<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>DPDPA as Strategy</title><link>https://amlegalsdpdpa.com/dpdpa-exposure-assessment</link><atom:link href="https://amlegalsdpdpa.com/dpdpa-strategy/feed.xml" rel="self" type="application/rss+xml"/><description>A strategy field guide to India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: eight arguments on resilience over implementation, and twelve sector briefings on how unclear thinking breaks DPDPA programmes.</description><language>en-in</language><item><title>DPDPA Compliance: Why Resilience Beats Implementation</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-resilience-not-implementation</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-resilience-not-implementation</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>DPDPA implementation ends on a date. Resilience begins on it. Why India's data protection law rewards organisations built to survive a breach, not just pass a checklist.</description></item><item><title>Seven DPDPA Mistakes That Start as Unclear Thinking</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-unclear-thinking</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-unclear-thinking</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Before data leaks, clarity leaks. Seven common assumptions that quietly break DPDPA implementation in Indian companies, and the clearer thought that replaces each.</description></item><item><title>DPDPA Data Mapping: The Map Is the Defence</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-data-mapping</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-data-mapping</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>You cannot protect what you have not named. Why a living data map is the foundation of DPDPA compliance, breach response and every Data Principal right.</description></item><item><title>DPDPA Consent Requirements: Consent Is a Contract You Must Prove</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-consent-architecture</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-consent-architecture</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Under Section 6 of DPDPA, consent must be free, specific, informed, unconditional and unambiguous, and as easy to withdraw as to give. Why a banner is not a consent architecture.</description></item><item><title>DPDPA Breach Notification: The First 72 Hours</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-breach-72-hours</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-breach-72-hours</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Under the DPDP Rules, 2025 a personal data breach must be intimated to the Board and affected Data Principals without delay, with a detailed report within 72 hours. What the first three days actually demand.</description></item><item><title>DPDPA Data Processors: Your Vendor's Breach Is Your Breach</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-processors-vendors</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-processors-vendors</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Under Section 8 of DPDPA the Data Fiduciary remains responsible for processing by its Data Processors. How to govern vendors, SDKs and cloud providers as part of your own estate.</description></item><item><title>DPDPA for Boards: Significant Data Fiduciary and Governance</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-board-governance</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-board-governance</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>What boards and CXOs must ask about DPDPA: ownership, Significant Data Fiduciary duties under Section 10, data protection officers, impact assessments and audits.</description></item><item><title>DPDPA Penalties Explained: Up to ₹250 Crore and How the Board Decides</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-penalties-exposure</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-penalties-exposure</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>The DPDPA penalty schedule: up to ₹250 crore for failed security safeguards, ₹200 crore for breach intimation and children's data, ₹150 crore for SDF duties, ₹50 crore otherwise, and the factors the Board weighs.</description></item><item><title>DPDPA for Banks and BFSI: Where Retention Meets Erasure</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-banking-bfsi</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-banking-bfsi</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>How DPDPA applies to banks and financial institutions in India: KYC retention under PMLA versus erasure, vendor chains, breach intimation alongside RBI and CERT-In reporting.</description></item><item><title>DPDPA for Fintech and NBFCs: Speed Is Not a Consent Strategy</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-fintech-nbfc</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-fintech-nbfc</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>How DPDPA applies to fintechs, NBFCs and digital lenders: purpose-bound consent for app permissions, lending service providers as processors, and alternative-data scoring.</description></item><item><title>DPDPA for Hospitals, Healthcare and Pharma</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-healthcare-pharma</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-healthcare-pharma</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>How DPDPA applies to hospitals, diagnostics, healthtech and pharma: patient consent, the narrow medical-emergency legitimate use, clinical trial data and TPAs.</description></item><item><title>DPDPA for EdTech: Children's Data and Verifiable Parental Consent</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-edtech-children</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-edtech-children</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Under Section 9 of DPDPA a child is anyone under 18. EdTech platforms need verifiable parental consent and may not track, behaviourally monitor or target advertising at children.</description></item><item><title>DPDPA for E-commerce and D2C Brands</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-ecommerce-d2c</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-ecommerce-d2c</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>How DPDPA applies to e-commerce and D2C: marketing consent, pixels and SDKs as processors, dark patterns, and the three-year erasure rule for large platforms under the DPDP Rules.</description></item><item><title>DPDPA for SaaS and IT Services: Processor or Fiduciary?