Clear Thinking on DPDPA: The Clarity Tree | DPDPA as Strategy Clear Thinking on DPDPA: The Clarity Tree | DPDPA as Strategy
01 Know. Do we know what we hold?
02 Ask. Did we ask properly?
03 Guard. Would it hold under attack?
04 Tell. Could we speak within hours?
05 Let go. Do we let go on time?
Situation
The law is not new to your data. Your data is new to the law.
Complication
Most programmes were built to be finished. The Act was written to be tested.
Resolution
Think first. Then build only what survives the worst week.
First principles
Strip the Act to what cannot be reduced further.
Hover each assumption
Principle 01
Our data is our asset. The data is not yours. You hold it on trust.
Principle 02
More data is more value. Purpose is the boundary. Outside it, you have no right.
Principle 03
The vendor is responsible. Every hand that touches the data is your hand.
Principle 04
We will speak once we are sure. Silence is not a pause. It is a decision.
Principle 05
Keep it, just in case. Every permission expires. Plan for the day it does.
The clarity method
Five moves from a tangle to a tested programme.
{{ s.num }}
{{ s.name }}
{{ s.lineage }}
Move {{ cur.num }} · {{ cur.lineage }}
{{ cur.line }}
{{ cur.body }}
What you walk out with
{{ cur.output }}
The matrix
Not every gap deserves this quarter.
Plot every system by exposure and by readiness. The top-left square is where the budget goes first. Everything else waits its turn, in writing.
{{ dotInfo.kick }}
{{ dotInfo.name }}
{{ dotInfo.text }}
Act this quarter
Defend and evidence
Schedule it
Maintain
{{ d.name }}
← Low readiness Exposure ↑ · Illustrative estate High readiness →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).
DPDPA for Banks and BFSI: Where Retention Meets Erasure DPDPA for Bank Partners: DSAs, Collection Agents and Business Correspondents KYC Retention vs DPDPA Erasure: What Banks Must Keep and What They Must Let Go Bank Data Breach Reporting in India: CERT-In, RBI and DPDPA Together DPDPA for Boards: Significant Data Fiduciary and Governance DPDPA Breach Notification: The First 72 Hours DPDPA Briefing Agent: Your Sector, Your Concern, Your Reading Order DPDPA Consent Requirements: Consent Is a Contract You Must Prove DPDPA Data Mapping: The Map Is the Defence DPDPA for E-commerce and D2C Brands Dark Patterns and DPDPA Consent: Why Tricks Are Not Agreement The DPDP Rules' Three-Year Erasure Rule for E-commerce Platforms Tracking Pixels, SDKs and DPDPA: The Processors Hiding in Your Tag Manager Adaptive Learning and DPDPA's Ban on Behavioural Monitoring of Children DPDPA for EdTech: Children's Data and Verifiable Parental Consent Verifiable Parental Consent Under DPDPA: A Practical Guide for EdTech DPDPA Exemptions for Schools and Educational Institutions DPDPA Questions Answered: Consent, Breach, Penalties, Sectors Account Aggregators and DPDPA: India's Working Model of Granular Consent Alternative Data Credit Scoring and DPDPA Purpose Limitation Fintech App Permissions Under DPDPA: Why Permission Is Not Consent DPDPA for Fintech and NBFCs: Speed Is Not a Consent Strategy Age Verification for Gaming Platforms Under DPDPA The Three-Year Erasure Rule for Online Gaming Platforms Player Telemetry, Behavioural Data and DPDPA DPDPA for Online Gaming Platforms DPDPA for Government Contractors and Vendors Returning and Deleting Citizen Data at the End of a Government Contract The State Exemption Under DPDPA Section 17(2)(a): What Vendors Must Know Production Data in Test Environments: A Hidden DPDPA Risk for Government Vendors Patient Consent Under DPDPA: Treatment Is Not a Blank Cheque DPDPA for Hospitals, Healthcare and Pharma Sharing Medical Reports on WhatsApp: The DPDPA Risk Hospitals Ignore Hotel CCTV and Guest Wi-Fi Under DPDPA Hotel Guest ID Copies and DPDPA: Collect What the Law Names Loyalty Programmes and Guest Profiling Under DPDPA DPDPA for Hotels, Travel and Hospitality Background Verification Vendors and DPDPA Candidate and Applicant Data Under DPDPA: Recruitment Is Not Employment Employee Monitoring and DPDPA: Where Necessity Ends DPDPA for HR, Employers and Staffing Firms Insurance Agents, Brokers and DPDPA: Governing the Distribution Chain Health Claims Data, TPAs and DPDPA Data Minimisation in Insurance Underwriting Under DPDPA DPDPA for Insurers, Brokers and TPAs DPDPA Penalties Explained: Up to ₹250 Crore and How the Board Decides Clinical Trial and Research Data Under DPDPA DPDPA Data Processors: Your Vendor's Breach Is Your Breach DPDPA Compliance: Why Resilience Beats Implementation DPDPA Vendor Questionnaires: How SaaS Companies Win Enterprise Procurement DPDPA for SaaS and IT Services: Processor or Fiduciary? Is Your SaaS Company a Data Processor or Data Fiduciary Under DPDPA? Sub-Processors Under DPDPA: Mapping the Chain Behind Your SaaS SIM KYC and Retailers: DPDPA Risk at the Edge of the Telecom Network Handling DPDPA Data Principal Rights at Telecom Scale Significant Data Fiduciary Readiness for Telecom Operators DPDPA for Telecom Operators and ISPs Seven DPDPA Mistakes That Start as Unclear Thinking