Data Privacy
under Indian law.
The DPDP Act, 2023 is in force in name and phased in substance: the Data Protection Board provisions commenced on 13 November 2025, Consent Manager registration under s.6(9) opens on 13 November 2026, and the entire operative regime — notice, consent, security safeguards, breach intimation, children's data, Data Principal rights, cross-border and the penalty Schedule — commences on 13 May 2027. Everything you build between now and then is measured against that date.
Last reviewed: 19 August 2026 · every citation on this page names the dataset it came from
- 9governing provisions
- 13product capabilities
- 2free tools
- 1free templates
- 5audiences
The DPDP Act, 2023 uses its own vocabulary, and using GDPR's instead is the first mistake. There is a Data Fiduciary, a Data Processor and a Data Principal; there is no 'controller' and no Article 28. Section 4 sets the grounds for processing, s.5 the notice, and s.6 consent — with s.6(10) placing the burden of proving valid consent on the Data Fiduciary, which is why consent-record architecture matters more than consent-notice wording.
Section 8 carries the general obligations: reasonable security safeguards under s.8(4)-(5), fleshed out by Rule 6 of the DPDP Rules 2025 including a one-year minimum retention for logs; breach intimation under s.8(6) with Rule 7's two-stage clock; and erasure under s.8(7)-(8) with Rule 8 and the Third Schedule. Section 9 governs children's data with verifiable parental consent under Rule 10, s.10 sets Significant Data Fiduciary obligations under Rule 13, ss.11-14 carry Data Principal rights with Rule 14's grievance mechanics, and s.16 is the cross-border restriction power that Rule 15 and Rule 13(4) operate through.
The free Data Processing Agreement in the library is drafted to this Act rather than translated from GDPR: statutory Data Fiduciary / Data Processor / Data Principal vocabulary, the Rule 6 security floor including the one-year log minimum, a breach window short enough for the Fiduciary's own 72-hour Board report, and cross-border handled the way s.16 actually works. The readiness quiz is fifteen weighted questions, each carrying its own section or rule citation, with every gap grouped against the phase date that makes it enforceable.
The provisions, with their section numbers.
Each row names the dataset it was taken from — the seeded statute library, the compliance calendar's own statutory reference, the bare Limitation Act, or the DPDP research set. Nothing here was written from memory.
Tools that apply to this work.
Each runs in your browser. Nothing is uploaded anywhere, and none of them needs an account.
Free templates for this area.
Free to copy, modify and use commercially, without attribution. They are starting points, not advice — have a qualified advocate or company secretary review anything before you sign it.
The capabilities that do this work.
Every one of these is a real feature page with its own status — Live, Beta or Soon. If it says Beta, it is in beta.
Self-serve gap analysis against DPDP Act §6 + §13 with a remediation plan.
Default region AWS ap-south-1 (Mumbai). Backups stay in India.
AES-256 at rest, TLS 1.3 in transit, AWS Mumbai region by default.
We do not train models on customer content without explicit opt-in. Default is off.
User-pasted text is sanitised before reaching the LLM.
A searchable record of state-changing actions across the workspace.
Role-based access (admin / member / guest) with per-folder overrides.
Per-document share links with expiry, password, and watermarking.
Firm-branded watermarks on shared documents; recipient-tagged prints.
Air-gapped install via Helm chart. No outbound telemetry when AIR_GAPPED=true.
Three-tier extraction cascade so PDF, DOCX, and scanned bilingual contracts all work.
Red, amber, or green for every clause, with an explanation and confidence score.
See which clauses are present, missing, or non-standard across your portfolio.
The people who do data privacy work.
Custom AI. Unlimited seats. Your data, your cloud.
Legal protection without the legal fees.
Stop signing investor docs you don't fully understand.
MSAs, SOWs and retainers — reviewed in seconds.
AI-native SEBI, RBI and AMFI compliance.
Data Privacy — the questions people actually ask.
Is the DPDP Act enforceable right now?
Not against an ordinary Data Fiduciary. G.S.R. 843(E) commenced the Act in three tranches. On 13 November 2025 only the Data Protection Board provisions came into force — s.1(2), s.2, ss.18-26, s.35, ss.38-43 and s.44(1) and (3), plus Rules 1, 2 and 17-21. Section 27, the Board's power to entertain complaints and inquire, was not among them: that phase created the institution, not the jurisdiction. On 13 November 2026 only s.6(9) and s.27(1)(d) commence, both about Consent Manager registration. The operative regime and the penalty Schedule commence on 13 May 2027.
Can I reuse my GDPR DPA in India?
You can, and it will read wrong. The DPDP Act uses statutory terms GDPR does not — Data Fiduciary, Data Processor, Data Principal — and its obligations do not map cleanly onto Article 28. The free DPDP data processing agreement in the library is drafted to the Act and the Rules directly: the Rule 6 security floor with its one-year log minimum, a breach window short enough for the Fiduciary's own reporting clock, and cross-border handled the way s.16 actually works rather than through an adequacy analogy.
How does the DPDP readiness quiz score me?
Fifteen weighted questions, each citing its own section of the Act or rule of the DPDP Rules 2025, producing a gap list grouped by the phase date on which each gap becomes enforceable. It is a self-assessment aid — explicitly not a compliance audit, not legal advice, and not a defence. Anything the underlying research could not confirm is carried as an open item rather than filled in with something plausible.
What does LexVio itself do with the documents I upload?
Storage is AES-256 at rest and TLS 1.3 in transit, with AWS Mumbai (ap-south-1) as the default region and backups kept in India. Models are not trained on customer content without explicit opt-in, and the default is off. User-pasted text is sanitised before it reaches the model as a prompt-injection defence. For deployments that cannot use a cloud at all, the air-gapped Helm install emits no outbound telemetry.
A map of the material, not advice on your matter. These hubs point at statutory text, free calculators and product capabilities. They are not legal advice, they do not create an advocate-client relationship, and they are no substitute for reading the bare Act as currently amended. Indian law is fact- and state-specific — stamp duty, registration and several employment obligations vary by state, and limitation turns on facts a web page cannot know. Take advice on your own facts before acting.
The law is in the document.
Let LexVio read it first.
Paste any contract. Get a Legal Health Score and the top risks in 30 seconds. No account needed.
Try the free scanner →