DPDP Act 2023 · DPDP Rules 2025
Everything you need to know about DPDP compliance
A plain-language, searchable guide — from what the Act is, to breaches, children's data, penalties, and how TATA Tele Vishwaas AI helps you prove it.
117 questions
1 · FOUNDATIONS
Understanding the DPDP Act
Q1 What is the DPDP Act?
The Digital Personal Data Protection Act, 2023 is India's first comprehensive law dedicated to protecting the digital personal data of individuals. It received Presidential assent on 11 August 2023. It governs how organizations collect, use, share, protect, and delete personal data — and gives individuals enforceable rights over data about them.
Q2 Why does the law exist?
Three forces made it inevitable: the Supreme Court's 2017 Puttaswamy judgment declared privacy a fundamental right (and a fundamental right needs a working law); India went digital faster than its safeguards did; and repeated data misuse — leaked databases, unchecked telemarketing — made it clear that "trust us" had to become "prove it".
Q3 What is the single idea behind the whole law?
Personal data is borrowed, not owned. Like money deposited in a bank: the bank holds it and uses it to provide services, but it still belongs to the depositor, who can demand a statement, corrections, and closure. The Act makes every organization behave like that bank — which is why it calls you a Data Fiduciary: someone who holds something valuable in trust.
Q4 Is the law in force right now?
The Act is law, the Data Protection Board is operational, and the DPDP Rules were notified on 13 November 2025 with a staggered commencement: some provisions took effect immediately, while several substantive obligations become enforceable 18 months from notification. Plan against the applicable commencement dates — not a single imagined "go-live" day.
Verify current dates before relying on them; notifications evolve.
Q5 What are the DPDP Rules?
The Rules operationalize the Act: notice formats, breach-report windows, verifiable parental-consent approaches, retention norms for certain large platforms, and more. Where this FAQ mentions "the Rules", it means the DPDP Rules, 2025.
Q6 How is DPDP different from GDPR?
Materially. DPDP is consent-centric with a short list of stated "legitimate uses" (no open-ended "legitimate interest"); notices must be offered in the 22 scheduled languages plus English; there is no breach materiality threshold (plan for every breach to be notifiable); a child is anyone under 18; and governance is India-specific (Data Protection Board, Consent Managers, SDF designations). A GDPR programme is a head start — not a certificate.
Q7 Is there a "sensitive personal data" category with stricter rules?
No. Unlike some other laws, the DPDP Act protects all digital personal data with one uniform standard. (Children's data and SDF status add extra obligations, but not via a "sensitive data" category.)
2 · SCOPE
Does it apply to me?
Q1 Does the DPDP Act apply to my business?
Almost certainly yes, if you process digital personal data in India — collected digitally, or collected on paper and then typed into a computer or phone — or if you are outside India but process personal data in connection with offering goods or services to individuals in India.
Q2 What counts as "personal data"?
Any data about an individual who is identifiable by or in relation to that data: names, phone numbers, email and postal addresses, financial details, health information, identifiers, photographs, and so on.
Q3 What does the Act <i>not</i> cover?
Data an individual makes publicly available themselves; data processed for purely personal or domestic purposes; and certain exemptions for the State (security, law enforcement) and for research and statistics under prescribed safeguards. A purely paper register that never gets digitized is outside the Act — until someone photographs it or types it into Excel.
Q4 I'm a small business — does this really matter to me?
Yes. There is no small-business exemption for the core duties. A small organization still holds names, mobile numbers, addresses, customer records, employee information, payment details, even patient information. The important question is: what personal data do I process, why, where is it stored, and how do I protect it? See the small & micro organizations section for specifics.
Q5 I only have a few customers. Do I still need to bother?
Volume is only one factor. Even a small organization should understand the personal data it processes and establish sensible processes for security, retention, access, requests, and incidents. Enforcement is complaint-driven — it takes one unhappy customer, not a million.
3 · WHO'S WHO
The key roles, in plain words
Q1 Who is a Data Principal?
The individual the data is about — your customer, employee, patient, resident, user. For a child, the term includes their parent or lawful guardian. Data Principals also have duties: no impersonation, no suppressing material information, no false or frivolous complaints (penalty up to ₹10,000).
Q2 Who is a Data Fiduciary?
The organization that decides why and how personal data is processed — that's you, if you collect customer or employee data. A fiduciary is someone who holds something valuable in trust for someone else; the law's whole design flows from that word.
Q3 Who is a Data Processor?
A data-handling vendor that processes personal data on your behalf — your cloud provider, billing software, payroll processor, SMS gateway, gate-management app. You remain answerable for what they do with the data. Outsourcing the work does not outsource the liability.
Q4 What is a Significant Data Fiduciary (SDF)?
A larger, higher-risk data handler that the government specifically notifies as "significant", based on factors like the volume and sensitivity of data and risk to individuals. SDF status attaches extra duties to the same organization (see the SDF section) — it is not a separate kind of entity.
Q5 What is a Consent Manager?
A registered platform through which individuals can give, manage, review, and withdraw consent in one place — registered under Rule 4 with prescribed conditions. As these mature, individuals may manage consent for your services through them, so your systems should be able to interoperate.
Don't casually call any consent tool a "Consent Manager" — under the Act it is a specific, registered role.
Q6 What is the Data Protection Board of India (DPBI)?
The digital-first regulator: it receives complaints online, conducts proceedings online, investigates breaches, and imposes penalties. Appeals go to the TDSAT (the telecom appellate tribunal). The barrier for an unhappy individual to complain is one online form — not one lawsuit.
4 · ASK HONESTLY
Notice & consent
Q1 What must my notice contain?
Before or at the time you ask for consent, tell the individual, in clear and plain language: what personal data you want, why (the specific purpose), how they can exercise their rights and withdraw consent, and how to complain — to you and to the Data Protection Board.
Q2 In which languages?
The notice must be available in English or any of the 22 languages in the Eighth Schedule of the Constitution, at the individual's option. A customer in Chennai should be able to read your notice in Tamil, not just legal English.
Q3 What makes consent valid under the Act?
It must be free (not forced — you cannot deny an unrelated service because someone refused an unrelated data use), specific (tied to a stated purpose — "we may use your data for business purposes" is a blank cheque, and the Act bans blank cheques), informed (given after the notice), unconditional and unambiguous, and given by a clear affirmative action — no pre-ticked boxes.
Q4 Can I bundle consent into my terms and conditions?
No. A signature buried in a 40-page document covering "any use we like" is precisely what the Act invalidates. Consent must be specific, informed, and separable.
Q5 How easy must withdrawal be?
As easy as giving consent. If signing up took one tap, unsubscribing cannot take three phone calls and a written letter. Once withdrawn, you must stop processing (and have your processors stop) within a reasonable time, unless another legal ground applies.
Q6 Can I use data collected for one purpose for something else?
No — purpose limitation is central. If someone hands you their house keys to water the plants, you don't get to read their diary. Data collected for delivery does not automatically become data for marketing; that needs its own recorded yes.
Q7 What records of consent should I keep?
Who consented, to what, when, and via which notice version. You carry the burden of proving valid consent if disputed — a consent state your downstream systems ignore is evidence against you, not for you.
5 · LAW-PERMITTED USES
When you don't need consent ("legitimate uses")
Q1 Are there situations where separate consent isn't required?
Yes — the Act permits certain uses without fresh consent, which it calls "legitimate uses", including: data the individual voluntarily provided for a specified purpose and hasn't objected to (a customer sharing their number for a repair callback); employment-related purposes; medical emergencies, epidemics, and disasters; the State's specified functions, subsidies, and benefits; and compliance with law or court orders.
Q2 Is "legitimate use" a loophole I can rely on for marketing?
No. A law-permitted use covers the narrow purpose it names — the repair callback, not a lifetime of promotional SMS. Marketing communications need consent, full stop.
Q3 How do I decide the lawful ground for each purpose?
Walk your register of processing purposes and mark each one: consent, or a specific legitimate use. Anything you cannot map to a ground — stop collecting it. The data you don't collect can't be breached, doesn't need consent, and never triggers a penalty.
6 · THEIR DATA, THEIR RIGHTS
People's rights over their data
Q1 What rights do Data Principals have?
- Access / summary — on request, a summary of their personal data you process, the processing activities, and the other Fiduciaries and Processors it was shared with (with prescribed exceptions).
- Correction, completion, updating — fix wrong data when asked.
- Erasure — delete their data when asked, unless retention is required for the stated purpose or by law.
- Grievance redressal — a working, time-bound complaint channel; they must use it before escalating to the Board, so make it genuinely functional.
- Nomination — naming a person to exercise these rights if they die or become incapacitated.
Q2 What should happen when someone asks "what data do you have about me?"
Have a defined process: request received → identity verified → systems searched → data identified → action taken → outcome recorded → request closed. Verify identity before disclosing anything — releasing data to an impersonator is itself a breach.
Q3 Can I just tell someone their data was deleted?
You can communicate the outcome, but keep supporting evidence: deletion logs, timestamps, workflow records, affected systems, authorized users, and any retention exceptions. The goal is moving from "we believe it was deleted" to "here is the evidence of the deletion process and outcome."
Q4 What if the law requires me to retain some of the data they want erased?
