Skip to main content

Overview

The Digital Personal Data Protection Act, 2023 (Act 22 of 2023, the DPDP Act) is India’s data protection law. It sets duties for Data Fiduciaries (who decide the purpose and means of processing), rights and duties for Data Principals (the individuals the data is about), and a Data Protection Board of India to enforce it. The Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E), notified 13 November 2025) are the final implementing rules; the January 2025 text (G.S.R. 02(E)) was a draft. When an AI agent reads a mailbox, places an order or processes documents for a person, it processes that person’s digital personal data. The organisation that decides why and how is usually the Data Fiduciary. The agent is software, not a Data Processor: a Data Processor is a person that processes data on a fiduciary’s behalf (s.2(k)).
This page maps Grantex features to DPDP provisions. It is not legal advice and not a certification. Grantex is a technical control that helps a Data Fiduciary evidence some obligations; it is not a registered Consent Manager, and it does not notify the Board or Data Principals. Consult qualified counsel about your own obligations.
Grantex is owned by Orchestrum Technologies LLP. Inventor and owner: Sanjeev Kumar. Ownership or IP questions may be sent to sanjeev@orchestrum.in or mishra.sanjeev@gmail.com.

When the obligations apply

The Rules bring the Act into force in three stages (Rules r.1). As of 30 September 2026 only the first has started. A proposal in January 2026 to shorten the transition was not adopted as of this writing. Check the current position before relying on these dates.

Territorial scope (s.3)

The Act applies to the processing of digital personal data within India, whether the data was collected in digital form or collected otherwise and digitised. It also applies to processing outside India if it is in connection with offering goods or services to Data Principals within India. It does not apply to processing by an individual for a personal or domestic purpose, or to personal data the Data Principal made publicly available, or that another person made publicly available under a legal obligation. Whether it applies to your deployment depends on these facts, not on where your servers are.

Section and rule mapping

“Grantex provides” describes shipped behaviour of the auth service’s /v1/dpdp routes and core grants. Everything else is yours. A Consent Manager is a person registered with the Board through which Data Principals give, manage, review and withdraw consent (ss.6(7)-(9)). Under Rule 4 and the First Schedule, registration opens on 13 November 2026 and requires, among other things, an Indian company with a net worth of at least Rs 2 crore, an interoperable platform independently certified, data that the Consent Manager itself cannot read, a seven-year machine-readable record of consents, and no sub-contracting of its obligations. Grantex is not registered as a Consent Manager and is not built as one: it acts for the developer (the Data Fiduciary), not for the Data Principal, and it keeps consent records the developer can read. Use it to keep the fiduciary’s own evidence.

Retention floors and erasure

Two retention floors from 13 May 2027 shape what erasure can remove:
  • r.6(1)(e): logs and personal data kept for one year to detect and remediate unauthorised access.
  • r.8(3): personal data, associated traffic data and processing logs kept for at least one year from the date of processing, for the purposes in the Seventh Schedule, even after an erasure request.
Grantex’s erasure therefore marks consent records erased and keeps them, and never modifies audit entries; its response lists what was retained and why. Deleting retained rows after the floor passes is your database retention decision.

Examples

Record consent against an active grant:
Produce a DPDP audit export for a period:
The export’s data holds exportType, dateRange, generatedAt, developerId, consentRecords, auditLog (at most 1,000 entries; see truncated) and grievances. It is not a format prescribed by the Board. See DPDP Compliance for every feature.

FAQ

Do the DPDP obligations apply to us today?

As of 30 September 2026 the notice, consent, security, breach, erasure, rights and penalty provisions are not yet in force; they apply from 13 May 2027. Building the controls now gives time to test them.

Does Grantex handle grievances for us?

No. Grantex records grievances, the response period you publish and the due date, and a review workflow. Receiving, answering and meeting the period is your process, run by your DPO or designated person.

Does withdrawal revoke the agent’s access immediately?

Only if you ask: pass revokeGrant: true, or set DPDP_WITHDRAWAL_REVOKES_GRANT=true. The record’s own grant is revoked; grants delegated from it are revoked too only with DPDP_REVOCATION_CASCADE=true. The revocation is visible to services that check revocation state. Processing in your own systems must also stop. No. See above.

How does this relate to GDPR?

The same records support a GDPR Art. 15 access export (gdpr-article-15 with dataPrincipalId). GDPR has its own rules, for example a one-month response time for access requests (Art. 12(3)) and breach notification to the supervisory authority within 72 hours unless the breach is unlikely to result in a risk (Art. 33).

What are the penalties?

The Schedule to the Act sets maximum penalties per breach of a duty, up to Rs 250 crore for failing to take reasonable security safeguards. They are not a percentage of turnover, and they cannot be imposed for conduct before the relevant provisions commence.

Sources

Last modified on September 30, 2026