DPDPA as Strategy: Resilience, Not Implementation | India Data Protection
DPDPA as Strategy: Resilience, Not Implementation | India Data Protection
Five reframes
{{ strikeOld }} → {{ strikeNew }}
{{ c.old }} {{ c.neu }}
The quest is not implementation. It is resilience.
Implementation asks whether the documents exist. Resilience asks whether the organisation survives its worst week. The Data Protection Board will only ever ask the second question. See the clarity tree →
Same Act. Two very different programmes.
Implementation
Resilience
Question it asks Are we compliant?
Owner Legal, with IT
Artefact Policies and a notice
Time horizon Ends at the deadline
Vendors A clause in the contract
Measure of success Nothing was flagged
Question it asks Would we survive the worst week?
Owner The board, through every function
Artefact A living data map and drilled playbooks
Time horizon Starts at the deadline
Vendors Audited, mapped, rehearsed
Measure of success Something went wrong and nothing broke
Eight arguments for thinking before implementing.
Hover · Read
01 →
Resilience, not implementation
Nobody will penalise you for your policy. They will penalise you for the week it failed.
02 →
Unclear thinking is the first breach
The first breach is never technical. It is a sentence nobody challenged.
03 →
You cannot protect what you have not named
Your data map is your defence map. Without one, you have no defence.
04 →
Consent is a contract you have to prove
Consent obtained minus consent understood equals no defence.
05 →
The first 72 hours
The breach is an event. The silence is a decision.
06 →
Your vendor is your liability
Their breach. Your penalty.
07 →
The board question
Significant Data Fiduciary is not a title. It is a target.
08 →
What the Schedule actually costs
The ceiling is the law. The number is your conduct.
Twelve sectors · 48 briefings
Every sector has its own way of thinking wrongly.
Banking & BFSI 01
Fintech & NBFC 02
Healthcare & Pharma 03
EdTech & children's data 04
E-commerce & D2C 05
SaaS & IT services 06
Telecom 07
Insurance 08
HR & Staffing 09
Hospitality & Travel 10
Gaming 11
Government vendors 12
Sector · Banking & BFSI
Banks keep everything. The law now asks why.
The unclear thought RBI compliance means DPDPA compliance. Sectoral rules govern specific data; DPDPA governs all personal data and adds rights sectoral rules do not.
The clearer thought Map where sectoral law is stricter, and where DPDPA reaches further.
The Banking & BFSI briefing →
Three reporting clocks → Retention versus erasure → Agents and partners →
Sector · Fintech & NBFC
Your onboarding takes ninety seconds. Your liability lasts years.
The unclear thought If the user allows the permission, we have consent. An OS permission is not a notice; it does not state purpose.
The clearer thought Pair every permission with a purpose the customer can read and refuse.
The Fintech & NBFC briefing →
App permissions → Alternative-data scoring → The consent model that exists →
Sector · Healthcare & Pharma
The Act has no 'sensitive' category. Your patients do.
The unclear thought Treating the patient covers all processing. Section 7's medical legitimate uses are narrow; research, marketing and analytics need their own basis.
The clearer thought Separate care from everything built on top of care.
The Healthcare & Pharma briefing →
Care versus commerce → Reports on messaging apps → Trials and research →
Sector · EdTech
A child's data is not a cookie. Stop treating it like one.
The unclear thought Our users are over 13. DPDPA defines a child as under 18.
The clearer thought Assume most of your users are children, and design for it.
The EdTech & children's data briefing →
Verifiable parental consent → Personalisation or monitoring → Schools and exemptions →
Sector · E-commerce & D2C
Your funnel runs on consent. The Act just redefined consent.
The unclear thought Buying means agreeing to marketing. Purchase and marketing are separate purposes needing separate consent.
The clearer thought Ask for marketing on its own, and accept no.
The E-commerce & D2C briefing →
Pixels and SDKs → Dark patterns and consent → Dormant accounts →
Sector · SaaS & IT services
You think you're the processor. Your contract may disagree.
The unclear thought We're only a processor. Features that use client data for your own purposes make you a fiduciary for them.
The clearer thought Map role per processing activity, not per company.
The SaaS & IT services briefing →
Processor or fiduciary → The sub-processor chain → Winning the security review →
Sector · Telecom
A billion subscribers. A billion Data Principals.
