# AIZZENTEC — Full Extractable Corpus > Machine-readable restatement of content published on https://aizzentec.com/. Every answer below is self-contained and safe to quote in isolation. Source: AIZZENTEC ORION PRIVATE LIMITED, India. Last updated 2026-09-02. > This file is generated at build time from the site's own content. The topical corpus is authored; the index below it is derived, so it lists every page that exists and nothing that does not. --- ## About AIZZENTEC **What is AIZZENTEC?** AIZZENTEC is an India-based cybersecurity and privacy advisory delivering end-to-end DPDP readiness, built from real implementation experience inside Indian banks, fintechs, healthcare platforms and SaaS firms. The legal entity is AIZZENTEC ORION PRIVATE LIMITED. It publishes a free public DPDP hub at aizzentec.com alongside paid advisory engagements. **Who does AIZZENTEC serve?** Indian organisations subject to the Digital Personal Data Protection Act, 2023 — and foreign organisations processing the digital personal data of people in India. AIZZENTEC has worked with 150+ businesses across BFSI, fintech, healthcare, e-commerce, SaaS, gaming, EdTech and government. **What makes AIZZENTEC different from a policy-pack vendor?** Privacy obligations are converted into named owners, workflows, evidence and security controls that product and engineering teams can actually execute — not beautifully formatted documents that look great in audits and do very little when something goes wrong. Teams come in asking about DPDP and leave with consent, vendor risk, access control, logging and breach response connected as one programme. **What credentials does AIZZENTEC hold?** AIZZENTEC is authorised to perform HITRUST assessments — recognised assurance for security and privacy. Its practice leadership includes Chartered Accountants holding CISA, CEH, CDPSE and CFE certifications, with 15+ years of risk, cyber and analytics experience including at Grant Thornton, advising listed companies, family businesses and privately held firms. **How do I contact AIZZENTEC?** All enquiries, including DPDP, data protection and legal: Contact@aizzentec.com. Phone and WhatsApp: +91 8220 359 506. The team replies within one business day, typically faster. --- ## DPDP Act — scope and applicability **Does the DPDP Act apply to my business?** If you process the digital personal data of anyone in India — or offer goods or services to people in India from abroad — yes. There is no employee, revenue or data-volume threshold for baseline applicability under Section 3. **Does the DPDP Act apply to companies outside India?** Yes. Section 3(b) gives the Act extraterritorial reach: processing outside India is covered where it is connected to offering goods or services to Data Principals in India. A foreign SaaS company with Indian users is in scope, whether based in San Francisco or Singapore. **What does the DPDP Act not cover?** The Act applies to digital personal data only. It excludes personal or domestic use, and data made publicly available by the Data Principal herself or by anyone under a legal obligation to publish it. **Why does the DPDP Act exist?** The watershed moment was August 2017. A nine-judge constitutional bench of the Supreme Court, in Justice K.S. Puttaswamy (Retd.) v. Union of India, held unanimously that the right to privacy is a fundamental right protected by Article 21. That created a constitutional obligation on the State to enact a comprehensive data protection law. --- ## DPDP Act — timeline and enforcement **When do I actually have to comply with the DPDP Act?** The Rules were notified on 13 November 2025. Phase 1 procedural provisions are in force now. The Consent Manager framework is expected around November 2026. The substantive obligations crystallise on 13 May 2027. Most readiness programmes take 9–12 months, so the time to start is now. **What is the DPDP compliance deadline?** 13 May 2027 is the date substantive obligations become fully enforceable: notice and consent (Sections 5–6), legitimate uses (Section 7), Data Fiduciary duties (Section 8), children's data (Section 9), Significant Data Fiduciary obligations (Section 10), Data Principal rights (Sections 11–14), and the full Schedule of Penalties. **What is the full DPDP timeline?** August 2023: the DPDP Act, 2023 receives Presidential assent as Act No. 22 of 2023. 13 November 2025: MeitY notifies the DPDP Rules, 2025 via G.S.R. 846(E) — 22 Rules and 7 Schedules — and Phase 1 procedural provisions commence. ~November 2026: Phase 2, the Consent Manager framework. 13 May 2027: Phase 3, full enforcement. **Why is the 9-month runway to May 2027 the critical window?** Organisations that wait until May 2027 will find nine months barely enough — particularly for data discovery, consent re-engineering, vendor renegotiation and notice translation. RoPA, a DSAR portal, vendor remediation and security uplift are each 9–12 month efforts. --- ## DPDP Act — penalties **What are the penalties under the DPDP Act?** Civil penalties only — there are no criminal sanctions. Up to ₹250 crore for failure to take reasonable security safeguards, ₹200 crore for breach-notification or children's-data failures, ₹150 crore for Significant Data Fiduciary lapses, and ₹50 crore for any other contravention. Penalties apply per contravention and can cumulate. **Who imposes DPDP penalties?** The Data Protection Board of India (DPBI) imposes penalties under Section 33, read with the Schedule. Orders of the DPBI are appealable to the TDSAT within 60 days, with further appeals to the Supreme Court. **Can a data processor be penalised directly under the DPDP Act?** No. Data processors cannot be directly penalised by the DPBI. The Data Fiduciary remains liable for processor failures under Section 8(2), which is what makes vendor governance a critical compliance domain rather than a procurement formality. --- ## DPDP Act — lawful basis and consent **Do I need consent for everything under the DPDP Act?** No. The Act recognises two grounds — consent under Section 6, and the closed-list "legitimate uses" in Section 7 such as voluntary provision, legal compliance and employment. There is no broad "legitimate interests" basis like the GDPR's. **What makes consent valid under the DPDP Act?** Under Section 6, consent must be free, specific, informed, unconditional and unambiguous, signified through clear affirmative action — and withdrawable at any time with the same ease it was given. Every request must be accompanied by a Section 5 notice describing the data, purpose, withdrawal and rights mechanics. **What must a DPDP privacy notice contain?** A clear, itemised notice in plain language at or before collection: the data collected, the purposes, how to withdraw consent, how to exercise rights, and how to complain to the Data Protection Board. Section 5(3) requires it in English plus the 22 Eighth Schedule languages, with parity of content. **What is the most common consent mistake under DPDP?** Building consent capture but not withdrawal. Section 6(4) requires withdrawing consent to be exactly as easy as giving it. Most organisations bury the withdrawal link three menus deep. That asymmetry alone is an enforcement trigger — regulators check it first. **Is a single "I accept the privacy policy" checkbox enough?** No. Each purpose needs its own consent. A single checkbox covering account creation, marketing, behavioural analytics, third-party sharing and cookie-based tracking will not survive Section 6 scrutiny. Consent must be granular, purpose-specific and freely revocable. --- ## DPDP Act — Data Principal rights **What rights do Data Principals have under the DPDP Act?