DPDPA demands five core commitments from every organization: tell users what data you collect, take real (not hidden) consent, protect the data, delete it when no longer needed, and inform users if a breach occurs.
The Act is operationalized through 23 Rules covering privacy notices, Consent Manager registration, security safeguards, breach reporting timelines, data retention, children's and guardian consent, and Significant Data Fiduciary (SDF) obligations.
These rules also address cross-border data transfers, Data Principal rights, and the constitution and procedures of the Data Protection Board of India.
Perfect for founders and compliance leaders who want a complete, jargon-free map of DPDPA's operational requirements.