</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-saas-it-services</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-saas-it-services</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>How DPDPA applies to SaaS companies and IT services firms: processor versus fiduciary roles, the Section 17 exemption for processing foreign clients' data, and contract design.</description></item><item><title>DPDPA for Telecom Operators and ISPs</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-telecom</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-telecom</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>How DPDPA applies to telecom operators, ISPs and telecom value-added services: subscriber data at scale, dealer networks, SDF likelihood and overlap with the Telecommunications Act, 2023.</description></item><item><title>DPDPA for Insurers, Brokers and TPAs</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-insurance</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-insurance</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>How DPDPA applies to insurance: health and claims data, agents and brokers as processors, TPAs, underwriting purposes and retention after claims close.</description></item><item><title>DPDPA for HR, Employers and Staffing Firms</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-hr-staffing</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-hr-staffing</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>How DPDPA applies to employee and candidate data: the Section 7(i) employment legitimate use, background checks, candidates never hired, and staffing firms as processors.</description></item><item><title>DPDPA for Hotels, Travel and Hospitality</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-hospitality-travel</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-hospitality-travel</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>How DPDPA applies to hotels, airlines, OTAs and travel companies: passport and ID copies, guest registers, loyalty programmes and booking partners.</description></item><item><title>DPDPA for Online Gaming Platforms</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-gaming</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-gaming</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>How DPDPA applies to online gaming: minors on the platform, behavioural data, the DPDP Rules' three-year erasure requirement for large gaming intermediaries, and in-game advertising.</description></item><item><title>DPDPA for Government Contractors and Vendors</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-government-vendors</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-government-vendors</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>How DPDPA applies to companies processing personal data for government departments: the State exemption under Section 17(2)(a) does not automatically extend to vendors.</description></item><item><title>Bank Data Breach Reporting in India: CERT-In, RBI and DPDPA Together</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-bfsi-three-reporting-clocks</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-bfsi-three-reporting-clocks</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>One incident at a bank can start three clocks: CERT-In's six hours, the RBI's own reporting, and DPDPA intimation to the Board and every affected customer. How to run one playbook for all three.</description></item><item><title>KYC Retention vs DPDPA Erasure: What Banks Must Keep and What They Must Let Go</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-bfsi-retention-vs-erasure</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-bfsi-retention-vs-erasure</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>PMLA requires banks to keep KYC and transaction records. DPDPA requires erasure once purpose ends. How to separate the legal hold from everything that merely stayed.</description></item><item><title>DPDPA for Bank Partners: DSAs, Collection Agents and Business Correspondents</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-bfsi-agents-partners</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-bfsi-agents-partners</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Direct selling agents, collection agencies, business correspondents and co-lending partners all handle customer data. Under DPDPA the bank remains responsible for processing done on its behalf.</description></item><item><title>Fintech App Permissions Under DPDPA: Why Permission Is Not Consent</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-fintech-app-permissions</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-fintech-app-permissions</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>An Android or iOS permission grants access, not consent. How fintech and lending apps should pair every permission with a purpose, a notice and a real choice.</description></item><item><title>Alternative Data Credit Scoring and DPDPA Purpose Limitation</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-fintech-alternative-data</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-fintech-alternative-data</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Fintechs score credit on SMS, device and behavioural data. Under DPDPA, data collected for one purpose cannot silently feed another. How to use alternative data lawfully.</description></item><item><title>Account Aggregators and DPDPA: India's Working Model of Granular Consent</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-fintech-account-aggregator</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-fintech-account-aggregator</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>India's account aggregator framework already runs on purpose-bound, time-bound, revocable consent. Why it is the blueprint for DPDPA consent across fintech.</description></item><item><title>Patient Consent Under DPDPA: Treatment Is Not a Blank Cheque</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-healthcare-patient-consent</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-healthcare-patient-consent</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>DPDPA allows limited processing for medical emergencies. Routine care, analytics, research and marketing each need their own basis. How hospitals separate care from commerce.</description></item><item><title>Sharing Medical Reports on WhatsApp: The DPDPA Risk Hospitals Ignore</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-healthcare-reports-messaging</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-healthcare-reports-messaging</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Diagnostic labs and hospitals share reports over consumer messaging apps for speed. Under DPDPA, every forwarded copy is part of your data estate and your security duty.