** Chapter III confers four substantive rights on every Data Principal, exercisable against any Data Fiduciary processing her data: access to information about processing, correction and erasure, grievance redressal, and nomination. The Rules require a response within ninety days of receipt. **How long do I have to respond to a DSAR under DPDP?** Ninety days from receipt of the request, as required by the Rules. Note this is a different standard from the GDPR's one-month default, and applies to the full intake-to-fulfilment workflow including identity verification and system discovery. --- ## DPDP Act — Data Fiduciary obligations **What are the general obligations of a Data Fiduciary?** Section 8 requires accuracy, reasonable security safeguards, breach notification, storage limitation and erasure, and a grievance mechanism. Section 8(2) makes the Fiduciary liable for its processors — vendor failures are the Fiduciary's failures. **What security safeguards does the DPDP require?** Rule 6 sets the baseline: encryption, access control, multi-factor authentication, security logging retained for one year, backups, personnel training, and contractual safeguards flowed down to vendors. Failure here carries the highest penalty ceiling in the Schedule at ₹250 crore. **What is the DPDP breach notification timeline?** Rule 7 codifies a two-track intimation: to the Data Protection Board of India with prescribed contents, and to affected Data Principals as soon as feasible. The standard is "without delay" — likely hours, not days. It is not 72 hours; the 72-hour figure is GDPR. **How does DPDP breach notification interact with CERT-In?** They run in parallel and both clocks start from awareness. CERT-In requires reporting within 6 hours under the IT Act, 2000 regime; DPDP requires intimation "without delay"; RBI, IRDAI and SEBI impose their own sectoral timelines. Without an integrated playbook, contradictory disclosures are the norm. **What are the DPDP data retention defaults?** Erase personal data when consent is withdrawn or the purpose is no longer served. The Third Schedule sets three-year defaults from last activity for high-volume e-commerce, social-media and online-gaming entities, with 48-hour pre-erasure intimation to the Data Principal. --- ## DPDP Act — Significant Data Fiduciaries **Are we a Significant Data Fiduciary?** The Government will notify SDFs based on volume of data, sensitivity, sectoral exposure, risk to Data Principals, sovereignty, electoral democracy and use of emerging technology. Use the SDF Classifier at aizzentec.com/tools to gauge likelihood — if you are near the line, plan for the Rule 13 obligations now. **What must a Significant Data Fiduciary do?** Rule 13 obligations: appoint a Data Protection Officer based in India who reports to the Board, engage an independent data auditor, conduct annual Data Protection Impact Assessments and independent audits, and undertake periodic risk assessment. These are the most consequential pending notifications under the Act. **Who is likely to be designated an SDF?** Large fintech, e-commerce, social-media and gaming entities, and organisations processing large volumes of children's or sensitive data. Volume, sensitivity, sectoral and sovereign-interest factors push BFSI firms toward classification — they should build Rule 13 obligations in from day one. --- ## DPDP Act — children's data **We have under-18 users. What changes?** Section 9 requires verifiable parental consent before processing children's data, and prohibits tracking, behavioural monitoring and targeted advertising of children — absolutely, with no consent override. Self-declared age gates are not enough. **What counts as verifiable parental consent under Rule 10?** Rule 10 requires identity-verified parental consent before processing a child's data, plus verification that the consenting adult is in fact the parent or guardian. Workable architectures use DigiLocker, Aadhaar offline verification, or hybrid approaches. Self-declared age gates do not meet this bar. **Does Section 9 apply if only a minority of my users are children?** Yes. If any part of your platform can be accessed by a user under 18, Section 9 applies to that population. Health and fitness apps typically have adult majorities with a meaningful minority of parents using the app on behalf of children — the verifiable parental consent flow is still required. --- ## DPDP Act — cross-border transfer **Can we transfer personal data outside India?** Yes by default. Section 16 permits cross-border transfer except to countries the Government may restrict by notification — and none had been restricted as of May 2026. Sectoral rules from RBI and IRDAI may impose stricter localisation for specific data classes. --- ## DPDP versus GDPR and the SPDI Rules **How does the DPDP Act differ from the GDPR?** The DPDP Act recognises two lawful grounds — consent, or a closed-list legitimate use under Section 7 — against the GDPR's six lawful bases. There is no "legitimate interests" basis under DPDP. Breach notification is "without delay" rather than 72 hours, and DSAR response is 90 days rather than one month. **We already comply with the GDPR. Are we DPDP compliant?** Partly. The familiar parts are notice, security safeguards and rights fulfilment. The novel parts are the absence of a legitimate-interests basis, the Section 5(3) multilingual notice requirement, the verifiable parental consent standard, the Consent Manager ecosystem, and processor non-liability that concentrates risk on the Fiduciary. **Does DPDP replace the SPDI Rules?** The DPDP Act is India's comprehensive data protection statute and supersedes the narrower SPDI Rules framework for digital personal data. Organisations aligned only to SPDI will find DPDP substantially more demanding on consent architecture, breach response and vendor governance. --- ## Sector-specific guidance **How does DPDP affect banks and BFSI?** Banks, insurers and capital-market entities sit under RBI, IRDAI and SEBI — DPDP overlays all three. The sharpest conflict is retention: Section 12 of the PMLA requires 5-year retention from the end of the customer relationship, which overrides DPDP erasure for KYC records. Breach reporting runs concurrent CERT-In, RBI and DPDP clocks. **How does DPDP affect fintech?** Lending, payments and Account Aggregator flows layer DPDP consent on top of RBI digital-lending and PCI obligations. FLDG, Key Fact Statement, cooling-off, data minimisation and processor responsibility are already DPDP-aligned in spirit. The common failure is collecting on consent what could ride on a Section 7 legitimate use, creating brittle architectures that break on withdrawal. **How does DPDP affect healthcare?** Clinical retention rules and the ABDM consent regime collide with DPDP at almost every point. Sensitive health data typically sits across fragmented EMRs with no inventory, paper consent at intake, no digital withdrawal trail, and data shared with insurers, labs and research without Data Processing Agreements. **How does DPDP affect B2B SaaS?** The average B2B SaaS company has 30–80 sub-processors across cloud, analytics and communications. Flow-down and inventory are the long pole in the programme. A foreign SaaS with Indian users is in scope under Section 3(b) regardless of where it is incorporated. **How does DPDP affect EdTech?** Section 9 is the binding constraint. Self-declared age gates will not survive enforcement, and the ban on behavioural tracking and targeted advertising to children is absolute with no consent override. Building a real verification stack — DigiLocker, Aadhaar offline, or hybrid — is significant engineering work. --- ## Implementation **How long does a DPDP compliance programme take?