DPDP compliance
DPDP Act 2023 — Kerala Business Readiness
A working index of the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025 for Kerala businesses — applicability and roles, notices and consent, children’s data, breach response and the 72-hour clock, retention and security safeguards, vendor and processor terms, rights requests, the Board and TDSAT route, e-sign and domain questions, and AI-governance readiness. Rule numbers and statutory dates carry a verify note; confirm the Gazette position before acting. General information only.
Applicability, data fiduciaries, notices and consent
- DPDP applicability audit for Kerala business — do we fall under the Act
- Digitised offline data — registers, forms and CCTV logs brought online
- Foreign website or app serving Kerala customers — extraterritorial reach
- Personal or domestic use exclusion — family, household handling
- Publicly available data — blogs, self-published posts and statutory disclosures
- Fiduciary vs Processor — who is answerable when a vendor handles data
- Joint fiduciaries — marketplace, franchise and hospital-lab models
- Section 17(1)(a) — processing to enforce a legal right or claim
- Section 5 notice drafting — Malayalam + English, item by item
- Legacy data transition — s.5(2) notice for pre-Act consent
- Consent-flow design — free, specific, informed, unconditional, unambiguous
- Consent Manager — single-point consent dashboard
- Withdrawal — as easy to leave as to join, and what survives it
- Proving notice + consent — s.6(10) burden on the fiduciary
- Voluntary data (s.7(a)) and employment (s.7(i)) — consent-free but bounded
- State, medical-emergency and disaster uses — s.7(b)–(h) map
- Startup and notified-class relaxation — s.17(3) tracker
- Lawful purpose and purpose limitation — s.4 anchor memo
Rights, children, employees, CCTV and retention
- DSAR — right to access summary, sharing trail and processing note (s.11)
- Correction cascade — wrong phone, address or name across systems and vendors
- Erasure — delete me, unless purpose survives or law says keep
- Nomination — s.14 nominee for death or incapacity
- Section 15 defence — answering false, frivolous or impersonated requests
- Age-gating — verifiable parental consent before touching a child's data
- No tracking, monitoring or targeted ads at children — s.9(3) hard line
- Notified child-processing classes and verifiably-safe exemption — s.9(4)/(5) watch
- School-vendor pack — student app, bus GPS and fee-portal checklist
- HR pack — attendance, payroll and performance data under s.7(i)
- Ex-employee data — references, dues and deletion after exit
- CCTV SOP — shop, clinic and apartment cameras with people data
- Facial recognition on private premises — high-risk memo, default no
- Retention schedules — purpose-over means delete, unless law says keep
- PMLA/banking 10-year override — when another law beats erasure
- Hospital retention — treatment records vs delete-me requests
- Grievance-first rule — Board will not hear you before the fiduciary does
- Data Principal duties + Rs.10,000 track — the quiet penalty on individuals
Vendors, security, breach and grievances
- DPA drafting — s.8(2) valid-contract clauses Kerala vendors will sign
- Tiering — processor, sub-processor or second fiduciary
- Cross-border transfer — s.16 blacklist model and what to write in the DPA
- Breach indemnity — who pays when the processor leaks
- Reasonable safeguards checklist — s.8(5) without inventing mandates
- ISO 27001 mapping — using audit language without overclaiming
- Ransomware — when encryption of your own data is a personal data breach
- 72-hour + without-delay notices — Board and each affected principal
- Breach playbook — contain, assess, notify, submit, document, mitigate
- Late notice — delay condonation and mitigation story
- Victim push — breach victim's complaint to the Board
- Grievance mechanism + officer — s.8(10)/s.13 front door that must work
- Grievance SLA — counting the response window without guessing
- Consent Manager grievance — when the dashboard itself fails
- Law-enforcement sharing shield — s.11(2) replies without tipping off
- Accuracy duty — s.8(3) where data decides loans, jobs or admissions
- Publish the contact — s.8(9) DPO or answerable person on the website
- Processor erasure cascade — stopping the copies after stop
Significant data fiduciaries, the Board, TDSAT, e-sign and domains
- SDF readiness — will the Government notify us as Significant
- DPO appointment — India-based, Board-facing, grievance-owning
- DPIA drafting — description, risk, management for SDF processing
- Independent data audit — auditor who evaluates SDF compliance
- Gap-audit, ROPA, consent vault and training — the four-file SDF starter
- Board complaint drafting — s.27(1)(b) after grievance exhaust
- Voluntary undertaking — s.32 corporate-probation strategy
- How the Board starts — breach intimation, reference, court direction, suo-motu screen
- Mitigation for quantum — s.33(2) seven-factor story
- TDSAT appeal — 60 days, sufficient cause, 6-month endeavour
- Mediation — s.31 Board-directed settlement track
- E-sign harmonisation — consent records that survive evidence scrutiny
- INDRP + WHOIS — phishing domain using your brand to harvest data
- Phishing + blocking — s.37 DPDP vs s.69A IT Act takedown routes
- Intermediary clock — reports, acknowledgement and GAC/69A overlay
- E-commerce seller + platform — who owns the customer-data breach
- Dark patterns vs DPDP consent — when UI itself voids consent
- Section 37 blocking deep-dive — the 2-penalty gate most blogs skip
AI governance and compliance
- AI use policy for the office — which tools, which data, who approves
- Hallucination SOP — AI output never goes to court or client unverified
- Hiring-AI review — DPIA-style check before CV screening tools decide
- Shadow IT — personal Gmail, free bots and USB models with customer data
- AI vendor contracts — no-train clause for AI SaaS handling your data
- AI procurement checklist — DPDP + security before purchase
- Prompts and recordings stored — AI retention breach hiding in chat history
- Employee data for AI training — s.7(i) does not mean free corpus
- Training-data deletion pipeline — honouring s.12/s.8(7) inside ML systems
- Scraped-data licensing — copyright + DPDP lawful purpose together
- Deepfake response sprint — first 24 hours for a Kerala victim
- Brand deepfake — company director faked for fraud or defamation
- School deepfake — minor targeted; child-safety overlay
- Telecom UCC — promotional calls/SMS, DLT and consent proof
- AI support agents — notice + consent for recorded helpdesk calls/chats
- Voice-clone consent — using a person's voice in AI content
- Automated decisions — loan, screening or pricing tools and s.8(3) accuracy
- Research datasets — s.17(2)(b) archive/research/statistical path for AI data