</description></item><item><title>Clinical Trial and Research Data Under DPDPA</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-pharma-clinical-research</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-pharma-clinical-research</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Consent to a clinical trial does not extend to marketing a later product. How pharma and research teams scope purpose, retention and processors for trial and real-world data.</description></item><item><title>Verifiable Parental Consent Under DPDPA: A Practical Guide for EdTech</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-edtech-parental-consent</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-edtech-parental-consent</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>DPDPA requires verifiable consent of a parent before processing a child's data. What verification means under the Rules and how to build it into onboarding.</description></item><item><title>Adaptive Learning and DPDPA's Ban on Behavioural Monitoring of Children</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-edtech-behavioural-monitoring</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-edtech-behavioural-monitoring</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Section 9(3) bars tracking, behavioural monitoring and targeted advertising directed at children. What that means for adaptive learning, proctoring and engagement analytics.</description></item><item><title>DPDPA Exemptions for Schools and Educational Institutions</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-edtech-schools-exemptions</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-edtech-schools-exemptions</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>The DPDP Rules exempt certain processing by educational institutions from parts of Section 9. The exemption follows the purpose, not the product. What schools and EdTech vendors must know.</description></item><item><title>Tracking Pixels, SDKs and DPDPA: The Processors Hiding in Your Tag Manager</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-ecommerce-pixels-sdks</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-ecommerce-pixels-sdks</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Every advertising pixel and SDK sends personal data to a third party. Under DPDPA that is processing, often cross-border, and the brand remains responsible.</description></item><item><title>Dark Patterns and DPDPA Consent: Why Tricks Are Not Agreement</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-ecommerce-dark-patterns</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-ecommerce-dark-patterns</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Pre-ticked boxes, confirm-shaming and buried opt-outs fail DPDPA's clear affirmative action test and are regulated as unfair practices under India's dark patterns guidelines.</description></item><item><title>The DPDP Rules' Three-Year Erasure Rule for E-commerce Platforms</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-ecommerce-dormant-accounts</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-ecommerce-dormant-accounts</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Large e-commerce entities must erase personal data of users inactive for three years, after notice. How to build dormancy, notice and erasure into the customer lifecycle.</description></item><item><title>Is Your SaaS Company a Data Processor or Data Fiduciary Under DPDPA?</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-saas-processor-or-fiduciary</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-saas-processor-or-fiduciary</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Role under DPDPA follows who decides purpose and means. How SaaS companies map roles per activity, and why product features can quietly turn a processor into a fiduciary.</description></item><item><title>Sub-Processors Under DPDPA: Mapping the Chain Behind Your SaaS</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-saas-sub-processors</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-saas-sub-processors</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Monitoring, support, email, analytics: every SaaS runs on sub-processors. How to map the chain, flow obligations down and evidence them to enterprise customers.</description></item><item><title>DPDPA Vendor Questionnaires: How SaaS Companies Win Enterprise Procurement</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-saas-enterprise-procurement</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-saas-enterprise-procurement</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Indian enterprises are adding DPDPA questions to vendor due diligence. What buyers now ask and how resilient vendors answer faster than competitors.</description></item><item><title>SIM KYC and Retailers: DPDPA Risk at the Edge of the Telecom Network</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-telecom-retail-kyc</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-telecom-retail-kyc</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Retailers and distributors collect subscriber identity documents on behalf of telecom operators. Under DPDPA the operator remains responsible. How to govern the edge.</description></item><item><title>Significant Data Fiduciary Readiness for Telecom Operators</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-telecom-sdf-readiness</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-telecom-sdf-readiness</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Large telecom operators are strong candidates for Significant Data Fiduciary notification. What Section 10 and the Rules require and how to prepare before notification.</description></item><item><title>Handling DPDPA Data Principal Rights at Telecom Scale</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-telecom-rights-at-scale</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-telecom-rights-at-scale</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Access, correction, erasure and grievance requests at telecom volume cannot run on email. How to productise rights handling with identity checks and timelines built in.</description></item><item><title>Insurance Agents, Brokers and DPDPA: Governing the Distribution Chain</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-insurance-agents-brokers</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-insurance-agents-brokers</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Proposal forms travel through agents, branch teams and brokers before a policy issues. How insurers govern the distribution chain as part of their own data estate.