Blog

Practical writing on Digital Personal Data Protection (DPDP) Act compliance for Indian businesses.

Checklists, comparisons, and roadmaps — written for founders, COOs, and heads of compliance who need to act, not just read.

Regulatory Update 7 min read· September 2026

Data Processing Agreements Under the DPDP Act: Fixing Vendor Contracts Before May 2027

Under Section 8 of the DPDP Act, your business stays responsible for what your vendors do with personal data. Here is what a DPDP data processing agreement should cover, and a four-week plan to get your vendor contracts in order.

Read article
News & Analysis 7 min read· September 2026

Why VCs Are Now Asking About DPDP Compliance Before They Sign the Term Sheet

Indian venture investors have started treating DPDP readiness as a funding gate, not a legal footnote. Here is what founders should fix before their next round.

Read article
Data Principal Rights 6 min read· September 2026

The DPDP Act's Right to Nominate: The Compliance Item Most Indian SMEs Haven't Built Yet

Section 14 of the DPDP Act lets a user name a nominee to manage their data after death or incapacity. Rule 14(4) makes building that process a Data Fiduciary obligation, not a feature only social platforms need.

Read article
News & Analysis 7 min read· September 2026

The EU AI Act Deadline Just Moved to 2027 — Here's Why Indian AI Companies Shouldn't Relax

The EU's high-risk AI obligations were pushed from August 2026 to December 2027 under the new Digital Omnibus. Here's what actually changed, what didn't, and why Indian AI and SaaS companies still need to move on both EU AI Act readiness and DPDP compliance.

Read article
Regulatory Update 7 min read· September 2026

The DPDP Act's Quiet Deadline: What Changes on 14 November 2026 for Indian SMEs

14 November 2026 marks one year since the DPDP Rules were notified, and it is when the Data Protection Board is expected to shift from awareness-building to active supervision. Here is what actually changes, what doesn't, and how Indian SMEs should use the eight weeks that are left.

Read article
Regulatory Update 8 min read· September 2026

Are You a Significant Data Fiduciary Under the DPDP Act? How Indian Companies Can Tell Before the Government Decides

The DPDP Act's toughest duties fall on Significant Data Fiduciaries, a category defined loosely enough that a fast-growing Indian startup could land inside it without picturing itself as a data giant. Here's how to tell where you stand before the government decides.

Read article
Regulatory Update 7 min read· September 2026

The DPDP Act's One-Time Notice: What Indian SMEs Must Do About the Data They Already Hold

The DPDP Act's one-time notice under Section 5(2) applies to data you collected before the law took effect. Here's what Indian SMEs must tell existing users, and how to handle the withdrawals that follow.

Read article
News & Analysis 8 min read· September 2026

'Too Small to Be Fined' Is Over: What GDPR's 2026 Enforcement Wave Means for Indian SMEs Under DPDP

A EUR 825 million GDPR fine against Uber in August 2026 is the latest sign that privacy regulators no longer spare smaller companies. Here is what that enforcement trend means for Indian SMEs preparing for the DPDP Act's May 2027 deadline.

Read article
Regulatory Update 7 min read· September 2026

Do You Need a Data Protection Officer Under the DPDP Act? What Rule 13 Actually Says for Indian SMEs

Most Indian SMEs assume the DPDP Act requires a formal DPO the way GDPR does. It usually does not. Here is the difference between the Section 8(9) contact every business needs and the Rule 13 DPO that only Significant Data Fiduciaries must appoint.

Read article
News & Analysis 8 min read· September 2026

If Your Product Uses AI, the DPDP Act Already Applies: What Indian SMEs Should Check Now

AI and the DPDP Act are now tied together for Indian businesses. Here is what algorithmic due diligence under Rule 13 and the EU AI Act's recalibrated 2026 timeline mean for SMEs and startups building AI features.

Read article
Regulatory Update 7 min read· September 2026

Two Clocks, One Breach: Data Breach Reporting in India Under CERT-In and the DPDP Act

A serious incident now triggers two separate breach-reporting duties: CERT-In within six hours and the Data Protection Board within 72. Here's how Indian SMEs build one process that answers to both.

Read article
News & Analysis 8 min read· September 2026

India's Data Protection Board Is Being Assembled: What SMEs Should Fix Before It Starts Hearing Cases

India's Data Protection Board is being staffed in 2026, and the soft-enforcement phase is expected to end around November. Here are the four gaps Indian SMEs should close before the Board starts hearing cases.

Read article
Data Principal Rights 6 min read· July 2026

Grievance Redressal Under the DPDP Act: The 90-Day Obligation Indian SMEs Keep Postponing

Every Indian data fiduciary must publish a grievance officer and resolve complaints within 90 days. Here's what the DPDP Act's grievance-redressal rules mean for SMEs and startups.

Read article
Regulatory Update 7 min read· July 2026

The DPDP Privacy Notice: What Rule 3 Actually Requires from Indian SMEs

Your old privacy policy probably will not pass. Rule 3 of the DPDP Rules 2025 demands an itemised, single-purpose notice with easy consent withdrawal. This is how Indian SMEs can build one.

