11. Compliance Requirement for My Company
ISSUE #94Published: 9/25/2026

11. Compliance Requirement for My Company

Ankur Srivastava

Ankur Srivastava

Deputy-CISO / CISSP

Cyber Security & Business Continuity Expert with over 15 years of experience orchestrating InfoSec Governance, risk mitigation frameworks, and disaster recovery architectures. CISSP | M.S. in Cyber Laws & Information Security (IIIT).

Access Price

₹40
Preview

Description

DPDPA compliance starts with Lawful Purpose and Legal Basis—collect data only for a valid reason and with clear consent, then notify Data Principals about what you collect, why, and their rights.

Core Data Fiduciary obligations include data accuracy, purpose limitation, retention limits, reasonable security safeguards, and breach notification to both the Data Protection Board and affected individuals.

You must also publish contact details of a responsible person for queries and establish a grievance redressal mechanism for Data Principals.

Follow the November 2024 Rules to operationalize these requirements—covering Data Principal rights, cross-border transfers, and penalties—and you're on your way to full DPDPA compliance.