<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>dpdprules.org</title>
    <link>https://dpdprules.org/blog</link>
    <atom:link href="https://dpdprules.org/feed.xml" rel="self" type="application/rss+xml"/>
    <description>Articles on India's DPDP framework, every legal claim source backed.</description>
    <lastBuildDate>Thu, 27 Aug 2026 00:00:00 GMT</lastBuildDate>
    <item>
      <title>DPDP and cookies: the Act never mentions them</title>
      <link>https://dpdprules.org/blog/dpdp-cookie-consent-what-the-law-says</link>
      <guid>https://dpdprules.org/blog/dpdp-cookie-consent-what-the-law-says</guid>
      <pubDate>Wed, 26 Aug 2026 00:00:00 GMT</pubDate>
      <description>The word cookie appears 0 times in the DPDP Act 2023 and 0 times in the DPDP Rules 2025. So do explicit, granular and banner. What actually governs a cookie is the personal data inside it.</description>
    </item>
    <item>
      <title>DPDP and marketing consent: 2 regimes, and the one in force is not DPDP</title>
      <link>https://dpdprules.org/blog/dpdp-marketing-consent-whatsapp-sms</link>
      <guid>https://dpdprules.org/blog/dpdp-marketing-consent-whatsapp-sms</guid>
      <pubDate>Wed, 26 Aug 2026 00:00:00 GMT</pubDate>
      <description>Marketing to Indian customers sits under 2 separate regimes. The TRAI regulations are in force now and cover voice calls and messages. The DPDP consent rules are not in force until 2027.</description>
    </item>
    <item>
      <title>Is the Data Protection Board operational? 2 separate reasons it is not</title>
      <link>https://dpdprules.org/blog/is-the-data-protection-board-operational</link>
      <guid>https://dpdprules.org/blog/is-the-data-protection-board-operational</guid>
      <pubDate>Wed, 26 Aug 2026 00:00:00 GMT</pubDate>
      <description>The Data Protection Board of India exists in law and has no appointed members. Even fully staffed it could not take a complaint, because section 27 is not in force. Those are 2 different gaps.</description>
    </item>
    <item>
      <title>Deemed consent does not exist under the DPDP Act</title>
      <link>https://dpdprules.org/blog/dpdp-deemed-consent-does-not-exist</link>
      <guid>https://dpdprules.org/blog/dpdp-deemed-consent-does-not-exist</guid>
      <pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate>
      <description>The DPDP Act 2023 contains no deemed consent and no legitimate interest ground. Both phrases come from the 2022 consultation draft Bill, which was never introduced in Parliament. What replaced them is section 7, Certain legitimate uses, with 9 clauses.</description>
    </item>
    <item>
      <title>Data Protection Officer under the DPDP Act: who must appoint one</title>
      <link>https://dpdprules.org/blog/data-protection-officer-under-dpdp</link>
      <guid>https://dpdprules.org/blog/data-protection-officer-under-dpdp</guid>
      <pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate>
      <description>Only a notified Significant Data Fiduciary must appoint a DPO under section 10(2)(a). Every other Data Fiduciary owes a published contact person under Rule 9.</description>
    </item>
    <item>
      <title>Is the DPDP deadline 13 or 14 May 2027? Why sources disagree by 1 day</title>
      <link>https://dpdprules.org/blog/dpdp-commencement-date-13-or-14-november</link>
      <guid>https://dpdprules.org/blog/dpdp-commencement-date-13-or-14-november</guid>
      <pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate>
      <description>Gazette issue No. 760 is printed 13 November 2025; the eGazette file code stamped on that same issue and the Government's own PIB release record 14 November 2025. What that does to every computed DPDP deadline, from the official text.</description>
    </item>
    <item>
      <title>डेटा ब्रीच हो जाए तो क्या करें? DPDP नियम 7 और 2 समयसीमाएँ</title>
      <link>https://dpdprules.org/blog/dpdp-data-breach-kya-karein</link>
      <guid>https://dpdprules.org/blog/dpdp-data-breach-kya-karein</guid>
      <pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate>
      <description>डेटा ब्रीच के बाद भारत में 2 समयसीमाएँ हैं: CERT In को 6 घंटे, जो आज लागू है, और DPDP नियम 7, जो अभी लागू नहीं है। आधिकारिक हिंदी राजपत्र के पाठ के साथ।</description>
    </item>
    <item>
      <title>DPDP for schools and edtech: what the Fourth Schedule exemption really covers</title>
