Rule 4

Consent Manager registration opens13 Nov 2026

myconsent+

Sec. 10 · Rule 13

Roadmap

An assessment that names the row it assessed

Rule 13 gives a Significant Data Fiduciary twelve months between impact assessments and says nothing about the format. What makes one defensible a year later is that it points at a specific processing activity, a specific risk, and a mitigation somebody owned.

Months between assessments
12
Rule 13
Duties in the same rule
2
DPIA + audit
RoPA row assessed
1
Sec. 8(1)
Entities notified so far
0
Sec. 10
Who it is for

For a Significant Data Fiduciary's DPO, and the approver who has to sign the report.

Admin Console — Impact Assessment · Product analytics
  1. Does this activity process personal data of children?NoSec. 9+0
  2. Is the data transferred outside India?Yes — analyticsSec. 16+3
  3. Is a processor engaged under a valid contract?YesSec. 8(2)+0
  4. Can the principal withdraw without losing the service?YesSec. 6(4)+0
  5. Is retention bounded and enforced by a job?Bounded, not enforcedRule 8+2
  6. Would a breach here be reportable within 72 hours?YesRule 7+0

Risk score

5 / 18

Above threshold — mitigation required

Approver

Signed — Data Protection Officer

Next assessment due in 12 months

Every question carries the provision it tests. The score is the sum of what the answers weigh, not a rating of the organisation.

What the rule actually asks for

  1. Sec. 10 · Rule 13

    A questionnaire templated on the rule, not on a framework

    The questions come from what Rule 13 asks a Significant Data Fiduciary to have assessed, and each one carries the provision it tests. There is no ISO crosswalk and no maturity score, because neither is what the Board will ask for.

  2. Sec. 8(1)

    Assessed against a RoPA row, not a system name

    An assessment attaches to a processing activity in the register. That is what makes it reviewable a year later: the thing assessed still exists and still has the same identifier, even after the systems behind it were replaced.

  3. Rule 13

    Risk scoring with mitigations tracked to close

    Each answer contributes to a score, and a score above the threshold requires a mitigation with an owner and a date. An assessment where nothing was mitigated and nothing was accepted is not finished, and the workflow will not let it be signed.

  4. Rule 13

    A signed report, and the twelve-month clock

    The approver signs, the report is written to PDF with the register row and the chain digest, and the next assessment is scheduled twelve months from that date. The clock runs from the signature, which is the date the rule reasons about.

Free · No form

Run it on paper first

The module is on the roadmap and the duty may reach you before it ships. The questionnaire below is the one the product would put in front of you, with the provision each question tests, in a file you can run in a meeting today.

DPIA questionnaire (.md)

Rule 13 applies once you are notified under Sec. 10. Nobody has been, yet.

Questions people ask

Who has to do a Data Protection Impact Assessment?
Only a Significant Data Fiduciary. Sec. 10 of the DPDP Act, 2023 lets the Central Government notify a Data Fiduciary, or a class of them, as significant — taking into account the volume and sensitivity of personal data processed, the risk to Data Principals, and considerations including the sovereignty and integrity of India. Rule 13 of the DPDP Rules, 2025 then requires that entity to undertake a DPIA and an audit once every twelve months. If you have not been notified, the duty has not attached to you.
Has anyone been notified as a Significant Data Fiduciary yet?
Not at the time of writing. The classes have not been notified, so no entity currently carries the Rule 13 duty. Organisations that expect to be named — large consumer platforms, major financial institutions, health networks — are the ones preparing now, because the rule gives twelve months between assessments and no grace period for the first one.
How often, and when does the clock start?
Once every twelve months, running from the date the entity is notified as a Significant Data Fiduciary or included in a notified class. The rule pairs the assessment with an audit in the same cycle, so most teams run them together rather than treating them as two exercises.
What has to be in the report?
The Rules do not prescribe a format. What the duty implies is a description of the processing and its purpose, an assessment of the risk to Data Principals, and the measures taken to manage that risk — which is why the questionnaire here is organised by provision rather than by chapter. A report that cannot point at the activity it assessed and the mitigation it produced has not done the thing the rule asks for.
Is DPIA available today?
No. It is on the roadmap, and the tile on this site says so. The questionnaire below is real — it is the one we would ship — and the downloadable version is offered now precisely because the software is not ready and the assessment is still worth doing. If your notification arrives before our release does, run it on paper.

Next step

See it against your own processing

A walkthrough runs on your activities and your purposes, not a demo tenant. Thirty minutes, and you keep the notes.

Book a demo