Expert articles on DPDP compliance, IP law, cyber law, and legal advisory for Indian businesses
DPDPA doesn't imprison directors — but the IT Act 2000 does. Every director "in charge" of a company that commits a data offence is deemed personally guilty under Section 85. This guide explains exactly which CXOs are at risk, when the corporate veil fails, and the 10 steps every director must take to protect themselves.
Every Indian e-commerce business — from a one-person Shopify store to a full marketplace — is a Data Fiduciary under DPDPA 2023. This complete guide covers the 7 highest-risk practices in Indian e-commerce today, checkout consent architecture, retargeting and personalisation rules, delivery partner DPAs, BNPL data sharing, marketplace seller obligations, and a 60-day compliance roadmap.
Patient health data carries the highest penalty exposure under DPDPA — ₹250 crore for security breaches, ₹200 crore for concealing ransomware attacks. This premium guide covers every DPDPA obligation for hospitals, clinics, diagnostic labs, telemedicine platforms, pharma, and health insurers — including consent architecture, vendor DPAs, breach notification timelines, SDF designation risks, and a 12-week implementation roadmap.
Schools, colleges, coaching centres, and ed-tech platforms are among India's most data-intensive institutions — yet almost none are DPDPA-compliant. This guide covers Section 9 children's data obligations, consent architecture for admissions, vendor DPAs for ERP and school software, biometric data rules, staff data compliance, and a step-by-step academic-year compliance roadmap.
Every Indian business using WhatsApp to message customers is now regulated under the DPDP Act 2023 — and most are already in violation. This guide covers the 6 obligations triggered by WhatsApp Business use, the 3 risk tiers of messaging, consent requirements, opt-out obligations, breach risks, and a practical 5-step fix.
The DPDP Act 2023 applies to every business — no size exemption, no revenue threshold. This complete DPDPA compliance checklist covers all 35 obligations across consent, rights, breach notification, vendor management, children's data, and more — with legal references and a free PDF download.
The DPDP Act 2023 has no small business exemption — it applies to every startup and SME collecting personal data. This complete guide explains your 8 core obligations, the May 2027 deadline, what startups are NOT required to do, the most common mistakes, and a practical 90-day compliance roadmap.
India's DPDPA imposes fines up to ₹250 crore per violation. This complete guide explains every penalty tier, what triggers them, how the Data Protection Board calculates actual amounts, real-world scenarios for Indian businesses, and 10 steps to reduce your risk.
Section 8 of the DPDP Act 2023 is the most important provision for businesses — it lays down 8 binding obligations every Data Fiduciary must comply with. This article explains each obligation in plain language with practical guidance and a compliance checklist.