Overview
The Digital Personal Data Protection Act, 2023 (Act 22 of 2023, the DPDP Act) is India’s data protection law. It sets duties for Data Fiduciaries (who decide the purpose and means of processing), rights and duties for Data Principals (the individuals the data is about), and a Data Protection Board of India to enforce it. The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), notified 13 November 2025) are the final implementing rules; the January 2025 text (G.S.R. 02(E)) was a draft. When an AI agent reads a mailbox, places an order or processes documents for a person, it processes that person’s digital personal data. The organisation that decides why and how is usually the Data Fiduciary. The agent is software, not a Data Processor: a Data Processor is a person that processes data on a fiduciary’s behalf (s.2(k)). Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership or IP questions may be sent to sanjeev@orchestrum.in or mishra.sanjeev@gmail.com.When the obligations apply
The Rules bring the Act into force in three stages (Rules r.1). As of 30 September 2026 only the first has started.
A proposal in January 2026 to shorten the transition was not adopted as of
this writing. Check the current position before relying on these dates.
Territorial scope (s.3)
The Act applies to the processing of digital personal data within India, whether the data was collected in digital form or collected otherwise and digitised. It also applies to processing outside India if it is in connection with offering goods or services to Data Principals within India. It does not apply to processing by an individual for a personal or domestic purpose, or to personal data the Data Principal made publicly available, or that another person made publicly available under a legal obligation. Whether it applies to your deployment depends on these facts, not on where your servers are.Section and rule mapping
“Grantex provides” describes shipped behaviour of the auth service’s/v1/dpdp routes and core grants. Everything else is yours.
Consent Managers, and why Grantex is not one
A Consent Manager is a person registered with the Board through which Data Principals give, manage, review and withdraw consent (ss.6(7)-(9)). Under Rule 4 and the First Schedule, registration opens on 13 November 2026 and requires, among other things, an Indian company with a net worth of at least Rs 2 crore, an interoperable platform independently certified, data that the Consent Manager itself cannot read, a seven-year machine-readable record of consents, and no sub-contracting of its obligations. Grantex is not registered as a Consent Manager and is not built as one: it acts for the developer (the Data Fiduciary), not for the Data Principal, and it keeps consent records the developer can read. Use it to keep the fiduciary’s own evidence.Retention floors and erasure
Two retention floors from 13 May 2027 shape what erasure can remove:- r.6(1)(e): logs and personal data kept for one year to detect and remediate unauthorised access.
- r.8(3): personal data, associated traffic data and processing logs kept for at least one year from the date of processing, for the purposes in the Seventh Schedule, even after an erasure request.
erased and keeps them, and
never modifies audit entries; its response lists what was retained and why.
Deleting retained rows after the floor passes is your database retention
decision.
Examples
Record consent against an active grant:data holds exportType, dateRange, generatedAt,
developerId, consentRecords, auditLog (at most 1,000 entries; see
truncated) and grievances. It is not a format prescribed by the Board.
See DPDP Compliance for every feature.
FAQ
Do the DPDP obligations apply to us today?
As of 30 September 2026 the notice, consent, security, breach, erasure, rights and penalty provisions are not yet in force; they apply from 13 May 2027. Building the controls now gives time to test them.Does Grantex handle grievances for us?
No. Grantex records grievances, the response period you publish and the due date, and a review workflow. Receiving, answering and meeting the period is your process, run by your DPO or designated person.Does withdrawal revoke the agent’s access immediately?
Only if you ask: passrevokeGrant: true, or set
DPDP_WITHDRAWAL_REVOKES_GRANT=true. The record’s own grant is revoked;
grants delegated from it are revoked too only with
DPDP_REVOCATION_CASCADE=true. The revocation is visible to services that
check revocation state.
Processing in your own systems must also stop.
Is Grantex a Consent Manager?
No. See above.How does this relate to GDPR?
The same records support a GDPR Art. 15 access export (gdpr-article-15 with
dataPrincipalId). GDPR has its own rules, for example a one-month response
time for access requests (Art. 12(3)) and breach notification to the
supervisory authority within 72 hours unless the breach is unlikely to result
in a risk (Art. 33).
What are the penalties?
The Schedule to the Act sets maximum penalties per breach of a duty, up to Rs 250 crore for failing to take reasonable security safeguards. They are not a percentage of turnover, and they cannot be imposed for conduct before the relevant provisions commence.Sources
- Digital Personal Data Protection Act, 2023
- Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E))
Related Resources
- DPDP Compliance Module — what each feature does
- EU AI Act — EU AI Act mapping
- Compliance Evidence Pack API — audit-chain evidence
- Compliance Matrix — cross-framework mapping
- Blog: DPDP Act and AI Agents