India DPDP Act
DPDP Notice + Consent + Lawful Processing (Sec 4-7)

India DPDP Act DPDP-Scope-2023-Sec5-NoticeConsent-LawfulProcessing-PurposeLimitation-DataMinimisation: DPDP Act Sections 4-7 + Notice + Consent + Lawful Processing + Purpose Limitation + Data Minimisation + Legitimate Uses + Sec 4 Lawful Use + Sec 5 Notice + Sec 6 Consent + Sec 7 Legitimate Uses

Sections 4-7 of DPDP Act 2023 establish the foundational lawful processing framework. Section 4 Grounds for Processing Personal Data: a person may process the personal data of a Data Principal only in accordance with the provisions of this Act and for a lawful purpose - (a) for which the Data Principal has given her consent; or (b) for certain legitimate uses (Section 7). Section 5 Notice: every request made to a Data Principal for consent shall be accompanied or preceded by a notice given by the Data Fiduciary to the Data Principal informing her - (i) the personal data and the purpose for which the same is proposed to be processed; (ii) the manner in which she may exercise her rights under Section 11 (Right to Information) + Section 13 (Right to Grievance Redressal) + and may make a complaint to the Board (DPBI); (iii) the manner in which the Data Principal may make a complaint to the Board. Section 5(2) Multi-Language Notice: information given in the notice shall be available in English or any language specified in the Eighth Schedule of the Constitution (22 languages including Hindi + Tamil + Bengali + Telugu + Marathi + Gujarati + Kannada + Malayalam + Punjabi + Odia + Assamese + Urdu + Sanskrit + Sindhi + Konkani + Manipuri + Nepali + Kashmiri + Maithili + Santali + Dogri + Bodo). Section 6 Consent: must be free + specific + informed + unconditional + unambiguous with clear affirmative action + signify agreement to the processing for specified purpose + limited to such personal data as is necessary for such specified purpose. Section 6(4) Withdrawal of Consent: shall be as easy as giving consent + on withdrawal of consent the Data Fiduciary shall cease processing within a reasonable time + shall cause its Data Processors to cease processing the personal data of Data Principal. Section 6(5) Itemised Notice: itemising of personal data items and purposes. Section 6(7) Consent Manager: every Consent Manager shall be registered with the Data Protection Board of India + acts as a single point of contact to enable a Data Principal to give consent + manage consent + review consent + withdraw consent - this links DPDP to RBI Account Aggregator (NBFC-AA licensees register as Consent Managers under DPDP). Section 7 Certain Legitimate Uses (Lawful Without Consent): Personal data may be processed for the specified purpose for which the Data Principal has voluntarily provided her personal data + government processing for subsidy/benefit/service/licence/permit (with safeguards) + judicial functions + medical emergency + employment-related purpose + necessary to respond to medical emergency + necessary for safety of public during a disaster + breakdown of public order. Coordinates with RBI Account Aggregator Framework (DPDP Sec 6(7) Consent Manager links AA NBFC-AA licensees registered as DPDP CMs) + GDPR Art 13-14 + UK GDPR + Singapore PDPA + India Stack DPI + Aadhaar Act consent + 22 official languages + Constitution 8th Schedule. DPDP Sec 4-7 Notice + Consent + Lawful Processing applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 94 controls across 34 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

APPI · 3 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • AZ-DPA-14 Article 16 - Liability for violations
  • AZ-DPA-15 Article 17 - Dispute resolution

Bahrain PDPL · 3 controls

  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • FDBR-SensitiveData-Children-VoiceFacial Sensitive Data, Children's Privacy and Voice/Facial Recognition (Fla. Stat. 501.711, 501.1735)

ISO/IEC 29100:2024 · 3 controls

  • 29100-6.10 Information security
  • 29100-6.5 Use, retention and disclosure limitation
  • 29100-6.9 Accountability

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure

ISO/IEC 27400:2022 · 2 controls

  • 27400-5.4 Data and privacy risks
  • 27400-7.3 Data minimization and purpose limitation
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration
  • ItalyCodice-Garante-Enforcement-AdministrativeSanctions-Criminal-Art166-167-170-20MEUR-Coord-EDPB Italy Codice Garante Authority + Article 140-bis + Article 144 Complaints + Article 166 Administrative Sanctions up to EUR 20M/4% + Article 167 Criminal Offences + Article 170 Failure to Comply with Garante Orders + EDPB Coordination
  • ItalyCodice-SpecialCategories-Health-Workplace-Education-ScientificResearch-HistoricalResearch-Art75-92-96-99-101 Italy Codice Special Categories + Article 75 Administrative Fines + Article 92 Medical Records + Article 96 Education + Article 99 Scientific Research + Article 101 Historical Research + Workplace Privacy + Worker Monitoring Article 4 Workers Statute
  • AUPRV-4 APP 10-11 Quality, Security of Personal Information
  • AUPRV-7 Notifiable Data Breaches (NDB) Scheme, Incident Response
  • RUSPD-1 Scope, Definitions, Principles under 152-FZ
  • RUSPD-4 Special Categories, Biometric Data
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VIETNAMCYBER-4 Incident Reporting and Cooperation
  • AL-DPA-12 International Data Transfers
  • CA-10 Selects and Develops Control Activities
  • CTDPA-1 Definitions
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)

FedRAMP Rev 5 · 1 control

  • FedRAMP-PII-Privacy FedRAMP PII processing + privacy controls (NIST 800-53 Rev 5 PT family + Privacy Act)

IEEE 7000 · 1 control

  • IEEE7000-Values-Elicitation-Prioritisation-IEEE7000Family-Bias-Privacy-Transparency IEEE 7000 Clauses 6 + 6.1 - Ethical Values Elicitation + Prioritisation + IEEE 7000 Family Integration (Bias + Privacy + Transparency + Wellbeing)
  • DOM172-Lawful-Basis-Consent-Notice-Information-Duty-Articles-4-12-Quality-Principle-Purpose-Limitation-Minimisation Dominican Republic Law 172-13 Lawful Basis + Consent + Notice + Information Duty + Articles 4-12
  • PAKPDPB-8 Enforcement, Penalties, Complaints, Retention, Training
  • RIDTPPA-2 Consumer Rights (Access, Correction, Deletion, Portability, Opt-Out)

South Korea PIPA · 1 control

  • PIPA-Pseudonymisation-Article-28-2-3-Enforcement-PIPC-Investigation-Surcharges-3-Percent-Revenue-Article64-2 Korea PIPA Pseudonymisation + Article 28-2 + Enforcement + PIPC + Surcharges 3% + Article 63 + 64-2
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 94 it maps to, and the evidence behind each claim, over MCP and REST.