Skip to content
🚨 DPDP Rules 2025: Compliance Deadline 35 weeks awayRead handbook →

DPDP Act & Rules Explorer

Browse and search the Digital Personal Data Protection Act, 2023 and the Rules made under it, with every provision linked to the feature that discharges it.

What this is, and why it matters

The DPDP Act & Rules Explorer is the complete text of India’s data protection law inside DPDP Guard, in verbatim wording:

  • the Digital Personal Data Protection Act, 2023 — all nine chapters, sections 1 to 44, and the Schedule of penalties; and
  • the Digital Personal Data Protection Rules, 2025 — all 23 rules and all seven schedules.

The Act states the duty; the Rules state how it is actually performed. The seventy-two hour Board breach report, the minimum security safeguards, the erasure periods for e-commerce, gaming and social media fiduciaries, and the mechanics of verifiable parental consent all live in the Rules.

It exists so you never have to leave a compliance workflow to check what the law actually says. When you are drafting a DPIA, answering a grievance, or deciding whether an erasure request can be refused, the governing clause is one search away — and every section tells you which part of DPDP Guard you use to satisfy it.

This is a read-only reference. Nothing you do here changes your compliance records.

Before you start

  • Available to both Fiduciary Admin and DPO roles.
  • The Explorer rolls out gradually. If you see “not available for your account yet”, it has not reached your organization — no action is needed on your side.

Steps

  1. Open DPDP Act & Rules from the sidebar. The landing view is a directory grouped by instrument: the Act’s chapters, numbered as the Act numbers them (Chapter I to Chapter IX) plus its Schedule, then the Rules and their schedules. Each card shows how much it holds and how many assessable obligations — the leaf-level provisions that impose a testable duty you can hold your organisation against.

  2. Search the full text using the box at the top. The search covers both instruments at once and matches reference numbers as well as the verbatim text, so 6(1), erasure and seventy-two hours all work. Matches are highlighted, and a query that names a chapter (“Penalties and Adjudication”) surfaces that chapter too. Results are labelled by instrument — Section 7 and Rule 7 are different provisions, and the Explorer never lets them be confused.

  3. From any search result, choose Open in context to jump straight into the section that contains the clause, rather than reading it in isolation.

  4. Browse a chapter to read it section by section. Selecting a section expands it to its sub-sections and clauses, indented to their statutory depth.

  5. Use the copy icon next to any clause to copy a paste-ready citation — Section 6(1), Digital Personal Data Protection Act, 2023 or Rule 7(2)(b), Digital Personal Data Protection Rules, 2025 — straight into a DPIA, a grievance response, or a legal memo.

Linking the Act to your compliance posture

Where a section imposes an obligation you discharge inside DPDP Guard, the expanded section shows a Where you do this in DPDP Guard panel linking to the relevant features, with a one-line explanation of how each satisfies the provision. For example:

Section Where you do it
s. 5 — Notice Privacy Notices, Privacy Policy
s. 6 — Consent Consent Register, Consent Manager, Withdrawal Log, Consent Quality
s. 8 — General obligations Incident Reports, Data Processors, Retention Policies, Grievances, RoPA
s. 9 — Children’s data Children’s Data
s. 10 — Significant Data Fiduciary SDF Readiness, DPO Designation, DPIA Programs
s. 11–13 — Principal’s rights DSR Requests, Data Erasure, Grievances
s. 16 — Transfers outside India Cross-Border Transfers
s. 33 and the Schedule — Penalties Penalty Exposure
r. 6 — Reasonable security safeguards Audit & Governance, Data Processors
r. 7 — Breach intimation (72 hours) Incident Reports
r. 8 and Third Schedule — Erasure periods Retention Policies, Data Erasure
r. 10 — Verifiable parental consent Children’s Data
r. 13 — SDF annual DPIA and audit DPIA Programs, SDF Readiness
r. 14 — Rights and 90-day grievances DSR Requests, Grievances
First Schedule — Consent Manager CM Registration Wizard, CM Readiness

Provisions that impose no fiduciary workflow — definitions, the Board’s own constitution and service terms, rule-making machinery — carry no links, rather than pointing you at something loosely related.

Sharing a provision

Everything about your position in the Explorer lives in the URL: the part you are browsing, the provisions you have open, and any active search. You can copy the address bar and send a colleague a link that opens directly on the clause you are discussing, and your browser’s Back button steps back through the text instead of leaving the page.

What happens next

  • Nothing is written to your compliance records — the Explorer only reads the statutory text.
  • Citations you copy are plain text, safe to paste into any document.
  • Follow the links in Where you do this in DPDP Guard to act on a provision. If a linked feature has not been enabled for your organization yet, its page will tell you so.

Troubleshooting

  • “The requirement library is being prepared.” The statutory text has not been loaded onto your deployment yet. This is an operator-side task, not something you can fix from this page — contact your DPDP Guard administrator.
  • A search returns nothing. Search matches literally, so a typo in a reference number (6(1)) rather than 6(1)) will not match. Try a shorter term, or clear the box and browse by chapter instead.