Tell us where your data sits.We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
{{ strikeOld }}→ {{ strikeNew }}
The quest is not implementation.It is resilience.
Implementation asks whether the documents exist. Resilience asks whether the organisation survives its worst week. The Data Protection Board will only ever ask the second question.
See the clarity tree →Same Act. Two very different programmes.
Eight arguments for thinking before implementing.
Hover · ReadResilience, not implementation
Nobody will penalise you for your policy. They will penalise you for the week it failed.
Unclear thinking is the first breach
The first breach is never technical. It is a sentence nobody challenged.
You cannot protect what you have not named
Your data map is your defence map. Without one, you have no defence.
Consent is a contract you have to prove
Consent obtained minus consent understood equals no defence.
The first 72 hours
The breach is an event. The silence is a decision.
Your vendor is your liability
Their breach. Your penalty.
The board question
Significant Data Fiduciary is not a title. It is a target.
What the Schedule actually costs
The ceiling is the law. The number is your conduct.
Every sector has its own way of thinking wrongly.
Banks keep everything.The law now asks why.
Your onboarding takes ninety seconds.Your liability lasts years.
The Act has no 'sensitive' category.Your patients do.
A child's data is not a cookie.Stop treating it like one.
Your funnel runs on consent.The Act just redefined consent.
You think you're the processor.Your contract may disagree.
A billion subscribers.A billion Data Principals.
Your agent's phoneis part of your data estate.
The candidate you never hiredis still your Data Principal.
Guests check out.Their passports stay.
Your fastest-growing segmentmay legally be children.
The State's exemptionis not your exemption.
Which of these is true today?
Ceilings are statutory maximums, not predictions. Under Section 33 your conduct decides where you land.
Get a partner's first viewQuestions, answered plainly
All 115 questions →What is the difference between DPDPA implementation and DPDPA resilience?
Implementation produces the artefacts the Act requires: notices, consent flows, contracts, policies. Resilience is whether those artefacts hold under stress, such as a breach, a mass withdrawal of consent or a Board inquiry. The Act's penalties are triggered by failures in practice, so resilience is what reduces exposure.
Does DPDPA apply to B2B companies?
Yes. DPDPA applies to digital personal data of any individual, including employees, job candidates, client contacts and vendor staff. A B2B business model does not remove those Data Principals from scope.
Is a data map mandatory under DPDPA?
The Act does not use the term, but its obligations on notice, purpose limitation, security, erasure and Data Principal rights cannot be met without knowing where personal data sits. Significant Data Fiduciaries must also carry out data protection impact assessments, which depend on one.
What makes consent valid under DPDPA?
Section 6 requires consent to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to personal data necessary for the specified purpose. It must be as easy to withdraw as to give.
What is the breach notification timeline under DPDPA?
Under the DPDP Rules, 2025 a Data Fiduciary must intimate the Board and each affected Data Principal without delay on becoming aware of a personal data breach, and give the Board a detailed report within 72 hours, or a longer period the Board allows.
Is a Data Fiduciary liable for its Data Processor under DPDPA?
Yes. Section 8(1) makes the Data Fiduciary responsible for complying with the Act in respect of processing undertaken by it or on its behalf by a Data Processor.
What is a Significant Data Fiduciary under DPDPA?
A Significant Data Fiduciary is a Data Fiduciary or class notified by the Central Government under Section 10, considering factors such as volume and sensitivity of data, risk to Data Principals, and impact on sovereignty, security and public order.
What is the maximum penalty under DPDPA?
The highest ceiling in the Schedule is up to ₹250 crore, for failure of a Data Fiduciary to take reasonable security safeguards to prevent a personal data breach.
Tell us where your data sits.We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
A partner will reply within one working day.