Before data leaks,clarity leaks.

Every failed programme we have seen began as a sentence someone said with confidence in a meeting.

In one line: Yes. DPDPA applies to digital personal data of any individual, including employees, job candidates, client contacts and vendor staff. A B2B business model does not remove those Data Principals from scope.

The estate · Unclear thinking is the first breachHover to inspect

The first breach is never technical. It is a sentence nobody challenged.

The scene

'We don't really process personal data, we're B2B.' The room nodded. It was said by a company with forty thousand employee records, a CRM of named buyers, and a support line that recorded every call. The sentence cost nothing to say. It shaped eighteen months of decisions.

Where the thinking breaks

The unclear thoughtWhat it breaksThe clearer thought
We're B2B, so DPDPA is light for us. Ignores employees, contacts at clients, candidates and call recordings. Every named person in your systems is a Data Principal.
Consent solves everything. Consent can be withdrawn; processing built only on it collapses when it is. Map each purpose to consent or a legitimate use under Section 7, and know which is which.
Our vendor is certified. Certification is not a contract; under Section 8(1) the fiduciary stays responsible. Certify, contract, audit, and rehearse the vendor's breach with them.
Keep everything, just in case. Section 8(7) requires erasure when the purpose is served, unless law requires retention. Every retained record should have a reason you could say aloud to the Board.
We'll wait and see how enforcement goes. The first enforcement is somebody's; waiting makes it more likely to be yours. Let others be the precedent.

Why thinking comes first

DPDPA is a principles law. It asks whether safeguards were reasonable, whether consent was free and specific, whether retention served a purpose. Each of those is a judgement. Unclear thinking produces unreasonable judgements that look reasonable on paper.

Monday morning

  1. 01Write down the five sentences your leadership says most about privacy.
  2. 02Test each against the Act. Keep the ones that survive.
  3. 03Circulate the replacements. Language changes behaviour faster than policy.

Questions, answered plainly

Does DPDPA apply to B2B companies?

Yes. DPDPA applies to digital personal data of any individual, including employees, job candidates, client contacts and vendor staff. A B2B business model does not remove those Data Principals from scope.

Is consent the only lawful basis under DPDPA?

No. Section 7 sets out certain legitimate uses, including specified employment purposes, compliance with law and medical emergencies. Everything else generally needs consent that is free, specific, informed, unconditional and unambiguous.

Can a company keep personal data indefinitely under DPDPA?

Generally no. Section 8(7) requires erasure once the specified purpose is no longer served, unless retention is necessary to comply with law. The Rules add fixed timelines for certain large platforms.

Argument 03You cannot protect what you have not named.Read → Argument 04Consent is not a checkbox. It is a contract you have to prove.Read → Argument 05Silence after a breach is the most expensive sound.Read →

Tell us where your data sits.We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner