Practice · Advisory & compliance
Data protection & DPDP Act advocate in Ernakulam
I advise businesses and individuals on the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: applicability reviews, notices and consent flows, children's and employee data, vendor contracts, breach response, and complaints before the Data Protection Board and the TDSAT appeal route. I work from Ernakulam, and much of this work is done remotely.
Coverage
What does this area cover?
- Applicability, data fiduciaries, notices and consent — Whether the Act applies under s.3, who is the Data Fiduciary and who the Processor, item-wise notices under s.5 including the s.5(2) notice for consent taken before commencement, valid consent under s.6, Consent Managers, and the s.7 uses that need no consent.
- Rights, children, employees, CCTV and retention — Access, correction, erasure and nomination requests under ss.11 to 14, the s.15 duties of Data Principals, verifiable parental consent and the bar on tracking and targeted ads at children under s.9, HR data under s.7(i), CCTV procedures and retention schedules.
- Vendors, security, breach and grievances — Processor contracts under s.8(2), the Rule 6 minimum security safeguards, cross-border transfers under s.16, breach intimation to each affected person and to the Board with a detailed report within 72 hours under Rule 7, and a grievance system that answers on time.
- Significant data fiduciaries, the Board, TDSAT, e-sign and domains — Significant Data Fiduciary duties under s.10, complaints to the Data Protection Board after the grievance route, voluntary undertakings under s.32, appeals to TDSAT within 60 days under s.29, consent records that stand up as evidence, phishing domains and s.37 blocking.
- AI governance and compliance — Office AI-use policies, no-training clauses in AI vendor contracts, hiring and scoring tools checked for purpose and accuracy under s.8(3), deletion of personal data from training pipelines, voice-clone consent, and the first response when a person or brand is deepfaked.
Who must comply with the DPDP Act, and from when?
The Act applies to digital personal data processed in India, including data collected on paper and digitised later, and to processing outside India connected with offering goods or services to people in India (s.3). Purely personal or domestic use, and data that a person has made public herself, fall outside it. A shop that keeps customer numbers in a billing app, a clinic with patient records, a school with a fee portal and an employer with biometric attendance are all within it.
Commencement is phased under G.S.R. 843(E) and the DPDP Rules, 2025, both dated 13 November 2025. The Board provisions took effect that day. The Consent Manager registration rule applies one year after publication, around 14 November 2026. Most other obligations, including notices, consent, security safeguards, breach intimation, children’s data, retention and grievance redressal, apply from about 14 May 2027, eighteen months after publication. Two provisions matter for planning now: under s.5(2), customers whose consent was taken before commencement must get a notice as soon as reasonably practicable, and under s.17(3) relief for startups or other classes exists only if the government notifies it.
What does DPDP compliance work cover for a business?
For an e-commerce seller, a hospital or clinic, a school or an employer, DPDP compliance starts with a map of the personal data held and why. From that come the consent notice under Section 5 (in English and Malayalam where customers need it), consent management and withdrawal, security safeguards, a breach-response plan, retention and erasure, grievance redressal, and contracts with the vendors that process data on the business’s behalf — see data processing agreements. The entries are grouped under consent notices and consent management and AI governance and compliance. Appeals against the Data Protection Board’s orders go to the TDSAT under Section 29; a writ petition under Article 226 before the High Court of Kerala is kept for questions that route cannot answer.
Forums
Which court or authority hears it?
| Matter | Law | Forum | Time limit |
|---|---|---|---|
| Notice, consent, security, rights and retention duties | DPDP Act ss.4–17; DPDP Rules r.3, 5–16 | Internal compliance; Data Protection Board on complaint | Most apply from about 14 May 2027 (G.S.R. 843(E)) |
| Consent Manager registration | s.6(9); Rule 4 and First Schedule | Data Protection Board | s.6(9) and Rule 4 in force about 14 November 2026 |
| Personal data breach | s.8(6); Rule 7 | Data Protection Board and each affected Data Principal | Without delay; detailed Board report within 72 hours |
| Grievance by a Data Principal | ss.8(10), 13; Rule 14(3) | Data Fiduciary or Consent Manager | Published period, not more than 90 days |
| Complaint against a Data Fiduciary | ss.13(3), 27(1)(b), 28 | Data Protection Board (digital office) | After the grievance route is exhausted |
| Appeal against a Board order or direction | s.29 | TDSAT (Appellate Tribunal) | 60 days from receipt; later only on sufficient cause |
| Blocking access to a repeat offender's service | s.37 | Central Government on a Board reference | No fixed limit; needs penalties in two or more instances |
How it proceeds
How does a matter proceed?
- Applicability and data map. A written check of whether and how the Act applies, which personal data you hold, where it sits, which vendors handle it, and whether you are fiduciary or processor for each flow.
- Notices, consent and legacy data. Standalone notices in English and Malayalam under s.5 and Rule 3, consent that can be withdrawn as easily as it was given, and a s.5(2) notice plan for the existing customer base.
- Contracts, safeguards and retention. Processor agreements under s.8(2), Rule 6 safeguards recorded in a form the Board can inspect, retention schedules, and separate handling of children's and HR data.
- Breach and grievance drill. A Rule 7 playbook: notice to affected persons and the Board without delay, the 72-hour detailed report, and a grievance desk that meets its published response period.
- Board and TDSAT stage. Replies to Board notices, mitigation material under s.33(2), a voluntary undertaking under s.32 where suitable, and the TDSAT appeal within 60 days of receiving an order.
What should you keep ready?
- A list of personal data collected, by form, app, website and paper register
- Current privacy policy, terms, consent screens and CCTV signage
- Vendor list with contracts, hosting locations and sub-processors
- Security measures in place: access control, logging, backups and encryption
- HR, CCTV and customer-data retention practice as actually followed
- Any breach history, grievance log or complaint received
- A Board notice or order, with the date of receipt, if a proceeding has begun
Reading
Guides and articles on this area
- DPDP Readiness Checklist for Small Business
- DPDP Compliance Guide for Kerala Businesses to May 2027
- Your Personal Data Was Leaked by a Company: What You Can Do Under the DPDP Act
- CERT-In 6-Hour vs DPDP 72-Hour Breach Reporting: Which Clock Applies to Your Business?
- DPDP Act and Children's Data in India: Verifiable Parental Consent, Tracking Bans and What EdTech Must Change
- Cross-Border Data Transfers Under the DPDP Act: What Section 16 and Rule 15 Actually Allow
These answers follow the Act, the 2025 Rules and G.S.R. 843(E); confirm the Gazette position before acting. The DPDP readiness checklist sets out ten controls, this article on breach clocks compares CERT-In and DPDP reporting, and the matters index lists each obligation.
FAQ
Common questions
Does the DPDP Act apply to a small business?
When do DPDP Act obligations actually start?
How fast must a data breach be reported under the DPDP Rules?
Do we need to appoint a Data Protection Officer?
Can the Data Protection Board award me compensation?
Is a privacy policy on the website enough for DPDP compliance?
Matters
Every matter, by group
Each matter type with its law, forum, procedure, documents and limitation clock. All 90 on one page →
Related
Related practice areas
About the advocate: Adv. K J Muhammed Aslam, enrolled with the Bar Council of Kerala; office at High Court Junction, Ernakulam.