      <link>https://dpdprules.org/blog/dpdp-for-schools-and-edtech</link>
      <guid>https://dpdprules.org/blog/dpdp-for-schools-and-edtech</guid>
      <pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate>
      <description>The DPDP education carve out covers tracking and behavioural monitoring only. Admissions, fees and most edtech accounts will still need verifiable parental consent.</description>
    </item>
    <item>
      <title>Section 17 of the DPDP Act: what the exemptions actually switch off</title>
      <link>https://dpdprules.org/blog/dpdp-section-17-exemptions</link>
      <guid>https://dpdprules.org/blog/dpdp-section-17-exemptions</guid>
      <pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate>
      <description>Section 17(1) disapplies Chapter II, Chapter III and section 16 in 6 named situations, but never sections 8(1) and 8(5). The verified clause by clause map.</description>
    </item>
    <item>
      <title>Does the DPDP Act have a sensitive personal data category? No</title>
      <link>https://dpdprules.org/blog/dpdp-sensitive-personal-data</link>
      <guid>https://dpdprules.org/blog/dpdp-sensitive-personal-data</guid>
      <pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate>
      <description>The word sensitive appears nowhere in the DPDP Act, and there is no section 3(d). What actually creates higher duties: SDF notification, children's data and the Third Schedule.</description>
    </item>
    <item>
      <title>Supreme Court challenge to the DPDP Act: what stands today</title>
      <link>https://dpdprules.org/blog/dpdp-act-supreme-court-challenge</link>
      <guid>https://dpdprules.org/blog/dpdp-act-supreme-court-challenge</guid>
      <pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate>
      <description>Writ petitions in the Supreme Court challenge the DPDP Act's RTI amendment, exemptions and Board design. Notice issued, no stay: what stands in August 2026.</description>
    </item>
    <item>
      <title>Children's data under the DPDP Act: consent, bans and exemptions</title>
      <link>https://dpdprules.org/blog/dpdp-childrens-data-rules</link>
      <guid>https://dpdprules.org/blog/dpdp-childrens-data-rules</guid>
      <pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate>
      <description>Who is a child under the DPDP Act, the section 9 duties including parental consent and the tracking ban, Rule 10 verification and Fourth Schedule exemptions.</description>
    </item>
    <item>
      <title>DPDP compliance requirements for businesses: the complete obligations map (2026)</title>
      <link>https://dpdprules.org/blog/dpdp-compliance-requirements-for-businesses</link>
      <guid>https://dpdprules.org/blog/dpdp-compliance-requirements-for-businesses</guid>
      <pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate>
      <description>Every DPDP duty on a business: the 2 grounds for processing, notice, consent, section 8, rights, children, SDF duties and penalties, cited to the Gazette.</description>
    </item>
    <item>
      <title>What is a Consent Manager under the DPDP Act? Definition, registration and obligations</title>
      <link>https://dpdprules.org/blog/dpdp-consent-managers-explained</link>
      <guid>https://dpdprules.org/blog/dpdp-consent-managers-explained</guid>
      <pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate>
      <description>The Consent Manager explained from the primary sources: the section 2(g) definition, the section 6 consent channel, registration with the Board under Rule 4, and the First Schedule's Part A conditions and Part B obligations, quoted and cited.</description>
    </item>
    <item>
      <title>DPA clauses under the DPDP Act: what the law requires versus good drafting</title>
      <link>https://dpdprules.org/blog/dpdp-data-processing-agreement-clauses</link>
      <guid>https://dpdprules.org/blog/dpdp-data-processing-agreement-clauses</guid>
      <pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate>
      <description>The DPDP Act prescribes almost nothing about DPA content: a contract, Rule 6(1)(f) safeguards, erasure. Every other clause is drafting.</description>
    </item>
    <item>
      <title>Data protection audit under the DPDP Act: who must be audited and what the text requires</title>
