DPDP Act — Section-by-Section
Every obligation.
Mapped to a capability.
We've mapped every obligation in the DPDP Act and Rules to a specific Perfios Consent Manager capability — section by section, penalty by penalty. No generic compliance checklists. No gaps left unnamed.
Grounds for Processing
Personal data may only be processed for a lawful purpose — with consent or a legitimate use under S7
Critical
Purpose-linked consent capture with processing register; legal basis assigned to each activity
Notice Requirements
Notice must be served before or at the point of consent — in clear, plain language, with purpose and withdrawal rights
Critical
Multilingual, versioned, purpose-linked notices with full audit trail
Consent
Consent must be free, specific, informed, unconditional — and withdrawable with the same ease as giving it
Critical
Granular purpose-level consent, withdrawal flows, timestamp logging, and full lifecycle audit
Fiduciary Obligations
Implement security safeguards; notify breaches to Board and data principals within prescribed timelines
Critical
Breach detection workflows, notification templates, retention automation, processor contract clauses
Children's Data
Processing data of persons under 18 requires verifiable parental consent; no tracking or targeted ads
High
Guardian consent flows; age-gating support; advertising controls for child-identified accounts
Right to Access
Data principals may obtain a summary of personal data processed and processors it has been shared with
High
Self-service DPAR portal; data access summaries; processor disclosure logs
Correction & Erasure
Data principals may request correction of inaccurate data and erasure of data no longer needed
High
Deletion engine, correction workflows, processor cascade, grievance redressal
+10 more sections mapped — S2 Definitions, S3 Applicability, S7 Legitimate Uses, S10 SDFs, S13 Grievance, S14 Appeals, S15–22 Board Powers, S16 Exemptions, S17 Research, Cross-Border Transfers