Data Privacy Law

Why Your Startup Needs a Strong Terms of Service and Privacy Policy

Open the footer of almost any Indian startup website and you will find two links: “Terms of Service” and “Privacy Policy.” Click them and you will often find documents that are awkwardly worded, copy-pasted from a competitor, or wildly mismatched with what the product actually does. These two documents are doing more legal heavy lifting […]

Why Your Startup Needs a Strong Terms of Service and Privacy Policy Read More »

Penalties Under the DPDP Act 2023: What Non-Compliance Could Cost Your Business

When the Digital Personal Data Protection Act, 2023 was enacted, the headline that travelled fastest in startup circles was the ₹250 crore figure. It is, deservedly, a wake-up call. But the penalty structure under the DPDP Act is more nuanced than a single big number — and understanding the gradient of penalties is essential to

Penalties Under the DPDP Act 2023: What Non-Compliance Could Cost Your Business Read More »

DPDP Compliance Checklist for Startups: A Step-by-Step Guide

“Where do we even start?” That is the most common question founders ask once they realise the Digital Personal Data Protection Act, 2023 applies to them. The Act looks deceptively short — just over 40 sections — but its operational footprint inside a startup is enormous. From engineering to HR to vendor management, almost every

DPDP Compliance Checklist for Startups: A Step-by-Step Guide Read More »

Data Principal Rights Under DPDP Act: What Your Customers Can Demand

Until recently, an Indian customer who wanted to know what data a company held on her had little real recourse. The Digital Personal Data Protection Act, 2023 changes that. The Act gives every “data principal” — your user, employee, or customer — a clear bundle of rights, and it places the burden of honouring those

Data Principal Rights Under DPDP Act: What Your Customers Can Demand Read More »

Digital Personal Data Protection Act, 2023 – Research memo on statutory obligations of a “Data Fiduciary”

This memorandum summarizes the statutory obligations of a “Data Fiduciary” under India’s Digital Personal Data Protection Act, 2023 (DPDP Act). It focuses on Chapter II (Obligations of Data Fiduciary) and related provisions, and notes enforcement and penalties. A short commencement status is included to clarify timing of in‑force provisions. Statutory citations refer to the DPDP

Digital Personal Data Protection Act, 2023 – Research memo on statutory obligations of a “Data Fiduciary” Read More »