Skip to main content

Sources last verified on 20 August 2026. Methodology

DPIA under the DPDP Act: who must do one, what it contains, when it starts

Compliance

By Abhijeet Singh · Reviewed by dpdprules.org source verificationPublished · Last reviewed 7 min read

The short answer

Only a Significant Data Fiduciary, meaning a Data Fiduciary or class of Data Fiduciaries notified by the Central Government under section 10, must conduct a Data Protection Impact Assessment. Section 10(2)(c) defines the DPIA as a process comprising a description of the rights of Data Principals and the purpose of processing of their personal data, and assessment and management of the risk to those rights. Rule 13 requires the DPIA and an audit once in every period of twelve months from notification, and a report containing significant observations must be furnished to the Data Protection Board of India. There is no high risk trigger for other Data Fiduciaries: an organisation that has not been notified has no statutory DPIA duty. Section 10 and Rule 13 commence on 13 May 2027, a computed date that is interpretation until officially confirmed, and no Significant Data Fiduciary has been notified as of 23 August 2026.

Search for DPIA advice in India and most of what you find is GDPR practice with the labels swapped: high risk triggers, screening questionnaires, necessity and proportionality tests, sign off by a Data Protection Officer. The DPDP Act builds its Data Protection Impact Assessment differently, and the differences change who has to act and what they have to produce. This article states what section 10(2)(c) of the DPDP Act 2023 and Rule 13 of the DPDP Rules 2025 actually require, what has deliberately been left unprescribed, and which GDPR habits to unlearn, with every DPDP claim cited to the Gazette text.

The trigger is a notification, not a risk threshold

Under the GDPR, a DPIA duty can land on any controller: Article 35(1) requires one where processing is "likely to result in a high risk to the rights and freedoms of natural persons". Every organisation must therefore screen its own processing against a risk threshold.

The DPDP Act has no equivalent. The DPIA duty appears once in the Act, inside section 10(2)(c), and the obligations in section 10 fall only on a Significant Data Fiduciary: "any Data Fiduciary or class of Data Fiduciaries as may be notified by the Central Government under section 10", per the definition in section 2(z). There is no self assessment and no threshold you can compute for yourself. Either the Central Government has notified you, or your class, as significant, or the statutory DPIA duty does not exist for you.

Two consequences follow. First, an organisation processing personal data at enormous scale has no DPIA duty until a notification covers it. Second, once notified, the duty is unconditional: there is no risk screening step in which an assessment can conclude that no assessment is needed.

As of 23 August 2026, no Data Fiduciary or class has been notified as significant, so no organisation in India currently carries the statutory DPIA obligation. How notification works and what else it brings is covered in the Significant Data Fiduciary obligations guide.

What the Act says a DPIA is

Section 10(2)(c)(i) requires a Significant Data Fiduciary to undertake a "periodic Data Protection Impact Assessment, which shall be a process comprising a description of the rights of Data Principals and the purpose of processing of their personal data, assessment and management of the risk to the rights of the Data Principals, and such other matters regarding such process as may be prescribed".

Read that definition slowly, because it is the entire statutory content of the Indian DPIA. It asks for three things:

  1. a description of the rights of Data Principals
  2. the purpose of processing of their personal data
  3. assessment and management of the risk to the rights of the Data Principals

The unit of analysis is the rights of the people whose data you process. The statutory rights of a Data Principal, access, correction and erasure, grievance redressal and nomination, live in sections 11 to 14, so a DPIA that cannot describe how those rights operate across your processing has missed the assignment before any risk scoring begins. Notice also what the definition does not mention: security architecture, vendor inventories, legitimate interests, necessity or proportionality. A DPIA under the DPDP Act is not a security review with a new name.

What Rule 13 adds: a twelve month clock and a report to the Board

The Act says "periodic" and leaves the schedule to the Rules. Rule 13 of the DPDP Rules 2025 supplies it.

The cycle. Rule 13(1) requires the Significant Data Fiduciary, "once in every period of twelve months from the date on which it is notified as such or is included in the class of Data Fiduciaries notified as such", to undertake a Data Protection Impact Assessment and an audit "to ensure effective observance of the provisions of this Act and the rules made thereunder". The clock starts at notification, not at a financial year end, and the DPIA travels together with the audit as one annual compliance exercise.

The report. Rule 13(2) requires the Significant Data Fiduciary to cause "the person carrying out the Data Protection Impact Assessment and audit to furnish to the Board a report containing significant observations". The findings do not stay internal: the Data Protection Board of India receives the significant observations every cycle, as a matter of course.

