Rule 7 of the DPDP Rules 2025 sets two clocks after a personal data breach: immediate intimation to affected individuals and to the Board, then detailed information to the Board within 72 hours.
The engineering owned slice of a DPDP program: safeguards, retention timers, breach detection, consent withdrawal paths and rights machinery, with the cross functional dependencies made explicit.
A small team's path through the DPDP framework: settle applicability, map your data, and build the five duty clusters in dependency order while the runway lasts.
Free, specific, informed, unconditional and unambiguous, given by clear affirmative action, limited to what the purpose needs, withdrawable with comparable ease, and yours to prove.
Individuals get a right to readily available grievance redressal, organisations must publish a response period not exceeding 90 days, and the Board only comes after this channel is exhausted.
Four rights every Data Principal holds: access to what is held and shared, correction and erasure, grievance redressal, and nomination, with the duties that come along.
Engaging a Data Processor is lawful only under a valid contract, and the safeguards rule requires safeguard provisions in it. The 2 anchors, and what to add.