Not every record can be deleted immediately — tax, medical-records, or other legal retention requirements may apply. Document the legitimate retention requirement and the exception; delete what has no such requirement.
Q5 What if we miss our response timelines?
Publish contact details of someone able to answer processing questions and respond to grievances within the prescribed period. An unanswered grievance inbox is an audit finding waiting to become a penalty — and an unresolved grievance is the individual's on-ramp to the Board.
Q6 What are the response timelines?
Under the Rules: grievances must be redressed within 30 days (Section 13), and requests to exercise the rights of access, correction, erasure, and nomination within 90 days. Publish contact details of someone able to answer processing questions. An unanswered grievance inbox is an audit finding waiting to become a penalty — and an unresolved grievance is the individual's on-ramp to the Board.
7 · THE ₹250-CRORE DUTY
Security safeguards
Q1 What does the Act require for security?
Every Data Fiduciary must implement reasonable security safeguards to prevent personal data breaches — for the data it holds and the data its processors hold on its behalf. Per the Rules, that means measures such as encryption/obfuscation/masking/tokenization, access control, logging and monitoring to detect and trace unauthorized access, backups and continuity, log retention, and contracts binding processors to equivalent safeguards.
Q2 What does a minimum credible security programme look like, in plain terms?
- Lock the data itself — scramble it so it's unreadable if stolen (encryption), at rest and in transit; show masked values where real ones aren't needed.
- Limit who can see it — access on a need-to-know basis, re-checked regularly. The sales intern does not need the full customer database.
- Keep a tamper-proof activity trail (logs), watch it, retain it per the Rules.
- Close the everyday doors — security updates, endpoint protection, and a second proof of identity at login (multi-factor authentication) on anything touching personal data.
- Keep tested backups — ransomware destroying personal data is a breach and a continuity failure.
- Get your defences tested — at least yearly, including simulated attacks on internet-facing systems.
- Hold less in the first place — data minimisation and enforced retention limits are security controls, not just compliance ones. Data you no longer hold cannot be breached, leaked, or demanded back.
Q3 Who can access my information within a compliance platform?
Access should be governed by authentication, authorisation, and role-based access controls, on the same least-privilege principle you'd expect internally: users see only what their role requires. Ask any vendor to show you the model, not just describe it.
Q4 What security certifications should a compliance platform hold?
Only certifications the product/company has actually obtained should ever be represented to you — treat anything vaguer as a claim to verify. Relevant credentials to ask for include ISO/IEC 27001, ISO/IEC 27701, SOC 2 Type II, independent penetration-testing and vulnerability-assessment reports, secure-SDLC assessments, and cloud security certifications, alongside hosting architecture, encryption, privileged-access controls, audit logging, and backup/disaster-recovery arrangements.
Q5 Does a compliance platform's ISO 27001 certification mean the platform itself is DPDP compliant?
No. ISO 27001 demonstrates an Information Security Management System framework for the vendor — it does not, by itself, certify that the platform (or your use of it) satisfies every DPDP Act requirement. Present it, and any other security certification, as evidence of security governance, not as a blanket "DPDP certification."
See the DPDP-certified-software question in Cyber insurance & certifications for the same distinction applied to the whole compliance market.
Q6 Why does security get so much attention?
It carries the single highest penalty in the Act — up to ₹250 crore per instance. And "we outsourced it to a vendor" is not a defense: the Fiduciary answers for its processors.
8 · OWN IT FAST
Data breaches & incident response
Q1 What counts as a personal data breach?
Any unauthorized processing, disclosure, loss, or compromise of personal data. A lost laptop, a hacked email account, a leaked directory PDF, a misconfigured cloud bucket — all breaches.
Q2 Who must I notify, and when?
- Every affected Data Principal — promptly, in clear language: what happened, what it means for them, what you're doing, what they should do, whom to contact.
- The Data Protection Board — an initial intimation without delay, followed by a detailed report within the prescribed window (the Rules set it at 72 hours of becoming aware, extendable on request).
Q3 Is there a "too small to report" threshold?
No. Unlike some foreign laws, the DPDP framework has no materiality filter — plan on the assumption that every breach is notifiable. Treat a breach like a gas leak: the building doesn't debate whether the leak is "material" before warning residents.
Q4 How do breaches actually happen?
People (phishing, social engineering, accidental disclosure), technology (vulnerabilities, malware, ransomware), configuration (open cloud storage, wrong permissions), access (stolen credentials, excessive privileges, insider activity), third parties (vendor compromise), and physical loss (stolen devices). No single control eliminates all of these — which is why the Act asks for a programme, not a product.
Q5 What should happen in the first hours after discovering a breach?
