This release is a pre-release and may not be stable for production use.
dpdpkit-policies
Versioned policy packs for India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. Every legal number that dpdpkit uses lives here. Examples are the 48-hour pre-erasure warning, the one-year log floor and the 90-day grievance ceiling. None of them are in code.
Disclaimer. dpdpkit is software that helps you implement obligations under India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. It does not provide legal advice and does not guarantee compliance. Decisions about notices, purposes, retention and incident reporting must be made by you or your counsel.
Install
Installed automatically with pip install dpdpkit. On its own:
pip install dpdpkit-policies
Use
from dpdpkit_policies import load_pack
pack = load_pack("dpdp-rules-2025.v1", overlays=[])
pack["retention"]["erasure_pre_notice_hours"] # 48
dpdpkit-policies list
dpdpkit-policies validate # every shipped pack and overlay
dpdpkit-policies validate my-pack.yaml # your own file
dpdpkit-policies rule-map --format md # rule-to-code table for the docs site
Versioning
- Pack ids (
dpdp-rules-2025.v1,.v2…) change when the law or its numbers change. A pack is never edited after release; a new version is added instead. - The package uses CalVer (
2026.10.0) and is released independently of dpdpkit's code packages, so a rule change ships without a code release.
Rule-change process
- Watch official sources: MeitY notifications, the eGazette, the Data Protection Board website.
- Open an issue with the
rule-changelabel linking the official text. - Numbers only changed → new pack version + new release of this package. No code release.
- New obligation → feature added to
dpdpkit-corebehind a flag, then enabled by the new pack. - Every
CHANGELOG.mdentry cites the notification.
Pack format
See src/dpdpkit_policies/packs/dpdp-rules-2025.v1.yaml
and the JSON Schema in src/dpdpkit_policies/schema/. Overlays are
described in overlays/README.md.
Licence
Apache-2.0.
Metadata
Release files for dpdpkit-policies 2026.10.0a1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| dpdpkit_policies-2026.10.0a1.tar.gz | 16.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| dpdpkit_policies-2026.10.0a1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 31.7 kB
Release files / dpdpkit_policies-2026.10.0a1.tar.gz
| Download URL | dpdpkit_policies-2026.10.0a1.tar.gz |
|---|---|
| Size | 16.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
3fb1fb28e2b173c325e6662aa35ac84d12202d1a357d224554a90f00716400f7
|
|
BLAKE2b-256 checksum How to use checksums |
a50293b4b8f30ce4dfbd9815a2329060cb58dca400e18eccb34d807613e56e67
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.
Transparency logRelease files / dpdpkit_policies-2026.10.0a1-py3-none-any.whl
| Download URL | dpdpkit_policies-2026.10.0a1-py3-none-any.whl |
|---|---|
| Size | 15.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0385fb3a304022158081bded709532e4fd354b9f451fae22bab8aaacfadcaa6e
|
|
BLAKE2b-256 checksum How to use checksums |
d0fffc9a05bc412451e9e48d3d9a440849f9154f49c03687eff84d66afa9c72e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.
Transparency log