DPDPA Section 8 explained: a data fiduciary's duties for accuracy, security, breach notification, retention, erasure and grievance redressal.
A data fiduciary must take reasonable security safeguards to prevent a personal data breach, including where a processor holds the data. Failure to take such safeguards is the single most heavily penalised obligation under the Act.
On becoming aware of a breach, the fiduciary must notify the Data Protection Board and each affected data principal in the form and manner the Rules prescribe. Have an incident-response runbook ready so these notifications can go out within the required timelines.
Personal data must be erased once the purpose is no longer being served and retention is not required by law, and on withdrawal of consent. In practice that means purpose-based retention schedules and a deletion process, not indefinite storage.
ConsentX supports this with configurable retention and an erasure audit trail, so deletion is provable rather than assumed.
A data fiduciary may engage a processor only under a valid contract, and remains accountable for the data. You must publish the contact details of a Data Protection Officer or a person able to answer questions about processing, and operate a grievance-redressal mechanism for data principals.
This page is a plain-English summary of the Digital Personal Data Protection Act, 2023 for general information and is not legal advice. Confirm your obligations with qualified counsel.
DPDPA-native consent, Section 9 age-gate and verifiable receipts. Start free or take the DPDPA quiz.