37 of the Act's 50 clauses and 44 of its 58 actionable requirements, with consent, rights and breach each carrying its own record.
The DPDP Act runs on consent: who gave it, for what purpose, whether they can take it back, and whether you can show all of it later. The largest penalty in the Act, up to ₹250 crore, attaches to failing to take reasonable security safeguards under Sec. 8(5). So the Act's most costly requirement is not a privacy notice. It is access control.

From 51 overlapping requirement mappings across the platform.
Multi-factor and adaptive authentication on access to personal data, with the factor used recorded against each access, under Sec. 8(4) and 8(5).
Consent with a lawful basis recorded per data item, and withdrawal made as easy as giving consent.
Verifiable parental consent under Sec. 9, with purposes marked as not permitted for children and no advertising identifier issued.
Retention per purpose, with erasure carrying through to processors under Sec. 8(7).
Consent Manager carries most of the Act, because most of the Act is about consent. Workforce IAM and adaptive MFA carry Sec. 8(5), the security safeguard the largest penalty attaches to.
| Module | Clauses | Count |
|---|---|---|
| CIAM Consent Manager | 4(1), 5(1), 5(1)(i), 5(1)(iii), 5(2)(a), 5(3), 6(1), 6(3), 6(4), 6(6), 6(10), 8(3), 8(4), 8(6), 8(7)(a), 8(7)(b), 8(9), 8(10), 9(1), 9(2), 9(3), 10(2)(a)(iv), 10(2)(c)(i), 10(2)(c)(ii), 11(1)(a), 11(1)(b), 11(1)(c), 12(2)(a), 12(2)(b), 12(2)(c), 12(3), 13(2), 15(d), 15(e), 36 | 35 |
| Workforce IAM | 6(1), 8(5), 15(b), 15(d), 15(e) | 5 |
| Adaptive MFA | 8(5), 15(b), 15(e) | 3 |
| DLP | 8(6) | 1 |
| Audit logging and SIEM export | 36 | 1 |
The 14 requirements Akku does not cover are appointments, registrations, contracts and legal drafting, plus two that bind a registered Consent Manager and an intermediary under the IT Act rather than the fiduciary deploying Akku.