Agent skill · Data & Analytics

dpdpa

Expert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor. Use this skill whenever a user asks about the DPDPA, DPDP Act, DPDP Rules 2025, India data privacy law, Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary, Data Protection Board of India, consent under DPDPA, notice requirements, breach notification India, children's data India, cross-border data transfer India, India privacy compliance, DPDPA gap analysis, DPDPA vs GDPR, or any obligation under India's personal data protection framework. Also trigger for: \"Section 6 consent\", \"Sec

lawve-aigithub.com/lawve-aiGitHub ↗
claude-codeNOASSERTION
Install
npx skills add lawve-ai/awesome-legal-skills --skill dpdpa-tanaji-hemant-naik --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 7
SKILL.md size: 26 KB
Bundled scripts: none
Path: skills/dpdpa-tanaji-hemant-naik/SKILL.md
Open the folder on GitHub →
Where it comes from
Stars: 618
Language: Python

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

Review
written from the skill's own SKILL.md · Aug 5, 2026

What it does

The skill acts as an expert India DPDPA compliance advisor for legal, privacy, and compliance teams. It covers the full text of the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, with emphasis on timelines, terminology, and structured guidance for compliance tasks.

How it works

The guidance is organized around foundational rules and specific sections. It prescribes:

  • Using DPDPA terminology (Data Fiduciary, Data Principal, Data Processor, Significant Data Fiduciary) and citing obligations by Section X or Rule Y, e.g., Rule 3 of the DPDP Rules 2025.
  • Phase-aware timelines (Board operational from 13 November 2025; full compliance by 13 May 2027).
  • Two lawful bases for processing: Consent (Section 6) and Certain Legitimate Uses (Section 7) with an exhaustive eight-category list; outside these, processing requires consent.
  • Notice requirements (Section 5 implementing Rule 3) with explicit elements to be disclosed to Data Principals.
  • Strict criteria for valid consent (free, specific, informed, unconditional, unambiguous) and withdrawal procedures (Section 6(4)).
  • Section 7’s eight legitimate uses, including employment and disaster/medical emergency provisions, noting the list is exhaustive.
  • General obligations (Section 8) including engaging processors under contract (Rule 16), data quality, security safeguards (Rule 7), and breach notification (Rule 6).
  • Special rules for children (Section 9) with parental consent, age verification (Rule 10/12), and penalties (₹200 crore).
  • Obligations for SDFs (Section 10) like DPO appointment, DPIA, independent data audit, and localization, noting that as of April 2026 no SDFs are publicly designated yet.

When to use it

Trigger conditions include questions about: Data Fiduciary obligations, Data Principal rights, cross-border transfers, breach notification timelines, children’s data, DPIA requirements, and GDPR vs DPDPA comparisons. Specific triggers listed in the skill include references to Section 6 consent, Section 7 legitimate uses, Section 9 children’s data, Section 10 SDF, Rule 6 breach notification, Rule 13 SDF obligations, Data Protection Board complaints, verifiable parental consent, DPIA roadmap, and global privacy law discussions.

What it can touch

The skill references tools and sections for drafting notices, policy reviews, consent mechanism checks, breach workflows, and SDF assessments. Explicitly, it discusses engaging processors under contract (Rule 16), breach notification timelines (Rule 6), and DPIA/Audit activities (Section 10 + Rule 13).

Caveats

Key limitations include: only digital personal data is covered; the Rules define operational specifics; the Board becomes operational from 13 November 2025, with full substantive compliance by 13 May 2027. Some items depend on future Central Government notifications (e.g., SDF designations, cross-border transfer restrictions) and are flagged as contingent.

From the SKILL.md

# India DPDPA — Digital Personal Data Protection Act, 2023 Skill > **Last verified:** 2026-07-03 You are an expert **India DPDPA compliance advisor** assisting **legal, privacy, and compliance teams** at Indian organisations AND global organisations that process personal data of individuals in India. Your knowledge covers the full text of the **Digital Personal Data Protection Act, 2023** (passed 11 August 2023) and the **Digital Personal Data Protection Rules, 2025** (notified 13 November 2025), which set the operative compliance timeline. **Full compliance deadline: 13 May 2027** (18 months from Rules notification). --- ## Foundational Rules 1. **Digital-only scope.** The DPDPA applies only to **digital personal data** — data in digital form, or data that is non-digital and subsequently digitised. Physical/paper records that are never digitised fall outside its scope. This is a critical difference from GDPR, which covers all personal data regardless of medium. 2. **Two lawful bases only.** Unlike GDPR's six lawful bases, the DPDPA provides only two: **(a) Consent** (Section 6) and **(b) Certain Legitimate Uses** (Section 7 — a closed list of eight enumerated categories). There is

What's inside
Steps it walks through
  1. Foundational Rules
  2. How to Respond
  3. DPDPA at a Glance
  4. Scope and Application (Sections 1 and 3)
  5. Chapter II — Data Fiduciary Obligations (Sections 4–10)
  6. Section 4 — Grounds for Processing
  7. Section 5 — Notice
  8. Section 6 — Consent
  9. Section 7 — Certain Legitimate Uses (Closed List)
  10. Section 8 — General Obligations of Data Fiduciary
  11. Section 9 — Processing of Personal Data of Children
  12. Section 10 — Additional Obligations of Significant Data Fiduciaries (SDFs)
  13. Chapter III — Rights and Duties of Data Principals (Sections 11–15)
  14. Data Principal Rights
Ships with 6 files
  • LICENSE
  • README.md
  • references/gdpr-comparison.md
  • references/rights-and-obligations.md
  • references/rules-2025.md
  • references/sections-reference.md
More from awesome-legal-skills
All skills →
About this skill
What does the dpdpa skill do?

Expert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor. Use this skill whenever a user asks about the DPDPA, DPDP Act, DPDP Rules 2025, India data privacy law, Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary, Data Protection Board of India, consent under DPDPA, notice requirements, breach notification India, children's data India, cross-border data transfer India, India privacy compliance, DPDPA gap analysis, DPDPA vs GDPR, or any obligation under India's personal data protection framework. Also trigger for: \"Section 6 consent\", \"Sec

How do I install it?

Run `npx skills add lawve-ai/awesome-legal-skills --skill dpdpa-tanaji-hemant-naik --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From lawve-ai/awesome-legal-skills, a repository with 618 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going