</description></item><item><title>Health Claims Data, TPAs and DPDPA</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-insurance-claims-health-data</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-insurance-claims-health-data</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Claims files hold diagnoses, bank details and family information, handled by TPAs and hospitals. How insurers secure the claims chain and prepare for breach intimation.</description></item><item><title>Data Minimisation in Insurance Underwriting Under DPDPA</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-insurance-underwriting-minimisation</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-insurance-underwriting-minimisation</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Section 6 limits consent to data necessary for the purpose. How insurers decide what underwriting genuinely needs, and stop collecting for the file.</description></item><item><title>Candidate and Applicant Data Under DPDPA: Recruitment Is Not Employment</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-hr-candidate-data</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-hr-candidate-data</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>DPDPA's employment legitimate use covers employees. Candidates who were never hired need their own basis and a retention limit. How employers and staffing firms handle CV data.</description></item><item><title>Employee Monitoring and DPDPA: Where Necessity Ends</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-hr-employee-monitoring</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-hr-employee-monitoring</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Productivity trackers, keystroke logging and webcam checks raise DPDPA questions of necessity and purpose. How employers set limits they can defend.</description></item><item><title>Background Verification Vendors and DPDPA</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-hr-background-verification</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-hr-background-verification</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Background checks collect education, employment, address and sometimes criminal records. How employers limit, contract and audit verification vendors under DPDPA.</description></item><item><title>Hotel Guest ID Copies and DPDPA: Collect What the Law Names</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-hospitality-id-copies</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-hospitality-id-copies</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Hotels collect passports and identity documents at check-in. How to collect only what law requires, restrict access and erase on schedule under DPDPA.</description></item><item><title>Loyalty Programmes and Guest Profiling Under DPDPA</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-hospitality-loyalty</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-hospitality-loyalty</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Loyalty programmes build rich guest profiles. How hotels and airlines define purpose, get consent and avoid turning loyalty into surveillance.</description></item><item><title>Hotel CCTV and Guest Wi-Fi Under DPDPA</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-hospitality-cctv-wifi</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-hospitality-cctv-wifi</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>CCTV footage and Wi-Fi login data are personal data. How hotels set retention, access and notice for surveillance and connectivity systems.</description></item><item><title>Age Verification for Gaming Platforms Under DPDPA</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-gaming-age-assurance</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-gaming-age-assurance</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>A self-declared birth year is not verification. How gaming platforms design age assurance and parental consent that meet DPDPA and the DPDP Rules.</description></item><item><title>Player Telemetry, Behavioural Data and DPDPA</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-gaming-player-telemetry</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-gaming-player-telemetry</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Games log every action. Linked to an account or device, telemetry is personal data, and for children, behavioural monitoring is restricted under Section 9(3).</description></item><item><title>The Three-Year Erasure Rule for Online Gaming Platforms</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-gaming-dormant-erasure</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-gaming-dormant-erasure</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>The DPDP Rules require large online gaming intermediaries to erase data of users inactive for three years, after notice. How to plan dormancy and erasure.</description></item><item><title>The State Exemption Under DPDPA Section 17(2)(a): What Vendors Must Know</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-govt-exemption-scope</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-govt-exemption-scope</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>The Central Government may exempt notified instrumentalities of the State. Private contractors are not automatically covered. How vendors read the exemption and their contracts.</description></item><item><title>Returning and Deleting Citizen Data at the End of a Government Contract</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-govt-contract-end</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-govt-contract-end</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>When a government IT contract ends, citizen data often stays with the vendor. How to plan data return, deletion and certification under DPDPA.</description></item><item><title>Production Data in Test Environments: A Hidden DPDPA Risk for Government Vendors</title><link>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-govt-test-environments</link><guid>https://amlegalsdpdpa.com/dpdpa-strategy/dpdpa-govt-test-environments</guid><pubDate>Fri, 25 Sep 2026 00:00:00 GMT</pubDate><description>Copying production data into development and test environments is common and dangerous. How vendors mask, minimise and govern non-production data.</description></item></channel></rss>
