Skip to main content

Sources last verified on 17 August 2026. Methodology

Blog

Articles and updates

Answer first articles on real DPDP questions. Every article names its author and reviewer, shows published and last reviewed dates, and cites official sources for every legal claim.

Roles

Data Fiduciary vs Data Processor under DPDP

The two roles in one test: who decides why and how the data is used. What each role owes, why one company can hold both roles, and why responsibility never transfers.

Applicability

Does DPDP apply to B2B SaaS companies?

Usually yes, twice over: as a Data Fiduciary for your own users and as a Data Processor for customer data. What each role means and what your contracts must carry.

Applicability

Does DPDP apply to foreign companies?

The Act reaches foreign companies serving people in India, and largely steps back from foreign data handled under Indian outsourcing contracts.

Applicability

Does the DPDP Act apply to startups in India?

What the Act's application section actually says, why company size does not appear in it, and the one honest caveat about future exemption notifications.

Breach response

DPDP data breach reporting: what Rule 7 actually requires

Rule 7 of the DPDP Rules 2025 sets two clocks after a personal data breach: immediate intimation to affected individuals and to the Board, then detailed information to the Board within seventy two hours.

Children

DPDP rules for children's personal data

Under eighteen means child. What the Act prohibits, what verifiable parental consent requires under Rule 10, guardian verification under Rule 11, and the conditional exemptions.

Compliance

DPDP compliance checklist for CTOs

The engineering owned slice of a DPDP program: safeguards, retention timers, breach detection, consent withdrawal paths and rights machinery, with the cross functional dependencies made explicit.

Compliance

DPDP compliance checklist for startups

A small team's path through the DPDP framework: settle applicability, map your data, and build the five duty clusters in dependency order while the runway lasts.

Consent

What counts as valid consent under DPDP?

Free, specific, informed, unconditional and unambiguous, given by clear affirmative action, limited to what the purpose needs, withdrawable with comparable ease, and yours to prove.

Transfers

Cross border data transfers under DPDP

Transfers are allowed by default, subject to two government levers: foreign state access requirements and notified country restrictions.

Rights

DPDP grievance redressal: the ninety day ceiling

Individuals get a right to readily available grievance redressal, organisations must publish a response period not exceeding ninety days, and the Board only comes after this channel is exhausted.

Rights

Your DPDP rights, explained in plain language

Four rights every Data Principal holds: access to what is held and shared, correction and erasure, grievance redressal, and nomination, with the duties that come along.

Vendors

DPDP processor contracts: what must be in them

Engaging a Data Processor is lawful only under a valid contract, and the safeguards rule requires safeguard provisions in it. What the two anchors require and what a sensible contract adds.

Retention

DPDP data retention and erasure: Rule 8 explained

The three retention mechanics in Rule 8: timed erasure for Third Schedule classes, the forty eight hour warning, and the one year floor for logs and data, plus where other laws take over.

Children

What is verifiable consent under DPDP?

Consent for children must come from a verified parent or guardian. The two verification paths Rule 10 gives and the four cases it illustrates.

Notice

What must a DPDP privacy notice contain?

Rule 3 requires a standalone, plain language notice with an itemised description of the data, the specified purposes, and working paths to withdraw consent, exercise rights and complain to the Board.