Follow a rehearsed playbook: identify → contain → assess affected systems and data → determine impact → meet notification requirements → remediate → root-cause analysis → corrective actions → keep records. Your data map is what turns "assess affected individuals" from weeks into hours.
Q6 What is RCA and why does the regulator care?
Root Cause Analysis — identifying why an incident occurred rather than patching the symptom. Example: data exposed (incident) → wrong cloud-sharing permission (immediate cause) → excessive privileges and no periodic access review (root cause) → least-privilege access + reviews + monitoring (corrective action). The Board weighs your mitigation conduct when setting penalties; a documented incident-to-resolution trail matters.
Q7 Can a compliance platform actually manage RCA and corrective actions, or is that still a manual exercise?
A structured workflow can hold it end to end: incident details, severity, impact, root cause, corrective action, responsible person, target date, supporting evidence, management approval, and closure — creating one documented trail from incident to resolution instead of a scattered mix of emails and meeting notes.
Q8 If I implement controls after a breach, does that erase the consequences?
No. Post-incident fixes help with remediation and future risk, but they don't automatically remove liability for the earlier event. That is the argument for building the programme before the bad day.
9 · THE STRICTEST LANE
Children's data
Q1 Who is a "child" under the DPDP Act?
Anyone under 18 — older than most foreign laws. For children, consent must come verifiably from the parent or lawful guardian.
Q2 What is required — and banned — for children's data?
Required: verifiable parental/guardian consent before processing (the Rules describe acceptable verification approaches, including identity/age details already available or virtual tokens issued against them). Banned: tracking, behavioral monitoring, and targeted advertising directed at children, and any processing likely to cause a detrimental effect on a child's well-being. Penalties run up to ₹200 crore.
Q3 We're not an ed-tech — do we still need to worry?
Check rather than assume. Coaching classes, playschools, gyms with teen members, gaming apps, society clubs — children's data appears in many ordinary businesses. If you serve under-18s, implement verifiable parental consent and disable tracking/targeted ads for them. If you don't, implement reasonable age-assurance at signup so "we didn't know" is defensible.
10 · MILK, NOT WINE
Retention & deletion
Q1 How long can I keep personal data?
Only as long as the stated purpose is being served, or a legal retention requirement applies. When the purpose is over, erase the data and cause your processors to erase it. The Rules also prescribe time-bound retention limits for certain large platform classes, with deletion after prolonged user inactivity unless the user re-engages after notice.
Q2 What's a practical way to think about retention?
Data is milk, not wine — it does not get more valuable with age. It goes bad, becomes a liability, and eventually a penalty. Ex-members, discharged patients, moved-out tenants, passed-out students: their data has an expiry date, not a forever home.
Q3 What does a working deletion practice look like?
A defined retention period for every processing activity ("forever" is not a period); automated deletion where possible (manual deletion calendars die within a quarter); deletion extended to backups (on their own defined cycle) and to your processors; and user notification before inactivity-based erasure so they can re-engage.
Q4 Deleting on request vs deleting proactively — which applies?
Both. Erasure on request is one duty; proactive erasure when the purpose is served is another. "We'll delete when someone asks" satisfies only the first.
11 · YOUR LIABILITY TRAVELS
Vendors & Data Processors
Q1 My vendors hold the data — isn't that their problem?
No. The Data Fiduciary remains answerable for its Data Processors. Your gate app, billing software, or lab portal holding data badly is your problem under the Act.
Q2 What must be in my contract with each processor?
Processing only on your instructions; security safeguards equivalent to yours; breach notification to you without delay; erasure or return of data on termination; and audit rights. Then risk-rank vendors and actually verify the critical ones — certifications, questionnaires, or audits. "The contract said they were secure" has never impressed any auditor, anywhere.
Q3 What visibility should I maintain over vendors?
A living inventory: vendor name, services, data categories accessed, purpose, systems touched, contractual obligations, security requirements, risk rating, review status, and open corrective actions.
Q4 What happens if my vendor suffers a breach?
It's your breach too, operationally: your notification duties to affected individuals and the Board don't disappear because the incident happened inside a supplier. This is why breach-notice-to-you clauses and tested escalation paths with vendors matter.
Q5 Can a compliance platform tell me which vendors have access to personal data?
That's the point of a vendor-management module: a structured inventory covering vendor name, services provided, data categories accessed, purpose, systems touched, contractual obligations, security requirements, risk rating, review status, and open corrective actions — kept live rather than rebuilt from memory before every audit.
Q6 What exactly does a vendor-management module track for each vendor?
A per-vendor record with: vendor name; services provided; data categories accessed; purpose; systems touched; contractual obligations; security requirements; risk rating; review status; and open corrective actions — the same fields an auditor would ask you to produce, kept current instead of reconstructed under deadline.
