08

DPDP

India's data protection law applies to almost every business that has customers. Most have done nothing about it.

12

Obligations tracked

7

Statutory forms

0

Things you do

CONSENT
NOTICE
GRIEVANCE OFFICER
BREACH REPORTING
RETENTION
CHILDREN'S DATA
CERT-IN

What this covers

The Digital Personal Data Protection Act applies to any business processing the personal data of people in India. That is not a technology-company obligation - it is a customer-list obligation, and it covers a cafe with a loyalty programme as much as a SaaS platform.

The requirements are not exotic. You need a lawful basis for what you collect, a notice telling people what you are doing with it, a way for them to withdraw consent, a named grievance officer, a retention limit, and a plan for what happens if data leaks. Children's data needs verifiable parental consent.

Separately, CERT-In directions require Indian entities to report cyber incidents within a prescribed window and retain logs for 180 days. These two frameworks are often confused. They are different, and both apply.

The calendar

Every obligation, with dates.

Consent and lawful basis

Form · -

When · Before collection

Any personal data of people in India

Privacy notice

Form · -

When · At the point of collection

Every data fiduciary

Consent withdrawal mechanism

Form · -

When · Continuous

Every data fiduciary

Grievance officer

Form · -

When · Named and published

Every data fiduciary

Data principal rights process

Form · -

When · Within prescribed timelines

Access, correction, erasure requests

Retention and deletion policy

Form · -

When · Continuous

Every data fiduciary

Children's data - parental consent

Form · -

When · Before collection

Users under 18

Personal data breach notification

Form · -

When · Within the prescribed window

Every breach

Processor and vendor agreements

Form · -

When · Before sharing data

Every sub-processor

Cyber incident reporting

Form · CERT-In

When · Within the prescribed window

Every body corporate

Log retention

Form · CERT-In

When · 180 days

Every body corporate

Significant data fiduciary obligations

Form · -

When · If notified

DPIA, audit, data protection officer

Our side

What we do.

If you miss it

The DPDP Act carries financial penalties at a scale that is unusual for Indian regulation, with the highest tier attaching to a failure to take reasonable security safeguards to prevent a breach. The practical exposure arrives earlier than the regulator does, though: enterprise customers now ask for your privacy posture in procurement, and a startup that cannot answer loses the deal long before it hears from anyone official.

Digital Personal Data Protection Act, 2023 · Information Technology Act, 2000 · CERT-In Directions, 2022

Process

How it runs.

  1. 01

    We map the data

    What you collect, why, where it lives, who else can see it. Most founders have never written this down.

  2. 02

    We build the paperwork

    Notice, consent, retention, grievance officer, processor agreements. All of it, drafted for your product.

  3. 03

    We keep it aligned

    When you add a vendor or launch a feature that collects something new, the map updates.

Questions founders ask

If you hold names, emails or phone numbers of people in India, yes. Turnover and headcount do not exempt you.

No, though they share concepts. If you also serve EU users, GDPR applies in parallel and its requirements are stricter in places. We will tell you which applies where.

No. A notice is one requirement of several. Consent mechanics, a grievance officer, retention limits and processor agreements are separate obligations.

No, and we will never tell you it is. Those are contractual certifications your customers require. DPDP is law. We track both, but they are different things.

Notification obligations run on short timelines, and CERT-In's window is shorter still. We draft the response plan in advance, because the middle of an incident is the wrong time to work out who to tell.

Related

Compliance you do not have to think about.

Tell us your CIN and what you are worried about. We will tell you exactly what applies to your company.

Every filing under this service is reviewed and signed by a practising Company Secretary or Chartered Accountant engaged on your account.