Blog
Practical writing on Digital Personal Data Protection (DPDP) Act compliance for Indian businesses.
Checklists, comparisons, and roadmaps — written for founders, COOs, and heads of compliance who need to act, not just read.
Data Processing Agreements Under the DPDP Act: Fixing Vendor Contracts Before May 2027
Under Section 8 of the DPDP Act, your business stays responsible for what your vendors do with personal data. Here is what a DPDP data processing agreement should cover, and a four-week plan to get your vendor contracts in order.
Why VCs Are Now Asking About DPDP Compliance Before They Sign the Term Sheet
Indian venture investors have started treating DPDP readiness as a funding gate, not a legal footnote. Here is what founders should fix before their next round.
The DPDP Act's Right to Nominate: The Compliance Item Most Indian SMEs Haven't Built Yet
Section 14 of the DPDP Act lets a user name a nominee to manage their data after death or incapacity. Rule 14(4) makes building that process a Data Fiduciary obligation, not a feature only social platforms need.
The EU AI Act Deadline Just Moved to 2027 — Here's Why Indian AI Companies Shouldn't Relax
The EU's high-risk AI obligations were pushed from August 2026 to December 2027 under the new Digital Omnibus. Here's what actually changed, what didn't, and why Indian AI and SaaS companies still need to move on both EU AI Act readiness and DPDP compliance.
The DPDP Act's Quiet Deadline: What Changes on 14 November 2026 for Indian SMEs
14 November 2026 marks one year since the DPDP Rules were notified, and it is when the Data Protection Board is expected to shift from awareness-building to active supervision. Here is what actually changes, what doesn't, and how Indian SMEs should use the eight weeks that are left.
Are You a Significant Data Fiduciary Under the DPDP Act? How Indian Companies Can Tell Before the Government Decides
The DPDP Act's toughest duties fall on Significant Data Fiduciaries, a category defined loosely enough that a fast-growing Indian startup could land inside it without picturing itself as a data giant. Here's how to tell where you stand before the government decides.
The DPDP Act's One-Time Notice: What Indian SMEs Must Do About the Data They Already Hold
The DPDP Act's one-time notice under Section 5(2) applies to data you collected before the law took effect. Here's what Indian SMEs must tell existing users, and how to handle the withdrawals that follow.
'Too Small to Be Fined' Is Over: What GDPR's 2026 Enforcement Wave Means for Indian SMEs Under DPDP
A EUR 825 million GDPR fine against Uber in August 2026 is the latest sign that privacy regulators no longer spare smaller companies. Here is what that enforcement trend means for Indian SMEs preparing for the DPDP Act's May 2027 deadline.
Do You Need a Data Protection Officer Under the DPDP Act? What Rule 13 Actually Says for Indian SMEs
Most Indian SMEs assume the DPDP Act requires a formal DPO the way GDPR does. It usually does not. Here is the difference between the Section 8(9) contact every business needs and the Rule 13 DPO that only Significant Data Fiduciaries must appoint.
If Your Product Uses AI, the DPDP Act Already Applies: What Indian SMEs Should Check Now
AI and the DPDP Act are now tied together for Indian businesses. Here is what algorithmic due diligence under Rule 13 and the EU AI Act's recalibrated 2026 timeline mean for SMEs and startups building AI features.
Two Clocks, One Breach: Data Breach Reporting in India Under CERT-In and the DPDP Act
A serious incident now triggers two separate breach-reporting duties: CERT-In within six hours and the Data Protection Board within 72. Here's how Indian SMEs build one process that answers to both.
India's Data Protection Board Is Being Assembled: What SMEs Should Fix Before It Starts Hearing Cases
India's Data Protection Board is being staffed in 2026, and the soft-enforcement phase is expected to end around November. Here are the four gaps Indian SMEs should close before the Board starts hearing cases.
Grievance Redressal Under the DPDP Act: The 90-Day Obligation Indian SMEs Keep Postponing
Every Indian data fiduciary must publish a grievance officer and resolve complaints within 90 days. Here's what the DPDP Act's grievance-redressal rules mean for SMEs and startups.
The DPDP Privacy Notice: What Rule 3 Actually Requires from Indian SMEs
Your old privacy policy probably will not pass. Rule 3 of the DPDP Rules 2025 demands an itemised, single-purpose notice with easy consent withdrawal. This is how Indian SMEs can build one.
