This release is a pre-release and may not be stable for production use.
dpdpkit-core
The rules engine behind dpdpkit. It provides a consent ledger, versioned notices, rights requests and grievances, retention and erasure, audit evidence, and a CLI for India's Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025.
Disclaimer. dpdpkit is software that helps you implement obligations under India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. It does not provide legal advice and does not guarantee compliance. Decisions about notices, purposes, retention and incident reporting must be made by you or your counsel.
Core has no web framework and no database driver. Framework adapters
(dpdpkit-fastapi, dpdpkit-django) implement its
Repository protocol and expose it over the REST contract defined in
dpdpkit-spec.
Install
pip install dpdpkit # core + policy packs + CLI
pip install "dpdpkit[fastapi]" # with the FastAPI adapter
Use
from dpdpkit import InMemoryRepository, MemoryNotifier, kit_from_config, load_config, sync_notice
config = load_config("dpdpkit.yaml") # `dpdpkit init` writes a starter file
kit = kit_from_config(config, InMemoryRepository(), notifier=MemoryNotifier(), signing_key="change-me")
sync_notice(kit, config) # publishes the notice if its text changed
kit.consent.grant("u_42", "marketing") # recorded against the current notice version
kit.consent.check("u_42", "marketing") # True
kit.consent.withdraw("u_42", "marketing") # one call, same as granting
kit.rights.open("u_42", "erasure") # due dates come from the policy pack
kit.retention.run() # warns, then erases only after a delivered warning
kit.ledger.verify() # raises LedgerTampered(row_id) if a row was edited
Modules
| Module | Responsibility |
|---|---|
dpdpkit.policy |
Load and validate a policy pack; typed accessors for every legal number |
dpdpkit.registry |
Purposes, data items, legal basis (consent / DPDP Act s.7), processors, data stores |
dpdpkit.notices |
Versioned notices, content hash, locale fallback, required-link check |
dpdpkit.ledger |
Append-only SHA-256 hash chains (consent + audit) per tenant, verify(), root-hash export |
dpdpkit.consent |
grant, deny, withdraw, check, current state, signed receipts |
dpdpkit.rights |
Access, correction, completion, updating, erasure, nomination and grievance requests |
dpdpkit.retention |
Erasure schedules, pre-erasure warnings, legal holds, needs_attention, processor fan-out |
dpdpkit.events |
In-process event bus and HMAC-signed webhooks |
dpdpkit.notify |
Notifier protocol with delivery receipts; memory, console and SMTP transports |
dpdpkit.export |
Principal export (JSON, HTML) and evidence packs (CSV + PDF zip) |
Fail-safe rules
- An erasure runs only after its warning is recorded as delivered, and only once the full warning
period has passed since delivery. Otherwise it moves to a
needs_attentionqueue. - Missing contact details, failed deliveries, failing erasure handlers and legal holds all stop erasure.
- Every state change writes a ledger or audit entry before it takes effect.
- A missing or invalid policy pack means the kit refuses to start. There are no built-in defaults.
- There is no function that submits anything to an authority.
CLI
dpdpkit init # starter dpdpkit.yaml
dpdpkit policy show | list | diff OLD NEW
dpdpkit ledger verify --kit myapp.dpdp:kit # exit code 2 if tampered
dpdpkit retention preview --kit myapp.dpdp:kit
dpdpkit export --principal u_42 --format html --kit myapp.dpdp:kit
dpdpkit export --evidence --out evidence.zip --kit myapp.dpdp:kit
Writing an adapter
Implement dpdpkit.repository.Repository (see its docstring for the rules) and run the
dpdpkit-conformance suite from dpdpkit-spec against your HTTP layer.
Development
uv venv && uv pip install -e ../dpdpkit-policies -e ".[dev]"
pytest && ruff check . && mypy
Licence
Apache-2.0.
Metadata
Release files for dpdpkit-core 0.1.0a1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| dpdpkit_core-0.1.0a1.tar.gz | 55.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| dpdpkit_core-0.1.0a1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 106.8 kB
Release files / dpdpkit_core-0.1.0a1.tar.gz
| Download URL | dpdpkit_core-0.1.0a1.tar.gz |
|---|---|
| Size | 55.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
93df0d6fad5521635897e22400da36fc5ca3e7031b212fd2d194a76927c2d213
|
|
BLAKE2b-256 checksum How to use checksums |
9a8891b3259220b78c0d50630badc7f9ac0a52e91eb862d2a031c779e5562d19
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.
Transparency logRelease files / dpdpkit_core-0.1.0a1-py3-none-any.whl
| Download URL | dpdpkit_core-0.1.0a1-py3-none-any.whl |
|---|---|
| Size | 51.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
94034830543ce5bb0410f85172423a379e4fbca908c91bfc4caa38630977c03d
|
|
BLAKE2b-256 checksum How to use checksums |
344831018761ce642e4c06bff676c3bcfb3f059fb34def147c110b111e3417a0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.
Transparency log