DPDPAcademyKnow the law. Prove it.
Home/Obligations
Chapter II · Sections 4–10

The Compliance Lifecycle, Ask To Erase

Sections 4 to 10 read as a sequence - from the moment data is asked for to the moment it must be deleted. Accountability never moves: the Data Fiduciary answers for its processors, whatever the contract says.

Step 01 · § 4Establish the groundProcess only for a lawful purpose - one not expressly forbidden by law - with consent, or under a certain legitimate use.
Step 02 · § 5Give noticeItemise the data and purpose, how rights are exercised, and how to complain to the Board - before or with the consent request. Pre-Act consents need a fresh notice too.
Step 03 · § 6Take consent properlyFree, specific, informed, unconditional, unambiguous, limited to the data necessary - withdrawable as easily as it was given, and provable by you in a proceeding.
Step 04 · § 8(5)Safeguard the dataReasonable security safeguards to prevent a personal data breach - including data held on your behalf by a processor. The single most expensive obligation to miss.
Step 05 · § 8(6)Report a breachIntimate the Board and every affected Data Principal in the prescribed form and manner. No materiality threshold appears in the section.
Step 06 · § 8(7)–(8)Erase when doneOn withdrawal of consent, or once the purpose is no longer served - and cause your processors to erase. The purpose is deemed served-out after the prescribed period of no contact.
Step 07 · § 8(9)–(10)Stay reachablePublish contact details of the Data Protection Officer or a person who can answer questions, and run an effective grievance mechanism.
Step 08 · § 8(3)Keep it accurateWhere data will be used to make a decision affecting the Data Principal, or disclosed to another Fiduciary, ensure completeness, accuracy and consistency.
Children - section 9Verifiable consent of the parent or lawful guardian before any processing. No processing likely to cause a detrimental effect on a child's well-being. No tracking, no behavioural monitoring, no targeted advertising directed at children.Government may exempt notified classes or purposes, or notify an age above which a verifiably safe Fiduciary is exempt. § 9(4)–(5)
Significant Data Fiduciaries - section 10Appoint a Data Protection Officer based in India, answerable to the board of directors and the contact point for grievances. Appoint an independent data auditor. Run periodic Data Protection Impact Assessments and audits.Notification turns on data volume and sensitivity, risk to rights, sovereignty and integrity of India, electoral democracy, security of the State and public order. § 10(1)

Certain legitimate uses - section 7

Nine closed categories where consent is not the basis. Read them narrowly: they are the exception, not a second consent regime.

(a) Data voluntarily provided for a specified purpose, where consent was not refused
(b) State providing a prescribed subsidy, benefit, service, certificate, licence or permit
(c) State functions under law, sovereignty and integrity, or security of the State
(d) Legal obligations to disclose information to the State
(e) Compliance with a judgment, decree or order
(f) Medical emergency threatening life or health
(g) Epidemic, outbreak of disease or other public-health threat
(h) Disaster or breakdown of public order
(i) Employment purposes, or safeguarding the employer from loss or liability
At a glance

The consent lifecycle, end to end

DPDP consent lifecycleA notice under section 5 precedes the consent request under section 6. Consent may be given directly or routed through a Consent Manager under section 6(7). Processing then proceeds under section 4. Consent can be withdrawn at any time under section 6(4), on which processing must cease under section 6(6). Erasure follows under section 8(7)(a), either on withdrawal or once the purpose is deemed no longer served under section 8(8), and the Data Fiduciary must cause its processors to erase under section 8(7)(b).Notice§ 5 · Rule 3Consent§ 6(1)Processing§ 4Consent Manager§ 6(7)–(9)her choiceWithdrawal§ 6(4)Cease processing§ 6(6)Erase§ 8(7)(a)Processor must erase§ 8(7)(b)Purpose deemed served§ 8(8) · § 8(11)Dashed routes are alternatives, not additional steps.
The consent lifecycle under sections 5 to 8. Withdrawal is not the end of the obligation - it starts the erasure path, and that path reaches your processors too.
Section 8(1)

The obligation you cannot contract away

Section 8(1) makes the Data Fiduciary responsible for compliance irrespective of any agreement to the contrary, and irrespective of any failure by the Data Principal to carry out her own duties. Two consequences follow, and both are easy to miss.

First, a processor contract allocates work and cost, never liability. When a processor loses data, the Board still looks at the Data Fiduciary. Second, a Data Principal who breaches her section 15 duties - say, by supplying false information - does not thereby reduce your obligations towards her data. Her breach is separately penalisable at up to ₹10,000; yours is not offset by it.

Note also the narrower scope of section 8(3). The duty to ensure completeness, accuracy and consistency bites only where the data is likely to be used for a decision affecting the Data Principal, or disclosed to another Data Fiduciary. It is not the general accuracy principle GDPR applies to all processing.

Act meets Rules

Where “as may be prescribed” got prescribed

Four of these duties are stated in the Act as principles and filled in by the DPDP Rules, 2025. The Rules are where the engineering work actually lives.

