Electronics and Information Technology Version: 2023/2025 AC (6) AU (7) CA (2) CM (3) CP (5) IA (3) IR (4) MP (1) PE (1) PM (11) PT (6) RA (3) SA (4) SC (5) SI (8)
AC Access Control
| Control | Name | India DPDPA References |
|---|---|---|
| AC-02 | Account Management | Rules.6(1)(b) |
| AC-03 | Access Enforcement | Act.8(5)Act.11Rules.6(1)(b)Rules.Sch1.B.3-4Rules.Sch1.B.7Rules.Sch2 |
| AC-04 | Information Flow Enforcement | Act.16Rules.13(4)Rules.15 |
| AC-06 | Least Privilege | Act.8(5)Rules.6(1)(b)Rules.Sch1.B.7 |
| AC-17 | Remote Access | Rules.6(1)(b) |
| AC-21 | Information Sharing | Rules.15 |
AU Audit and Accountability
| Control | Name | India DPDPA References |
|---|---|---|
| AU-02 | Event Logging | Rules.6(1)(c) |
| AU-03 | Content of Audit Records | Rules.6(1)(c) |
| AU-06 | Audit Record Review, Analysis, and Reporting | Act.8(5)Rules.6(1)(c)Rules.Sch1.B.7 |
| AU-07 | Audit Record Reduction and Report Generation | Rules.6(1)(c) |
| AU-10 | Non-repudiation | Act.6(10) |
| AU-11 | Audit Record Retention | Rules.6(1)(e)Rules.8(3)Rules.Sch1.B.3-4 |
| AU-12 | Audit Record Generation | Rules.6(1)(c) |
CA Security Assessment and Authorization
CM Configuration Management
CP Contingency Planning
IA Identification and Authentication
IR Incident Response
MP Media Protection
| Control | Name | India DPDPA References |
|---|---|---|
| MP-06 | Media Sanitization | Act.8(7)Rules.8(1) |
PE Physical and Environmental Protection
| Control | Name | India DPDPA References |
|---|---|---|
| PE-03 | Physical Access Control | Rules.6(1)(b) |
PM Program Management
| Control | Name | India DPDPA References |
|---|---|---|
| PM-01 | Information Security Program Plan | Rules.6(1)(g) |
| PM-05 | System Inventory | Act.11 |
| PM-14 | Testing, Training, and Monitoring | Act.8(4)Rules.6(1)(g) |
| PM-18 | Privacy Program Plan | Act.8(1)Act.8(4) |
| PM-19 | Privacy Program Leadership Role | Act.8(1)Act.8(4)Act.8(9)Act.10(2)(a)Rules.9Rules.Sch2 |
| PM-20 | Dissemination of Privacy Program Information | Act.6(3)Act.8(9)Rules.9Rules.14(1)-(2)Rules.14(3)Rules.Sch2 |
| PM-21 | Accounting of Disclosures | Act.11Rules.Sch1.B.3-4 |
| PM-22 | Personally Identifiable Information Quality Management | Act.8(3)Act.12(2)Rules.Sch2 |
| PM-25 | Minimization of Personally Identifiable Information Used in Testing, Training, and Research | Rules.Sch2 |
| PM-26 | Complaint Management | Act.8(9)Act.8(10)Act.13Rules.9Rules.14(1)-(2)Rules.14(3) |
| PM-27 | Privacy Reporting | Rules.13(1)-(2)Rules.Sch1.B.12 |
PT Personally Identifiable Information Processing and Transparency
| Control | Name | India DPDPA References |
|---|---|---|
| PT-01 | Policy and Procedures | Act.8(4) |
| PT-02 | Authority to Process Personally Identifiable Information | Act.4Act.6(6)Act.7Act.9(3)Rules.Sch2 |
| PT-03 | Personally Identifiable Information Processing Purposes | Act.4Act.5(1)Act.5(2)Act.6(1)Act.7Rules.3Rules.Sch2 |
| PT-04 | Consent | Act.4Act.5(1)Act.6(1)Act.6(3)Act.6(4)Act.6(6)Act.6(7)-(9)Act.9(1)Rules.3Rules.4Rules.10Rules.11 |
| PT-05 | Privacy Notice | Act.5(1)Act.5(2)Act.5(3)Act.6(3)Rules.3Rules.Sch2 |
| PT-07 | Specific Categories of Personally Identifiable Information | Act.9(1)Act.9(2)Act.9(3)Rules.10 |
RA Risk Assessment
SA System and Services Acquisition
| Control | Name | India DPDPA References |
|---|---|---|
| SA-04 | Acquisition Process | Act.8(2)Rules.6(1)(f) |
| SA-08 | Security and Privacy Engineering Principles | Act.6(1)Act.8(4)Rules.Sch2 |
| SA-09 | External System Services | Act.6(6)Act.8(1)Act.8(2)Act.8(5)Act.8(7)Act.16Rules.6(1)(f)Rules.8(3)Rules.13(4)Rules.15Rules.Sch1.B.7 |
| SA-11 | Developer Testing and Evaluation | Rules.13(3) |
SC System and Communications Protection
| Control | Name | India DPDPA References |
|---|---|---|
| SC-07 | Boundary Protection | Act.8(5)Rules.13(4)Rules.Sch1.B.7 |
| SC-08 | Transmission Confidentiality and Integrity | Act.8(5)Rules.6(1)(a)Rules.Sch1.B.2Rules.Sch1.B.7Rules.Sch2 |
| SC-12 | Cryptographic Key Establishment and Management | Act.8(5)Rules.6(1)(a)Rules.Sch1.B.2Rules.Sch1.B.7 |
| SC-13 | Cryptographic Protection | Act.8(5)Rules.6(1)(a)Rules.Sch1.B.2Rules.Sch1.B.7 |
| SC-28 | Protection of Information at Rest | Act.8(5)Rules.6(1)(a)Rules.Sch1.B.7Rules.Sch2 |
SI System and Information Integrity
| Control | Name | India DPDPA References |
|---|---|---|
| SI-02 | Flaw Remediation | Act.8(5)Rules.Sch1.B.7 |
| SI-03 | Malicious Code Protection | Act.8(5)Rules.Sch1.B.7 |
| SI-04 | System Monitoring | Act.8(5)Rules.6(1)(c)Rules.Sch1.B.7 |
| SI-06 | Security and Privacy Function Verification | Rules.6(1)(g) |
| SI-07 | Software, Firmware, and Information Integrity | Act.8(5)Rules.Sch1.B.7 |
| SI-12 | Information Management and Retention | Act.6(1)Act.8(7)Act.12(3)Rules.6(1)(e)Rules.8(1)Rules.8(3)Rules.Sch1.B.3-4Rules.Sch2 |
| SI-18 | Personally Identifiable Information Quality Operations | Act.8(3)Act.12(2)Act.12(3)Rules.Sch2 |
| SI-19 | De-identification | Rules.6(1)(a) |