Practice · Advisory & compliance

Data protection & DPDP Act advocate in Ernakulam

I advise businesses and individuals on the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025: applicability reviews, notices and consent flows, children's and employee data, vendor contracts, breach response, and complaints before the Data Protection Board and the TDSAT appeal route. I work from Ernakulam, and much of this work is done remotely.

Adv. K J Muhammed Aslam · Bar Council of Kerala · High Court Junction, Ernakulam
90 matter types · See every matter → · Contact details →

Coverage

What does this area cover?

  • Applicability, data fiduciaries, notices and consent — Whether the Act applies under s.3, who is the Data Fiduciary and who the Processor, item-wise notices under s.5 including the s.5(2) notice for consent taken before commencement, valid consent under s.6, Consent Managers, and the s.7 uses that need no consent.
  • Rights, children, employees, CCTV and retention — Access, correction, erasure and nomination requests under ss.11 to 14, the s.15 duties of Data Principals, verifiable parental consent and the bar on tracking and targeted ads at children under s.9, HR data under s.7(i), CCTV procedures and retention schedules.
  • Vendors, security, breach and grievances — Processor contracts under s.8(2), the Rule 6 minimum security safeguards, cross-border transfers under s.16, breach intimation to each affected person and to the Board with a detailed report within 72 hours under Rule 7, and a grievance system that answers on time.
  • Significant data fiduciaries, the Board, TDSAT, e-sign and domains — Significant Data Fiduciary duties under s.10, complaints to the Data Protection Board after the grievance route, voluntary undertakings under s.32, appeals to TDSAT within 60 days under s.29, consent records that stand up as evidence, phishing domains and s.37 blocking.
  • AI governance and compliance — Office AI-use policies, no-training clauses in AI vendor contracts, hiring and scoring tools checked for purpose and accuracy under s.8(3), deletion of personal data from training pipelines, voice-clone consent, and the first response when a person or brand is deepfaked.

Who must comply with the DPDP Act, and from when?

The Act applies to digital personal data processed in India, including data collected on paper and digitised later, and to processing outside India connected with offering goods or services to people in India (s.3). Purely personal or domestic use, and data that a person has made public herself, fall outside it. A shop that keeps customer numbers in a billing app, a clinic with patient records, a school with a fee portal and an employer with biometric attendance are all within it.

Commencement is phased under G.S.R. 843(E) and the DPDP Rules, 2025, both dated 13 November 2025. The Board provisions took effect that day. The Consent Manager registration rule applies one year after publication, around 14 November 2026. Most other obligations, including notices, consent, security safeguards, breach intimation, children’s data, retention and grievance redressal, apply from about 14 May 2027, eighteen months after publication. Two provisions matter for planning now: under s.5(2), customers whose consent was taken before commencement must get a notice as soon as reasonably practicable, and under s.17(3) relief for startups or other classes exists only if the government notifies it.

What does DPDP compliance work cover for a business?

For an e-commerce seller, a hospital or clinic, a school or an employer, DPDP compliance starts with a map of the personal data held and why. From that come the consent notice under Section 5 (in English and Malayalam where customers need it), consent management and withdrawal, security safeguards, a breach-response plan, retention and erasure, grievance redressal, and contracts with the vendors that process data on the business’s behalf — see data processing agreements. The entries are grouped under consent notices and consent management and AI governance and compliance. Appeals against the Data Protection Board’s orders go to the TDSAT under Section 29; a writ petition under Article 226 before the High Court of Kerala is kept for questions that route cannot answer.

Forums

Which court or authority hears it?

Which authority deals with it, and when
MatterLawForumTime limit
Notice, consent, security, rights and retention dutiesDPDP Act ss.4–17; DPDP Rules r.3, 5–16Internal compliance; Data Protection Board on complaintMost apply from about 14 May 2027 (G.S.R. 843(E))
Consent Manager registrations.6(9); Rule 4 and First ScheduleData Protection Boards.6(9) and Rule 4 in force about 14 November 2026
Personal data breachs.8(6); Rule 7Data Protection Board and each affected Data PrincipalWithout delay; detailed Board report within 72 hours
Grievance by a Data Principalss.8(10), 13; Rule 14(3)Data Fiduciary or Consent ManagerPublished period, not more than 90 days
Complaint against a Data Fiduciaryss.13(3), 27(1)(b), 28Data Protection Board (digital office)After the grievance route is exhausted
Appeal against a Board order or directions.29TDSAT (Appellate Tribunal)60 days from receipt; later only on sufficient cause
Blocking access to a repeat offender's services.37Central Government on a Board referenceNo fixed limit; needs penalties in two or more instances

Limits run from the date the law specifies; check them against your own dates.