Data Retention Under the DPDP Act: Why 'Keep Everything' Is Now a Liability for Indian SMEs
The DPDP Rules 2025 turn old data from an asset into a risk. Here is how Indian SMEs should think about retention, erasure, and the 48-hour deletion notice.
Reasonable Security Safeguards Under the DPDP Act: The Obligation Indian SMEs Keep Underestimating
Security safeguards carry the DPDP Act's steepest penalty at Rs 250 crore, yet it's the obligation most SMEs overlook. Here's what Section 8(5) and Rule 6 require, and how to prepare before 2027.
Cross-Border Data Transfer Under the DPDP Act: What Indian SMEs on Foreign SaaS Should Check Now
Most Indian SMEs move personal data abroad every day through tools like AWS, Google Workspace and HubSpot. Here is what the DPDP Act's cross-border transfer rules actually require, and the short list of things to sort before May 2027.
Data Principal Rights Under the DPDP Act: Building a Request-Handling Process Before It's Required
Access, correction, erasure, and grievance redressal: the DPDP Act gives every customer real rights over their data. A practical guide for Indian SMEs on building a process to handle these requests before the obligations take effect.
Children's Data Under the DPDP Act: The Compliance Project Indian EdTech and Gaming Startups Should Start Now
The DPDP Rules, 2025 require verifiable parental consent before you process any under-18 user's data. Here's what Section 9 and Rule 10 mean for Indian edtech, gaming and consumer apps, and what to build now.
Consent Manager or Consent Platform? What Indian SMEs Actually Need Before November 2026
"Do we have to register as a DPDP consent manager?" Almost always, no. Here is the difference between a registered Consent Manager and the consent platform your SME actually needs before the 13 November 2026 deadline.
The DPDP Compliance Clock Has Started: What India's 2026 Deadlines Mean for SMEs
India's DPDP Rules are now in force and the real deadlines land in 2026 and 2027. Here is a plain-English read on the three dates that matter and what a small business should actually do first.
The Complete DPDP Act Compliance Checklist for Indian SMEs (2026 Edition)
A 32-point, six-pillar checklist mapped to every principal obligation under the Digital Personal Data Protection Act, 2023 — what to do, in what order, with realistic timelines and budgets for a 50–500 person Indian business.
DPDP Act vs GDPR: 7 Differences That Will Trip Up Indian Startups
If you've ported a GDPR program to India, here's where the Digital Personal Data Protection Act, 2023 diverges — consent architecture, cross-border transfers, Significant Data Fiduciary thresholds, and breach notification timelines.
Common DPDP Act Mistakes Startups Make in the First 90 Days
Five recurring mistakes we've seen across SaaS, fintech, and HR tech — and the inexpensive fixes that close roughly 60% of your real regulatory exposure.
Vendor Compliance Under DPDP Act: A Practical Playbook
How to inventory your vendors, classify processor risk, and update DPAs without burning legal hours you don't have. Templates and negotiation tactics included.
HR Data Privacy Obligations Under India's DPDP Act
Employee data is in scope. Here's what HR and ops leaders need to operationalize — from offer letter to exit interview — without paralyzing the business.
DPDP Act Readiness Roadmap 2026–2027
An 18-month implementation roadmap for mid-size Indian businesses — quarter-by-quarter, with realistic budgets, headcount asks, and milestone-level deliverables.
Consent Under DPDP Act: Why 'Accept All' Banners Will Hurt You
Granular, informed, revocable. We break down what a defensible consent system looks like in 2026 — and why the cookie banner pattern from 2019 GDPR is the wrong reference.
Breach Notification: Your First 72 Hours Under DPDP Act
A practical incident response timeline mapped to Digital Personal Data Protection Act's notification obligations. Who to call, what to document, and how to avoid the mistakes that turn incidents into investigations.
Significant Data Fiduciary: Are You One Without Knowing It?
The thresholds, the obligations, and the practical signals that you're operating like an SDF — even before formal designation. Includes a self-assessment.
One Digital Personal Data Protection (DPDP) Act brief a month. No fluff.
A short, opinionated monthly note on what changed in Digital Personal Data Protection (DPDP) Act enforcement, what we're seeing across client engagements, and what to do about it.
Digital Personal Data Protection (DPDP) Act-grade handling. Unsubscribe anytime.