Foundations
DPDP, Explained
Plain-English explainers on India's Digital Personal Data Protection Act — what it is, who it applies to, and what it asks of anyone collecting personal data. Start here, then go deeper into the specifics.
DPDP consent, explained: what counts as valid consent under India's data lawUnder India's DPDP Act, consent must be free, specific, informed, unconditional and unambiguous — by clear affirmative action. What that means, in plain English.What a DPDP privacy notice must containUnder India's DPDP Act, your notice must itemise what data you collect and why, and say how to withdraw consent, exercise rights, and complain. The full checklist.Data Principal rights under DPDP — and how a business must fulfil themThe DPDP Act gives every person rights over their data — access, correction, erasure, grievance redressal, nomination and withdrawal. What each one means, and what a business must do to honour it.Data retention and erasure under DPDP: how long you can keep data, and when you must delete itUnder India's DPDP Act you must erase personal data once its purpose is served or consent is withdrawn — with no fixed universal limit, but hard 3-year rules for large platforms. What retention DPDP actually requires.DPDP breach notification: what the 72-hour rule actually requiresThe DPDP '72-hour rule' is widely misread. You must tell the Data Protection Board and affected people without delay — and file a detailed report to the Board within 72 hours. What you must report, to whom, and when.DPDP penalties, explained: the fines for getting data protection wrongThe DPDP Act's penalty schedule runs up to ₹250 crore for weak security and ₹200 crore for a mishandled breach. The full tier list, who decides the amount, and when it starts to bite.DPDP timeline and deadlines: what's in force now, and what's comingIndia's DPDP Rules were notified on 13 November 2025 with a staggered rollout. The Board and penalties are live now; the substantive obligations become binding on 13 May 2027. The full timeline.When DPDP doesn't need consent: legitimate uses (s.7)India's DPDP Act lists nine 'legitimate uses' where personal data can be processed without consent — voluntary sharing, employment, medical emergencies, and more.Significant Data Fiduciary obligations under DPDP, explainedA Significant Data Fiduciary is a high-risk business the government names under the DPDP Act, carrying extra duties — an India-based DPO, independent audits, annual DPIAs, and data localisation. What they are, and whether you're one.Does DPDP apply to offline, paper-based customer forms?The DPDP Act covers digital personal data — including paper records the moment they're scanned, photographed or typed into a system. When a paper form is in scope, and when it isn't.DPDP vs the old IT Act / SPDI Rules: what changedBefore the DPDP Act, India's data protection lived in IT Act Section 43A and the SPDI Rules, 2011 — narrow, sensitive-data-only, weakly enforced. What the DPDP Act changes, and what it means if you did SPDI/ISO compliance.Common DPDP myths for small businesses, cleared up"We're too small." "It's only for big tech." "Our privacy policy covers us." The most common DPDP myths small businesses believe — and what the Act actually requires.