What “Implementation-Ready” Looks Like
The Rules don’t take effect all at once. They roll out in stages — which sounds like breathing room, but works differently in practice than it first appears. THE ROLLOUT, IN THREE STAGES IMMEDIATE Nov 2025 Provisions setting up the Data Protection Board of India take effect straight away. +12 MONTHS Nov 2026 Rules governing […]
What Changes for Organisations Under the DPDP Rules
Three specific changes from the Rules are worth knowing before anything else, because they affect nearly every organisation processing personal data in India. THREE CONCRETE CHANGES RETENTION A one-year floor A minimum retention period applies before certain data can be treated as no longer needed — three years for some categories. ERASURE NOTICE 48 hours’ […]
How the DPDP Rules Turn the Act into Day-to-Day Practice
On 13 November 2025, MeitY notified the DPDP Rules — the moment the Act stopped being a set of principles and started becoming something organisations could actually build against. WHAT THE RULES ACTUALLY COVER NOTICES Format and content What a compliant notice has to say, and how it has to be presented to count. CONSENT […]
Penalties Under the DPDP Act: What Non-Compliance Costs
The number that gets quoted most about the DPDP Act is its top penalty. Here’s that figure in context, alongside the rest of the scale. Failure Inadequate security safeguards, leading to a breach Failing to notify a breach Non-compliance on children’s data Significant Data Fiduciary duties not met Other contraventions of the Act or Rules […]
Accountability Under the Act: Who Answers for What
The Act is deliberately one-sided about who’s on the hook when something goes wrong. Here’s why that’s the design, not an oversight. WHERE ACCOUNTABILITY SITS DATA FIDUCIARY Carries the obligations And faces the Board’s penalties if it falls short — this is where accountability lives under the Act. DATA PROCESSOR No direct statutory duties Bound […]
What the Act Expects of a Data Fiduciary
If Data Principals get rights, Data Fiduciaries get the matching list of duties. Here’s the baseline every one of them carries. THE BASELINE DUTIES ACCURACY & SECURITY Keep data correct and safe Reasonable security safeguards are a standing duty, not a one-time setup task. BREACH RESPONSE Notify when things go wrong The Board, and affected […]
The Rights Every Data Principal Has
As a Data Principal, the Act gives you four specific rights over your own data. Here’s what each one actually lets you do.1. Right to access — see a summary of what data an organisation holds about you, and who else it’s been shared with. 2. Right to correction and erasure — fix data that’s […]
Legitimate Uses: When Consent Isn’t Required
Door two. Section 7 lists nine specific situations where an organisation can process personal data without asking first — narrower than it might sound. A FEW EXAMPLES FROM THE LIST VOLUNTARY Data you handed over yourself You give your number to a shop for a receipt — they can use it for exactly that, nothing […]
Consent: The Default Basis for Processing
Consent is the door most organisations walk through most often. The Act is specific about what actually counts. VALID CONSENT MUST BE 1 Free Given without pressure, and without being a condition for an unrelated service. 2 Specific Tied to a stated purpose — not a blanket yes to everything an organisation might do. 3 […]
What Counts as Lawful Processing
Before an organisation can touch your personal data at all, the Act asks one question: on what legal basis? There are exactly two acceptable answers. THE ONLY TWO DOORS IN DOOR ONE Consent You say YES, clearly and specifically, to a stated purpose DOOR TWO Lawful purpose A person may process the personal data for […]