DPIA under the DPDP Act: who needs one, when, and how to run it

DPIA

DPIA under the DPDP Act: who needs one, when, and how to run it

The Data Protection Impact Assessment is mandatory only for Significant Data Fiduciaries — but there is a strong case for running one voluntarily. Here is the India-specific version, without the GDPR baggage.

Quick answer: Under Section 10 of the DPDP Act, only Significant Data Fiduciaries (SDFs) — entities designated by the Central Government based on data volume, sensitivity, and risk — must conduct periodic Data Protection Impact Assessments. Everyone else can run one voluntarily, and should for high-risk processing: a documented DPIA is direct mitigation evidence under Section 33(2) if the Data Protection Board ever inquires into your practices.

DPIA is an SDF obligation — not a universal one

A lot of advice circulating in India is copy-pasted from GDPR, where a DPIA is mandatory for any "high-risk" processing regardless of who you are. The DPDP Act works differently. Section 10 attaches the DPIA obligation to a class of entity, not a class of processing: the Significant Data Fiduciary.

The government designates SDFs based on factors listed in Section 10(1): volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential impact on the sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order. Sectors widely expected to see early SDF designations include large fintechs, healthcare platforms, telecom, social media, and major e-commerce players.

Once designated, an SDF must: appoint a Data Protection Officer based in India who reports to the Board of Directors, appoint an independent data auditor, and conduct periodic DPIAs and audits — with significant observations reported onward to the Data Protection Board.

Why non-SDFs run DPIAs anyway

Three practical reasons keep coming up in our engagements:

1. Penalty mitigation. Section 33(2) requires the Data Protection Board to consider the nature and gravity of a breach, whether you gained from it, and — critically — the mitigation measures you took. A dated, documented DPIA showing you identified and addressed risks before an incident is among the strongest artefacts you can put in front of the Board.

2. SDF readiness. Designation can arrive by notification. Companies that already have the DPIA muscle — templates, risk registers, sign-off workflows — absorb SDF obligations in weeks. Companies starting cold need quarters.

3. Enterprise procurement. Client security questionnaires increasingly ask "do you conduct privacy impact assessments?" A yes with evidence shortens deal cycles; a no invites deeper scrutiny of everything else.

What an India-specific DPIA covers

Do not simply reuse a GDPR DPIA template — several core GDPR concepts have no DPDP equivalent. There is no "legitimate interest" balancing test to document, because legitimate interest is not a lawful basis in India; consent and the enumerated legitimate uses in Section 7 are. Map your assessment to the actual DPDP obligations:

1. Processing inventory

What personal data, from whom, for which stated purposes, stored where, shared with which processors. This is the foundation — a DPIA over an incomplete inventory is theatre.

2. Lawful basis check

For each purpose: valid consent (free, specific, informed, unconditional, unambiguous, per Section 6) or a Section 7 legitimate use (voluntary provision, employment purposes, medical emergency, State functions, etc.). Flag anything riding on bundled or implied consent — that is your highest-probability violation.

3. Obligation-by-obligation risk scoring

Notice adequacy (Section 5), consent mechanics and withdrawal (Section 6), data accuracy and erasure (Section 8), security safeguards against Rule 6 minimums, breach detection and the 72-hour notification capability, children's data rules if applicable (Section 9), and Data Principal rights handling (Sections 11–14).

4. Residual risk and sign-off

For each identified gap: mitigation, owner, deadline. A DPIA without named owners and dates is a wish list. Senior management signs the residual risk they are accepting.

Does your processing need DPIA-level review?

Run the free 2-minute trigger check, then build the full assessment with our guided DPIA Builder.

Check your DPIA triggers →

How often, and who owns it

For SDFs, "periodic" will be defined by the Rules and your designation notification — annually is the safe working assumption. For voluntary DPIAs, run one whenever you launch a new product or feature touching personal data, onboard a new category of data (especially children's or financial data), materially change vendors or cross-border flows, or at least annually as a refresher.

Ownership: in an SDF, the DPO. In a mid-market company without a DPO, assign a single accountable owner — typically the CISO, head of legal, or a founder — and have them coordinate inputs from engineering, HR, and marketing. Committees do not finish DPIAs; owners do.

Common failure modes we see

The assessment covering only the marketing website while the actual product database goes unexamined. Consent flows assessed as designed rather than as shipped. Vendor processing assumed compliant because "they're ISO certified." And the classic: a beautiful DPIA document, zero of its mitigations implemented, discovered in that state during an incident review — which reads worse to a regulator than having no DPIA at all.

Frequently asked questions

Is a DPIA legally mandatory for my company under the DPDP Act?

Only if the Central Government designates you as a Significant Data Fiduciary under Section 10. Until then it is voluntary — but strongly advisable for high-risk processing, because a documented DPIA is mitigation evidence the Data Protection Board must consider under Section 33(2) when determining penalties.

How is a DPDP DPIA different from a GDPR DPIA?

The DPDP version maps to Indian obligations: consent validity under Section 6, notice under Section 5, Rule 6 security safeguards, 72-hour breach notification, and children's data rules. There is no legitimate-interest balancing test — that lawful basis does not exist under DPDP. Cross-border analysis is also simpler: transfers are permitted except to countries on a government-notified negative list.

Who should conduct the DPIA — internal team or external consultant?

Either works legally. Internal teams know the systems; external reviewers bring independence and pattern knowledge from other assessments. A pragmatic middle path: internal teams complete a structured template, an external specialist reviews and challenges it. For SDFs, note the separate requirement for an independent data auditor.

Previous Post Next Post

Get Free DPDP Checklist