Data Privacy & DPDPA

Follow the data. Understand the duty.

Consent, retention, Processor accountability and incident decisions, examined at the point where policy meets operations.

The context

Data Privacy & DPDPA.
The questions behind the work.

A privacy review begins with the processing activity: whose data is involved, who decides the purpose and means, and what each participant actually does. A Data Fiduciary and a Processor have different roles; the contract label is evidence, not the final answer. GDPR terminology should not be imported into an Indian assessment without checking the applicable statutory ground.

Abstract editorial architectural corridor
Read the practice notes

Five decisions.
Examined in detail.

The applicable framework

DPDP Act, 2023: sections 4–8, 11–13 and 16, as relevant. The substantive duties discussed here form part of the phased commencement programme; distinguish readiness work from duties already in force. Existing IT, cybersecurity and sector-specific requirements need their own assessment.