Skip to content
Back to Blog
·10 min read·compliance

DPIA Under DPDP: A Practical Guide for Indian Companies

How to run a Data Protection Impact Assessment under India DPDP Act 2023 — mandatory for Significant Data Fiduciaries, smart practice for everyone else.

BR

Bachao.AI Research Team

Cybersecurity Research

Check DPDP Compliance

Compliance risk for Indian SMBs

Non-compliance with the DPDP Act 2023 carries penalties up to ₹250 crore. This post explains what's at stake and what action to take.

A Data Protection Impact Assessment (DPIA) is a structured exercise that maps how personal data flows through a process, weighs whether the collection and use are actually necessary, and identifies risks to the people whose data it is before those risks turn into harm. Under India's Digital Personal Data Protection Act, 2023 (DPDP Act), a DPIA is a named legal obligation for organisations classified as Significant Data Fiduciaries (SDFs) — not a universal requirement for every business. Smaller companies are not legally bound to run one, but adopting the same discipline voluntarily is a high-leverage compliance habit: it catches privacy and security gaps long before an audit, a breach, or a regulator does.

What a DPIA Actually Is

Strip away the compliance vocabulary and a DPIA answers four questions in order: what personal data are we processing and why, is this the least data and access needed for that purpose, what could go wrong for the individual (the "Data Principal" in DPDP terminology) if this data is misused, lost, or over-retained, and what are we doing to reduce that risk before we proceed. It is deliberately a before-the-fact exercise — done at the design stage of a new product, feature, vendor integration, or data-sharing arrangement, not retrofitted after launch.

A DPIA is not a security audit and not a penetration test. A VAPT engagement tells you whether your systems can be broken into; a DPIA tells you whether you should be holding that data at all, and under what controls. The two are complementary.

When DPDP Makes a DPIA Relevant

The DPDP Act 2023 introduces the category of Significant Data Fiduciary — a Data Fiduciary that the Central Government designates based on factors such as the volume and sensitivity of personal data processed, risk to the rights of Data Principals, potential impact on the sovereignty and integrity of India, risk to electoral democracy, security of the State, and public order. Section 10 of the Act sets out these obligations for entities notified as SDFs, and they form a linked set:

    1. Appoint a Data Protection Officer (DPO) who is based in India and represents the Significant Data Fiduciary, and who reports to its Board of Directors or an equivalent governing body.
    2. Appoint an independent data auditor to evaluate compliance.
    3. Undertake a Data Protection Impact Assessment and a periodic audit, with the observations of both reported to the Board.
This is the specific legal hook: DPIA is not a stand-alone requirement floating in the Act, it is bundled with SDF status, an India-based DPO, and independent audit as one compliance package. Thresholds for who actually gets notified as an SDF are set by the Central Government — administered through the Ministry of Electronics and Information Technology — through rules and notifications under the Act rather than a static list in the statute itself, so the practical scope has room to expand over time.
ℹ️
INFO
If your organisation has not been notified as a Significant Data Fiduciary, you are not currently under a statutory obligation to run a DPIA under the DPDP Act. This guide treats DPIA as good practice for everyone and a compliance requirement specifically for SDFs — the two audiences need the same process, just different urgency.

Why Smaller Companies Should Run One Anyway

Most Indian startups and mid-market companies will never be designated a Significant Data Fiduciary, but many process the same categories of data — health records, financial details, children's data, large user bases — that make a DPIA genuinely useful regardless of legal compulsion. Three reasons to adopt it voluntarily:

  1. Fixing a design is cheaper than unwinding a breach. A DPIA before a signup flow ships costs a few hours. Fixing over-collection after 100,000 signups costs an engineering sprint, and possibly a complaint to the Data Protection Board.
  2. Enterprise and government customers increasingly ask for it. Vendor security questionnaires from larger counterparties are starting to ask "do you run privacy impact assessments," DPDP-notified or not — a trend industry bodies like the Data Security Council of India have tracked as privacy maturity becomes a procurement criterion.
  3. It creates the paper trail regulators actually want. A dated, signed-off DPIA is exactly the "reasonable security safeguard" evidence the DPDP Act's penalty provisions reward having and punish lacking.
💡
TIP
Start with your highest-risk data flow, not your whole company. A single DPIA on the process that touches the most sensitive data (payments, health, biometric, or minors' data) teaches the team the method faster than trying to assess everything at once.