** Most readiness programmes take 9–12 months. Data discovery, consent re-engineering, vendor renegotiation and notice translation into the Eighth Schedule languages are the long-pole activities. With Phase 3 enforcement on 13 May 2027, programmes should start no later than Q1 FY26. **What are the seven DPDP workstreams?** Notice and consent re-engineering; Data Principal rights and DSAR fulfilment; security safeguards under Rule 6; breach response; vendor and processor governance; children's data; and governance, DPO ownership and board reporting. AIZZENTEC's 28-question readiness assessment scores an organisation across all seven. **What are the most common DPDP implementation mistakes?** Treating it as a privacy-policy update rather than operational change; confusing lawful basis with consent and over-consenting data that Section 7 already permits; building consent capture but not withdrawal; ignoring Section 9 where any user could be under 18; and leaving DPDP as a legal-team problem instead of an engineering and product one. **Who owns DPDP inside an organisation?** DPDP fails when accountability is fuzzy. The board owns tone from the top, risk appetite, resourcing and quarterly exposure review. Legal owns the framework, policies, notice and consent design, vendor contracts and DPBI liaison. Engineering owns consent infrastructure, the DSAR platform, erasure pipelines and privacy-by-design in the SDLC. Marketing owns consent capture in customer journeys, martech audit and suppression lists. HR owns employee data flows and Section 7(i) scope. --- ## AIZZENTEC services **What advisory services does AIZZENTEC offer?** Ten engagements: DPDP Readiness Assessment, Data Protection Impact Assessments, Vendor DPA Roll-out, Breach Tabletop & Runbook, Fractional DPO, Custom Training & Workshops, Compliance Timeline & Regulatory Readiness, Consent Management Implementation, Data Principal Rights Implementation, and RoPA & Data Discovery. **What is a DPDP Readiness Assessment?** A structured, evidence-based assessment of current posture across all seven workstreams, producing a prioritised, sequenced 12-month roadmap. The deliverable is a gap register with effort, cost and dependency mapping — a plan that can move straight into implementation. **What is AIZZENTEC's Fractional DPO service?** A named Data Protection Officer meeting the Section 10(2)(a) requirements, with monthly programme review and a quarterly board pack — without a full-time hire. Designed for Significant Data Fiduciaries without an internal DPO and for mid-stage organisations building the function. **What DPDP training does AIZZENTEC deliver?** Four tiers. A 90-minute board and executive briefing on strategic, financial and reputational implications. A 90-minute all-employee awareness programme designed for 1,000+ learners at a time. A two-day practitioner intensive with workshops and real templates. And 2–5 day specialist bootcamps covering DPIA, breach response command, children's data, cross-border transfer, SDF readiness, and vendor and DPA negotiation. **Does AIZZENTEC offer free DPDP tools?** Yes. A penalty exposure estimator, SDF classifier, cross-border transfer explorer, Consent Manager integration checker, DPIA requirement checker, a compliance readiness checklist, and 16 production-grade templates — all free, at aizzentec.com/tools. The 28-question readiness assessment runs entirely in the browser. **What DPDP templates does AIZZENTEC publish?** Sixteen, including: a privacy notice compliant with Sections 5, 6 and 8 and Rules 3 and 14; a cookie notice with granular consent categories; a consent UX specification with wireframes and audit trail; RoPA; a Data Processing Agreement; a vendor due-diligence questionnaire; a DPIA with necessity and proportionality tests; a DPO job description with seven weighted KRAs aligned to Section 10(2)(a); a verifiable parental consent workflow; a five-phase breach response runbook with RACI matrix; a Rule 6 security safeguards checklist; and a quarterly board privacy risk report. --- ## Disclaimer This hub provides general information about the DPDP Act, 2023 and the DPDP Rules, 2025. It is not legal advice and does not create an advisor–client relationship. For a specific situation, seek professional advice. Calculators, checklists and templates are starting points to be adapted to your context and reviewed by qualified professionals. **Attribution**: AIZZENTEC — https://aizzentec.com --- ## Site index — pages Every indexable English page, with its canonical URL. Localized editions exist at /{code}/… for 17 further languages; see sitemap.xml. - **DPDP Compliance Consultants India | AIZZENTEC, Chennai** — https://aizzentec.com/ Aizzentec helps Indian businesses achieve DPDP compliance: readiness assessment, implementation, training and free tools. Chennai-based, serving India-wide. - **Products — Bhairava AI SOC and EKA learning platform** — https://aizzentec.com/products Products from the Aizzentec group: Bhairava, a governed AI SOC and NOC platform, and EKA, a unified learning, examination and assessment platform. - **DPDP Act 2023 Explained: Rules, Obligations, Penalties** — https://aizzentec.com/dpdp-101 A practitioner's guide to India's Digital Personal Data Protection Act 2023 and DPDP Rules 2025: who it applies to, key obligations, penalties and deadlines. - **DPDP Act 2023 Full Text, Rules and Schedules | Annotated** — https://aizzentec.com/act-rules Full text of the DPDP Act 2023, DPDP Rules 2025 and Schedules, searchable section by section with plain-English practitioner commentary on each provision. - **Data Principal Rights Under the DPDP Act | Submit a Request** — https://aizzentec.com/rights Your rights under the DPDP Act 2023: access, correction, erasure, grievance redressal and nomination. Submit a request here; we respond within 90 days. - **DPDP Implementation Roadmap: 9-Month Plan to May 2027** — https://aizzentec.com/implementation Step-by-step DPDP implementation roadmap for Indian organisations: workstreams, role playbooks and a sequenced plan to reach compliance before 13 May 2027. - **DPDP Tools: Penalty Calculator, SDF Classifier, Templates** — https://aizzentec.com/tools Free DPDP tools built by practitioners: penalty calculator, Significant Data Fiduciary classifier, decision trees, checkers and 16 ready-to-use templates. - **DPDP Penalty Calculator: Estimate Your Exposure | Free Tool** — https://aizzentec.com/tools/penalty-estimator Free DPDP penalty calculator. Estimate maximum civil penalty exposure under the Schedule to the DPDP Act 2023, contravention by contravention, in your browser. - **Significant Data Fiduciary Classifier | DPDP SDF Test** — https://aizzentec.com/tools/sdf-classifier Free Significant Data Fiduciary classifier. Seven questions based on Section 10(1) of the DPDP Act gauge whether your organisation is likely to be an SDF. - **DPDP Readiness Assessment: Free 28-Question Self-Check** — https://aizzentec.com/assessment Free DPDP readiness assessment. 