dpdpa

Provides compliance guidance on India's Digital Personal Data Protection Act, 2023 and DPDP Rules 2025.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill dpdpa-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dpdpa
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/dpdpa
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill dpdpa-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Legal, privacy, and compliance teams need accurate, section-cited guidance on India's Digital Personal Data Protection Act, 2023 and the DPDP Rules 2025, but the framework differs significantly from GDPR and carries penalties up to ₹250 crore for non-compliance. ## Core Features & Use Cases - Gap Analysis: Produces structured compliance gap tables mapping obligations to sections and rules, with evidence requirements and common gaps for Data Fiduciaries, children's data, and Significant Data Fiduciaries. - Notice, Consent & Breach Guidance: Drafts Rule 3-compliant notices, reviews consent mechanisms against Section 6 validity criteria, and provides 72-hour breach notification procedures per Rule 6. - GDPR Comparison: Maps GDPR terminology and obligations to DPDPA equivalents, highlighting the 8 substantive differences for teams transitioning from EU compliance. - Use Case: A global SaaS company with Indian users asks whether its legitimate-interests-based analytics are lawful in India; the skill explains that DPDPA has no legitimate interests basis and maps the processing to consent or Section 7 legitimate uses. ## Quick Start Ask the assistant to run a DPDPA gap analysis on your privacy notice and consent flow, citing the relevant sections and DPDP Rules 2025.

Frequently Asked Questions about dpdpa

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run a DPDPA compliance gap analysis?

A DPDPA gap analysis maps each obligation to its Act section or DPDP Rule, records current status, evidence required, and gap notes. This skill produces structured gap tables covering notice, consent, security safeguards, processor contracts, breach notification, retention, and grievance mechanisms.

What are the key differences between DPDPA and GDPR?

DPDPA covers only digital personal data, offers just two lawful bases with no legitimate interests ground, uses a blacklist approach for cross-border transfers, sets the child age threshold at 18, and caps penalties at fixed INR amounts rather than a percentage of global turnover.

Does DPDPA apply to companies outside India?

Yes, DPDPA has extraterritorial reach under Section 3. Any organisation processing digital personal data in connection with offering goods or services to individuals located in India is a Data Fiduciary, even if the processing occurs offshore.

What is the DPDPA breach notification timeline?

Data Fiduciaries must notify the Data Protection Board within 72 hours of becoming aware of a personal data breach, per Section 8(6) and Rule 6. Unlike GDPR, all breaches must be reported regardless of risk threshold, and failure to notify carries penalties up to ₹200 crore.

When does full DPDPA compliance become mandatory?

The DPDP Rules 2025 were notified on 13 November 2025, with the Data Protection Board operational immediately. Full substantive compliance under Sections 3-17 is required from 13 May 2027, after an 18-month transition period.

What are the limitations of DPDPA compliance guidance from this skill?

The skill provides general compliance information, not legal advice. Several obligations depend on pending government notifications, such as SDF designations, cross-border restrictions, and prescribed timelines, so guidance must be verified against current MeitY gazette publications.