      <link>https://dpdprules.org/blog/dpdp-data-protection-audit-requirements</link>
      <guid>https://dpdprules.org/blog/dpdp-data-protection-audit-requirements</guid>
      <pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate>
      <description>Only notified Significant Data Fiduciaries need a DPDP audit: the independent auditor in section 10(2)(b), on the 12 month Rule 13 cycle.</description>
    </item>
    <item>
      <title>Does the DPDP notice have to be in 22 languages? What section 5(3) actually says</title>
      <link>https://dpdprules.org/blog/dpdp-notice-language-requirements</link>
      <guid>https://dpdprules.org/blog/dpdp-notice-language-requirements</guid>
      <pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate>
      <description>Section 5(3) gives the Data Principal the option of English or any Eighth Schedule language. A readiness duty, not 22 published versions.</description>
    </item>
    <item>
      <title>Additional obligations of a Significant Data Fiduciary: DPO, auditor, DPIA</title>
      <link>https://dpdprules.org/blog/dpdp-significant-data-fiduciary-obligations</link>
      <guid>https://dpdprules.org/blog/dpdp-significant-data-fiduciary-obligations</guid>
      <pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate>
      <description>What section 10 adds once you are notified: an India based DPO answerable to the board, an independent auditor, and the 12 month Rule 13 DPIA and audit cycle.</description>
    </item>
    <item>
      <title>DPIA under the DPDP Act: who must do one, what it contains, when it starts</title>
      <link>https://dpdprules.org/blog/dpia-under-dpdp-act</link>
      <guid>https://dpdprules.org/blog/dpia-under-dpdp-act</guid>
      <pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate>
      <description>Only notified Significant Data Fiduciaries must run a DPIA, on the 12 month Rule 13 cycle. What section 10(2)(c) defines, and what GDPR habits do not carry.</description>
    </item>
    <item>
      <title>DPDP Act for HR teams: employee data, section 7 and what needs consent</title>
      <link>https://dpdprules.org/blog/dpdp-act-for-hr-teams-employee-data</link>
      <guid>https://dpdprules.org/blog/dpdp-act-for-hr-teams-employee-data</guid>
      <pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate>
      <description>Section 7(i) of the DPDP Act lets employers process employee personal data for the purposes of employment without consent, but the exemption has edges: it does not cover everything HR touches, and the general obligations still apply.</description>
    </item>
    <item>
      <title>DPDP compliance checklist for small businesses: 10 steps (2026)</title>
      <link>https://dpdprules.org/blog/dpdp-compliance-checklist-small-business</link>
      <guid>https://dpdprules.org/blog/dpdp-compliance-checklist-small-business</guid>
      <pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate>
      <description>A 10 step DPDP compliance checklist sized for small Indian businesses: map your data, pick the ground for each purpose, fix your notice and consent, prepare for breaches and rights requests, each step cited to the exact provision.</description>
    </item>
    <item>
      <title>A data breach just hit your organisation: the hour by hour response under DPDP</title>
      <link>https://dpdprules.org/blog/data-breach-at-your-organisation-what-to-do</link>
      <guid>https://dpdprules.org/blog/data-breach-at-your-organisation-what-to-do</guid>
      <pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate>
      <description>What to do when your organisation becomes aware of a personal data breach: contain and anchor the clock, run the 2 Rule 7 duties in parallel, file the 72 hour Board submission, then stabilise.</description>
    </item>
    <item>
      <title>DPDP Act क्या है? फुल फॉर्म, नियम और तारीखें (2026)</title>
      <link>https://dpdprules.org/blog/dpdp-act-kya-hai</link>
      <guid>https://dpdprules.org/blog/dpdp-act-kya-hai</guid>
      <pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate>
      <description>DPDP का फुल फॉर्म है Digital Personal Data Protection। DPDP Act 2023 भारत का डेटा संरक्षण कानून है और DPDP Rules 2025 इसे लागू करते हैं। यह कब से लागू है, किस पर लागू होता है और जुर्माने कितने हैं, आधिकारिक राजपत्र के संदर्भ के साथ।</description>
