Public-interest institution
Standards, interpretation guidance, and professional capacity for the Digital Personal Data Protection Act, 2023.
The Act, layered over a single record. Six frameworks make each layer implementable.
The Act states obligations. It does not state procedures, competencies or evidence. Those are the three things an organisation is actually audited on.
The Digital Personal Data Protection Act, 2023 sets obligations for every organisation that handles the personal data of people in India. It does not say how those obligations are met in practice. That work, the slow work of interpretation, procedure and capability, falls to the institutions around the law.
The Forum exists to do that work in public. It develops frameworks that translate statutory obligations into implementable practice, publishes its interpretation openly, and builds the professional competence the Act assumes but does not create.
Everything the Forum publishes is its reading of the law, not the law. It carries no regulatory force, and it is published in the open precisely so that it can be examined, contested and improved.
Select an obligation to see which framework carries it. Statutory text is paraphrased.
{{ selected.text }}
Every framework goes through the same four steps.
Chapter 01, Mumbai. Expected first week of September 2026. Operationalising DPDPA, who will lead in India's trust era?
Chapter 01 register →The Forum is independent. It accepts no vendor endorsement, publishes its standards freely, and does not act for any government body. Its governance, funding and conflict-of-interest rules are published on the governance register.
Read the governance commitments