Picture a bank two weeks from launching a lending app. To score applicants faster, it will pull income records, location and phone contacts. Legal asks one question: What happens to the people whose data is being processed?
The room doesn’t have an answer. Product knows the features and security knows the controls. But nobody has one single document showing what could go wrong for the customer, how big the risk is and what the firm plans to do about them.
That’s where a Data Protection Impact Assessment (DPIA) comes in. Under India’s data protection law, it is a structured process for documenting the purpose of processing, the rights of data principals, the risks to those rights and how those risks will be managed. For Significant Data Fiduciaries, the DPDP Act and Rules make DPIAs a repeat compliance requirement.
This guide covers how to conduct a DPIA under DPDPA in seven steps, who must run one, how often, and what gets reported to the Data Protection Board.
What is a DPIA under the DPDP Act?
Section 10(2)(c) of the DPDP Act, 2023 requires Significant Data Fiduciaries to undertake periodic Data Protection Impact Assessments. It describes a DPIA as a process covering the rights of Data Principals, the reason for processing their personal data, management of risks to those rights, and other matters prescribed by the Rules.
Read that definition closely and the structure of the exercise falls out of it. Three fixed elements, plus whatever the Rules prescribe.
Rule 13 of the DPDP Rules, 2025 adds the operational detail. As set out in the official FAQs on Data Fiduciary and Significant Data Fiduciary, a Significant Data Fiduciary must undertake a Data Protection Impact Assessment and an audit once every twelve months, and submit a report containing significant observations to the Board.
Who must conduct one, and when
The obligation is tied to SDF designation, not just to the organisational size.
- Significant Data Fiduciaries: notified by the Central Government under Section 10(1), based on the volume and sensitivity of data processed, risk to the rights of Data Principals, and impact on the sovereignty and security of India
- The clock starts at designation: the twelve-month cycle runs from the date an entity is notified as a Significant Data Fiduciary, or included in a notified class
- Everyone else: a DPIA is not mandatory, but it is the cleanest way to evidence due care for high-risk processing such as profiling, biometrics, children’s data or large-scale financial records
Timing matters for planning. According to the Press Information Bureau, the Rules follow an eighteen-month phased schedule, with the main operational obligations applying from May 13, 2027.
A step-by-step DPIA methodology
Each step produces a written output. Together they form the file an auditor or the Board will actually read.
- Confirm the trigger and scope: A DPIA runs on a defined processing activity. Fix the boundary first. Between annual tests, companies may choose to revisit a DPIA when material changes alter the processing risk. For example, a new product, new processor, new category of personal data or significant change in processing purpose.
- Map the data and the flow: Record what is collected, why, who touches it, where it sits and how long it stays. Include processors and any movement outside India. A DPIA built on a stale data inventory fails quietly.
- Test the lawful basis: Check whether the activity runs on valid consent under Section 4 or falls within one of the certain legitimate uses under Section 7.
- Describe the rights at stake: List the Data Principal rights the activity touches. Access, correction, erasure, grievance redressal and nomination. Then state how each one is delivered in practice, with timelines.
- Assess the risk of harm: Rate likelihood and impact from the individual’s point of view. Identity theft, financial loss, discrimination, exclusion and loss of confidentiality.
- Fix, then measure what is left: Give every mitigation an owner and a date. Record the residual risk in plain language, along with the decision to proceed, change or stop. Auditors read that decision record first.
- Report and reset the clock: The person carrying out the DPIA and audit must furnish the Board a report containing significant observations from the DPIA and audit. Record the next 12-month assessment date immediately so the cycle does not lapse.
What else Rule 13 expects alongside the DPIA
The DPIA does not sit on its own. Rule 13 packages it with three other duties that shape what the assessment must examine.
- Algorithmic due diligence: verifying that software used to host, display, upload, publish, store or share data does not pose a risk to the rights of Data Principals
- Independent audit: carried out on the same twelve-month cycle as the DPIA
- Restricted transfers: keeping specified personal data, and the traffic data about its flow, inside India where a government-constituted committee has said so
Skipping the assessment is not a paperwork issue. The Schedule to the DPDP Act allows penalties of up to ₹150 crore for failure to meet the additional obligations of a Significant Data Fiduciary under Section 10.
Conclusion
The methodology is not complicated. Scope it, map it, test the basis, name the rights, rate the harm, fix what you can and report what remains. The difficulty is doing it on a real system, with real vendors, in a way that holds up twelve months later when the next cycle begins. That is usually a question of ownership and evidence rather than templates.
At CyberNX, our Digital Personal Data Protection Act consulting team helps enterprises work out how to conduct a DPIA under DPDPA, build the supporting evidence and prepare the report that goes to the Data Protection Board. Talk to our experts and get your first assessment cycle right.
How to conduct a DPIA under DPDPA FAQs
Is a DPIA mandatory for every organisation in India?
No. It is a statutory duty only for entities notified as Significant Data Fiduciaries, under Section 10(2)(c) of the DPDP Act and Rule 13 of the DPDP Rules, 2025. Other Data Fiduciaries can run one voluntarily, and it is worth doing for high-risk processing because it creates documented proof of due care.
How often must a DPIA be carried out?
Once every twelve months from the date the entity is notified as a Significant Data Fiduciary, or included in a notified class. An independent audit runs on the same cycle, and a report containing significant observations from both must be furnished to the Data Protection Board.
Can a GDPR DPIA template be reused for DPDPA?
Partly. The risk methodology transfers well, but the Indian framing is built around the rights of Data Principals rather than a general risk-to-freedoms test. The annual cadence, the reporting line to the Board and the algorithmic due diligence step are additions most European templates do not carry.
What happens if a Significant Data Fiduciary skips the DPIA?
It is a breach of the additional obligations under Section 10. The Schedule to the Act permits penalties of up to ₹150 crore, with the Data Protection Board deciding the actual amount after inquiry, based on the nature and gravity of the breach.