    </item>
    <item>
      <title>DPDP breach notification: 72 hours to the Board, 6 hours to CERT In</title>
      <link>https://dpdprules.org/blog/dpdp-breach-72-hours-cert-in-6-hours</link>
      <guid>https://dpdprules.org/blog/dpdp-breach-72-hours-cert-in-6-hours</guid>
      <pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate>
      <description>India runs 2 separate breach clocks: DPDP Rule 7 gives 72 hours for the detailed Board submission, while the CERT In directions require reporting cyber incidents within 6 hours. Who reports what, to whom, on which clock.</description>
    </item>
    <item>
      <title>DPDP vs GDPR: key differences for Indian businesses (2026)</title>
      <link>https://dpdprules.org/blog/dpdp-vs-gdpr-key-differences</link>
      <guid>https://dpdprules.org/blog/dpdp-vs-gdpr-key-differences</guid>
      <pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate>
      <description>How India's DPDP Act 2023 differs from the EU GDPR: scope, lawful bases, Consent Managers, breach clocks, fixed rupee penalties versus turnover percentages, children's data, cross border transfers and DPIA triggers, in one table.</description>
    </item>
    <item>
      <title>What is DPDP? India's data protection law, explained from the official text</title>
      <link>https://dpdprules.org/blog/what-is-dpdp</link>
      <guid>https://dpdprules.org/blog/what-is-dpdp</guid>
      <pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate>
      <description>DPDP stands for Digital Personal Data Protection. The DPDP Act 2023 is India's data protection law and the DPDP Rules 2025 operationalise it, in force in phases from 13 November 2025.</description>
    </item>
    <item>
      <title>Do you need to register as a Consent Manager? Rule 4 and who it applies to</title>
      <link>https://dpdprules.org/blog/consent-managers-under-dpdp</link>
      <guid>https://dpdprules.org/blog/consent-managers-under-dpdp</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>Most ordinary businesses do not need to register as a Consent Manager: it is a registered intermediary, not consent management software. What Rule 4 actually sets up.</description>
    </item>
    <item>
      <title>Data Fiduciary vs Data Processor under DPDP</title>
      <link>https://dpdprules.org/blog/data-fiduciary-vs-data-processor</link>
      <guid>https://dpdprules.org/blog/data-fiduciary-vs-data-processor</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>The 2 roles in 1 test: who decides why and how the data is used. What each role owes, why one company can hold both roles, and why responsibility never transfers.</description>
    </item>
    <item>
      <title>Does DPDP apply to B2B SaaS companies?</title>
      <link>https://dpdprules.org/blog/does-dpdp-apply-to-b2b-saas</link>
      <guid>https://dpdprules.org/blog/does-dpdp-apply-to-b2b-saas</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>Usually yes, twice over: as a Data Fiduciary for your own users and as a Data Processor for customer data. What each role means and what your contracts must carry.</description>
    </item>
    <item>
      <title>Does DPDP apply to foreign companies?</title>
      <link>https://dpdprules.org/blog/does-dpdp-apply-to-foreign-companies</link>
      <guid>https://dpdprules.org/blog/does-dpdp-apply-to-foreign-companies</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>The Act reaches foreign companies serving people in India, and largely steps back from foreign data handled under Indian outsourcing contracts.</description>
    </item>
    <item>
      <title>Does the DPDP Act apply to startups? No size test, and 3 places size counts</title>
      <link>https://dpdprules.org/blog/does-dpdp-apply-to-startups</link>
      <guid>https://dpdprules.org/blog/does-dpdp-apply-to-startups</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>Section 3 carries no turnover, headcount or user threshold, so a 2 person company is inside the Act. Size still decides which duties bite, in 3 named places, and section 17(3) names startups without exempting a single one.</description>
    </item>
    <item>
      <title>DPDP Act 2023 and Rules 2025: what is in force in August 2026?</title>
      <link>https://dpdprules.org/blog/dpdp-act-rules-what-is-in-force-2026</link>