28 questions across seven workstreams give a scored readiness profile and prioritised next steps. Runs in your browser. - **DPDP Compliance by Industry: BFSI, Fintech, Health, SaaS** — https://aizzentec.com/sectors Sector-specific DPDP compliance playbooks for BFSI, fintech, healthcare, e-commerce, SaaS and more: friction points, retention conflicts and regulator overlaps. - **DPDP Knowledge Hub: Practitioner Guides and Deep-Dives** — https://aizzentec.com/knowledge Practitioner-authored DPDP guides on consent UX, breach response playbooks, vendor remediation, SDF classification and the questions clients ask most often. - **DPDP Regulatory Updates and Notifications Tracker 2026** — https://aizzentec.com/updates Live tracker of DPDP Act developments: MeitY notifications, draft rules, Data Protection Board enforcement signals and what each one means for your compliance. - **DPDP Compliance Services: Assessment to Implementation** — https://aizzentec.com/services DPDP advisory from readiness assessment to an operating compliance programme: gap analysis, implementation, and a virtual DPO. Serving all of India. - **DPDP Training Programmes for Boards, DPOs and Engineers** — https://aizzentec.com/training Role-specific DPDP Act training: board briefings, DPO workshops, engineering bootcamps and front-line awareness. Four tiers mapped to who needs what depth. - **DPDPA Certificate Course: 6-Module DPDP Certification** — https://aizzentec.com/dpdpa-certificate-course Get certified on India's DPDP Act 2023. A structured 6-module DPDPA certificate course covering legal foundations, practical compliance and AI governance. - **DPDP vs GDPR: Key Differences Explained (2026) | AIZZENTEC** — https://aizzentec.com/dpdp-vs-gdpr DPDP Act vs GDPR compared: scope, consent, lawful bases, rights, breach rules, penalties and timelines. A glossary-style guide for Indian and global businesses. - **Data Fiduciary vs Data Processor: DPDP Act Explained** — https://aizzentec.com/data-fiduciary-vs-data-processor Data Fiduciary vs Data Processor under India's DPDP Act 2023: definitions, obligations, liability, contract clauses and a 5-question test to classify your role. - **What Is a Consent Manager? DPDP Act Explained | AIZZENTEC** — https://aizzentec.com/what-is-a-consent-manager-dpdp Consent Manager under India's DPDP Act 2023: definition, who can register, INR 2 crore net worth rule, obligations, how it works, and how it differs from a CMP. - **Significant Data Fiduciary Explained: DPDP Act Guide** — https://aizzentec.com/significant-data-fiduciary-explained Significant Data Fiduciary under the DPDP Act 2023: designation criteria, DPO, audit, DPIA and algorithmic due diligence, penalties and a readiness roadmap. - **DPDP Act vs IT Act SPDI Rules: Key Changes | AIZZENTEC** — https://aizzentec.com/dpdp-act-vs-it-act-spdi-rules DPDP Act 2023 vs IT Act SPDI Rules 2011 compared: scope, consent, security, breach reporting, penalties and what carries over. Includes a migration checklist. - **About Aizzentec: DPDP and Cybersecurity Advisory, Chennai** — https://aizzentec.com/about Aizzentec is a Chennai-based privacy and cybersecurity advisory delivering end-to-end DPDP readiness, built from implementation experience inside Indian firms. - **Privacy Notice | AIZZENTEC** — https://aizzentec.com/privacy How AIZZENTEC collects, uses, shares and protects your personal data — written to meet Section 5 of the DPDP Act and Rule 3 of the DPDP Rules, 2025. - **DPDP Act Blog: Compliance Guides and Analysis | AIZZENTEC** — https://aizzentec.com/blog Practitioner guides to the DPDP Act: cross-border transfers, breach response, penalties, sector playbooks for banking, health and retail, and the 2027 runway. - **Cookie Policy | AIZZENTEC** — https://aizzentec.com/cookie-policy What aizzentec.com stores on your device and why: five first-party browser-storage entries, no cookies of our own, and Google Analytics only after you opt in. - **Terms of Use | AIZZENTEC** — https://aizzentec.com/terms The terms on which AIZZENTEC makes this DPDP hub and its resources available to you. Information, not legal advice. - **Section 1 DPDP Act: Short title and commencement | AIZZENTEC** — https://aizzentec.com/act-rules/section-1 Section 1 of the DPDP Act 2023: Short title and commencement. The full text as notified, with what it asks of an organisation in practice. - **Section 2 DPDP Act: Definitions | AIZZENTEC** — https://aizzentec.com/act-rules/section-2 Section 2 of the DPDP Act 2023: Definitions. The full text as notified, with what it asks of an organisation in practice. - **Section 3 DPDP Act: Application of Act | AIZZENTEC** — https://aizzentec.com/act-rules/section-3 Section 3 of the DPDP Act 2023: Application of Act. The full text as notified, with what it asks of an organisation in practice. - **Section 4 DPDP Act: Grounds for processing personal data** — https://aizzentec.com/act-rules/section-4 Section 4 of the DPDP Act 2023: Grounds for processing personal data. The full text as notified, with what it asks of an organisation in practice. - **Section 5 DPDP Act: Notice | AIZZENTEC** — https://aizzentec.com/act-rules/section-5 Section 5 of the DPDP Act 2023: Notice. The full text as notified, with its sub-sections and illustrations, and what it asks of an organisation in practice. - **Section 6 DPDP Act: Consent | AIZZENTEC** — https://aizzentec.com/act-rules/section-6 Section 6 of the DPDP Act 2023: Consent. The full text as notified, with its sub-sections and illustrations, and what it asks of an organisation in practice. - **Section 7 DPDP Act: Certain legitimate uses | AIZZENTEC** — https://aizzentec.com/act-rules/section-7 Section 7 of the DPDP Act 2023: Certain legitimate uses. The full text as notified, with what it asks of an organisation in practice. - **Section 8 DPDP Act: General obligations of Data Fiduciary** — https://aizzentec.com/act-rules/section-8 Section 8 of the DPDP Act 2023: General obligations of Data Fiduciary. The full text as notified, with what it asks of an organisation in practice. - **Section 9 DPDP Act: Processing of personal data of children** — https://aizzentec.com/act-rules/section-9 Section 9 of the DPDP Act 2023: Processing of personal data of children. The full text as notified, with what it asks of an organisation in practice. - **Section 10 DPDP Act: Significant Data Fiduciary duties** — https://aizzentec.com/act-rules/section-10 Section 10 of the DPDP Act 2023: Additional obligations of Significant Data Fiduciary. The full text as notified. - **Section 11 DPDP Act: Right to access personal data** — https://aizzentec.com/act-rules/section-11 Section 11 of the DPDP Act 2023: Right to access information about personal data. The full text as notified, with what it asks of an organisation in practice. - **Section 12 DPDP Act: Right to correction and erasure** — https://aizzentec.com/act-rules/section-12 Section 12 of the DPDP Act 2023: Right to correction and erasure of personal data. The full text as notified, with what it asks of an organisation in practice. - **Section 13 DPDP Act: Right of grievance redressal** — https://aizzentec.com/act-rules/section-13 Section 13 of the DPDP Act 2023: Right of grievance redressal. The full text as notified, with what it asks of an organisation in practice. - **Section 14 DPDP Act: Right to nominate | AIZZENTEC** — https://aizzentec.com/act-rules/section-14 Section 14 of the DPDP Act 2023: Right to nominate. The full text as notified, with what it asks of an organisation in practice. - **Section 15 DPDP Act: Duties of Data Principal | AIZZENTEC** — https://aizzentec.com/act-rules/section-15 Section 15 of the DPDP Act 2023: Duties of Data Principal. The full text as notified, with what it asks of an organisation in practice. - **Section 16 DPDP Act: Personal data processed outside India** — https://aizzentec.com/act-rules/section-16 Section 16 of the DPDP Act 2023: Processing of personal data outside India. The full text as notified, with what it asks of an organisation in practice. - **Section 17 DPDP Act: Exemptions | AIZZENTEC** — https://aizzentec.com/act-rules/section-17 