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

The DPIA Workflow, Step by Step

graph TD A[Screening Trigger] --> B[Describe the Processing] B --> C[Assess Necessity and Proportionality] C --> D[Identify Risks to Data Principals] D --> E[Decide Mitigations] E --> F{Residual Risk Decision} F -->|Low or Accepted Risk| G[Sign-off by DPO and Owner] F -->|High Residual Risk - Do Not Proceed| H[Escalate or Redesign] G --> I[Periodic Review] classDef normal fill:#1e3a5f,stroke:#3B82F6,color:#e2e8f0 classDef success fill:#1e3d2f,stroke:#10B981,color:#e2e8f0 classDef danger fill:#5f1e1e,stroke:#EF4444,color:#e2e8f0 class A,B,C,D,E,F normal class G,I success class H danger

Step 1 — Screening trigger

Decide which projects require a DPIA before they proceed: a new feature collecting personal data, a new vendor with data access, a change to retention periods, cross-border transfer, or a new automated decision system. A short screening checklist — does this touch personal data, is any of it sensitive, is the volume material — filters out projects that do not need a full assessment.

Step 2 — Describe the processing

Document, in plain language, what personal data is collected, from whom, through what channel, where it is stored, who can access it, how long it is retained, and whether it moves to a third party or outside India. This is the factual baseline everything else is assessed against.

Step 3 — Assess necessity and proportionality

For every field collected, ask whether the stated purpose can be achieved with less. This is where most DPIAs earn their keep — it is common to find fields collected "in case we need it later" with no defined purpose, exactly the kind of collection the DPDP Act's purpose-limitation principle discourages.

Step 4 — Identify risks to Data Principals

Think from the individual's side, not the company's. What happens to them if this data is exposed, sold, misused, retained indefinitely, or used for an automated decision — a loan, a job screen, a credit score — without recourse. Rank risks by likelihood and severity, not by how uncomfortable they are to write down.

Step 5 — Decide mitigations

For each risk, assign a concrete control: encryption at rest, role-based access, a retention and deletion schedule, processor contract clauses, anonymisation before analytics use, or an opt-out mechanism. A mitigation with no owner and no date is a note, not a mitigation.

Step 6 — Residual risk decision

After mitigations, some risk remains. The DPIA must make an explicit call: is the residual risk low enough to accept, or high enough that the project should not proceed as designed. Document the decision — do not leave it implied.

Step 7 — Sign-off

The DPIA is reviewed and formally signed off, typically by the DPO (or whoever holds that role at a smaller company) with the business owner, and escalated to leadership or the Board for higher-risk assessments. For a Significant Data Fiduciary, findings feed into what is reported to the Board under the Act.

Step 8 — Periodic review

A DPIA is not a one-time document. Revisit it when processing changes materially, and on a fixed cadence — annually is a common baseline — since data flows tend to drift as teams add fields and integrations.

Who Signs Off on a DPIA

RoleTypical Responsibility
Data Protection Officer (or privacy lead)Owns the DPIA process, challenges necessity claims, holds sign-off authority
Business / Product OwnerProvides the processing description, commits to mitigations and their timelines
Engineering or Security LeadValidates that technical controls (access, encryption, retention tooling) are actually implementable
Legal / ComplianceConfirms consent language, contractual clauses with processors, and regulatory fit
Board or Leadership (for high-risk or SDF-scale assessments)Receives DPIA and audit observations, approves proceeding on high-residual-risk items
⚠️
WARNING
A DPIA signed off by only one person, especially only the engineer who built the feature, is not an independent check — it is a self-review. Independence of the reviewer from the person building the feature is what makes the sign-off worth anything.

Risk Categories a Typical DPIA Surfaces

The chart below is illustrative — actual distribution varies by company and sector — but it reflects the pattern most first-time DPIAs uncover: the biggest gaps are in what is collected and who can see it, not in headline-grabbing technical exploits.

pie title Illustrative DPIA Findings by Category - Indicative Only "Excessive collection" : 28 "Weak access control" : 24 "Long retention" : 20 "Third-party sharing" : 18 "No deletion path" : 10
🛡️
SECURITY
"No deletion path" is a small slice by count but a disproportionately large legal exposure — the DPDP Act gives Data Principals a right to erasure, and a system with no engineered way to delete a specific person's data on request cannot honour that right no matter how good its other controls are.