12 · EXTRA DUTIES FOR THE BIG & RISKY
Significant Data Fiduciaries (SDFs)
Q1 What extra duties do SDFs carry?
- Appoint a Data Protection Officer (DPO) — based in India, reporting to the board of directors, serving as the grievance contact point.
- Appoint an independent data auditor to evaluate compliance.
- Conduct periodic Data Protection Impact Assessments (DPIAs) — a structured "what could go wrong for individuals, and what are we doing about it" exercise — and periodic audits.
- Perform due diligence on algorithmic software used with personal data, to verify it doesn't pose a risk to Data Principals' rights.
- Comply with any government-specified restrictions on transferring specified data outside India.
Q2 How do I know if I'm an SDF?
The government notifies SDF designations based on factors like data volume and sensitivity and risk to individuals. If you expect to qualify (large consumer platforms, BFSI, health, telecom at scale), build the DPO/auditor/DPIA muscles early — someone should be formally watching for notifications.
Q3 Can data leave India?
Under the baseline regime, cross-border transfer is permitted except to countries restricted by government notification — and sector regulators' rules (e.g., financial data) continue to apply. SDFs may face stricter requirements for specified data. Watch the notifications; this is one of the fastest-moving parts of the regime.
13 · THE STAKES
The Board considers nature, gravity, duration, repetitiveness, and your mitigation conduct. For perspective: the top slab exceeds the annual profit of most mid-sized Indian companies.
Penalties & enforcement
Q1 What are the maximum penalties?
| Failure | Maximum penalty (per instance) |
|---|---|
| Reasonable security safeguards | ₹250 crore |
| Breach notification (Board / individuals) | ₹200 crore |
| Children's data obligations | ₹200 crore |
| SDF obligations | ₹150 crore |
| Any other provision | ₹50 crore |
| Duties of a Data Principal | ₹10,000 |
Q2 How would the authorities even know I haven't complied?
A complaint by a Data Principal; a data breach; a mishandled request; vendor incidents; information surfacing in proceedings; regulatory inquiries. The better question is not "will anyone find out?" but "can I demonstrate that my organization took appropriate steps?"
Q3 If nobody complains, am I safe?
Not necessarily — and building a strategy on "no one will notice" is building on the assumption that no breach will ever occur. A proactive programme reduces risk and creates the evidence trail that protects you when something does go wrong.
Q4 Can I plead ignorance of the law?
Lack of awareness is not a compliance strategy. Assess applicability, understand obligations, establish controls — the prudent sequence hasn't changed since the Act passed.
14 · DPDP FOR THE REST OF US
Small & micro organizations
Q1 What data does a typical small organization actually hold?
- Clinic / lab / pharmacy — patient names, contacts, histories, prescriptions, reports, insurance, payments.
- Shop / mart — customer names and mobiles (billing/loyalty), purchase history, addresses, UPI references.
- Housing society / RWA — resident directories, tenant agreements, vehicle numbers, visitor logs, CCTV footage, staff ID copies, children's details.
- Gym / salon / coaching class — member contacts, photos, health declarations, students' (children's!) details, parent contacts.
- NGO / club — donor, beneficiary, and volunteer records, ID proofs, bank details.
Q2 What are the riskiest everyday habits to kill first?
Customer/patient data on personal phones; member data forwarded in open WhatsApp groups; lending or selling contact lists to marketers (never — that's processing without consent); ID photocopies in unlocked drawers or open shared drives; CCTV footage shown to any curious person; the "temporary" Excel export that lives forever.
Q3 What's the smallest credible compliance programme?
Twelve steps, mostly discipline: (1) name one owner and display a contact; (2) make the one-page data map — that page is 60% of your compliance; (3) write a short plain-language notice, translated locally; (4) separate service messages from promotions, with "stop" honored in one step; (5) kill the risky habits; (6) lock every device and account — passwords, per-person logins, a second login proof (OTP/authenticator — "MFA"); (7) put every data-handling vendor ("Data Processor") on written terms; (8) set expiry dates per data type and actually delete; (9) be ready to show/fix/delete anyone's data within days; (10) keep a half-page breach plan; (11) handle children's data with gloves; (12) walk the data map once a year.
Q4 Does a housing society really need all this for a resident directory?
Sharing the full directory as a PDF in the society WhatsApp group is disclosure without consent, repeated daily. Share minimal role-based lists instead (or take recorded resident consent), put the gate-app vendor under a written agreement, give CCTV footage only to the affected person or lawful authorities, and delete ex-residents' data after dues settle.
Q5 I'm a doctor or run a clinic — why should I worry about DPDP?