Rule 13 also carries two neighbouring duties, algorithmic due diligence under Rule 13(3) and a conditional localisation restriction under Rule 13(4), which are covered in the Significant Data Fiduciary obligations guide.

What has not been prescribed

The Act anticipates more detail: the definition in section 10(2)(c)(i) ends with "such other matters regarding such process as may be prescribed", and section 40(2)(k) creates the rulemaking power for "the other matters comprising the process of Data Protection Impact Assessment". That hook exists, but as of 23 August 2026 it has not been used. Rule 13 prescribes cadence and reporting; no rule prescribes a DPIA template, a methodology, a screening list of processing operations, or any content beyond the Act's own definition.

Honest consequences of that gap:

  • There is no official DPIA format to fill in, and any template you see is a vendor's or adviser's construction, not a prescribed form.
  • Whether the annual DPIA is one organisation wide exercise or a set of assessments per processing activity is not specified. Rule 13(1) speaks of "a Data Protection Impact Assessment and an audit" directed at observance of the whole framework, which reads naturally as a compliance wide exercise, but that reading is interpretation, not text.
  • Nothing in the Act or Rules requires a DPIA to be published, registered or filed in advance. The only mandated output that leaves the organisation is the Rule 13(2) report of significant observations to the Board.

Five GDPR habits to unlearn

If your privacy programme grew up on Article 35, these are the assumptions to check at the door. The GDPR positions below are orientation pointers to the official EUR Lex text of Regulation (EU) 2016/679, not restatements to rely on.

  1. "We screen each project for high risk." GDPR thinking starts with a risk threshold; Article 35(3) even lists cases where a DPIA is required in particular. Under the DPDP Act the trigger is status, not risk: notification as a Significant Data Fiduciary switches the duty on for you, and its absence switches it off, whatever the risk profile of a given project.
  2. "Our DPIA follows the Article 35(7) structure." The GDPR minimum contents include a systematic description of processing, an assessment of necessity and proportionality, and mitigation measures. The DPDP definition is shorter and aims elsewhere: rights of Data Principals, purpose of processing, and assessment and management of risk to those rights. You may keep the fuller GDPR structure if it serves you, but what the Indian text asks for is the rights centred core.
  3. "We consult the regulator only if residual risk stays high." Article 36 makes prior consultation an exception for unmitigated high risk. Rule 13(2) inverts the relationship: the Board hears from a Significant Data Fiduciary every cycle, because the report of significant observations is mandatory, with no residual risk filter and no concept of prior approval.
  4. "One DPIA per new project, then file it away." The GDPR DPIA attaches to a type of processing, typically before launch. The DPDP DPIA runs on the calendar: once in every period of twelve months from notification, aimed at effective observance of the Act and Rules as a whole, whether or not anything new launched that year.
  5. "The DPO owns the DPIA." The GDPR wires the DPO into the DPIA through Article 35(2). The DPDP text does not: section 10(2) creates the Data Protection Officer, the independent data auditor and the DPIA as parallel duties, and Rule 13(2) refers only to "the person carrying out the Data Protection Impact Assessment and audit". Who conducts the DPIA is unspecified; the express independence requirement in section 10(2)(b) attaches to the data auditor, not to whoever runs the DPIA.

When the duty starts

Section 10 of the Act and Rule 13 of the Rules sit in the final commencement group: notification G.S.R. 843(E) brings section 10 into force eighteen months from publication of the commencement gazette, and Rule 1(4) does the same for Rule 13. Both compute to 13 May 2027, which is interpretation until officially confirmed. Even after that date, the duty reaches only organisations the Central Government has notified, and as of 23 August 2026 it has notified none. The full sequence of what applies when is on the timeline.

Should you run one anyway?

If you are not notified, the Act asks no DPIA of you, and nothing in this framework changes that by volume, sector or sensitivity. Two reasons to consider a lighter, voluntary risk assessment regardless, offered as recommendation rather than requirement: every Data Fiduciary already carries the general obligations of section 8, including reasonable security safeguards to prevent personal data breach under section 8(5), and a periodic look at where personal data flows and what could harm the people behind it is the cheapest way to keep those duties honest. And if your scale or sensitivity makes future notification plausible, a working assessment habit is the part of Significant Data Fiduciary readiness that takes longest to build from zero.

What to do now

Confirm what you are with the role tool, then generate your obligation set with the company compliance plan, where the DPIA and audit cycle appears as conditional actions clearly marked as applying only if notified. If you run a GDPR programme and need the wider map of differences, read DPDP vs GDPR. The official texts live at section 10 and Rule 13, each with its Gazette citation.

