How to Conduct a Data Protection Impact Assessment Under the DPDP Rules 2025
- Kaustav Chowdhury

- 2 days ago
- 5 min read
The Digital Personal Data Protection Act, 2023 (DPDP Act), together with the Digital Personal Data Protection Rules, 2025 (DPDP Rules), has introduced a structured framework for data governance in India. Among its most significant compliance obligations is the Data Protection Impact Assessment (DPIA), which must be conducted by every entity designated as a Significant Data Fiduciary (SDF). Rule 13 of the DPDP Rules, 2025, read with Section 10(2)(c) of the DPDP Act, sets out the requirements: what the DPIA must evaluate, how frequently it must be conducted, and what must be reported to the Data Protection Board of India. This guide explains the process from start to finish, covering the designation criteria for SDFs, the substantive contents of a DPIA, the reporting obligations, and the penalties that apply for non-compliance.
What Is a DPIA Under Indian Law
A Data Protection Impact Assessment is a systematic evaluation of how an organisation's personal data processing activities affect the rights of Data Principals (the individuals whose data is processed). Unlike a simple compliance audit, a DPIA goes deeper: it assesses whether the processing is proportionate to its stated purpose, whether the technical and organisational safeguards are adequate given the volume and sensitivity of data involved, and whether algorithmic or automated decision-making systems create risks for Data Principals. The DPDP Act does not prescribe a specific template for the DPIA, but the DPDP Rules, 2025 specify the key areas that the assessment must cover. The DPIA is not a one-time exercise; it must be conducted at least once every twelve months.
Who Must Conduct a DPIA: Significant Data Fiduciaries
The DPIA obligation applies exclusively to entities designated as Significant Data Fiduciaries (SDFs) by the Central Government under Section 10 of the DPDP Act. The designation is based on several factors: the volume and sensitivity of personal data processed, the risk to the rights of Data Principals, the potential impact on the sovereignty and integrity of India, the risk to electoral democracy, and the potential impact on security of the State and public order. As of August 2026, the Central Government has not yet published a comprehensive list of designated SDFs, though notifications are expected in phases. Entities processing large volumes of personal data, particularly in sectors such as financial services, healthcare, telecommunications, and e-commerce, should anticipate designation and begin preparing their DPIA frameworks proactively. All Data Fiduciaries (not just SDFs) must comply with the general obligations under the DPDP Act, but the DPIA requirement is an additional obligation imposed only on SDFs.
Contents of a DPIA Under Rule 13
Rule 13 of the DPDP Rules, 2025 requires the DPIA to evaluate several key areas. First, legal compliance: whether the processing aligns with the provisions of the DPDP Act, the applicable Rules, and the lawful purpose limitations set out in the Act. Second, Data Principal rights protection: whether individuals can realistically exercise their rights of access, correction, erasure, and grievance redressal without friction. Third, safeguard adequacy: whether the technical and organisational measures deployed are proportionate to the nature, scale, and sensitivity of the data processed. This includes encryption standards, access controls, data minimisation practices, and incident response protocols. Fourth, risk minimisation: whether the risks created by large-scale processing, sensitive data handling, or automated decision-making systems are identified, reduced, and controlled. Fifth, algorithmic assessment: the DPDP Rules specifically require assurance that algorithmic systems used for processing do not endanger Data Principal rights. This is particularly relevant for organisations deploying AI-based profiling, credit scoring, or automated content moderation systems.
Appointing the Data Protection Officer and Independent Auditor
Before conducting a DPIA, an SDF must appoint a Data Protection Officer (DPO) based in India, who reports directly to the board of directors or equivalent governing body. The DPO is responsible for overseeing the DPIA process, serving as the point of contact for the Data Protection Board of India, and ensuring that the organisation's data processing activities remain compliant. Additionally, the SDF must appoint an independent data auditor to conduct periodic audits. The DPIA findings and the independent audit report operate as complementary compliance instruments: the DPIA is an internal self-assessment, while the audit provides external validation.
Reporting to the Data Protection Board
Significant observations from the DPIA and the independent audit must be reported to the Data Protection Board of India. While the DPDP Rules do not prescribe a specific form for this reporting, the expectation is that the SDF will submit a summary of findings, identified risks, and remedial actions taken or planned. The Data Protection Board, established under Chapter 5 of the DPDP Act, is an independent body empowered to handle complaints, investigate violations, direct corrective actions, and impose penalties. The Board may request additional information or direct the SDF to take specific remedial measures based on the DPIA and audit submissions.
Penalties for Non-Compliance
The penalty framework under the DPDP Act is set out in the Schedule to the Act, referenced under Section 33(1). Breach of the additional obligations of Significant Data Fiduciaries, which includes failure to conduct a DPIA, attracts a penalty of up to Rs 150 crore per instance. Other related penalties include: up to Rs 250 crore for failure to take reasonable security safeguards to prevent a personal data breach; up to Rs 200 crore for failure to notify the Board and affected Data Principals of a breach; and up to Rs 50 crore as the residual penalty for breach of any other provision of the Act or Rules. When determining the penalty amount, the Board weighs the nature, gravity, and duration of the breach, the type of data affected, whether the breach was repeated, any gains or losses resulting from the breach, and the mitigating actions taken by the entity.
Key Takeaways
The DPIA obligation under Rule 13 of the DPDP Rules, 2025 applies only to Significant Data Fiduciaries designated by the Central Government under Section 10 of the DPDP Act.
A DPIA must be conducted at least once every twelve months and must cover legal compliance, Data Principal rights, safeguard adequacy, risk minimisation, and algorithmic assessment.
SDFs must appoint a Data Protection Officer based in India and an independent data auditor.
Significant observations from the DPIA and audit must be reported to the Data Protection Board of India.
Penalties for SDF non-compliance can reach up to Rs 150 crore per instance; the maximum penalty under the Act is Rs 250 crore.
Related Reading
How to Comply with the DPDP Act 2023 Before the May 2027 Enforcement Deadline
How to Draft and Negotiate a SaaS Agreement Under Indian Law: Key Clauses and Compliance
How to Respond to a CCPA Investigation or Notice Under the Consumer Protection Act 2019
How to Set Up a Compliance Calendar for a Private Limited Company in India

Comments