Clinics routinely handle some of the most sensitive personal data there is: patient identities, histories, prescriptions, reports, billing, and appointment communications. A structured process for what's collected, where it lives, who can access it, why it's used, and when it's deleted or retained isn't optional paperwork — it's the difference between a defensible practice and one relying on staff memory.
15 · THE HOW
Building the compliance programme
Q1 Where do I start?
Assign ownership, then map your data. Compliance without an owner is a rumor; and you cannot protect what you can't find. Inventory every system that stores or touches personal data — applications, databases, file shares, SaaS tools, cloud buckets, laptops, paper-to-digital scans — and map each flow: what comes in, from whom, why, where stored, who accesses, which vendors receive it, when it's deleted.
Q2 Why is the "register of processing activities" so central?
Because everything else reads from it: notices are written per purpose in the register; consent is captured per purpose; rights responses query it; breach scoping uses it; audits walk it. Keep it living — purpose, data categories, categories of individuals, recipients, retention period, and security measures per activity.
Q3 What's the honest sequence for the full programme?
Discover → Classify → Assess → Configure → Correct → Monitor → Evidence. In practice: ownership; data inventory and register; lawful ground per purpose; notices rewritten; consent lifecycle built (capture / record / honor / withdraw); rights-request workflow; retention and deletion; security hardening; processor contracts; breach playbook (rehearsed twice a year); children's data handling; training; annual gap assessment with findings tracked to closure.
Q4 Why start now instead of at the deadline?
Because the runway exists precisely because the work is slow. Discovery alone — finding what data you have, where it is, who accesses it, which vendors receive it — takes weeks to months, and every gap it surfaces needs time to fix. The Rules commenced in phases from November 2025; starting at the deadline leaves no time to correct what discovery finds.
Q5 Why should I pay for the software now instead of waiting until the last minute?
Because compliance cannot be achieved effectively overnight. You may first need to discover: What data you have. Where it is stored. Who can access it. Why it is being processed. Which vendors receive it. How long it is retained. How deletion is performed. How customer requests are handled. The earlier these gaps are identified, the more time the organisation has to correct them.
Q6 How important is training?
Most breaches begin with a human, not a hacker. Annual all-hands awareness in plain language, role-specific modules for HR/marketing/engineering/support, and attendance records — an auditor will ask, and "we sent an email once" is not training.
16 · PROVE IT
Proving compliance: evidence & audits
Q1 What's the strongest evidence that we take data protection seriously?
Not a privacy policy — an evidence trail: policy → process → implementation → monitoring → incident management → corrective action → audit trail. From "I think we are compliant" to "I can demonstrate what we have done."
Q2 What will an auditor or regulator actually ask for?
Policies; data inventories and the processing register; consent and notice records; rights-request logs with timestamps; deletion records; vendor contracts and reviews; incident records with RCA and corrective actions; audit logs; training records; compliance reports. If retrieving those takes weeks, the programme exists on paper only.
Q3 What management visibility should leadership expect?
A live view of: overall compliance posture, the data inventory, open rights requests, pending deletions, high-risk repositories, vendor risks, incidents and corrective actions, overdue activities, and audit readiness. If leadership can't see it, leadership can't own it — and the Act expects leadership to own it.
Q4 What are the five levels of visibility a programme should give management?
A useful way to structure the whole programme. Each level answers one question leadership should be able to ask at any moment — and if any level has no answer, that is the gap to close next.
- 1 · Discover — what personal data do I have, and where is it?
- 2 · Govern — why am I collecting it, and who is responsible for it?
- 3 · Protect — who can access it, and how is it protected?
- 4 · Respond — what happens when a customer makes a request, or an incident occurs?
- 5 · Evidence — can I demonstrate what happened, when it happened, and who performed the action?
Q5 Can management actually see the overall compliance status inside the platform, not just on paper?
Yes, where the product configuration supports it: a management dashboard surfacing overall compliance status, the data inventory, open Data Principal requests, pending deletion actions, high-risk data repositories, vendor risks, incidents, open corrective actions, overdue activities, and audit readiness — a single live screen instead of a status meeting built from memory.
17 · ADJACENT QUESTIONS
Cyber insurance & certifications
Q1 Should I take cyber insurance?
It can be a sensible part of risk management — but insurance is risk transfer, not compliance. It doesn't collect consent, honor rights, or notify breaches.
Q2 If I already have cyber insurance, why do I need a compliance platform too?
Because they address different risks. Cyber insurance = financial risk transfer — it can help cover specified losses after something goes wrong, subject to the policy. A compliance platform = governance, control, monitoring, and evidence — it helps you meet the underlying data-protection obligations (consent, rights, breach notice, retention) in the first place, and reduces operational risk rather than just paying for it after the fact. Insurance and a platform are complementary, not substitutes for each other.
