dpdpa
Expert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor. Use this skill whenever a user asks about the DPDPA, DPDP Act, DPDP Rules 2025, India data privacy law, Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary, Data Protection Board of India, consent under DPDPA, notice requirements, breach notification India, children's data India, cross-border data transfer India, India privacy compliance, DPDPA gap analysis, DPDPA vs GDPR, or any obligation under India's personal data protection framework. Also trigger for: \"Section 6 consent\", \"Sec
npx skills add lawve-ai/awesome-legal-skills --skill dpdpa-tanaji-hemant-naik --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
What it does
The skill acts as an expert India DPDPA compliance advisor for legal, privacy, and compliance teams. It covers the full text of the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, with emphasis on timelines, terminology, and structured guidance for compliance tasks.
How it works
The guidance is organized around foundational rules and specific sections. It prescribes:
- Using DPDPA terminology (Data Fiduciary, Data Principal, Data Processor, Significant Data Fiduciary) and citing obligations by Section X or Rule Y, e.g., Rule 3 of the DPDP Rules 2025.
- Phase-aware timelines (Board operational from 13 November 2025; full compliance by 13 May 2027).
- Two lawful bases for processing: Consent (Section 6) and Certain Legitimate Uses (Section 7) with an exhaustive eight-category list; outside these, processing requires consent.
- Notice requirements (Section 5 implementing Rule 3) with explicit elements to be disclosed to Data Principals.
- Strict criteria for valid consent (free, specific, informed, unconditional, unambiguous) and withdrawal procedures (Section 6(4)).
- Section 7’s eight legitimate uses, including employment and disaster/medical emergency provisions, noting the list is exhaustive.
- General obligations (Section 8) including engaging processors under contract (Rule 16), data quality, security safeguards (Rule 7), and breach notification (Rule 6).
- Special rules for children (Section 9) with parental consent, age verification (Rule 10/12), and penalties (₹200 crore).
- Obligations for SDFs (Section 10) like DPO appointment, DPIA, independent data audit, and localization, noting that as of April 2026 no SDFs are publicly designated yet.
When to use it
Trigger conditions include questions about: Data Fiduciary obligations, Data Principal rights, cross-border transfers, breach notification timelines, children’s data, DPIA requirements, and GDPR vs DPDPA comparisons. Specific triggers listed in the skill include references to Section 6 consent, Section 7 legitimate uses, Section 9 children’s data, Section 10 SDF, Rule 6 breach notification, Rule 13 SDF obligations, Data Protection Board complaints, verifiable parental consent, DPIA roadmap, and global privacy law discussions.
What it can touch
The skill references tools and sections for drafting notices, policy reviews, consent mechanism checks, breach workflows, and SDF assessments. Explicitly, it discusses engaging processors under contract (Rule 16), breach notification timelines (Rule 6), and DPIA/Audit activities (Section 10 + Rule 13).
Caveats
Key limitations include: only digital personal data is covered; the Rules define operational specifics; the Board becomes operational from 13 November 2025, with full substantive compliance by 13 May 2027. Some items depend on future Central Government notifications (e.g., SDF designations, cross-border transfer restrictions) and are flagged as contingent.
# India DPDPA — Digital Personal Data Protection Act, 2023 Skill > **Last verified:** 2026-07-03 You are an expert **India DPDPA compliance advisor** assisting **legal, privacy, and compliance teams** at Indian organisations AND global organisations that process personal data of individuals in India. Your knowledge covers the full text of the **Digital Personal Data Protection Act, 2023** (passed 11 August 2023) and the **Digital Personal Data Protection Rules, 2025** (notified 13 November 2025), which set the operative compliance timeline. **Full compliance deadline: 13 May 2027** (18 months from Rules notification). --- ## Foundational Rules 1. **Digital-only scope.** The DPDPA applies only to **digital personal data** — data in digital form, or data that is non-digital and subsequently digitised. Physical/paper records that are never digitised fall outside its scope. This is a critical difference from GDPR, which covers all personal data regardless of medium. 2. **Two lawful bases only.** Unlike GDPR's six lawful bases, the DPDPA provides only two: **(a) Consent** (Section 6) and **(b) Certain Legitimate Uses** (Section 7 — a closed list of eight enumerated categories). There is
- Foundational Rules
- How to Respond
- DPDPA at a Glance
- Scope and Application (Sections 1 and 3)
- Chapter II — Data Fiduciary Obligations (Sections 4–10)
- Section 4 — Grounds for Processing
- Section 5 — Notice
- Section 6 — Consent
- Section 7 — Certain Legitimate Uses (Closed List)
- Section 8 — General Obligations of Data Fiduciary
- Section 9 — Processing of Personal Data of Children
- Section 10 — Additional Obligations of Significant Data Fiduciaries (SDFs)
- Chapter III — Rights and Duties of Data Principals (Sections 11–15)
- Data Principal Rights
What does the dpdpa skill do?
Expert India Digital Personal Data Protection Act, 2023 (DPDPA) compliance advisor. Use this skill whenever a user asks about the DPDPA, DPDP Act, DPDP Rules 2025, India data privacy law, Data Fiduciary obligations, Data Principal rights, Significant Data Fiduciary, Data Protection Board of India, consent under DPDPA, notice requirements, breach notification India, children's data India, cross-border data transfer India, India privacy compliance, DPDPA gap analysis, DPDPA vs GDPR, or any obligation under India's personal data protection framework. Also trigger for: \"Section 6 consent\", \"Sec
How do I install it?
Run `npx skills add lawve-ai/awesome-legal-skills --skill dpdpa-tanaji-hemant-naik --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From lawve-ai/awesome-legal-skills, a repository with 618 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.
