DPDP Compliance · 27 articles

DPDP Compliance

DPDP Act 2023 obligations, breach response, rights fulfilment, sector overlays.

Compliance

DPDP for Startups: A Practical Data Fiduciary Checklist You Can Action This Week

You do not need an enterprise GRC team to get DPDP-ready. A practical startup checklist you can start this week.

May 25, 2026 · 1 min read
Compliance

RBI Cybersecurity Framework 2026: What Banks and NBFCs Must Actually Do

RBI raised the bar in 2026: independent vendor assessments and evidence, not self-attestation. Here is what is actually required.

May 25, 2026 · 1 min read
Compliance

The 6-Hour Rule: Building One Breach Playbook for CERT-In, DPDP, and RBI

CERT-In: 6 hours. DPDP: 72. RBI/SEBI/IRDAI: their own. One incident, five clocks — here is how to run them as one playbook.

May 25, 2026 · 1 min read
Compliance

DPDP Enforcement Has Begun: ₹250 Crore Penalties and the Data Protection Board

The DPDP grace period is over. The Board is live, and the penalty for a breach reaches ₹250 crore.

May 25, 2026 · 1 min read
Compliance

DPDP Act Operational Compliance: A 2026 Data Fiduciary Engineering Playbook

Moving beyond DPDP commentary to engineering execution. Data inventory, consent engineering, right-to-erasure implementation, and the 72-hour breach runbook.

May 22, 2026 · 8 min read
Compliance

Scenario Brief: What Tighter RBI Cyber Master Direction Controls Would Mean for PSOs

Tabletop-ready regulatory scenario: continuous control monitoring, board-level cyber risk committees, and a 4-hour SLA on critical incident notification for PSOs.

May 22, 2026 · 2 min read
Compliance

Scenario Brief: How a DPDP Penalty for S3 Misconfiguration Could Unfold

Tabletop-ready compliance scenario: how a public S3 bucket leaking identity documents could lead to a major DPDP Board penalty, and what Data…

May 22, 2026 · 2 min read
Compliance

DPDP Phase 2 Effective Date Locked: What Indian SaaS Must Ship by August 2026

What just shifted MeitY’s notification of Phase 2 of the DPDP Rules has locked the effective date for several previously-flagged sections. The…

May 14, 2026 · 6 min read
Academy

Module 8 · Data Masking, Tokenisation, Pseudonymisation

Why this module exists. “Use real production data in development” is the line that produces audit findings and breaches. The alternatives —…

May 14, 2026 · 4 min read
Academy

Module 9 · Privacy Engineering Beyond Compliance

Why this module exists. “Privacy by design” is a phrase in every privacy framework and a practice in few organisations. The shift…

May 14, 2026 · 4 min read