Seven DPDPA Mistakes That Start as Unclear Thinking
Seven DPDPA Mistakes That Start as Unclear Thinking
The first breach is never technical. It is a sentence nobody challenged.
The scene
'We don't really process personal data, we're B2B.' The room nodded. It was said by a company with forty thousand employee records, a CRM of named buyers, and a support line that recorded every call. The sentence cost nothing to say. It shaped eighteen months of decisions.
Where the thinking breaks
The unclear thought What it breaks The clearer thought
We're B2B, so DPDPA is light for us.
Ignores employees, contacts at clients, candidates and call recordings.
Every named person in your systems is a Data Principal.
Consent solves everything.
Consent can be withdrawn; processing built only on it collapses when it is.
Map each purpose to consent or a legitimate use under Section 7, and know which is which.
Our vendor is certified.
Certification is not a contract; under Section 8(1) the fiduciary stays responsible.
Certify, contract, audit, and rehearse the vendor's breach with them.
Keep everything, just in case.
Section 8(7) requires erasure when the purpose is served, unless law requires retention.
Every retained record should have a reason you could say aloud to the Board.
We'll wait and see how enforcement goes.
The first enforcement is somebody's; waiting makes it more likely to be yours.
Let others be the precedent.
Why thinking comes first
DPDPA is a principles law. It asks whether safeguards were reasonable, whether consent was free and specific, whether retention served a purpose. Each of those is a judgement. Unclear thinking produces unreasonable judgements that look reasonable on paper.
Monday morning
01 Write down the five sentences your leadership says most about privacy.
02 Test each against the Act. Keep the ones that survive.
03 Circulate the replacements. Language changes behaviour faster than policy.
Questions, answered plainly
Does DPDPA apply to B2B companies? +
Yes. DPDPA applies to digital personal data of any individual, including employees, job candidates, client contacts and vendor staff. A B2B business model does not remove those Data Principals from scope.
Is consent the only lawful basis under DPDPA? +
No. Section 7 sets out certain legitimate uses, including specified employment purposes, compliance with law and medical emergencies. Everything else generally needs consent that is free, specific, informed, unconditional and unambiguous.
Can a company keep personal data indefinitely under DPDPA? +
Generally no. Section 8(7) requires erasure once the specified purpose is no longer served, unless retention is necessary to comply with law. The Rules add fixed timelines for certain large platforms.
Argument 03 You cannot protect what you have not named. Read →
Argument 04 Consent is not a checkbox. It is a contract you have to prove. Read →
Argument 05 Silence after a breach is the most expensive sound. Read →
Tell us where your data sits. We'll show you where the exposure is.
A partner replies within one working day, with a first view on your penalty exposure.
Speak to a partner →
Under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: notice — Section 5 read with Rule 3; consent — Section 6, with Consent Managers under Rule 4; reasonable security safeguards — Section 8(5) and Rule 6; personal data breach intimation — Section 8(6) and Rule 7; erasure — Section 8(7) and Rule 8; children's data — Section 9 and Rule 10; Significant Data Fiduciaries — Section 10 and Rule 13; Data Principal rights — Sections 11 to 14 and Rule 14; transfer outside India — Section 16 and Rule 15; penalties — Section 33 and the Schedule. Published by AMLEGALS (Anandaday Misshra, Founder & Managing Partner).
