3:  Structure of DPDPA - Sections and Rules
ISSUE #86Published: 9/21/2026

3: Structure of DPDPA - Sections and Rules

Ankur Srivastava

Ankur Srivastava

Deputy-CISO / CISSP

Cyber Security & Business Continuity Expert with over 15 years of experience orchestrating InfoSec Governance, risk mitigation frameworks, and disaster recovery architectures. CISSP | M.S. in Cyber Laws & Information Security (IIIT).

Access Price

20
Preview

Description

Understand the structure of India's DPDPA 2023—how the Act's 10 sections map to operational Rules introduced by the Central Government under Section 40.

The Act (passed by Parliament) defines core concepts like Data Fiduciary, Data Principal, consent, rights, penalties, and the Data Protection Board of India.

The Rules (issued November 2024) provide the actionable "how-to"—covering breach notification, consent manager registration, log retention, and duties of Significant Data Fiduciaries.

Perfect for founders and leaders who need the big picture of the Act but rely on the Rules for day-to-day compliance implementation.