# Data Protection Impact Assessment

**Digital Personal Data Protection Act, 2023 — Sec. 10 · DPDP Rules, 2025 — Rule 13**

---

## Before you start

Rule 13 requires a **Significant Data Fiduciary** to undertake a Data Protection
Impact Assessment and an audit **once every twelve months**, running from the date
it is notified as such or is included in a notified class.

Two things follow from that, and both matter before you fill this in:

1. **If you have not been notified under Sec. 10, this duty has not attached to
   you.** The Sec. 8 duties have. This assessment is still worth running — it is
   how most teams discover which Sec. 8 duties they are not meeting — but it is
   not yet a compliance obligation for you.
2. **At the time of writing, no entity has been notified.** The classes have not
   been notified either. Organisations preparing now are doing so because the rule
   allows no grace period for the first assessment.

The Rules do not prescribe a format for the report. This questionnaire is
organised by provision rather than by chapter, so that each answer points at the
duty it tests.

---

## Section 0 — Scope

| Field | Answer |
|---|---|
| Processing activity assessed | |
| Register row reference | |
| Assessment date | |
| Assessor | |
| Approver | |
| Next assessment due | |

> Assess **one processing activity per report**. An assessment covering "the
> platform" cannot be reviewed a year later, because the thing assessed has no
> stable identifier. If you keep a processing register, the row reference is that
> identifier.

---

## Section 1 — What is processed, and why

**1.1** What personal data does this activity process? List by category.
`Sec. 5(1)`

**1.2** What is the purpose? Use the words that appear in the notice given to the
Data Principal, not an internal project name. `Sec. 5(1)`

**1.3** Is every category in 1.1 necessary for the purpose in 1.2? Name any that
are not. `Sec. 6(1)`
*Risk weight: +2 for each category that is not necessary.*

**1.4** Does this activity process the personal data of children, or of persons
with a lawful guardian? `Sec. 9`
*Risk weight: +4 if yes and verifiable parental consent is not obtained.*

---

## Section 2 — The basis

**2.1** Does this activity run on consent (Sec. 6) or on a legitimate use
(Sec. 7)? State which. `Sec. 6 · Sec. 7`

**2.2** If consent: is it specific to this purpose, or bundled with others?
`Sec. 6(1)`
*Risk weight: +4 if bundled. Bundled consent fails the standard.*

**2.3** If consent: can the Data Principal withdraw it as easily as it was given?
`Sec. 6(4)`
*Risk weight: +3 if withdrawal is harder than granting.*

**2.4** On withdrawal, does processing actually stop — in this system and in every
downstream system? Name the ones where it does not. `Sec. 6(6)`
*Risk weight: +4 for each system where it does not.*

**2.5** If a legitimate use: which clause of Sec. 7, and does the activity stay
within it?

---

## Section 3 — Who else touches it

**3.1** Which Data Processors are engaged for this activity? `Sec. 8(2)`

**3.2** Is each engaged under a valid contract? `Sec. 8(2)`
*Risk weight: +4 for each processor without one.*

**3.3** Does any processor sub-process, and is that permitted by the contract?

**3.4** Is personal data from this activity transferred outside India?
`Sec. 16 · Rule 15`
*Risk weight: +3 if yes.*

**3.5** If transferred: to which country, and has the Central Government
restricted it?
*Risk weight: +8 if the destination is restricted.*

---

## Section 4 — How long, and how it ends

**4.1** What is the retention period, and from what event does it run?
`Sec. 8(7) · Rule 8`

**4.2** Is erasure enforced by a scheduled job, or does it depend on somebody
remembering? `Rule 8`
*Risk weight: +2 if not enforced automatically.*

**4.3** Is there personal data still held under this activity whose purpose is no
longer being served?
*Risk weight: +4 if yes.*

---

## Section 5 — Safeguards

**5.1** What reasonable security safeguards protect this data? `Sec. 8(5)`

> The Schedule attaches its largest penalty — up to ₹250 crore — to the failure to
> take reasonable security safeguards. This is the highest-consequence question in
> the document.

**5.2** Is the data encrypted at rest and in transit?
*Risk weight: +4 if not.*

**5.3** Who has standing access to it, and is that access logged?
*Risk weight: +3 if standing access is not logged.*

**5.4** Are personal identifiers (Aadhaar, PAN, account numbers) stored in free
text, documents or logs where they are not needed?
*Risk weight: +3 if yes.*

---

## Section 6 — When it goes wrong

**6.1** If a breach occurred here, could you identify the affected Data Principals?
`Sec. 8(6) · Rule 7`
*Risk weight: +4 if not.*

**6.2** Could you intimate them and report to the Board with particulars within
72 hours? `Rule 7`
*Risk weight: +4 if not.*

**6.3** Who owns that response, by name?

---

## Section 7 — Rights

**7.1** Can a Data Principal obtain a summary of the personal data processed under
this activity? `Sec. 11`
*Risk weight: +3 if not.*

**7.2** Can they obtain correction and erasure? `Sec. 12`
*Risk weight: +3 if not.*

**7.3** Is there a published grievance route, with a named officer and a response
window? `Sec. 13`
*Risk weight: +4 if not.*

---

## Scoring

Sum the risk weights.

| Score | Reading |
|---|---|
| 0–5 | Low. Record the assessment and the date. |
| 6–14 | Elevated. Each contributing answer needs a mitigation with an owner and a date. |
| 15+ | High. The activity should not continue in its current form pending mitigation. |

The score is a prompt for the conversation, not a rating of the organisation. An
activity scoring zero with an answer nobody checked is worse than one scoring
twelve with twelve owners against it.

---

## Sign-off

| | |
|---|---|
| Mitigations recorded | ☐ |
| Owners and dates assigned | ☐ |
| Residual risk accepted by | |
| Approver signature | |
| Date | |
| Next assessment due | |

---

*Published by MyConsent+ — https://myconsentplus.com/products/dpia/*

*This questionnaire is a working template, not legal advice. It cites the
provisions it tests so that each question can be checked against the bare Act and
the Rules. Where your assessment turns on the interpretation of a provision, take
advice on that provision.*
