The most expensive obligation in the DPDP Act is a security obligation

37 of the Act's 50 clauses and 44 of its 58 actionable requirements, with consent, rights and breach each carrying its own record.

The DPDP Act runs on consent: who gave it, for what purpose, whether they can take it back, and whether you can show all of it later. The largest penalty in the Act, up to ₹250 crore, attaches to failing to take reasonable security safeguards under Sec. 8(5). So the Act's most costly requirement is not a privacy notice. It is access control.

  • What Akku does under the Act
  • Rights, breach and grievances, each with a record behind it
  • Which module carries which clauses
  • What sits outside
37 / 50
Clauses of the Act
44 / 58
Actionable leaf-level requirements

From 51 overlapping requirement mappings across the platform.

What Akku does under the Act

Multi-factor and adaptive authentication on access to personal data, with the factor used recorded against each access, under Sec. 8(4) and 8(5).

Consent with a lawful basis recorded per data item, and withdrawal made as easy as giving consent.

Verifiable parental consent under Sec. 9, with purposes marked as not permitted for children and no advertising identifier issued.

Retention per purpose, with erasure carrying through to processors under Sec. 8(7).

Rights, breach and grievances, each with a record behind it

Data principal rights, Sec. 11 to 12A summary of data held, produced on request. Disclosure of which third parties received what, and why. Correction, completion, update and erasure, each recorded with what changed, which downstream systems the change reached, and when it completed.
Breach, Sec. 8(6)Detection through DLP with the detection timestamp recorded, the date the Data Protection Board was informed, and notification to each affected data principal showing which data items were involved.
Grievances, Sec. 8(10) and 13(2)A submission facility in the self-service portal, the Data Protection Officer named as owner, and response times measured against the prescribed period.

Which module carries which clauses

Consent Manager carries most of the Act, because most of the Act is about consent. Workforce IAM and adaptive MFA carry Sec. 8(5), the security safeguard the largest penalty attaches to.

ModuleClausesCount
CIAM Consent Manager4(1), 5(1), 5(1)(i), 5(1)(iii), 5(2)(a), 5(3), 6(1), 6(3), 6(4), 6(6), 6(10), 8(3), 8(4), 8(6), 8(7)(a), 8(7)(b), 8(9), 8(10), 9(1), 9(2), 9(3), 10(2)(a)(iv), 10(2)(c)(i), 10(2)(c)(ii), 11(1)(a), 11(1)(b), 11(1)(c), 12(2)(a), 12(2)(b), 12(2)(c), 12(3), 13(2), 15(d), 15(e), 3635
Workforce IAM6(1), 8(5), 15(b), 15(d), 15(e)5
Adaptive MFA8(5), 15(b), 15(e)3
DLP8(6)1
Audit logging and SIEM export361

What sits outside

The 14 requirements Akku does not cover are appointments, registrations, contracts and legal drafting, plus two that bind a registered Consent Manager and an intermediary under the IT Act rather than the fiduciary deploying Akku.

Tell us which framework you're being measured against.

Send us the framework, the audit date and what you already run. We'll come back with the mapping for your environment and the evidence Akku produces for each control.