§ 5 - NoticeRule 3
The notice must itemise, not summariseAn itemised description of the personal data to be processed, the specified purpose, and a specific description of the goods, services or uses that the processing enables. It must be presented in clear and plain language and stand independently of other information, with links to withdraw consent, exercise rights and complain to the Board.What it means to build: A privacy policy does not satisfy this. The notice is a discrete artefact tied to the consent request, and it has to name the data rather than gesture at categories.
§ 8(5) - SafeguardsRule 6
Named measures, and a one-year log floorEncryption, obfuscation, masking or virtual tokens; appropriate access controls with visibility over who accessed what; retention of access logs and processing logs for at least one year; regular monitoring and review of those logs; business continuity and recovery arrangements; and the same obligations flowed down to processors by contract.What it means to build: The log floor is the operationally expensive one. One year of access and processing logs, monitored rather than merely stored, is an infrastructure commitment more than a policy commitment.
§ 8(6) - BreachRule 7
Two audiences, two clocks, no thresholdAffected Data Principals are told without delay. The Board receives an initial intimation without delay, then a detailed report within 72 hours, extendable only by the Board. There is no harm threshold anywhere in the section or the rule.What it means to build: This is the widest gap from GDPR. Article 33 lets you skip notification where a breach is unlikely to result in risk, and only tells individuals when risk is high. Here every personal data breach is reportable to both.
§ 8(7)–(8) - ErasureRule 8
An inactivity clock, and a warning before deletionFor specified classes of platform above stated user thresholds - e-commerce, online gaming and social media - personal data is erased after three years of user inactivity, with at least 48 hours notice to the individual before deletion. Separately, logs are kept a minimum of one year for lawful requests and investigations before being erased.What it means to build: Two systems, pulling opposite ways: delete the person's data on an inactivity timer, keep the logs about it for a year. Both need to be automated, and the 48-hour notice needs a delivery path that still works for a dormant account.
Worked example

One phone number, four sections

A delivery app collects a customer's mobile number so it can send order updates. Six months later, marketing wants to use the same numbers for promotional messages. Follow the sections in order and the answer is not a judgement call.

§ 4Is there a lawful basis for the original collection?Yes. The number is collected for order updates, a lawful purpose not forbidden by law, on the customer's consent. Nothing here is difficult.
§ 5 + Rule 3What did the notice have to say?It had to itemise the personal data (the mobile number), state the specified purpose (delivery updates for orders placed), describe the service that enables, and link to withdrawal, rights and Board complaints - in plain language, standing on its own rather than buried in terms of service.
§ 6(1)Does that consent stretch to marketing?No. Consent is limited to the personal data necessary for the specified purpose, and the specified purpose was order updates. Marketing is a different purpose, so it needs its own notice and its own consent. There is no legitimate-interest basis to fall back on, and none of the nine certain legitimate uses in section 7 covers promotional messaging.
§ 8(7)–(8)When must the number be deleted?When the customer withdraws consent, or as soon as it is reasonable to assume the purpose is no longer served - whichever is earlier. The Act deems the purpose served-out once the customer neither approaches you for it nor exercises any right for the prescribed period, and section 8(11) clarifies that means no contact initiated by her. You must also cause your SMS processor to erase its copy.

The trap is step three. Teams arriving from GDPR reach for legitimate interests to justify the marketing use, find it missing, and then try to read section 7(a) - data voluntarily provided - as a substitute. It is not: 7(a) is tied to the purpose for which the data was volunteered, which brings you back to order updates.

§ 8(6) · Rule 7

The breach sequence, in order

Two audiences and two clocks. Run them in parallel, because the obligation to the individual does not wait on the report to the Board.

01 · On becoming awareEvery affected Data PrincipalA description of the breach, its likely consequences, the measures being taken to mitigate it, and what the individual can do to protect themselves. Delivered through the channels you already hold for them.
02 · Without delayThe Data Protection BoardAn initial intimation covering the nature and extent of the breach, when and where it occurred, and its likely impact.
03 · Within 72 hoursThe Data Protection BoardA detailed report: the events and circumstances that led to the breach, the mitigation measures taken, the remedial steps to prevent recurrence, and confirmation of the intimations given to affected Data Principals. Extendable only on the Board's allowance.

Sections 4 to 10 sit in the eighteen-month tranche of the commencement notification, so these duties bite in mid-May 2027. The Rules are already notified, which means what they will require is known rather than speculative - see the commencement timeline and what binds you until then.

Eight steps down. One Schedule to go.See what each missed obligation costs before you sit the exam.

DPDP Academy Editorial: Legal education and implementation guidance. DPDP Academy Source Review: Primary-source verification against Gazette and MeitY publications; last checked 9 August 2026 against the DPDP Act, 2023 and notified DPDP Rules, 2025. Educational information, not legal advice.

Review standards and attribution →