The unclear thought Telecom law governs our data. Sectoral rules and DPDPA apply together; neither excuses the other.
The clearer thought Build one control set that satisfies both.
The Telecom briefing →
KYC at the retail edge → SDF readiness → Rights at scale →
Sector · Insurance
Your agent's phone is part of your data estate.
The unclear thought Agents are regulated separately. Agent licensing is not a data processing contract.
The clearer thought Govern agents' data handling as processing on your behalf.
The Insurance briefing →
Agents and brokers → Claims and health data → Underwriting minimisation →
Sector · HR & Staffing
The candidate you never hired is still your Data Principal.
The unclear thought Employee data is exempt. Section 7(i) covers specified employment purposes, not everything done with staff data.
The clearer thought Map each HR process to the employment use, or to consent.
The HR & Staffing briefing →
Candidate data → Employee monitoring → Background verification →
Sector · Hospitality & Travel
Guests check out. Their passports stay.
The unclear thought The law requires us to take IDs. Legal requirements cover specific records for specific periods, not a permanent archive.
The clearer thought Collect what the law names. Keep it as long as it says.
The Hospitality & Travel briefing →
Guest ID copies → Loyalty and profiling → CCTV and guest Wi-Fi →
Sector · Gaming
Your fastest-growing segment may legally be children.
The unclear thought An age gate solves it. A self-declared year is not verification.
The clearer thought Design age assurance that a regulator would call reasonable.
The Gaming briefing →
Age assurance → Player telemetry → Dormant players →
Sector · Government vendors
The State's exemption is not your exemption.
The unclear thought Government work is exempt. Section 17(2)(a) exempts notified instrumentalities of the State; vendors are not automatically covered.
The clearer thought Read the notification. Then read your contract.
The Government vendors briefing →
The scope of the exemption → Data at contract end → Real citizens in test data →
Sixty-second exposure check
Which of these is true today?
{{ c.label }}
{{ c.sec }}
Highest ceiling engaged
{{ maxCap }}
{{ headCount }}
Tick what is true. Each line maps to a head of the Schedule to the Act.
{{ h.head }} · {{ h.sec }} {{ h.cap }}
Ceilings are statutory maximums, not predictions. Under Section 33 your conduct decides where you land.
Get a partner's first view →
Questions, answered plainly All 115 questions →
What is the difference between DPDPA implementation and DPDPA resilience? +
Implementation produces the artefacts the Act requires: notices, consent flows, contracts, policies. Resilience is whether those artefacts hold under stress, such as a breach, a mass withdrawal of consent or a Board inquiry. The Act's penalties are triggered by failures in practice, so resilience is what reduces exposure.
Does DPDPA apply to B2B companies? +
Yes. DPDPA applies to digital personal data of any individual, including employees, job candidates, client contacts and vendor staff. A B2B business model does not remove those Data Principals from scope.
Is a data map mandatory under DPDPA? +
The Act does not use the term, but its obligations on notice, purpose limitation, security, erasure and Data Principal rights cannot be met without knowing where personal data sits. Significant Data Fiduciaries must also carry out data protection impact assessments, which depend on one.
What makes consent valid under DPDPA? +
Section 6 requires consent to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to personal data necessary for the specified purpose. It must be as easy to withdraw as to give.
What is the breach notification timeline under DPDPA? +
Under the DPDP Rules, 2025 a Data Fiduciary must intimate the Board and each affected Data Principal without delay on becoming aware of a personal data breach, and give the Board a detailed report within 72 hours, or a longer period the Board allows.
Is a Data Fiduciary liable for its Data Processor under DPDPA? +
Yes. Section 8(1) makes the Data Fiduciary responsible for complying with the Act in respect of processing undertaken by it or on its behalf by a Data Processor.
What is a Significant Data Fiduciary under DPDPA? +
A Significant Data Fiduciary is a Data Fiduciary or class notified by the Central Government under Section 10, considering factors such as volume and sensitivity of data, risk to Data Principals, and impact on sovereignty, security and public order.
What is the maximum penalty under DPDPA? +
The highest ceiling in the Schedule is up to ₹250 crore, for failure of a Data Fiduciary to take reasonable security safeguards to prevent a personal data breach.
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Received
A partner will reply within one working day.
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).
