DPDPA Act India · 2025

Exempt from DPDPA? Before you assume yes — read this.

Most founders and CTOs are asking this question right now — and the answer depends entirely on what data you collect, how you process it, and who you collect it from. Getting it wrong in either direction is costly.

Prefer to reach us directly? Contact us here

Three questions that determine your DPDPA exposure

What data do you collect?

If your product or platform collects name, email, phone number, location, or any identifier of an Indian individual — DPDPA applies to you in some form.

What is your role?

Are you a Data Fiduciary deciding why and how data is processed? Or a Data Processor acting on behalf of another? Your obligations differ significantly under the Act.

What are your obligations?

From consent notices to breach notifications to data retention limits — your obligations under DPDPA depend on your role, your data volume, and your sector.

You should speak to us if...

You collect personal data from Indian users through your app, website, or platform

You process personal data on behalf of another organisation as a vendor or service provider

You store, share, or transfer personal data across systems, vendors, or geographies

You use AI tools, CRMs, or marketing platforms that handle user data

You are preparing for a funding round and want your compliance house in order

You have received a customer or enterprise client asking about your data protection practices

What our free 30-minute DPDPA scoping call covers

01

Applicability check

We confirm whether DPDPA applies to your organisation and in what capacity — Fiduciary, Processor, or both.

02

Role identification

We clarify your role under the Act and what that means for your obligations, timelines, and risk exposure.

03

Obligation overview

We walk through your key obligations — consent, breach notification, data retention, and rights management — in plain language.

04

Next steps

We give you a clear, honest view of what needs to happen next — whether that is a full assessment or just targeted fixes.

20+ Years

Practitioner experience across IBM, PwC, ANZ and Fortune 500

ISO 42001 LI · CISSP · CISM · CISA · CCSP

Certifications held by our lead advisor

India · EU · UK · US

Multi-jurisdiction privacy and compliance coverage

Request your free 30-minute DPDPA scoping call

No obligation. No jargon. Just clarity on whether DPDPA applies to you and what to do next. Pick a slot below, or use the form.

Pick a time that works for you

Or send us a note

Or reach us directly