Measuring Your Organisation’s Privacy Maturity
This closes the Learn journey. Before moving deeper, here’s a way to place your organisation honestly on the path from bare compliance to genuine maturity. STAGE 1 Reactive Privacy gets attention only when a problem, request or deadline forces it. STAGE 2 Compliant The fundamentals from Module 5 are in place and functioning, consistently. STAGE […]
Responsible Data Use Beyond the Letter of the Law
The DPDP Act sets a legal floor. Responsible data use is a separate, higher standard — one the law doesn’t require, but that mature organisations hold themselves to anyway. THE GAP BETWEEN LEGAL AND RESPONSIBLE LEGAL Technically permitted A legitimate use or valid consent covers it — the Act has no objection. RESPONSIBLE Would you […]
Understanding Consent Architecture
Consent, treated seriously, isn’t a single checkbox on a signup form. In a mature organisation, it’s closer to a system — which is what “consent architecture” refers to. CAPTURE Record what was agreed, precisely Across every product surface where consent is collected, not just the main one. PROPAGATE Reach every system that uses the data […]
Building a Culture Around Data Governance
Policies and processes only hold up if the people following them actually understand why they matter. That’s the difference culture makes. Policy-only Staff follow the data-handling rules because they’re told to Privacy training is an annual box-ticking session New situations not covered by policy cause confusion Culture Staff understand why the rules exist, and flag […]
Digital Trust as a Business Advantage
Digital trust as the reason the DPDP Act exists at all. Here, it’s worth revisiting as something organisations can actively build — and benefit from. WHAT TRUST ACTUALLY EARNS YOU RETENTION People stay longer When they believe their data is handled responsibly, they don’t feel the need to look elsewhere. WILLINGNESS TO SHARE Better data, […]
Everyday Governance: Making Compliance Routine, Not Reactive
This covers nine specific fundamentals — notices, consent, purpose, rights, grievances, children, processors, security, records. Here’s how they fit together. THE FUNDAMENTALS, IN ONE PLACE BEFORE Notice, consent, purpose limitation Set the terms honestly before any data is collected at all. DURING Rights, children’s safeguards, processor contracts Keep the relationship fair while the data is […]
Recordkeeping and Evidence: Building Your Audit Trail
Accountability under the DPDP Act isn’t just about doing the right thing — it’s about being able to show you did. That’s what recordkeeping is actually for. WHAT’S WORTH KEEPING CONSENT LOGS What, when, and how withdrawn A record of what someone agreed to, not just the current state of their preferences. RETENTION A minimum […]
Security Safeguards Every Data Fiduciary Should Know
“Reasonable security safeguards” is the single phrase tied to the Act’s highest penalty tier. Here’s what it means at an introductory level. WHY THIS ONE MATTERS THE MOST ₹250 CRORE The top penalty tier Attached specifically to failing to implement reasonable security safeguards that leads to a breach. STANDING DUTY Not a one-time setup Security […]
Working with Data Processors: Roles and Responsibilities
Almost every organisation uses vendors that touch personal data — cloud hosting, payment processing, customer support tools. Here’s how the Act treats that relationship. FIDUCIARY AND PROCESSOR, SIDE BY SIDE DATA FIDUCIARY Carries the Act’s obligations Decides why and how data is processed, and answers to the Board if something goes wrong. DATA PROCESSOR Acts […]
Processing Children’s Data: Consent and Safeguards
The Act treats anyone under 18 as a child, and sets a noticeably higher bar for processing their data than it does for adults. WHAT’S DIFFERENT FOR CHILDREN’S DATA CONSENT Verifiable parental consent Not just a checkbox saying “I am a parent” — the consent-giver’s identity has to be verifiable. NO TRACKING No behavioural monitoring […]