      <guid>https://dpdprules.org/blog/dpdp-act-rules-what-is-in-force-2026</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>A source backed status check: which parts of India's DPDP framework operate today, which dates are official, and which dates are computed.</description>
    </item>
    <item>
      <title>From complaint to penalty: how the Data Protection Board process works</title>
      <link>https://dpdprules.org/blog/dpdp-board-complaint-inquiry-appeal</link>
      <guid>https://dpdprules.org/blog/dpdp-board-complaint-inquiry-appeal</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>Sections 27 to 34 and Rules 19 and 22: what starts the Data Protection Board, the 6 month inquiry clock, the section 33(2) factors and the 60 day appeal.</description>
    </item>
    <item>
      <title>DPDP data breach reporting: what Rule 7 actually requires</title>
      <link>https://dpdprules.org/blog/dpdp-breach-reporting-rule-7</link>
      <guid>https://dpdprules.org/blog/dpdp-breach-reporting-rule-7</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>Rule 7 of the DPDP Rules 2025 sets 2 clocks after a personal data breach: immediate intimation to affected individuals and to the Board, then detailed information to the Board within 72 hours.</description>
    </item>
    <item>
      <title>DPDP compliance checklist for CTOs</title>
      <link>https://dpdprules.org/blog/dpdp-compliance-checklist-for-ctos</link>
      <guid>https://dpdprules.org/blog/dpdp-compliance-checklist-for-ctos</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>The engineering owned slice of a DPDP program: safeguards, retention timers, breach detection, consent withdrawal paths and rights machinery, with the cross functional dependencies made explicit.</description>
    </item>
    <item>
      <title>DPDP compliance checklist for startups</title>
      <link>https://dpdprules.org/blog/dpdp-compliance-checklist-for-startups</link>
      <guid>https://dpdprules.org/blog/dpdp-compliance-checklist-for-startups</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>A small team's path through the DPDP framework: settle applicability, map your data, and build the 5 duty clusters in dependency order while the runway lasts.</description>
    </item>
    <item>
      <title>DPDP consent requirements: what section 6 actually demands</title>
      <link>https://dpdprules.org/blog/dpdp-consent-requirements</link>
      <guid>https://dpdprules.org/blog/dpdp-consent-requirements</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>Section 6 sets 5 qualities, a clear affirmative action, a necessity limit and a proof burden that lands on you. 10 sub sections, 4 illustrations, and none of it in force yet.</description>
    </item>
    <item>
      <title>Does DPDP require data localisation? Cross border transfers, and the 1 rule that does</title>
      <link>https://dpdprules.org/blog/dpdp-cross-border-transfers</link>
      <guid>https://dpdprules.org/blog/dpdp-cross-border-transfers</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>Transfers out of India are permitted by default under Rule 15. But Rule 13(4) does impose localisation, once it commences, on Significant Data Fiduciaries for data the Central Government specifies, including its traffic data.</description>
    </item>
    <item>
      <title>DPDP grievance redressal: what Rule 14(3) says about 90 days</title>
      <link>https://dpdprules.org/blog/dpdp-grievance-redressal-90-days</link>
      <guid>https://dpdprules.org/blog/dpdp-grievance-redressal-90-days</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>Individuals get a right to readily available grievance redressal, Rule 14(3) names 90 days in a sentence that lost its object, and the Board only comes after this channel is exhausted.</description>
    </item>
    <item>
      <title>Data Principal rights under the DPDP Act: sections 11 to 14</title>
      <link>https://dpdprules.org/blog/dpdp-individual-rights-explained</link>
      <guid>https://dpdprules.org/blog/dpdp-individual-rights-explained</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>The 4 Chapter III rights, plus section 6(4) withdrawal. What each one reaches, the consent gate on 2 of them, and the 3 exemptions that remove all 4.</description>
    </item>
    <item>
      <title>DPDP Act penalties: fines up to Rs 250 crore explained (2026)</title>