Section 17 of the DPDP Act 2023: Exemptions. The full text as notified, with what it asks of an organisation in practice. - **Section 18 DPDP Act: Establishment of Board | AIZZENTEC** — https://aizzentec.com/act-rules/section-18 Section 18 of the DPDP Act 2023: Establishment of Board. The full text as notified, with what it asks of an organisation in practice. - **Section 19 DPDP Act: Composition of the Board | AIZZENTEC** — https://aizzentec.com/act-rules/section-19 Section 19 of the DPDP Act 2023: Composition of the Board. The full text as notified, with what it asks of an organisation in practice. - **Section 20 DPDP Act: Salary, allowances and term of office** — https://aizzentec.com/act-rules/section-20 Section 20 of the DPDP Act 2023: Salary, allowances payable to and term of office. The full text as notified, with what it asks of an organisation in practice. - **Section 21 DPDP Act: Disqualifications for Board members** — https://aizzentec.com/act-rules/section-21 Section 21 of the DPDP Act 2023: Disqualifications for Board members. The full text as notified, with what it asks of an organisation in practice. - **Section 22 DPDP Act: Resignation and filling of vacancy** — https://aizzentec.com/act-rules/section-22 Section 22 of the DPDP Act 2023: Resignation by Members and filling of vacancy. The full text as notified, with what it asks of an organisation in practice. - **Section 23 DPDP Act: Proceedings of Board | AIZZENTEC** — https://aizzentec.com/act-rules/section-23 Section 23 of the DPDP Act 2023: Proceedings of Board. The full text as notified, with what it asks of an organisation in practice. - **Section 24 DPDP Act: Officers and employees of Board** — https://aizzentec.com/act-rules/section-24 Section 24 of the DPDP Act 2023: Officers and employees of Board. The full text as notified, with what it asks of an organisation in practice. - **Section 25 DPDP Act: Members and officers as public servants** — https://aizzentec.com/act-rules/section-25 Section 25 of the DPDP Act 2023: Members and officers to be public servants. The full text as notified, with what it asks of an organisation in practice. - **Section 26 DPDP Act: Powers of Chairperson | AIZZENTEC** — https://aizzentec.com/act-rules/section-26 Section 26 of the DPDP Act 2023: Powers of Chairperson. The full text as notified, with what it asks of an organisation in practice. - **Section 27 DPDP Act: Powers and functions of Board** — https://aizzentec.com/act-rules/section-27 Section 27 of the DPDP Act 2023: Powers and functions of Board. The full text as notified, with what it asks of an organisation in practice. - **Section 28 DPDP Act: Procedure to be followed by Board** — https://aizzentec.com/act-rules/section-28 Section 28 of the DPDP Act 2023: Procedure to be followed by Board. The full text as notified, with what it asks of an organisation in practice. - **Section 29 DPDP Act: Appeal to Appellate Tribunal** — https://aizzentec.com/act-rules/section-29 Section 29 of the DPDP Act 2023: Appeal to Appellate Tribunal. The full text as notified, with what it asks of an organisation in practice. - **Section 30 DPDP Act: Tribunal orders executable as a decree** — https://aizzentec.com/act-rules/section-30 Section 30 of the DPDP Act 2023: Tribunal orders executable as a decree. The full text as notified, with what it asks of an organisation in practice. - **Section 31 DPDP Act: Alternate dispute resolution** — https://aizzentec.com/act-rules/section-31 Section 31 of the DPDP Act 2023: Alternate dispute resolution. The full text as notified, with what it asks of an organisation in practice. - **Section 32 DPDP Act: Voluntary undertaking | AIZZENTEC** — https://aizzentec.com/act-rules/section-32 Section 32 of the DPDP Act 2023: Voluntary undertaking. The full text as notified, with what it asks of an organisation in practice. - **Section 33 DPDP Act: Penalties | AIZZENTEC** — https://aizzentec.com/act-rules/section-33 Section 33 of the DPDP Act 2023: Penalties. The full text as notified, with its sub-sections and illustrations, and what it asks of an organisation in practice. - **Section 34 DPDP Act: Penalties credited to Consolidated Fund** — https://aizzentec.com/act-rules/section-34 Section 34 of the DPDP Act 2023: Penalties credited to Consolidated Fund. The full text as notified, with what it asks of an organisation in practice. - **Section 35 DPDP Act: Protection of action in good faith** — https://aizzentec.com/act-rules/section-35 Section 35 of the DPDP Act 2023: Protection of action taken in good faith. The full text as notified, with what it asks of an organisation in practice. - **Section 36 DPDP Act: Power to call for information** — https://aizzentec.com/act-rules/section-36 Section 36 of the DPDP Act 2023: Power to call for information. The full text as notified, with what it asks of an organisation in practice. - **Section 37 DPDP Act: Government power to issue directions** — https://aizzentec.com/act-rules/section-37 Section 37 of the DPDP Act 2023: Power of Central Government to issue directions. The full text as notified, with what it asks of an organisation in practice. - **Section 38 DPDP Act: Consistency with other laws | AIZZENTEC** — https://aizzentec.com/act-rules/section-38 Section 38 of the DPDP Act 2023: Consistency with other laws. The full text as notified, with what it asks of an organisation in practice. - **Section 39 DPDP Act: Bar of jurisdiction | AIZZENTEC** — https://aizzentec.com/act-rules/section-39 Section 39 of the DPDP Act 2023: Bar of jurisdiction. The full text as notified, with what it asks of an organisation in practice. - **Section 40 DPDP Act: Power to make rules | AIZZENTEC** — https://aizzentec.com/act-rules/section-40 Section 40 of the DPDP Act 2023: Power to make rules. The full text as notified, with what it asks of an organisation in practice. - **Section 41 DPDP Act: Laying of rules and notifications** — https://aizzentec.com/act-rules/section-41 Section 41 of the DPDP Act 2023: Laying of rules and certain notifications. The full text as notified, with what it asks of an organisation in practice. - **Section 42 DPDP Act: Power to amend Schedule | AIZZENTEC** — https://aizzentec.com/act-rules/section-42 Section 42 of the DPDP Act 2023: Power to amend Schedule. The full text as notified, with what it asks of an organisation in practice. - **Section 43 DPDP Act: Power to remove difficulties** — https://aizzentec.com/act-rules/section-43 Section 43 of the DPDP Act 2023: Power to remove difficulties. The full text as notified, with what it asks of an organisation in practice. - **Section 44 DPDP Act: Amendments to certain Acts | AIZZENTEC** — https://aizzentec.com/act-rules/section-44 Section 44 of the DPDP Act 2023: Amendments to certain Acts. The full text as notified, with what it asks of an organisation in practice. - **Rule 1 DPDP Rules: Short title and commencement | AIZZENTEC** — https://aizzentec.com/act-rules/rule-1 Rule 1 of the DPDP Rules 2025: Short title and commencement. The full text as notified, with what it asks of an organisation in practice. - **Rule 2 DPDP Rules: Definitions | AIZZENTEC** — https://aizzentec.com/act-rules/rule-2 Rule 2 of the DPDP Rules 2025: Definitions. The full text as notified, with its sub-sections and illustrations, and what it asks of an organisation in practice. - **Rule 3 DPDP Rules: Notice to the Data Principal | AIZZENTEC** — https://aizzentec.com/act-rules/rule-3 Rule 3 of the DPDP Rules 2025: Notice given by Data Fiduciary to Data Principal. The full text as notified, with what it asks of an organisation in practice. - **Rule 4 DPDP Rules: Consent