Exposure mapping · Digital Personal Data Protection Act

Tell us where your data sits.We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

₹250 CrHighest ceiling in the Schedule
72 hrsFor the detailed breach report
56Briefings across 12 sectors
Your data estateHover to inspect
The penalty rarely comes from the system you secured. It comes from the one nobody mapped.
Five reframes

{{ strikeOld }}→ {{ strikeNew }}

The quest is not implementation.It is resilience.

Implementation asks whether the documents exist. Resilience asks whether the organisation survives its worst week. The Data Protection Board will only ever ask the second question.

See the clarity tree →

Same Act. Two very different programmes.

Question it asksAre we compliant?
OwnerLegal, with IT
ArtefactPolicies and a notice
Time horizonEnds at the deadline
VendorsA clause in the contract
Measure of successNothing was flagged
Question it asksWould we survive the worst week?
OwnerThe board, through every function
ArtefactA living data map and drilled playbooks
Time horizonStarts at the deadline
VendorsAudited, mapped, rehearsed
Measure of successSomething went wrong and nothing broke

Eight arguments for thinking before implementing.

Hover · Read
01→

Resilience, not implementation

Nobody will penalise you for your policy. They will penalise you for the week it failed.

02→

Unclear thinking is the first breach

The first breach is never technical. It is a sentence nobody challenged.

03→

You cannot protect what you have not named

Your data map is your defence map. Without one, you have no defence.

04→

Consent is a contract you have to prove

Consent obtained minus consent understood equals no defence.

05→

The first 72 hours

The breach is an event. The silence is a decision.

06→

Your vendor is your liability

Their breach. Your penalty.

07→

The board question

Significant Data Fiduciary is not a title. It is a target.

08→

What the Schedule actually costs

The ceiling is the law. The number is your conduct.

Twelve sectors · 48 briefings

Every sector has its own way of thinking wrongly.

Sector · Banking & BFSI

Banks keep everything.The law now asks why.

The unclear thoughtRBI compliance means DPDPA compliance.Sectoral rules govern specific data; DPDPA governs all personal data and adds rights sectoral rules do not.
The clearer thoughtMap where sectoral law is stricter, and where DPDPA reaches further.
Sector · Fintech & NBFC

Your onboarding takes ninety seconds.Your liability lasts years.

The unclear thoughtIf the user allows the permission, we have consent.An OS permission is not a notice; it does not state purpose.
The clearer thoughtPair every permission with a purpose the customer can read and refuse.
Sector · Healthcare & Pharma

The Act has no 'sensitive' category.Your patients do.

The unclear thoughtTreating the patient covers all processing.Section 7's medical legitimate uses are narrow; research, marketing and analytics need their own basis.
The clearer thoughtSeparate care from everything built on top of care.
Sector · EdTech

A child's data is not a cookie.Stop treating it like one.

The unclear thoughtOur users are over 13.DPDPA defines a child as under 18.
The clearer thoughtAssume most of your users are children, and design for it.
Sector · E-commerce & D2C

Your funnel runs on consent.The Act just redefined consent.

The unclear thoughtBuying means agreeing to marketing.Purchase and marketing are separate purposes needing separate consent.
The clearer thoughtAsk for marketing on its own, and accept no.
Sector · SaaS & IT services

You think you're the processor.Your contract may disagree.

The unclear thoughtWe're only a processor.Features that use client data for your own purposes make you a fiduciary for them.
The clearer thoughtMap role per processing activity, not per company.
Sector · Telecom

A billion subscribers.A billion Data Principals.

The unclear thoughtTelecom law governs our data.Sectoral rules and DPDPA apply together; neither excuses the other.
The clearer thoughtBuild one control set that satisfies both.
Sector · Insurance

Your agent's phoneis part of your data estate.

The unclear thoughtAgents are regulated separately.Agent licensing is not a data processing contract.
The clearer thoughtGovern agents' data handling as processing on your behalf.
Sector · HR & Staffing

The candidate you never hiredis still your Data Principal.

The unclear thoughtEmployee data is exempt.Section 7(i) covers specified employment purposes, not everything done with staff data.
The clearer thoughtMap each HR process to the employment use, or to consent.
Sector · Hospitality & Travel

Guests check out.Their passports stay.

The unclear thoughtThe law requires us to take IDs.Legal requirements cover specific records for specific periods, not a permanent archive.
The clearer thoughtCollect what the law names. Keep it as long as it says.
Sector · Gaming

Your fastest-growing segmentmay legally be children.

The unclear thoughtAn age gate solves it.A self-declared year is not verification.
The clearer thoughtDesign age assurance that a regulator would call reasonable.
Sector · Government vendors

The State's exemptionis not your exemption.

The unclear thoughtGovernment work is exempt.Section 17(2)(a) exempts notified instrumentalities of the State; vendors are not automatically covered.
The clearer thoughtRead the notification. Then read your contract.
Sixty-second exposure check

Which of these is true today?

Highest ceiling engaged {{ maxCap }} {{ headCount }} Tick what is true. Each line maps to a head of the Schedule to the Act.
{{ h.head }} · {{ h.sec }}{{ h.cap }}

Ceilings are statutory maximums, not predictions. Under Section 33 your conduct decides where you land.

Get a partner's first view

Questions, answered plainly

All 115 questions →

What is the difference between DPDPA implementation and DPDPA resilience?

Implementation produces the artefacts the Act requires: notices, consent flows, contracts, policies. Resilience is whether those artefacts hold under stress, such as a breach, a mass withdrawal of consent or a Board inquiry. The Act's penalties are triggered by failures in practice, so resilience is what reduces exposure.

Does DPDPA apply to B2B companies?

Yes. DPDPA applies to digital personal data of any individual, including employees, job candidates, client contacts and vendor staff. A B2B business model does not remove those Data Principals from scope.

Is a data map mandatory under DPDPA?

The Act does not use the term, but its obligations on notice, purpose limitation, security, erasure and Data Principal rights cannot be met without knowing where personal data sits. Significant Data Fiduciaries must also carry out data protection impact assessments, which depend on one.

What makes consent valid under DPDPA?

Section 6 requires consent to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to personal data necessary for the specified purpose. It must be as easy to withdraw as to give.

What is the breach notification timeline under DPDPA?

Under the DPDP Rules, 2025 a Data Fiduciary must intimate the Board and each affected Data Principal without delay on becoming aware of a personal data breach, and give the Board a detailed report within 72 hours, or a longer period the Board allows.

Is a Data Fiduciary liable for its Data Processor under DPDPA?

Yes. Section 8(1) makes the Data Fiduciary responsible for complying with the Act in respect of processing undertaken by it or on its behalf by a Data Processor.

What is a Significant Data Fiduciary under DPDPA?

A Significant Data Fiduciary is a Data Fiduciary or class notified by the Central Government under Section 10, considering factors such as volume and sensitivity of data, risk to Data Principals, and impact on sovereignty, security and public order.

What is the maximum penalty under DPDPA?

The highest ceiling in the Schedule is up to ₹250 crore, for failure of a Data Fiduciary to take reasonable security safeguards to prevent a personal data breach.

Tell us where your data sits.We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Received

A partner will reply within one working day.