      <link>https://dpdprules.org/blog/dpdp-penalties-schedule-explained</link>
      <guid>https://dpdprules.org/blog/dpdp-penalties-schedule-explained</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>The DPDP Act 2023 caps penalties in its Schedule, up to 250 crore rupees for failing security safeguards. Section 33 sets who imposes them and how.</description>
    </item>
    <item>
      <title>Do you need a contract with your Data Processor under DPDP?</title>
      <link>https://dpdprules.org/blog/dpdp-processor-contracts</link>
      <guid>https://dpdprules.org/blog/dpdp-processor-contracts</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>Engaging a Data Processor is lawful only under a valid contract, and the safeguards rule requires safeguard provisions in it. The 2 anchors, and what to add.</description>
    </item>
    <item>
      <title>DPDP data retention and erasure: Rule 8 and the 2 minimum floors</title>
      <link>https://dpdprules.org/blog/dpdp-retention-rule-8-explained</link>
      <guid>https://dpdprules.org/blog/dpdp-retention-rule-8-explained</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>The DPDP framework sets no retention period. It sets a purpose test, 1 deemed timer for 3 named classes, and 2 rules that make you keep data for a year.</description>
    </item>
    <item>
      <title>DPDP Rule 6 security safeguards, explained control by control</title>
      <link>https://dpdprules.org/blog/dpdp-rule-6-security-safeguards</link>
      <guid>https://dpdprules.org/blog/dpdp-rule-6-security-safeguards</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>Rule 6 names its minimums: encryption or masking, access control, logs, backups, 1 year retention, contract terms and organisational measures.</description>
    </item>
    <item>
      <title>Voluntary undertakings under section 32: the DPDP settlement track</title>
      <link>https://dpdprules.org/blog/dpdp-voluntary-undertakings-section-32</link>
      <guid>https://dpdprules.org/blog/dpdp-voluntary-undertakings-section-32</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>Section 32 of the DPDP Act 2023 lets the Data Protection Board accept a voluntary undertaking that bars further proceedings on its contents. Breaking it revives the penalty route.</description>
    </item>
    <item>
      <title>Is a name and email address personal data under DPDP?</title>
      <link>https://dpdprules.org/blog/is-name-email-personal-data-dpdp</link>
      <guid>https://dpdprules.org/blog/is-name-email-personal-data-dpdp</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>Usually yes in ordinary business records. The Act's definition turns on identifiability, and in real records names and email addresses identify people. What the definition says and what follows.</description>
    </item>
    <item>
      <title>Significant Data Fiduciary: what changes if you are notified</title>
      <link>https://dpdprules.org/blog/significant-data-fiduciary-explained</link>
      <guid>https://dpdprules.org/blog/significant-data-fiduciary-explained</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>SDF status arrives by government notification against the section 10 factors, not by crossing a user count. The real numbers in the framework, the duties that follow, and the vendor thresholds that do not exist.</description>
    </item>
    <item>
      <title>What is verifiable consent under DPDP?</title>
      <link>https://dpdprules.org/blog/what-is-verifiable-consent-dpdp</link>
      <guid>https://dpdprules.org/blog/what-is-verifiable-consent-dpdp</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>Consent for children must come from a verified parent or guardian. The 2 verification paths Rule 10 gives and the 4 cases it illustrates.</description>
    </item>
    <item>
      <title>What must a DPDP privacy notice contain? Section 5 and Rule 3</title>
      <link>https://dpdprules.org/blog/what-must-a-dpdp-privacy-notice-contain</link>
      <guid>https://dpdprules.org/blog/what-must-a-dpdp-privacy-notice-contain</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
      <description>Section 5 names 3 things the notice must inform. Rule 3 sets its shape and 2 minimums. Neither is in force yet. What the text requires, and what it does not.</description>
    </item>
  </channel>
</rss>