The DPDP Act applies to any entity processing personal data of individuals in India, regardless of where the entity itself is located.
Key obligations include obtaining verifiable consent, appointing a Data Protection Officer for significant data fiduciaries, and notifying the Data Protection Board of India of breaches.
Penalties are steep — up to ₹250 crore per instance for failure to implement reasonable security safeguards — making early compliance audits essential.
Our cyber law desk offers a structured gap-assessment covering consent architecture, data-processing agreements and breach-response playbooks.
Have a question about cyber law & data protection?
A relevant EcoVijay specialist can discuss the practical implications for your situation in an introductory consultation.
Book a Consultation