A DPIA Template You Can Adopt Today

You do not need specialised software to start. A shared document with these sections, filled in per project, is a working DPIA template:

SectionWhat to Capture
Project name and ownerWho is accountable for this processing
Data inventoryFields collected, source, sensitivity classification
Purpose and legal basisWhy each field is needed, under what DPDP consent or legitimate-use basis
Data flow mapSystems, vendors, and geographies the data passes through
Risk registerEach identified risk, likelihood, severity, and current control
Mitigation planAction, owner, target date, verification method
Residual risk decisionAccepted / not accepted, and by whom
Sign-offNames, roles, and date
Review dateNext scheduled reassessment
🎯Key Takeaway
A DPIA is not paperwork for its own sake — it is the cheapest point in the lifecycle to catch over-collection, weak access control, and missing deletion paths, before they become a breach, a complaint to the Data Protection Board, or a lost enterprise deal. Significant Data Fiduciaries must run one under the DPDP Act; every other company should run one anyway.
6Factors considered by the Central Government when designating a Significant Data Fiduciary under DPDP Act Section 10 (MeitY)
Up to ₹250 croreMaximum penalty schedule under DPDP Act 2023 for failure to take reasonable security safeguards (MeitY)

A DPIA works best as one input into a broader compliance and security programme, not a stand-alone exercise. Once its risk register flags which systems hold the most sensitive data, that is the list worth putting through a technical security audit — Bachao.AI's automated VAPT platform, built by Dhisattva AI Pvt Ltd, gives Indian teams that follow-through without a multi-week manual engagement, and can be paired with a CERT-In empanelled partner where an empanelled audit is specifically required. The DPDP compliance page covers how DPIA documentation fits alongside a technical audit, and a free VAPT scan is a reasonable place to start.

This article is general guidance on DPDP compliance practice, not legal advice — consult qualified counsel to assess your organisation's specific obligations.

For more on how DPDP obligations connect to day-to-day security practice, browse the Bachao.AI blog.

Frequently Asked Questions

Is a DPIA legally mandatory for every company under the DPDP Act?
No. The DPDP Act 2023 attaches the DPIA obligation specifically to organisations designated as Significant Data Fiduciaries, alongside appointing an India-based Data Protection Officer and an independent data auditor. Companies not designated as SDFs are not under a statutory DPIA obligation, though running one voluntarily is good practice.
What is a Significant Data Fiduciary?
It is a category of Data Fiduciary that the Central Government can designate under Section 10 of the DPDP Act, based on factors including the volume and sensitivity of personal data processed and the risk to Data Principals' rights, among others. SDFs carry extra obligations, including DPIA, an India-based DPO, and independent audit.
How often should a DPIA be reviewed?
At minimum whenever the underlying processing changes materially — a new data field, a new vendor, a new retention period — and on a fixed cadence, commonly annually, since data flows tend to drift over time.
Who should sign off on a DPIA?
The Data Protection Officer or equivalent privacy lead together with the business owner of the project, with escalation to leadership or the Board for higher-risk assessments. Sign-off by only the person who built the feature is not an independent review.
Does a DPIA replace a security audit or VAPT?
No. A DPIA assesses whether data collection and use are necessary and proportionate; a VAPT assesses whether the systems holding that data can be technically compromised. They are complementary, and DPIA findings often identify which systems most need a technical audit.
What happens if a DPIA finds a high residual risk?
The project should not proceed as designed. The finding gets escalated for redesign, additional mitigation, or a leadership decision on whether the residual risk is acceptable — that decision has to be explicit and documented, not assumed by default.
BR

Bachao.AI Research Team

Cybersecurity Research

AI-powered security research and threat intelligence from the Bachao.AI team. Covering the latest vulnerabilities, CVEs, and cybersecurity developments affecting Indian businesses.

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

See where your business stands against the DPDP Act 2023

Free automated scan — risk score in under 2 hours. No credit card required.

Check DPDP Compliance
Find your vulnerabilitiesStart free scan →