Read article
Regulatory Update 8 min read· July 2026

Data Retention Under the DPDP Act: Why 'Keep Everything' Is Now a Liability for Indian SMEs

The DPDP Rules 2025 turn old data from an asset into a risk. Here is how Indian SMEs should think about retention, erasure, and the 48-hour deletion notice.

Read article
Regulatory Update 7 min read· July 2026

Reasonable Security Safeguards Under the DPDP Act: The Obligation Indian SMEs Keep Underestimating

Security safeguards carry the DPDP Act's steepest penalty at Rs 250 crore, yet it's the obligation most SMEs overlook. Here's what Section 8(5) and Rule 6 require, and how to prepare before 2027.

Read article
Regulatory Update 8 min read· July 2026

Cross-Border Data Transfer Under the DPDP Act: What Indian SMEs on Foreign SaaS Should Check Now

Most Indian SMEs move personal data abroad every day through tools like AWS, Google Workspace and HubSpot. Here is what the DPDP Act's cross-border transfer rules actually require, and the short list of things to sort before May 2027.

Read article
Data Principal Rights 7 min read· July 2026

Data Principal Rights Under the DPDP Act: Building a Request-Handling Process Before It's Required

Access, correction, erasure, and grievance redressal: the DPDP Act gives every customer real rights over their data. A practical guide for Indian SMEs on building a process to handle these requests before the obligations take effect.

Read article
Children's Data 8 min read· July 2026

Children's Data Under the DPDP Act: The Compliance Project Indian EdTech and Gaming Startups Should Start Now

The DPDP Rules, 2025 require verifiable parental consent before you process any under-18 user's data. Here's what Section 9 and Rule 10 mean for Indian edtech, gaming and consumer apps, and what to build now.

Read article
Regulatory Update 7 min read· July 2026

Consent Manager or Consent Platform? What Indian SMEs Actually Need Before November 2026

"Do we have to register as a DPDP consent manager?" Almost always, no. Here is the difference between a registered Consent Manager and the consent platform your SME actually needs before the 13 November 2026 deadline.

Read article
Regulatory Update 7 min read· July 2026

The DPDP Compliance Clock Has Started: What India's 2026 Deadlines Mean for SMEs

India's DPDP Rules are now in force and the real deadlines land in 2026 and 2027. Here is a plain-English read on the three dates that matter and what a small business should actually do first.

Read article
Checklist 14 min read· May 2026

The Complete DPDP Act Compliance Checklist for Indian SMEs (2026 Edition)

A 32-point, six-pillar checklist mapped to every principal obligation under the Digital Personal Data Protection Act, 2023 — what to do, in what order, with realistic timelines and budgets for a 50–500 person Indian business.

Read article
Comparison 10 min read· May 2026

DPDP Act vs GDPR: 7 Differences That Will Trip Up Indian Startups

If you've ported a GDPR program to India, here's where the Digital Personal Data Protection Act, 2023 diverges — consent architecture, cross-border transfers, Significant Data Fiduciary thresholds, and breach notification timelines.

Read article
Strategy 6 min read· April 2026

Common DPDP Act Mistakes Startups Make in the First 90 Days

Five recurring mistakes we've seen across SaaS, fintech, and HR tech — and the inexpensive fixes that close roughly 60% of your real regulatory exposure.

Read article
Vendor Ops 12 min read· April 2026

Vendor Compliance Under DPDP Act: A Practical Playbook

How to inventory your vendors, classify processor risk, and update DPAs without burning legal hours you don't have. Templates and negotiation tactics included.

Read article
HR Compliance 9 min read· March 2026

HR Data Privacy Obligations Under India's DPDP Act

Employee data is in scope. Here's what HR and ops leaders need to operationalize — from offer letter to exit interview — without paralyzing the business.

Read article
Roadmap 14 min read· March 2026

DPDP Act Readiness Roadmap 2026–2027

An 18-month implementation roadmap for mid-size Indian businesses — quarter-by-quarter, with realistic budgets, headcount asks, and milestone-level deliverables.

Read article
Consent 8 min read· February 2026

Consent Under DPDP Act: Why 'Accept All' Banners Will Hurt You

Granular, informed, revocable. We break down what a defensible consent system looks like in 2026 — and why the cookie banner pattern from 2019 GDPR is the wrong reference.

Read article
Incident Response 11 min read· February 2026

Breach Notification: Your First 72 Hours Under DPDP Act

A practical incident response timeline mapped to Digital Personal Data Protection Act's notification obligations. Who to call, what to document, and how to avoid the mistakes that turn incidents into investigations.

Read article
Regulatory 9 min read· January 2026

Significant Data Fiduciary: Are You One Without Knowing It?

The thresholds, the obligations, and the practical signals that you're operating like an SDF — even before formal designation. Includes a self-assessment.

Read article

One Digital Personal Data Protection (DPDP) Act brief a month. No fluff.

A short, opinionated monthly note on what changed in Digital Personal Data Protection (DPDP) Act enforcement, what we're seeing across client engagements, and what to do about it.

Digital Personal Data Protection (DPDP) Act-grade handling. Unsubscribe anytime.