How it proceeds

How does a matter proceed?

  1. Applicability and data map. A written check of whether and how the Act applies, which personal data you hold, where it sits, which vendors handle it, and whether you are fiduciary or processor for each flow.
  2. Notices, consent and legacy data. Standalone notices in English and Malayalam under s.5 and Rule 3, consent that can be withdrawn as easily as it was given, and a s.5(2) notice plan for the existing customer base.
  3. Contracts, safeguards and retention. Processor agreements under s.8(2), Rule 6 safeguards recorded in a form the Board can inspect, retention schedules, and separate handling of children's and HR data.
  4. Breach and grievance drill. A Rule 7 playbook: notice to affected persons and the Board without delay, the 72-hour detailed report, and a grievance desk that meets its published response period.
  5. Board and TDSAT stage. Replies to Board notices, mitigation material under s.33(2), a voluntary undertaking under s.32 where suitable, and the TDSAT appeal within 60 days of receiving an order.

What should you keep ready?

  • A list of personal data collected, by form, app, website and paper register
  • Current privacy policy, terms, consent screens and CCTV signage
  • Vendor list with contracts, hosting locations and sub-processors
  • Security measures in place: access control, logging, backups and encryption
  • HR, CCTV and customer-data retention practice as actually followed
  • Any breach history, grievance log or complaint received
  • A Board notice or order, with the date of receipt, if a proceeding has begun

These answers follow the Act, the 2025 Rules and G.S.R. 843(E); confirm the Gazette position before acting. The DPDP readiness checklist sets out ten controls, this article on breach clocks compares CERT-In and DPDP reporting, and the matters index lists each obligation.

FAQ

Common questions

Does the DPDP Act apply to a small business?
Yes, if it processes digital personal data; the Act has no general small-business exemption. Under s.17(3) the Central Government may notify classes of fiduciaries, including startups, that are relieved of certain duties, but only by notification.
When do DPDP Act obligations actually start?
In phases. The Board provisions took effect on 13 November 2025 and the Consent Manager rule about a year later; most fiduciary obligations, including notice, consent, security and breach reporting, apply from about 14 May 2027 under G.S.R. 843(E).
How fast must a data breach be reported under the DPDP Rules?
Without delay, to each affected Data Principal and to the Board. Rule 7 also requires a detailed report to the Board within 72 hours of becoming aware of the breach, unless the Board allows a longer period on written request.
Do we need to appoint a Data Protection Officer?
Only if notified as a Significant Data Fiduciary under s.10, which requires a Data Protection Officer based in India. Every other fiduciary must still publish the contact of a person who can answer questions about its processing, under s.8(9).
Can the Data Protection Board award me compensation?
No. Board penalties go to the Consolidated Fund of India; a person who suffered loss from a breach needs a separate civil claim, after using the fiduciary's grievance route and, where needed, a Board complaint.
Is a privacy policy on the website enough for DPDP compliance?
No. The Act needs working systems: itemised notices, consent that can be withdrawn, security safeguards, breach intimation, retention and erasure, and a grievance process with a published response period of not more than 90 days.

About the advocate: Adv. K J Muhammed Aslam, enrolled with the Bar Council of Kerala; office at High Court Junction, Ernakulam.

General information, not legal advice.

Contact

3rd Floor, Lalan Towers (KGL Builders), Vanchi Square, High Court Junction, Ernakulam, Kerala 682031 · Monday – Saturday, 10:00 – 18:30 (by appointment)

A note before you read on. In keeping with the Bar Council of India Rules, this website provides information about Adv. K J Muhammed Aslam, and general legal information, only to those who seek it of their own accord. It is not an advertisement or solicitation, and nothing here is legal advice. By continuing, you acknowledge you are visiting voluntarily. Full disclaimer.