Grievance Redressal: What Every Data Fiduciary Must Provide
When something goes wrong with how your data was handled, the Act gives you a specific, two-step path to raise it. THE ESCALATION PATH STEP ONE Complain to the organisation Every Data Fiduciary and Consent Manager must provide a readily available way to register a grievance. STEP TWO Escalate to the Board If the response […]
Data Principal Rights in Practice: Access, Correction and Erasure
Here’s what actually needs to happen when someone exercises one. WHAT A REAL REQUEST NEEDS A CHANNEL Somewhere to actually ask Published on the website or app — not something a user has to hunt for. A PROCESS A defined path to resolution Someone owns it, and it doesn’t rely on the request happening to […]
Purpose Limitation: Using Data Only for What You Said
Purpose limitation sounds abstract until you see it applied to a real example — one the Act itself uses to illustrate the point. A WORKED EXAMPLE THE APP A telemedicine service It asks for medical details to provide a consultation — a clear, specific, necessary purpose. THE OVER-ASK Also requests your contact list Not needed […]
Consent in Practice: Collection, Renewal and Withdrawal
Giving consent is only the first moment in a much longer relationship with your data. Here’s what the Act expects to happen after that first click. THE CONSENT LIFECYCLE GIVE The initial, specific yes Tied to a notice, a purpose, and a clear affirmative action. MANAGE Review what you’ve agreed to See what consents are […]
Is Your Organisation DPDP-Ready?
Before moving into the practical fundamentals, here’s a short, honest self-check.1. Could you list every place personal data lives in your organisation, right now, without a scramble? 2. For each of those, could you say whether it’s processed under consent or a specific legitimate use? 3. Does your current notice actually meet the Rules’ content […]
Building a Privacy Operations Function
The organisations that handle the DPDP Act best tend to treat privacy as an ongoing function, not a project with an end date. Here’s the difference that makes. Project mindset “We did our DPDP compliance work last quarter.” New products launch, then privacy gets consulted afterward Vendor contracts get updated only when someone remembers Function […]
What Governance Looks Like Under the DPDP Act
“Governance” gets used loosely in compliance conversations. Under the DPDP Act, it means something fairly concrete: who owns what, and who’s accountable when something goes wrong. THREE GOVERNANCE BASICS OWNERSHIP A named person or team Not “IT” or “legal” in the abstract — someone specific who’s accountable for DPDP compliance. VISIBILITY Leadership actually sees the […]
Turning Obligations into Operations
A policy document that says the right things and a business that actually does them are two different achievements. Here’s the gap between them. Policy (on paper) “We obtain consent before processing personal data.” “We respond to data subject requests promptly.” “We delete data once it’s no longer needed.” Operations (in practice) A consent flow […]
The Core Responsibilities Every Business Now Carries
Whatever your size or sector, if you process personal data, a common baseline of responsibility applies. Here’s what sits inside that baseline.1. A lawful basis for every category of personal data you process — consent, or a legitimate use, never assumed. 2. A notice that actually meets the Rules’ content requirements, not a generic privacy-policy […]
Where Organisations Commonly Get the Rules Wrong
A few assumptions come up again and again as organisations start preparing for the DPDP Rules. Most of them trace back to comparing the Act to something it isn’t.1. Assuming old IT Act compliance is enough — a privacy notice and security policy built for the narrow SPDI regime doesn’t automatically satisfy the DPDP Act’s […]