Manager registration and duties** — https://aizzentec.com/act-rules/rule-4 Rule 4 of the DPDP Rules 2025: Registration and obligations of Consent Manager. The full text as notified, with what it asks of an organisation in practice. - **Rule 5 DPDP Rules: Processing for State subsidy or service** — https://aizzentec.com/act-rules/rule-5 Rule 5 of the DPDP Rules 2025: Processing for State subsidy or service. The full text as notified, with what it asks of an organisation in practice. - **Rule 6 DPDP Rules: Reasonable security safeguards** — https://aizzentec.com/act-rules/rule-6 Rule 6 of the DPDP Rules 2025: Reasonable security safeguards. The full text as notified, with what it asks of an organisation in practice. - **Rule 7 DPDP Rules: Intimation of personal data breach** — https://aizzentec.com/act-rules/rule-7 Rule 7 of the DPDP Rules 2025: Intimation of personal data breach. The full text as notified, with what it asks of an organisation in practice. - **Rule 8 DPDP Rules: When a purpose is no longer served** — https://aizzentec.com/act-rules/rule-8 Rule 8 of the DPDP Rules 2025: When a purpose is no longer served. The full text as notified, with what it asks of an organisation in practice. - **Rule 9 DPDP Rules: Contact for questions about processing** — https://aizzentec.com/act-rules/rule-9 Rule 9 of the DPDP Rules 2025: Contact for questions about processing. The full text as notified, with what it asks of an organisation in practice. - **Rule 10 DPDP Rules: Verifiable parental consent for a child** — https://aizzentec.com/act-rules/rule-10 Rule 10 of the DPDP Rules 2025: Verifiable parental consent for a child. The full text as notified, with what it asks of an organisation in practice. - **Rule 11 DPDP Rules: Verifiable consent: lawful guardian** — https://aizzentec.com/act-rules/rule-11 Rule 11 of the DPDP Rules 2025: Verifiable consent: lawful guardian. The full text as notified, with what it asks of an organisation in practice. - **Rule 12 DPDP Rules: Exemptions for children's data** — https://aizzentec.com/act-rules/rule-12 Rule 12 of the DPDP Rules 2025: Exemptions for children's data. The full text as notified, with what it asks of an organisation in practice. - **Rule 13 DPDP Rules: Significant Data Fiduciary duties** — https://aizzentec.com/act-rules/rule-13 Rule 13 of the DPDP Rules 2025: Additional obligations of Significant Data Fiduciary. The full text as notified. - **Rule 14 DPDP Rules: Rights of Data Principals | AIZZENTEC** — https://aizzentec.com/act-rules/rule-14 Rule 14 of the DPDP Rules 2025: Rights of Data Principals. The full text as notified, with what it asks of an organisation in practice. - **Rule 15 DPDP Rules: Transfer of personal data outside India** — https://aizzentec.com/act-rules/rule-15 Rule 15 of the DPDP Rules 2025: Transfer of personal data outside the territory of India. The full text as notified. - **Rule 16 DPDP Rules: Exemption for research and statistics** — https://aizzentec.com/act-rules/rule-16 Rule 16 of the DPDP Rules 2025: Exemption for research and statistics. The full text as notified, with what it asks of an organisation in practice. - **Rule 17 DPDP Rules: Appointment of Chairperson and Members** — https://aizzentec.com/act-rules/rule-17 Rule 17 of the DPDP Rules 2025: Appointment of Chairperson and other Members. The full text as notified, with what it asks of an organisation in practice. - **Rule 18 DPDP Rules: Salary and service terms of Members** — https://aizzentec.com/act-rules/rule-18 Rule 18 of the DPDP Rules 2025: Salary and service terms of Members. The full text as notified, with what it asks of an organisation in practice. - **Rule 19 DPDP Rules: Board meetings and authentication** — https://aizzentec.com/act-rules/rule-19 Rule 19 of the DPDP Rules 2025: Board meetings and authentication. The full text as notified, with what it asks of an organisation in practice. - **Rule 20 DPDP Rules: The Board as a digital office** — https://aizzentec.com/act-rules/rule-20 Rule 20 of the DPDP Rules 2025: Functioning of Board as digital office. The full text as notified, with what it asks of an organisation in practice. - **Rule 21 DPDP Rules: Board officers and employees | AIZZENTEC** — https://aizzentec.com/act-rules/rule-21 Rule 21 of the DPDP Rules 2025: Board officers and employees. The full text as notified, with what it asks of an organisation in practice. - **Rule 22 DPDP Rules: Appeal to Appellate Tribunal | AIZZENTEC** — https://aizzentec.com/act-rules/rule-22 Rule 22 of the DPDP Rules 2025: Appeal to Appellate Tribunal. The full text as notified, with what it asks of an organisation in practice. - **Rule 23 DPDP Rules: Calling for information | AIZZENTEC** — https://aizzentec.com/act-rules/rule-23 Rule 23 of the DPDP Rules 2025: Calling for information. The full text as notified, with what it asks of an organisation in practice. ## Site index — Knowledge Hub articles Practitioner deep-dives published on https://aizzentec.com/knowledge. Each opens in place on that page. - **Reading the DPDP Act & Rules together: a practitioner's guide** — https://aizzentec.com/knowledge#featured The Act gives you the duties; the Rules give you the operational detail. Here's how to read them in tandem. (~14 min read) - **Section 5 notice: what 'fair, transparent and itemised' actually means** — https://aizzentec.com/knowledge#a01 A line-by-line walkthrough of the notice requirements, with examples of compliant and non-compliant notices. (~9 min read) - **Lawful basis under Section 7: when consent isn't required** — https://aizzentec.com/knowledge#a02 Section 7 lists six 'legitimate uses' that don't need consent. Most teams under-use them — or over-use them. Both are dangerous. (~11 min read) - **Designing a consent UX that won't get you fined** — https://aizzentec.com/knowledge#a03 Granularity, withdrawal-parity, dark-pattern avoidance and the audit trail. The four pillars of compliant consent capture. (~10 min read) - **Building a DSAR fulfilment workflow that scales** — https://aizzentec.com/knowledge#a04 From request intake to identity verification to the 90-day SLA. The five-stage workflow used by mature programmes. (~12 min read) - **The 72-hour breach response: what good looks like** — https://aizzentec.com/knowledge#a05 The decision points, communication choreography, and timing model used by clients who've actually managed a notifiable breach. (~13 min read) - **BFSI: where DPDP and RBI/IRDAI obligations collide** — https://aizzentec.com/knowledge#a06 KYC retention vs DSAR erasure, payment data localisation, breach notification race conditions — the real points of friction. (~11 min read) - **Healthcare: the ABDM-DPDP harmonisation problem** — https://aizzentec.com/knowledge#a07 Two consent regimes, overlapping retention obligations, and the central question — when does NDHM compliance equal DPDP compliance? (~10 min read) - **EdTech and Section 9: the verifiable parental consent problem** — https://aizzentec.com/knowledge#a08 Why self-declared age gates won't survive enforcement, and the four architectures we've seen actually work. (~11 min read) - **Vendor remediation: the longest pole in your DPDP programme** — https://aizzentec.com/knowledge#a09 Why the DPA roll-out takes 12-18 months for most organisations, and how to sequence it intelligently. (~9 min read) - **Significant Data Fiduciary classification: should you self-prepare?