Q3 If I have cyber insurance, can't the insurer just pay the DPDP penalty?
Don't assume that. Coverage depends on the policy, exclusions, conditions, and applicable law — and some regulatory penalties may not be insurable at all. Worse, an insurer can potentially contest a claim precisely because you failed to maintain the controls you attested to. Insurance is an additional layer — not a substitute for compliance.
Q4 Can an insurance company deny a claim because I did not maintain appropriate controls?
Potentially, depending on the policy terms and circumstances. This is another reason why organisations should maintain appropriate security controls, documented processes and evidence.
Q5 Does ISO 27001 (or SOC 2) mean an organization is DPDP compliant?
No. ISO 27001 evidences an information-security management framework; it does not certify compliance with the DPDP Act's specific obligations (consent, notices, rights, children's data, breach notification). Present certifications as evidence of security governance — never as a blanket "DPDP certification".
Q6 Is there any "DPDP certified" software?
Be cautious of any such blanket claim. The meaningful questions are: which DPDP requirements does the product support, what controls does it implement, what does it automate, what evidence does it generate, and which independent security certifications does it actually hold?
18 · REALITY CHECK
Common myths & objections
Q1 "We're too small; this doesn't apply to us."
The Act applies regardless of size. Some duties scale with SDF status, but notice, consent, security, breach notification, and rights apply to everyone.
Q2 "We comply with GDPR, so we're done."
A strong foreign-law programme is a head start, not a certificate — see the DPDP-vs-GDPR question for the material differences.
Q3 "Consent buried in our terms covers us."
Bundled, non-specific consent is precisely what the Act invalidates.
Q4 "A breach only matters if it's serious."
There is no materiality threshold — plan for every breach to be notifiable.
Q5 "Compliance is a one-time project."
It's an operating discipline: new products, new vendors, and new government notifications all change your obligations.
Q6 "The deadlines are far away; we'll start later."
The Rules commenced in phases from November 2025, and a real programme takes months to build. The 18-month runway for substantive obligations exists because the work is slow — starting at the deadline leaves no time to fix what discovery finds.
Q7 "Why can't I just maintain an Excel sheet?"
For a very small, simple operation, you might. But as data, systems, staff, and vendors grow, spreadsheets can't trigger reminders, maintain audit trails, run workflows, monitor exceptions, or demonstrate historical evidence. The compliance question isn't "do you have a file?" — it's "can you prove what happened, when, and who did it?"
Q8 "If nothing has gone wrong so far, our approach must be working."
Absence of a discovered incident is not evidence of control. The greater risk of doing nothing is the absence of visibility: you cannot protect what you do not know you have.
19 · TOOLING, HONESTLY
Compliance software & TATA Tele Vishwaas AI
Q1 Does the DPDP Act require me to buy software?
No. The Act mandates outcomes, not products. You can use manual processes, spreadsheets, or internal systems — but as volume and complexity grow, manual processes become difficult to manage, monitor, and evidence. A platform is the structured technology layer for doing this efficiently.
Q2 If I don't buy the software, am I automatically non-compliant?
No. An organisation can use manual processes, spreadsheets, internal systems or other technology to manage compliance. However, as the volume and complexity of data increases, manual processes can become difficult to manage, monitor and evidence. Our platform provides a structured technology layer for doing this more efficiently.
Q3 Can any software guarantee DPDP compliance?
No — and be wary of anyone who says otherwise. Compliance depends on your policies, people, processes, and decisions. A platform's honest job is to enable, monitor, and evidence compliance activities. Installing one is the beginning of the journey, not the end.
Q4 Can the platform guarantee 100% DPDP compliance?
No — and no software can, because compliance also depends on things outside any platform's control: your policies, your people, and how your organization actually behaves day to day. A cyber incident is never fully preventable either. The platform's job is to enable, monitor, and evidence the compliance activities that are within its scope — not to issue a 100% guarantee no honest vendor would stand behind.
Q5 Does installing the platform make my company DPDP compliant automatically?
No — implementation is the start of the journey, not its completion. A platform helps identify gaps and manage corrective actions, but the underlying business, legal, operational, and security decisions still have to be made by the organization.
Q6 Isn't this just another privacy-policy tool?
A privacy policy is one document; DPDP compliance is an operational chain — what data do I have → where is it → why do I have it → who accesses it → how long do I retain it → what happens when someone asks me to act on it. A platform exists to operationalize that chain, not to generate a policy PDF.
Q7 What business problem does a platform like this actually solve?
It converts data protection from a manual, memory-dependent activity — spreadsheets, emails, individual knowledge, scattered records — into a structured, measurable process with central workflows, monitoring, and evidence.
Q8 What does TATA Tele Vishwaas AI actually do?
