Resources
Learn DPDP Compliance.
What Is the DPDP Act, 2023
With the backstory covered, it’s time to meet the Act itself —...
Why Personal Data Became a Governance Issue in India
Ten years ago, nobody made laws about what happens to your personal...
Why the DPDP Act Needed a Separate Set of Rules
The Act was passed in August 2023. The Rules that actually explain...
From Legislation to Implementation: What the DPDP Act Means for Your Organisation
Everything so far has answered “what does the law say”. This module...
Writing a Notice People Actually Understand
Every consent request under the DPDP Act has to be paired with...
Privacy by Design: Building It In, Not Bolting It On
Everything so far has been about meeting the DPDP Act’s requirements. This...
India’s Digital Economy: The Story Behind the Law
By the time the DPDP Act arrived in 2023, India was already...
Learning from the World: Global Privacy Developments That Shaped India’s Approach
India wasn’t writing its privacy law in isolation. By 2023, most of...
Before the DPDP Act: India’s Data Protection Gap
For over a decade, narrow provisions of the IT Act and SPDI...
What Digital Trust Means — and Why the Government Is Building It
You’ve now seen why personal data needed protecting, how big India’s digital...
Who Does the DPDP Act Apply To?
It’s an Indian law, so it’s only for Indian companies” is one...
The People and Roles Behind the Act
Five terms do almost all the work in the DPDP Act. Once...
What Counts as Lawful Processing
Before an organisation can touch your personal data at all, the Act...
Consent: The Default Basis for Processing
Consent is the door most organisations walk through most often. The Act...
Legitimate Uses: When Consent Isn’t Required
Door two. Section 7 lists nine specific situations where an organisation can...
The Rights Every Data Principal Has
As a Data Principal, the Act gives you four specific rights over...
What the Act Expects of a Data Fiduciary
If Data Principals get rights, Data Fiduciaries get the matching list of...
Accountability Under the Act: Who Answers for What
The Act is deliberately one-sided about who’s on the hook when something...
Penalties Under the DPDP Act: What Non-Compliance Costs
The number that gets quoted most about the DPDP Act is its...
How the DPDP Rules Turn the Act into Day-to-Day Practice
On 13 November 2025, MeitY notified the DPDP Rules — the moment...
What Changes for Organisations Under the DPDP Rules
Three specific changes from the Rules are worth knowing before anything else,...
What “Implementation-Ready” Looks Like
The Rules don’t take effect all at once. They roll out in...
Where Organisations Commonly Get the Rules Wrong
A few assumptions come up again and again as organisations start preparing...
The Core Responsibilities Every Business Now Carries
Whatever your size or sector, if you process personal data, a common...
Turning Obligations into Operations
A policy document that says the right things and a business that...
What Governance Looks Like Under the DPDP Act
“Governance” gets used loosely in compliance conversations. Under the DPDP Act, it...
Building a Privacy Operations Function
The organisations that handle the DPDP Act best tend to treat privacy...
Is Your Organisation DPDP-Ready?
Before moving into the practical fundamentals, here’s a short, honest self-check.1. Could...
Consent in Practice: Collection, Renewal and Withdrawal
Giving consent is only the first moment in a much longer relationship...
Purpose Limitation: Using Data Only for What You Said
Purpose limitation sounds abstract until you see it applied to a real...
Data Principal Rights in Practice: Access, Correction and Erasure
Here’s what actually needs to happen when someone exercises one. WHAT A...
Grievance Redressal: What Every Data Fiduciary Must Provide
When something goes wrong with how your data was handled, the Act...
Processing Children’s Data: Consent and Safeguards
The Act treats anyone under 18 as a child, and sets a...
Working with Data Processors: Roles and Responsibilities
Almost every organisation uses vendors that touch personal data — cloud hosting,...
Security Safeguards Every Data Fiduciary Should Know
“Reasonable security safeguards” is the single phrase tied to the Act’s highest...
Recordkeeping and Evidence: Building Your Audit Trail
Accountability under the DPDP Act isn’t just about doing the right thing...
Everyday Governance: Making Compliance Routine, Not Reactive
This covers nine specific fundamentals — notices, consent, purpose, rights, grievances, children,...
Digital Trust as a Business Advantage
Digital trust as the reason the DPDP Act exists at all. Here,...
Building a Culture Around Data Governance
Policies and processes only hold up if the people following them actually...
Understanding Consent Architecture
Consent, treated seriously, isn’t a single checkbox on a signup form. In...
Responsible Data Use Beyond the Letter of the Law
The DPDP Act sets a legal floor. Responsible data use is a...
Measuring Your Organisation’s Privacy Maturity
This closes the Learn journey. Before moving deeper, here’s a way to...