Everything so far has answered “what does the law say”. This module answers a different question: what does it actually mean for the organisation you work at?
THREE STARTING QUESTIONS
1
What data do we hold?
Not what you assume — what an actual inventory would show, across every system and vendor.
2
On what basis?
For each category of data, is the lawful basis consent, or the legitimate use?
3
Could we prove it?
If the Board asked tomorrow, could you show your working — not just describe your intentions?
Most organisations can answer the first question in general terms and struggle badly with the third. That gap — between what you believe you’re doing and what you could actually demonstrate — is where DPDP risk concentrates.
The DPDP Act doesn’t just ask organisations to behave well. It asks them to be able to prove it.
SOURCES The DPDP Act, 2023 — official text, MeitY — https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf