Home/Obligations
Chapter II · Sections 4–10

The Compliance Lifecycle, Ask To Erase

Sections 4 to 10 read as a sequence — from the moment data is asked for to the moment it must be deleted. Accountability never moves: the Data Fiduciary answers for its processors, whatever the contract says.

Step 01 · § 4Establish the groundProcess only for a lawful purpose — one not expressly forbidden by law — with consent, or under a certain legitimate use.
Step 02 · § 5Give noticeItemise the data and purpose, how rights are exercised, and how to complain to the Board — before or with the consent request. Pre-Act consents need a fresh notice too.
Step 03 · § 6Take consent properlyFree, specific, informed, unconditional, unambiguous, limited to the data necessary — withdrawable as easily as it was given, and provable by you in a proceeding.
Step 04 · § 8(5)Safeguard the dataReasonable security safeguards to prevent a personal data breach — including data held on your behalf by a processor. The single most expensive obligation to miss.
Step 05 · § 8(6)Report a breachIntimate the Board and every affected Data Principal in the prescribed form and manner. No materiality threshold appears in the section.
Step 06 · § 8(7)–(8)Erase when doneOn withdrawal of consent, or once the purpose is no longer served — and cause your processors to erase. The purpose is deemed served-out after the prescribed period of no contact.
Step 07 · § 8(9)–(10)Stay reachablePublish contact details of the Data Protection Officer or a person who can answer questions, and run an effective grievance mechanism.
Step 08 · § 8(3)Keep it accurateWhere data will be used to make a decision affecting the Data Principal, or disclosed to another Fiduciary, ensure completeness, accuracy and consistency.
Children — section 9Verifiable consent of the parent or lawful guardian before any processing. No processing likely to cause a detrimental effect on a child's well-being. No tracking, no behavioural monitoring, no targeted advertising directed at children.Government may exempt notified classes or purposes, or notify an age above which a verifiably safe Fiduciary is exempt. § 9(4)–(5)
Significant Data Fiduciaries — section 10Appoint a Data Protection Officer based in India, answerable to the board of directors and the contact point for grievances. Appoint an independent data auditor. Run periodic Data Protection Impact Assessments and audits.Notification turns on data volume and sensitivity, risk to rights, sovereignty and integrity of India, electoral democracy, security of the State and public order. § 10(1)

Certain legitimate uses — section 7

Nine closed categories where consent is not the basis. Read them narrowly: they are the exception, not a second consent regime.

(a) Data voluntarily provided for a specified purpose, where consent was not refused
(b) State providing a prescribed subsidy, benefit, service, certificate, licence or permit
(c) State functions under law, sovereignty and integrity, or security of the State
(d) Legal obligations to disclose information to the State
(e) Compliance with a judgment, decree or order
(f) Medical emergency threatening life or health
(g) Epidemic, outbreak of disease or other public-health threat
(h) Disaster or breakdown of public order
(i) Employment purposes, or safeguarding the employer from loss or liability
Eight steps down. One Schedule to go.See what each missed obligation costs before you sit the exam.

DPDP Academy Editorial: Legal education and implementation guidance. DPDP Academy Source Review: Primary-source verification against Gazette and MeitY publications; last checked 2 August 2026 against the DPDP Act, 2023 and notified DPDP Rules, 2025. Educational information, not legal advice.

Review standards and attribution →