top of page
< Back

Data Privacy and Technology

The Digital Personal Data Protection Act, 2023 and its rules change what an Indian business must be able to demonstrate about the personal data it holds. We work on the operational side of that obligation, from consent notices and data principal rights through to the contracts that move data between parties.

WHAT WE DO
• DPDP Act applicability assessment and gap analysis
• Consent architecture, notices and preference management
• Data principal rights handling and grievance redressal
• Data Protection Officer appointment and Significant Data Fiduciary obligations
• Data processing addenda and vendor flow down terms
• Cross border transfer and localisation analysis
• CERT-In incident reporting timelines and log retention
• Intermediary obligations and safe harbour under section 79
• Electronic contracting and e-signature validity
• AI deployment risk and governance policy

HOW THE WORK IS ORGANISED
DPDP readiness · Technology contracting · Incident response · Intermediary and platform regulation

KEY INSTRUMENTS
Digital Personal Data Protection Act, 2023 · Information Technology Act, 2000 · SPDI Rules, 2011 · Intermediary Guidelines Rules, 2021 · CERT-In Directions, 2022

FEES
Fixed fee for defined scopes, retainer arrangements for ongoing volume, and time based billing where scope cannot be fixed in advance. The basis is agreed in writing before work begins and discussed at first contact.

DPDP Act readiness, technology contracting and incident response.

bottom of page