Expert articles on DPDP compliance, IP law, cyber law, and legal advisory for Indian businesses
Every Indian business using ChatGPT, Gemini, Copilot, Claude, Grammarly, or any AI tool is engaged in DPDPA-regulated data processing — and almost none have built the compliance architecture to match. This complete guide covers all four major AI platforms assessed individually, AI in HR/healthcare/finance, training your own AI on Indian data, AI vendor DPAs, employee AI usage policies, consent for AI processing, and a 30-day implementation roadmap.
Your legal clock starts the moment a breach is discovered. DPDPA Rule 6 requires notification to the Data Protection Board and all affected individuals — with ₹200 crore penalty for silence and ₹250 crore for the underlying breach. This operational playbook covers every action from Hour 0 containment to Board notification to individual user notices — with fill-in-the-blank templates for every document you need to complete.
Under the Digital Personal Data Protection Act 2023, every Significant Data Fiduciary in India must appoint a Data Protection Officer. But the DPDPA says almost nothing about who qualifies, what they must do day-to-day, what they can be held liable for, or whether your company even needs one.
Every Indian employer — from a 2-person startup to a 50,000-person enterprise — collects Aadhaar, salary, medical, biometric, and performance data from employees. All of it is regulated under DPDPA 2023 with zero headcount threshold. This complete guide covers lawful bases for 12 HR data categories, why appointment letters fail as consent, Aadhaar obligations, biometric attendance rules, BGV data flows, employee monitoring, exit-day deletion obligations, vendor DPAs, and a 60-day HR compliance roadmap.
Nine out of ten privacy policies on Indian websites fail DPDPA's Rule 3 requirements. This complete guide covers the 8 mandatory disclosures, plain language requirements, the critical difference between a privacy policy and a consent notice, cookie policy requirements, how to name third parties correctly, Grievance Officer disclosure, children's data sections, cross-border transfer disclosures, update frequency rules, a 12-section template, and a full compliance checklist.
DPDPA and GDPR share the same philosophy but differ fundamentally on lawful bases, rights, penalties, DPOs, cross-border transfers, and children's data. This complete comparison covers 14 dimensions — including what changes the moment you target EU users from India, why GDPR's "legitimate interests" basis doesn't exist in DPDPA, how penalties compare across every tier, and how to build a dual-compliance programme that satisfies both laws simultaneously.
Every Indian company using AWS, GCP, Azure, Salesforce, SAP, Workday, or any foreign SaaS is already transferring Indian personal data across borders. Section 16 of the DPDP Act governs these transfers — and the restricted country list is coming. This complete guide explains the Section 16 framework, cloud infrastructure obligations, MNC subsidiary requirements, Standard Contractual Clauses, sector-specific localisation rules, and a practical compliance roadmap for enterprises.
Under DPDP Rules 2025 Rule 13, Significant Data Fiduciaries must conduct a DPIA every 12 months and submit findings to the Data Protection Board. This complete guide explains what a DPIA is, who needs one, the 7-stage process, risk scoring framework (with a sample register), board approval obligations, and a full template structure.
India's financial sector faces the most complex DPDPA compliance challenge — dual obligations under both DPDPA and RBI frameworks. The April 2026 RBI advisory made data protection a board-level obligation. This complete guide covers NBFCs, lending apps, payment aggregators, credit bureau data, KYC obligations, and the 72-hour dual breach notification requirement.