TATA Tele Vishwaas AI is an India-first Privacy & Consent Management Platform built natively for the DPDP Act 2023 and DPDP Rules 2025. In operational terms it covers: consent collection (online and offline) with notices in all 22 scheduled languages plus English; tamper-evident, cryptographically verifiable consent records bound to the exact notice version and language shown; real-time propagation of consent decisions to downstream systems; Data Principal rights management with SLAs; a live RoPA register with 15 continuously-running DPDP gap checks; data discovery across AWS, Azure, Google Cloud, databases, file shares, and on-prem systems with DPDP lawful-basis verdicts; breach management aligned to the 72-hour framework; DPIA and Data Processor management; and a partner-led DPDP Readiness Assessment with a remediation ledger.
Q9 Will the platform delete or modify data inside my source systems?
No — by design it is read-only in your systems. Source-side fixes are performed by your people and closed by evidence acceptance; the platform tracks, verifies, and proves the remediation. It never deletes, masks, or modifies anything in your systems — sell that to your CISO as the feature it is.
Q10 Will all my data be physically moved into one place?
Not necessarily. A data-protection platform doesn't need to consolidate your business data into a single repository to be useful — it can instead maintain structured information about where data exists, how it's classified, and what controls or actions apply to it, while the data itself stays put.
Q11 Will the platform copy all my personal data?
No, not wholesale. TATA Tele Vishwaas AI's discovery is read-only in your source systems (see above) — it scans to identify and classify what's there and generates DPDP verdicts, rather than pulling your data into itself. What it does retain is metadata: what was found, where, its classification, and its lawful-basis status. Press any compliance vendor to be explicit about the same three things — what's scanned, what's stored, and what's transmitted off your systems — and treat minimum necessary access and least privilege as the standard to hold them to.
Q12 Where is TATA Tele Vishwaas AI hosted?
On secure cloud infrastructure with documented hosting location, encryption, backup, and access-management controls — details are provided to customers directly rather than left implicit. If you're evaluating any compliance vendor, insist on the same specifics in writing, not just asserted verbally in a sales call.
Q13 What happens to my data after I stop using the platform?
TATA Tele Vishwaas AI follows documented data-retention and exit procedures covering customer data, metadata, logs, and backups — including agreed deletion timelines, export of your records, and confirmation of secure deletion. These commitments sit in the customer agreement itself, not just in a support conversation.
Q14 What happens to my data after I stop using the platform? (exit procedure detail)
The customer should have clearly documented data-retention and exit procedures covering: Customer data. Metadata. Logs. Backups. Deletion timelines. Export requirements. Secure deletion. These requirements should also be incorporated into the customer agreement.
Q15 What benefit do I actually get from knowing where my data is?
It's what lets you answer the questions regulators, auditors, and customers actually ask: what data do you have, where is it, why are you using it, who can access it, who are you sharing it with, how long will you keep it, and what happens when the purpose ends. That visibility is the foundation everything else in a compliance programme is built on.
Q16 How does discovery help compliance rather than just finding files?
Because findings get a DPDP verdict, not just a location: every discovered item is checked against the consent ledger in the same platform — no lawful activity, no consent, consent withdrawn but data still present, child data without verifiable parental consent — and every finding passes a human review gate before action. You cannot prove lawful basis for data you don't know about; discovery plus verdicts closes that gap.
Q17 What's the return on investment from implementing a compliance platform?
It goes beyond avoiding a penalty. Expect reduced manual compliance effort, better visibility of personal data, faster response to Data Principal requests, stronger audit readiness, reduced dependence on spreadsheets, better vendor governance, faster incident response, real management visibility, and — not incidentally — more customer trust.
Q18 Why choose a platform instead of managing this internally with existing tools?
Because data protection shouldn't depend on memory, spreadsheets, emails, manual follow-ups, or one key employee who happens to remember where things are — nor on reacting only after a breach. A platform gives you a structured, technology-enabled way to discover, govern, protect, monitor, respond, and evidence, turning compliance from a periodic scramble into an ongoing business process.
Q19 What's the simplest way to understand the value of a platform like this?
Nobody sells you a certificate. The value is: know your data, control its use, protect it, respond to requests, manage incidents — and demonstrate all of it with evidence. From "I think we are compliant" to "I can show you what we have done."
Put another way: DPDP compliance is not about buying software. It is about knowing your data, controlling its use, protecting it, responding to Data Principal requests, and being able to demonstrate what you have done — a platform is what makes doing all of that systematic rather than heroic.
No matching questions
Try a different keyword, or pick All to browse every section.
Ready to move from questions to evidence?
See how an India-first privacy platform operationalizes the answers above — consent, rights, discovery, breach readiness, and the evidence trail that proves it.