Section 10, official textRule 13, official textAdditional obligations of a Significant Data Fiduciary: DPO, auditor, DPIADPDP vs GDPR: the differences that matter

Sources cited on this page

  1. [1]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 10, p. 8. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026Section 10(2)(c)(i): the periodic Data Protection Impact Assessment and its statutory definition. Section 10(1): Significant Data Fiduciary status arises only by Central Government notification. Section 10 begins on Gazette page 8 and concludes on page 9.
  2. [2]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 2, p. 2. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026Section 2(z) defines Significant Data Fiduciary as any Data Fiduciary or class of Data Fiduciaries notified by the Central Government under section 10. Section 2 begins on Gazette page 2 and concludes on page 3.
  3. [3]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 8, p. 7. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026Section 8: general obligations of every Data Fiduciary, including reasonable security safeguards under section 8(5), which apply regardless of Significant Data Fiduciary status. Section 8 begins on Gazette page 7 and concludes on page 8.
  4. [4]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 40, p. 18. Published 11 August 2023. Official source ↗ · Official requirement · Verified 23 August 2026Section 40(2)(k): the rulemaking power for the other matters comprising the process of Data Protection Impact Assessment under section 10(2)(c)(i). Section 40 begins on Gazette page 18 and concludes on page 19.
  5. [5]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 13, p. 29. Published 13 November 2025. Official source ↗ · Official requirement · Verified 23 August 2026Rule 13(1): the DPIA and audit once in every period of twelve months from notification. Rule 13(2): the report containing significant observations furnished to the Board. Rule 13(3) and 13(4): algorithmic due diligence and the conditional localisation restriction.
  6. [6]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 13, p. 29. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 23 August 2026The statement that no further DPIA process matters have been prescribed reflects the dpdprules.org provision registry, which ingests the full text of the DPDP Rules 2025 as corrected: Rule 13 is the only rule that addresses the Data Protection Impact Assessment, and it prescribes cadence and reporting, not content or methodology, as of the 23 August 2026 verification.
  7. [7]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), (c), p. 2. Published 13 November 2025. Official source ↗ · Official requirement · Verified 23 August 2026Notification G.S.R. 843(E) names section 10 in the group that comes into force eighteen months from the date of publication of the notification gazette.
  8. [8]Digital Personal Data Protection Rules, 2025 (English section of Gazette No. 760) (G.S.R. 846(E)), r. 1, (4), p. 24. Published 13 November 2025. Official source ↗ · Official requirement · Verified 23 August 2026Rule 1(4) places Rule 13 in the group of rules that come into force eighteen months after publication.
  9. [9]Commencement notification for the Digital Personal Data Protection Act, 2023 (G.S.R. 843(E)), p. 1. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 23 August 2026The calendar date 13 May 2027 for section 10 is computed from the publication date printed on Gazette issue No. 757 and is presented as interpretation until officially confirmed.
  10. [10]Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E)), p. 1. Published 13 November 2025. Official source ↗ · Interpretation, requires judgment · Verified 23 August 2026The calendar date 13 May 2027 for Rule 13 is computed from the publication date printed on Gazette issue No. 760 and is presented as interpretation until officially confirmed.
  11. [11]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 10, p. 8. Published 11 August 2023. Official source ↗ · Interpretation, requires judgment · Verified 23 August 2026The statement that no Significant Data Fiduciary has been notified reflects the dpdprules.org source registry and timeline, which record no such notification as of the 23 August 2026 verification. Under sections 2(z) and 10(1), the status exists only by Central Government notification.
  12. [12]Regulation (EU) 2016/679 (General Data Protection Regulation) (CELEX 32016R0679), Articles 35 and 36. Official source ↗ · Plain English explanation · Verified 23 August 2026GDPR positions in this article, including the Article 35(1) high risk trigger, the Article 35(7) minimum contents and the Article 36 prior consultation, are brief orientation pointers to the official EUR Lex text of Regulation (EU) 2016/679 for separate review; this site does not restate GDPR requirements as claims to rely on.
  13. [13]The Digital Personal Data Protection Act, 2023 (Gazette print hosted by MeitY) (Act No. 22 of 2023), s. 10, p. 8. Published 11 August 2023. Official source ↗ · Practical recommendation · Verified 23 August 2026The suggestion that organisations outside the Significant Data Fiduciary tier may run a lighter voluntary risk assessment is a recommendation of this site. The Act imposes the DPIA only through section 10(2)(c), so any such exercise is good practice, not a statutory duty.

dpiasignificant data fiduciaryrule 13auditgdpr comparison

Share this: