AMLEGALS — Strategic Lawyering

Clear Thinking on DPDPA: The Clarity Tree | DPDPA as Strategy

Clear Thinking on DPDPA: The Clarity Tree | DPDPA as Strategy

01 Know. Do we know what we hold?

02 Ask. Did we ask properly?

03 Guard. Would it hold under attack?

04 Tell. Could we speak within hours?

05 Let go. Do we let go on time?

Situation

The law is not new to your data. Your data is new to the law.

Complication

Most programmes were built to be finished. The Act was written to be tested.

Resolution

Think first. Then build only what survives the worst week.

First principles

Strip the Act to what cannot be reduced further.

Hover each assumption

Principle 01

Our data is our asset. The data is not yours. You hold it on trust.

Principle 02

More data is more value. Purpose is the boundary. Outside it, you have no right.

Principle 03

The vendor is responsible. Every hand that touches the data is your hand.

Principle 04

We will speak once we are sure. Silence is not a pause. It is a decision.

Principle 05

Keep it, just in case. Every permission expires. Plan for the day it does.

The clarity method

Five moves from a tangle to a tested programme.

{{ s.num }}

{{ s.name }}

{{ s.lineage }}

Move {{ cur.num }} · {{ cur.lineage }}

{{ cur.line }}

{{ cur.body }}

What you walk out with

{{ cur.output }}

The matrix

Not every gap deserves this quarter.

Plot every system by exposure and by readiness. The top-left square is where the budget goes first. Everything else waits its turn, in writing.

{{ dotInfo.kick }}

{{ dotInfo.name }}

{{ dotInfo.text }}

Act this quarter

Defend and evidence

Schedule it

Maintain

{{ d.name }}

← Low readiness Exposure ↑ · Illustrative estate High readiness →

Tell us where your data sits. We'll show you where the exposure is.

A partner replies within one working day, with a first view on your penalty exposure.

Speak to a partner →

Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).