FAQ

The DPDP questions we get asked on almost every first call.

Grouped roughly in the order they come up: what the law is, how consent has to work, what happens when something leaks, and what changes when children or vendors are involved. Where the honest answer is "it depends", we say what it depends on.

This is educational material written by practitioners who run security and compliance programmes, not by lawyers. It will make you a better-informed client of legal advice — it does not replace it.

The basics

What is the DPDP Act in one paragraph?

The Digital Personal Data Protection Act, 2023 is India's first dedicated law for digital personal data. It tells organisations how they may collect, use, share, secure and delete data about people, and it gives those people enforceable rights over it. The DPDP Rules, 2025 supply the operational detail — notice content, breach timelines, retention, children's data — and commence in stages.

Does it apply to my business?

If you hold information that can identify a person, in any digital form, then yes. There is no turnover threshold and no small-business exemption. A three-chair salon with customer numbers in a billing app is covered on exactly the same terms as a bank.

We are outside India. Are we in scope?

If you offer goods or services to people in India, yes. The Act reaches processing outside India done in connection with that offering.

How is this different from GDPR?

It is shorter, and it drops the separate category of sensitive data — everything is protected to one standard. There is no statutory data-portability right, cross-border transfer is permissive by default rather than restrictive, and penalties are set as absolute rupee ceilings rather than a percentage of turnover.

Is our old consent still valid?

Only if you go back and serve a compliant notice covering that earlier consent. Consent taken before the Act does not become invalid automatically, but it does need the notice the Act now demands.

Consent and notice

Can one checkbox cover marketing, analytics and delivery?

No. Consent must be specific to a purpose. Bundling unrelated purposes behind a single tick fails both the 'specific' and the 'free' tests, and it is one of the easiest failures for a regulator to spot from the outside.

Do we need the notice in regional languages?

The individual may ask for it in English or any language in the Eighth Schedule. In practice, publish it in English plus the languages your customers actually transact in, and keep each translation version-controlled.

What counts as proof of consent?

A record showing who consented, to which specific purpose, against which version of the notice, with the exact text they saw, the timestamp and the channel. A CRM flag saying 'consent: yes' proves nothing.

Someone withdraws consent. What must happen?

Stop the processing that depended on it, erase the data unless another law requires retention, and pass the withdrawal to every processor and downstream system that received it. Silent, partial withdrawal is a common and expensive failure.

Security and breaches

What are 'reasonable security safeguards' in practice?

Rule 6 gives the shape: encryption or equivalent protection, access control, logs kept for a year, backups that restore, contractual obligations on processors, and the ability to investigate. The standard is judged after an incident against what a competent peer would have done — so document the decisions you take.

Is the deadline 72 hours or 6 hours?

Both, for different regulators. The Data Protection Board must be told within 72 hours of your becoming aware; CERT-In's separate direction requires notification within six hours for qualifying cyber incidents. Affected individuals are told without undue delay.

What if we never noticed the breach?

That is the worst position under the Act. The obligation to hold reasonable safeguards includes being able to detect and investigate — which is why the security-failure clause carries the ₹250 crore ceiling and why monitoring is a compliance control, not just an IT preference.

Our vendor caused the leak. Are we still liable?

Yes. Processor engagement does not transfer accountability. You remain the Data Fiduciary; your recourse against the vendor is contractual, and it only exists if the contract exists.

Rights, children and vendors

How quickly must we answer a rights request?

The Act requires the fiduciary to respond within the period prescribed by the Rules, and expects a published, working grievance channel. Treat it as an operational SLA with an owner, not as post to be read when someone has time.

We teach children. What changes?

Almost everything. You need verifiable parental consent before processing, you may not track or behaviourally monitor a child, and you may not target advertising at them. Schools, coaching institutes and ed-tech carry the strictest duties in the Act.

Do we need a Data Protection Officer?

Only Significant Data Fiduciaries must appoint one, based in India and reporting to the board. Everyone else must still publish a contact for grievances — and someone internally should genuinely own privacy, whatever their job title says.

Can we keep using overseas cloud providers?

Generally yes. Cross-border transfer is permitted unless the government restricts a specific country, though sectoral rules — RBI payment data, for example — may still require Indian storage. Record where data goes and why.

Working with I2W

Are you a law firm?

No, and we will not pretend otherwise. We are a security operations firm. We map where your data lives, fix the technical controls, monitor them around the clock and produce the evidence a regulator or auditor asks for. Legal opinions come from your counsel; we make sure their advice is actually implemented.

Are you CERT-In empanelled?

No. We follow CERT-In directions and the NIST Cybersecurity Framework as guidance, and we are compliant with the DPDP Act. We hold ISO/IEC 27001:2022, ISO 9001:2015 and ISO/IEC 20000-1:2018, with SOC 2 Type II certification in progress. Where an empanelled auditor is mandatory, we say so and work alongside one.

Where does a DPDP programme usually start?

With a discovery exercise: every system, spreadsheet, group chat and backup that holds personal data, and the purpose for each. It is unglamorous, it takes days rather than months, and every subsequent decision depends on it.

What can you do in the first month?

Realistically: a complete data inventory, a gap list ranked by penalty exposure, a rewritten notice and consent flow, retention rules per data type, and monitoring in place so a breach is detected inside your 72-hour window rather than after it.

Still unsure

Bring us your specific situation instead of a hypothetical.

Forty-five minutes with your systems in front of us is worth more than any FAQ. You will leave with a ranked list of what to fix first, whether or not you work with us.