** — https://aizzentec.com/knowledge#a10 Volume isn't the only criterion. Five factors that increase your likelihood, and what to do before notification. (~10 min read) - **Cross-border transfers under Section 16: what's allowed today, what may change** — https://aizzentec.com/knowledge#a11 The default-permit regime, the specific-restriction power, and how to map your flows for either future. (~8 min read) - **The Data Protection Board of India: what to expect when it activates** — https://aizzentec.com/knowledge#a12 Composition, powers, procedural model, appeal route. The institution that will define enforcement. (~9 min read) - **Penalties: how the Schedule actually works (and how to limit exposure)** — https://aizzentec.com/knowledge#a13 Civil only, capped, allocated by section. The maths of the maximum-exposure calculation. (~8 min read) - **Phase 1, 2, 3: the realistic timeline of DPDP enforcement** — https://aizzentec.com/knowledge#a14 What's already enforceable, what comes mid-2026, and what crystallises on 13 May 2027. (~7 min read) - **DPDP Act vs GDPR: The 15 Differences That Change Your Compliance Programme** — https://aizzentec.com/knowledge#a15 DPDP Act vs GDPR in 15 rows, then which of your GDPR artefacts you can reuse, must rewrite and must build new before May 2027. (~12 min read) - **Virtual DPO Services in India: What a vDPO Does, What It Costs, and When You Need One** — https://aizzentec.com/knowledge#a16 What a virtual DPO does month by month, how it compares with an in-house hire, indicative INR fee bands and a 30-day onboarding plan. (~11 min read) - **DPDP Act Compliance for HR: Employee Data, Background Checks and Payroll Vendors** — https://aizzentec.com/knowledge#a17 How the Section 7 employment purpose works, when employee consent is still needed, payroll and BGV vendors, and retention against statutory holds. (~12 min read) - **DPDP Compliance for SaaS Companies: Processor Obligations, Sub-Processors and Customer DPAs** — https://aizzentec.com/knowledge#a18 Processor or fiduciary, what a DPDP processor must actually do, sub-processor flow-down, customer DPAs and answering DPDP questionnaires. (~12 min read) - **Data Processing Agreement Under DPDP: Mandatory Clauses and a Free Template** — https://aizzentec.com/knowledge#a19 The 12 clauses a DPDP data processing agreement cannot leave out, negotiation red lines, and how to roll a DPA across vendors you already have. (~12 min read) - **DPDP Act for Marketing Teams: Consent for WhatsApp, Email, SMS and CRM Data** — https://aizzentec.com/knowledge#a20 Consent for WhatsApp, email, SMS and CRM data under the DPDP Act, triaging a legacy database with no consent record, and cookie banners in India. (~12 min read) - **ISO 27001 and DPDP Act: How One Programme Covers Both (Control Mapping Included)** — https://aizzentec.com/knowledge#a21 Where an ISO 27001 ISMS already meets the DPDP Rule 6 safeguards, the gaps a certificate does not close, ISO 27701, and one audit calendar for both. (~12 min read) - **CERT-In Directions vs DPDP Breach Rules: Two Clocks, One Incident** — https://aizzentec.com/knowledge#a22 The CERT-In six-hour direction and the DPDP breach rules on one incident: diverging triggers, a T+0 to T+72h timeline, RACI and a single runbook. (~12 min read) - **DPDP Compliance for Fintech and NBFCs: Account Aggregator, Lending Apps and RBI Overlap** — https://aizzentec.com/knowledge#a23 How the DPDP Act sits on top of the RBI stack: Account Aggregator consent, digital lending limits, localisation, and a 90-day plan for NBFC teams. (~12 min read) - **DPDP Compliance Cost in India: What SMEs, Mid-Market and Enterprises Should Budget** — https://aizzentec.com/knowledge#a24 What DPDP compliance costs by company size, what the one-time programme includes, consultant fee bands, cost drivers and ongoing costs after go-live. (~12 min read) ## Site index — blog articles - **Cross-Border Data Transfer Under the DPDP Act: A Comprehensive 2026 Compliance Guide** — https://aizzentec.com/blog/cross-border-data-transfer-dpdp-act Cross-border data transfer under DPDP Act explained: Section 6 rules, notified jurisdictions, contractual safeguards and a phased compliance checklist. Last updated 2026-08-10. - **DPDP Act Compliance for Businesses: Opportunities and Strategies Under the Digital Personal Data Protection Act, 2023** — https://aizzentec.com/blog/dpdp-act-compliance-strategies-businesses DPDP Act compliance for businesses explained: core provisions, penalties up to ₹250 crore, and practical strategies for enterprises, SMEs and startups. Last updated 2026-08-06. - **Biometric Attendance Systems and the DPDP Act: How Fingerprint Scanners for Time Recording May Violate the Law** — https://aizzentec.com/blog/biometric-attendance-dpdp-act-violation Is your biometric attendance system DPDP Act compliant? Learn why fingerprint time recording risks violations — consent, DPIA, security — and how to fix it. Last updated 2026-08-02. - **What Is the DPDP Act 2025? Key Rules, Compliance Requirements, and Business Impact** — https://aizzentec.com/blog/what-is-dpdp-act-2025-guide What is the DPDP Act? Understand the DPDP Rules 2025, key compliance requirements, penalties up to ₹250 crore, and the May 2027 deadline for your business. Last updated 2026-07-29. - **DPDP Act Banking Sector Impact: Fortifying India’s Banking Backbone and Redefining the Rules of the Game** — https://aizzentec.com/blog/dpdp-act-banking-sector-impact The DPDP Act banking sector reset explained: consent at scale, RBI alignment, Rs 250 crore penalties, and how Indian banks can turn privacy into advantage. Last updated 2026-07-25. - **DPDP Act Compliance Checklist for Indian Businesses: What You Need to Do Now** — https://aizzentec.com/blog/dpdp-act-compliance-checklist A practical DPDP Act compliance checklist for Indian businesses: 11 steps covering consent, DPOs, breach response and training. Start your compliance now. Last updated 2026-07-21. - **Why the DPDP Act Matters for the Retail Sector: A 2026 Compliance Guide** — https://aizzentec.com/blog/dpdp-act-retail-sector-compliance Why the DPDP Act retail sector rules matter: consent for loyalty programs, breach notification and customer trust. A practical retail compliance guide. Last updated 2026-07-17. - **DPDP Act Penalties for Data Breaches: What Businesses Need to Know** — https://aizzentec.com/blog/data-breach-penalties-dpdp-act DPDP Act penalties explained: fines up to ₹250 crore for data breaches, sanctions for non-reporting, and the compliance steps that keep your business safe. Last updated 2026-07-13. - **Data Breach Notification Under the DPDP Act: Your 72-Hour Response Plan** — https://aizzentec.com/blog/data-breach-response-plan-dpdp-act-72-hours Data breach notification DPDP Act rules demand action in 72 hours. Get the phase-by-phase response plan, DPB template and severity matrix to stay compliant. Last updated 2026-07-09. - **AI and Machine Learning Under the DPDP Act: The Complete AI Compliance Guide for Organizations** — https://aizzentec.com/blog/ai-machine-learning-dpdp-act-compliance DPDP Act AI compliance explained: training data consent, algorithmic transparency and human oversight — with case studies and a practical AI/ML checklist. Last updated 2026-07-05. - **DPDP Act Compliance Deadline May 2027: The 12-Month Implementation Roadmap** — https://aizzentec.com/blog/dpdp-act-compliance-deadline-roadmap The DPDP Act compliance deadline is May 2027. Follow this month-by-month roadmap, budget framework and real case study to get your organisation compliant. Last updated 2026-07-01. - **DPDP Act Healthcare Compliance for Hospitals: A Comprehensive Guide** — https://aizzentec.com/blog/dpdp-act-healthcare-hospitals-compliance DPDP Act healthcare compliance guide for hospitals, labs & telemedicine: patient consent workflows, EMR rules, retention timelines