← All 13 practice areas
Practice area 12 of 13

Data Privacy
under Indian law.

The DPDP Act, 2023 is in force in name and phased in substance: the Data Protection Board provisions commenced on 13 November 2025, Consent Manager registration under s.6(9) opens on 13 November 2026, and the entire operative regime — notice, consent, security safeguards, breach intimation, children's data, Data Principal rights, cross-border and the penalty Schedule — commences on 13 May 2027. Everything you build between now and then is measured against that date.

Last reviewed: 19 August 2026 · every citation on this page names the dataset it came from

What's in this hub
  • 9governing provisions
  • 13product capabilities
  • 2free tools
  • 1free templates
  • 5audiences
Assembled from what LexVio actually ships. Nothing here is a roadmap item.
What this area covers

The DPDP Act, 2023 uses its own vocabulary, and using GDPR's instead is the first mistake. There is a Data Fiduciary, a Data Processor and a Data Principal; there is no 'controller' and no Article 28. Section 4 sets the grounds for processing, s.5 the notice, and s.6 consent — with s.6(10) placing the burden of proving valid consent on the Data Fiduciary, which is why consent-record architecture matters more than consent-notice wording.

Section 8 carries the general obligations: reasonable security safeguards under s.8(4)-(5), fleshed out by Rule 6 of the DPDP Rules 2025 including a one-year minimum retention for logs; breach intimation under s.8(6) with Rule 7's two-stage clock; and erasure under s.8(7)-(8) with Rule 8 and the Third Schedule. Section 9 governs children's data with verifiable parental consent under Rule 10, s.10 sets Significant Data Fiduciary obligations under Rule 13, ss.11-14 carry Data Principal rights with Rule 14's grievance mechanics, and s.16 is the cross-border restriction power that Rule 15 and Rule 13(4) operate through.

The free Data Processing Agreement in the library is drafted to this Act rather than translated from GDPR: statutory Data Fiduciary / Data Processor / Data Principal vocabulary, the Rule 6 security floor including the one-year log minimum, a breach window short enough for the Fiduciary's own 72-hour Board report, and cross-border handled the way s.16 actually works. The readiness quiz is fifteen weighted questions, each carrying its own section or rule citation, with every gap grouped against the phase date that makes it enforceable.

Indian law that governs this

The provisions, with their section numbers.

Each row names the dataset it was taken from — the seeded statute library, the compliance calendar's own statutory reference, the bare Limitation Act, or the DPDP research set. Nothing here was written from memory.

Act
Provision
What it says
Source
The Digital Personal Data Protection Act, 2023
s.5
Notice
The notice a Data Fiduciary must give a Data Principal, with the content detail supplied by Rule 3(a)-(c) of the DPDP Rules 2025.
DPDP dataset
The Digital Personal Data Protection Act, 2023
s.6
Consent
Free, specific, informed, unconditional and unambiguous consent — with s.6(10) putting the burden of proof on the Data Fiduciary.
DPDP dataset
The Digital Personal Data Protection Act, 2023
s.8(4)-(5)
Reasonable security safeguards
Read with Rule 6(1)(a)-(g), which supplies the security floor including the one-year minimum for logs.
DPDP dataset
The Digital Personal Data Protection Act, 2023
s.8(6)
Intimation of personal data breach
Read with Rule 7(1) and 7(2) — the two-stage breach intimation clock to the Data Principal and to the Board.
DPDP dataset
The Digital Personal Data Protection Act, 2023
s.9
Processing of personal data of children
Verifiable parental consent under Rule 10, guardianship for persons with disability under Rule 11, and the Fourth Schedule exemptions under Rule 12.
DPDP dataset
The Digital Personal Data Protection Act, 2023
s.10
Additional obligations of a Significant Data Fiduciary
Designation criteria in s.10(1) and obligations in s.10(2), operationalised by Rule 13.
DPDP dataset
The Digital Personal Data Protection Act, 2023
ss.11-14
Rights of the Data Principal
Access, correction and erasure, grievance redressal and nomination — with the mechanics in Rule 14(1)-(4).
DPDP dataset
The Digital Personal Data Protection Act, 2023
s.16
Processing outside India
The cross-border restriction power, read with Rule 15 and Rule 13(4). Not a GDPR-style adequacy regime.
DPDP dataset
The Digital Personal Data Protection Act, 2023
ss.28-34 and the Schedule
Board proceedings, appeals and penalties
The enforcement machinery, in force from 13 May 2027 under G.S.R. 843(E) cl.(c) — not from the 2025 or 2026 phase dates.
DPDP dataset
Free, no login

Tools that apply to this work.

Each runs in your browser. Nothing is uploaded anywhere, and none of them needs an account.

Free tool
DPDP Readiness Quiz

15-question weighted self-assessment against the DPDP Act 2023 and the DPDP Rules 2025.

Open tool →
Free tool
Free Contract Templates

India-first templates, free to copy, modify and use commercially, without attribution.

Open tool →
Drafting starting points

Free templates for this area.

Free to copy, modify and use commercially, without attribution. They are starting points, not advice — have a qualified advocate or company secretary review anything before you sign it.

Data Protection / Privacy
Data Processing Agreement (DPDP Act 2023) — India

Drafted to the DPDP Act 2023 and DPDP Rules 2025, not a re-badged GDPR Article 28 DPA. Statutory Data Fiduciary / Data Processor / Data Principal vocabulary, the Rule 6 security floor including the one-year log minimum, a breach window short enough for the Fiduciary's own 72-hour Board report, and cross-border handled the way Section 16 actually works.

Inside LexVio

The capabilities that do this work.

Every one of these is a real feature page with its own status — Live, Beta or Soon. If it says Beta, it is in beta.

CapabilityBeta
DPDP readiness assessment

Self-serve gap analysis against DPDP Act §6 + §13 with a remediation plan.

CapabilityLive
India data residency

Default region AWS ap-south-1 (Mumbai). Backups stay in India.

CapabilityLive
Encrypted vault

AES-256 at rest, TLS 1.3 in transit, AWS Mumbai region by default.

CapabilityLive
No model training on your data

We do not train models on customer content without explicit opt-in. Default is off.

CapabilityLive
Prompt injection defence

User-pasted text is sanitised before reaching the LLM.

CapabilityLive
Activity audit log

A searchable record of state-changing actions across the workspace.

CapabilityLive
Folder permissions

Role-based access (admin / member / guest) with per-folder overrides.

CapabilityLive
Shared document links

Per-document share links with expiry, password, and watermarking.

CapabilityBeta
Watermark & DRM

Firm-branded watermarks on shared documents; recipient-tagged prints.

CapabilityLive
On-prem deployment

Air-gapped install via Helm chart. No outbound telemetry when AIR_GAPPED=true.

CapabilityLive
Contract scanner

Three-tier extraction cascade so PDF, DOCX, and scanned bilingual contracts all work.

CapabilityLive
Clause-level risk scoring

Red, amber, or green for every clause, with an explanation and confidence score.

CapabilityLive
Nexus — Clause coverage map

See which clauses are present, missing, or non-standard across your portfolio.

Where it lives

The modules this area draws on.

Module
Compliance AI

SEBI, RBI, MCA/ROC and GST monitoring with alerts ahead of every deadline.

Module
Legal AI

Contract review, AI redlining, court research, fix suggestions and the Legal Health Score.

Who this is for

The people who do data privacy work.

Audience
Enterprise / MNC

Custom AI. Unlimited seats. Your data, your cloud.

Audience
Small Businesses

Legal protection without the legal fees.

Audience
Founders

Stop signing investor docs you don't fully understand.

Audience
Agencies

MSAs, SOWs and retainers — reviewed in seconds.

Audience
Financial Institutions

AI-native SEBI, RBI and AMFI compliance.

Questions

Data Privacy — the questions people actually ask.

Is the DPDP Act enforceable right now?

Not against an ordinary Data Fiduciary. G.S.R. 843(E) commenced the Act in three tranches. On 13 November 2025 only the Data Protection Board provisions came into force — s.1(2), s.2, ss.18-26, s.35, ss.38-43 and s.44(1) and (3), plus Rules 1, 2 and 17-21. Section 27, the Board's power to entertain complaints and inquire, was not among them: that phase created the institution, not the jurisdiction. On 13 November 2026 only s.6(9) and s.27(1)(d) commence, both about Consent Manager registration. The operative regime and the penalty Schedule commence on 13 May 2027.

Can I reuse my GDPR DPA in India?

You can, and it will read wrong. The DPDP Act uses statutory terms GDPR does not — Data Fiduciary, Data Processor, Data Principal — and its obligations do not map cleanly onto Article 28. The free DPDP data processing agreement in the library is drafted to the Act and the Rules directly: the Rule 6 security floor with its one-year log minimum, a breach window short enough for the Fiduciary's own reporting clock, and cross-border handled the way s.16 actually works rather than through an adequacy analogy.

How does the DPDP readiness quiz score me?

Fifteen weighted questions, each citing its own section of the Act or rule of the DPDP Rules 2025, producing a gap list grouped by the phase date on which each gap becomes enforceable. It is a self-assessment aid — explicitly not a compliance audit, not legal advice, and not a defence. Anything the underlying research could not confirm is carried as an open item rather than filled in with something plausible.

What does LexVio itself do with the documents I upload?

Storage is AES-256 at rest and TLS 1.3 in transit, with AWS Mumbai (ap-south-1) as the default region and backups kept in India. Models are not trained on customer content without explicit opt-in, and the default is off. User-pasted text is sanitised before it reaches the model as a prompt-injection defence. For deployments that cannot use a cloud at all, the air-gapped Helm install emits no outbound telemetry.

← Previous area
M&A
Next area →
General Legal
Back to all 13 practice areas →

A map of the material, not advice on your matter. These hubs point at statutory text, free calculators and product capabilities. They are not legal advice, they do not create an advocate-client relationship, and they are no substitute for reading the bare Act as currently amended. Indian law is fact- and state-specific — stamp duty, registration and several employment obligations vary by state, and limitation turns on facts a web page cannot know. Take advice on your own facts before acting.

The law is in the document.
Let LexVio read it first.

Paste any contract. Get a Legal Health Score and the top risks in 30 seconds. No account needed.

Try the free scanner →