Practice · For businesses

Data protection & DPDP compliance

On 14 May 2027, the Digital Personal Data Protection Act's obligations — and its penalties — commence for every business that processes personal data digitally. That is a fixed, gazetted date. My work is getting businesses there early, calmly, and in language their teams actually understand.

Who complies

Who must comply?

If your business collects customer data through an app, a website, a CRM, or even a WhatsApp catalogue, you are almost certainly a Data Fiduciary under the Act. The duties scale with size and risk — notified Significant Data Fiduciaries carry extra obligations like impact assessments and audits — but the core duties apply to everyone, from a Kochi startup to an established exporter.

What's involved

What compliance actually involves

  • Data mapping — knowing what personal data you hold, where it lives, who touches it, and why.
  • Notices and consent — itemised, plain-language notices; consent that can be withdrawn as easily as it was given.
  • Security safeguards — the Rule 6 minimums: encryption, access control, logging, backups, and contracts binding your processors to the same.
  • Breach readiness — a working 72-hour intimation playbook for the Data Protection Board and affected users, tested before it's needed.
  • Retention and erasure — deleting what the purpose no longer justifies, on a schedule you can prove.
  • Rights and grievances — machinery for access, correction and erasure requests, and a published grievance contact.
  • Children's data — verifiable parental consent where users are under 18.
  • Technology contracts — data processing agreements, vendor terms, SaaS agreements and privacy policies that match your actual data flows.

How I work

How I work with a business

  1. Readiness audit. A structured review of your data practices against the Act and the 2025 Rules.
  2. Gap report in business language. What's fine, what isn't, what it takes to fix — prioritised, without jargon.
  3. Documents and systems. Notices, consent flows, policies and DPAs drafted to fit how you actually operate.
  4. Breach playbook and training. Your team knows who does what in the first 72 hours.
  5. Review rhythm. The law is young and the Rules will evolve — compliance is kept current, not framed and forgotten.

Why a lawyer

Why a lawyer, and not only a consultant?

Much of the DPDP market is served by IT consultancies, and good ones matter — but compliance decisions are ultimately legal positions you may one day have to defend before the Data Protection Board. Advice from an advocate is built for that day: grounded in the text of the Act, alert to how enforcement actually works, and covered by professional privilege in your most sensitive conversations.

FAQ

Common questions

Does the DPDP Act apply to my small business?
Almost certainly yes. The Act applies to anyone processing digital personal data — there is no small-business carve-out from the core duties of notice, consent, security safeguards and breach reporting. Larger or higher-risk businesses may additionally be notified as Significant Data Fiduciaries with extra obligations, but the baseline applies to a two-person startup as much as to an enterprise.
What happens if we do nothing until 2027?
The obligations and the penalty provisions commence together on 14 May 2027. Consent systems, notices, vendor contracts and breach processes realistically take months to design and roll out, and the penalty ceiling for failing to maintain reasonable security safeguards alone is ₹250 crore. Starting in early 2027 means paying for haste; starting now means absorbing the work into normal operations.
We already have a privacy policy. Is that enough?
No. A policy is one document; the Act demands working machinery — itemised notices, consent that can be withdrawn as easily as it was given, security safeguards, a 72-hour breach-intimation process, retention and erasure practices, and grievance redressal. Compliance is operational, not editorial.
Do we need to appoint a Data Protection Officer?
Only Significant Data Fiduciaries — a category the government notifies — must appoint a DPO based in India. Every data fiduciary, however, must publish the contact of a person who can answer data-related questions, and must operate a grievance mechanism. For most SMEs the practical need is a trained internal owner, not a statutory DPO.

Get in touch

Talk to me before the deadline does

Tell me what your business does and how you collect customer data. I'll tell you plainly where you stand against the Act — and what a sensible path to 14 May 2027 looks like for your size.

3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction, Ernakulam, Kerala 682031 · Monday – Saturday, 10:00 – 18:30 (by appointment)

A note before you read on. As required by the Bar Council of India, this website only provides information about Adv. K J Muhammed Aslam to those who seek it of their own accord. It is not an advertisement or solicitation, and nothing here is legal advice. By continuing, you acknowledge you are visiting voluntarily. Full disclaimer.