and breach readiness. Last updated 2026-06-27. - **DPDP Act Compliance for Banks and NBFCs: The Financial Data Protection Guide** — https://aizzentec.com/blog/dpdp-act-banks-nbfc-compliance How DPDP Act compliance for banks and NBFCs works alongside RBI rules: KYC data protection, data localisation, credit bureau consent and breach duties. Last updated 2026-06-23. - **GDPR vs DPDP Act vs CCPA: The Complete Comparison Guide for Multinational Compliance** — https://aizzentec.com/blog/gdpr-vs-dpdp-act-vs-ccpa-comparison GDPR vs DPDP Act vs CCPA compared across 20+ parameters — consent, breach rules, penalties, data transfers — plus harmonization strategies for global firms. Last updated 2026-06-19. - **Why Certified Data Erasure Is Non-Negotiable Under the DPDP Act and GDPR** — https://aizzentec.com/blog/certified-data-erasure-dpdp-act-gdpr Certified data erasure is a legal duty under the DPDP Act and GDPR. See the penalties, the Morgan Stanley case, and a secure data disposal checklist for CISOs. Last updated 2026-06-15. - **Compensation for Data Breach Victims in India Under the DPDP Act, 2023: The Missing Remedy** — https://aizzentec.com/blog/data-breach-victim-compensation-dpdp-act Is there compensation for data breach victims in India? Why the DPDP Act, 2023 penalizes companies but leaves victims without direct remedies — explained. Last updated 2026-06-11. - **WhatsApp Business DPDP Act Compliance: Messaging Apps and Data Protection** — https://aizzentec.com/blog/whatsapp-business-dpdp-act-compliance WhatsApp Business DPDP Act compliance explained: opt-in rules, consent for promotional messages, data retention and message templates that keep you legal. Last updated 2026-06-07. - **Employee Data Protection Under the DPDP Act: The HR Department’s Guide to Workplace Privacy** — https://aizzentec.com/blog/dpdp-act-hr-employee-data-protection Employee data protection under the DPDP Act: consent forms, background checks, CCTV and biometric rules every HR team in India must follow to stay compliant. Last updated 2026-06-03. - **Director Liability Under the DPDP Act: CEO and Board Personal Accountability** — https://aizzentec.com/blog/directors-personal-liability-dpdp-act Director liability under the DPDP Act explained: Section 36 vicarious liability, Rs 5 crore personal penalties, D&O insurance gaps and board safeguards. Last updated 2026-05-30. ## Site index — free tools - **Penalty Exposure Estimator** — https://aizzentec.com/tools/penalty-estimator Compute exposure across the Schedule of Penalties, including the severity multiplier available to the DPBI under Section 33(2). Toggle contraventions to compute. - **SDF Classifier** — https://aizzentec.com/tools/sdf-classifier Answer seven yes/no questions based on the factors in Section 10(1). The classifier estimates your likelihood of Significant Data Fiduciary designation. - **Consent Manager Integration Checker** — https://aizzentec.com/tools#consent-manager-checker The DPDP Rules introduce a Consent Manager ecosystem (Section 6(6), Rule 4). Toggle the factors that apply to see whether integration is mandatory, recommended, or optional. - **DPIA Requirement Checker** — https://aizzentec.com/tools#dpia-checker A Data Protection Impact Assessment is mandatory for SDFs and for high-risk processing (Rule 13). Toggle the factors that apply to your processing. - **DPDP Compliance Readiness Checklist** — https://aizzentec.com/tools#readiness-checklist A working checklist across the core DPDP obligations. Your progress saves automatically in this browser. ## Site index — advisory services - **DPDP Readiness Assessment** — https://aizzentec.com/services#readiness-assessment A structured, evidence-based assessment of your current posture across all seven workstreams — with a prioritised, sequenced 12-month roadmap as the output. - **Data Protection Impact Assessments** — https://aizzentec.com/services#dpia DPIAs for high-risk processing activities, conducted by experienced practitioners. Required for Significant Data Fiduciaries; valuable for everyone. - **Vendor DPA Roll-out** — https://aizzentec.com/services#vendor-dpa End-to-end vendor remediation — discovery, triage, DDQ, DPA negotiation, exception management. The single longest-pole activity in most DPDP programmes. - **Breach Tabletop & Runbook** — https://aizzentec.com/services#breach-runbook Build (or refresh) your 72-hour breach response capability and stress-test it with two facilitated tabletop exercises. Best investment for limiting Section 8(5)/8(6) exposure. - **Fractional DPO** — https://aizzentec.com/services#fractional-dpo A named DPO meeting Section 10(2)(a) requirements, with monthly programme review and a quarterly board pack — without a full-time hire. - **Custom Training & Workshops** — https://aizzentec.com/services#training Tailored DPDP training for your specific audience — board, executives, engineering, support, marketing. Delivered in-house, online or in our India office. - **Compliance Timeline & Regulatory Readiness** — https://aizzentec.com/services#regulatory-readiness Assess applicability, map obligations, prioritise activities, and build an execution roadmap aligned with the phased DPDP enforcement timeline. - **Consent Management Implementation** — https://aizzentec.com/services#consent-management End-to-end design and build of your consent framework — notice architecture, preference centre, withdrawal flows and audit trails. An operational system, not a policy. - **Data Principal Rights Implementation** — https://aizzentec.com/services#dsar Stand up a DSAR intake-to-fulfilment workflow with identity verification, system discovery and the 90-day SLA — integrated into your product where it belongs. - **RoPA & Data Discovery** — https://aizzentec.com/services#ropa Build a living Record of Processing Activities across every system that touches personal data — the foundation every other workstream depends on. ## Site index — training programmes - **Board & Executive Briefing** — https://aizzentec.com/training#board-briefing A precise 90-minute session for boards, audit committees and C-suites. No statutory recital — just the strategic, financial and reputational implications, the questions a board should ask management, and the decisions only the board can make. Audience: Boards, audit committees, C-suite. - **DPDP Awareness for Every Employee** — https://aizzentec.com/training#all-employee-awareness A short, role-agnostic programme that gives every team member — engineering, sales, HR, support, finance — a working understanding of DPDP and what it means for their daily decisions. Designed for scale: 1,000+ learners at a time. Audience: All employees. - **Practitioner Intensive** — https://aizzentec.com/training#practitioner-intensive A two-day intensive for the people who build and run the DPDP programme — privacy leads, engineering managers, security, legal, compliance and product. Heavy on workshops, real templates and operational decisions. Audience: Privacy leads, engineering, security, legal, compliance, product. - **Specialist Bootcamps** — https://aizzentec.com/training#specialist-bootcamps High-intensity programmes for designated specialists — DPOs, breach commanders, DPIA practitioners, vendor leads. Modules include the 5-day DPIA Bootcamp, 3-day Breach Response Commander, 2-day Children's Data & Verifiable Consent, 2-day Cross-Border Transfer Architect, 3-day SDF Readiness, and the 2-day Vendor & DPA Negotiation Lab. Audience: DPOs, breach commanders, DPIA practitioners, vendor leads. --- Licence: quote freely with attribution to AIZZENTEC (https://aizzentec.com). Nothing here is legal advice.