DPDP Roles, explained simply

India's Digital Personal Data Protection Act. Who is who.

Plain language analysis of the DPDP Act 2023 and the DPDP Rules 2025. Three running series, written so an owner can follow them and a practitioner still finds them precise. Slide each row to see more.

Loopholes in the law

The shortcuts businesses try, and whether they actually work

Sector wise readiness

What the Act means for your line of business
Vendor risk Supply chain and vendor risk: outsourcing does not transfer accountability The series finale, and the layer on top of every sector map. Sub vendors several tiers down are where breaches hide and where the 72 hour clock quietly runs out. 19 Jul 2026 · 5 min Construction Construction and EPC: an offline business, fully in scope Two blind spots pull a concrete pouring firm into the full baseline: subcontractor chains several tiers deep, and biometric worker data at the site gate. 19 Jul 2026 · 4 min Energy Energy and smart metering: the privacy risk is the sampling rate A monthly reading is a number on a bill. At smart meter resolution it shows when a household wakes, cooks and goes on holiday. Minimisation is decided at the meter. 19 Jul 2026 · 4 min Manufacturing Manufacturing: low data volume does not mean no obligation We sell to businesses, not people, is mostly true and still does not get you out. Payroll and biometric attendance trigger the full baseline. One employee is enough. 19 Jul 2026 · 4 min IoT Automotive and IoT: telemetry is a record of a life Everywhere the driver went, a heart rate history, a home. A device that could stream everything usually does, because nobody set a limit at design time. 19 Jul 2026 · 4 min Real estate Real estate and proptech: the lead you bought has a consent history By the third hop nobody can say what that person agreed to. If you cannot show it, you cannot lawfully market to them, and buying the list does not fix it. 19 Jul 2026 · 4 min Retail Retail and omnichannel: the sale needs a payment, not a face Cameras analysing faces, a loyalty card on every basket, a POS holding card details. A data operation with a shopfront attached. 19 Jul 2026 · 4 min Non profit Non profits and NGOs: there is no small charity exemption No non profit exemption, no turnover threshold. The organisations most likely to assume they are exempt often hold the most sensitive beneficiary data of all. 15 Jul 2026 · 4 min Crypto Crypto and VDA exchanges: decentralised is not exempt A high value attack target that cannot erase on request. KYC security to a target grade bar, and the Rule 8(3) proviso documented dataset by dataset, not assumed. 14 Jul 2026 · 4 min Dating Matrimonial and dating: delete account is not erasure The person's data is not in their own row. It is in chats, photos and profiles others saved. Plus hard age assurance, because minor access is the risk that ends companies. 14 Jul 2026 · 4 min Recruitment Recruitment and staffing: the CV you kept for three years The purpose ended when the hiring decision did, but the CV is still searchable and still going to clients. "Might be useful someday" is not a purpose. 14 Jul 2026 · 4 min Prof. services Professional services: the advisers with the weakest controls Law, accounting, consulting and agency firms hold the most sensitive client data on the weakest contracts. Processor per engagement, Fiduciary for your own staff, and a 2015 confidentiality clause is not a DPA. 14 Jul 2026 · 4 min Consent Mgr Consent Managers: a role you apply for Not a tool you buy. A capitalised First Schedule role: registration opens around November 2026, Rs 2 crore net worth, blind routing, seven-year records. 6 Jul 2026 · 4 min Children Children and disability data: the layer no sector escapes Process a minor's or a protected adult's data and the duties apply from record one, whatever your sector or size. Verifiable parental consent, and a hard stop on targeting children. 6 Jul 2026 · 4 min Telecom Telecom and ISPs: retention pulls both ways DPDP says erase when the purpose ends; your licence says keep. The reconciliation, dataset by dataset, is exactly what an auditor wants on paper. 3 Jul 2026 · 4 min Gaming Gaming: the trigger is 50 lakh, not 2 crore E-commerce and social media hit the Third Schedule retention regime at 2 crore users. Online and real money gaming hits it at 50 lakh, a quarter of the bar. 1 Jul 2026 · 5 min AdTech AdTech and data brokers: can you prove provenance? Audience data lives or dies on consent provenance. The baseline applies to all, plus the traps: provenance dataset by dataset, role honesty, cross border, and the child targeting hard stop. 30 Jun 2026 · 5 min Healthcare Healthcare: what applies on day one, and what does not A clinic on its first 500 patients is not Apollo Hospitals. The baseline that always applies, and the child health and erasure traps. 29 Jun 2026 · 4 min Fintech & BFSI Fintech and BFSI: triggered versus day one duties A lending app on 10,000 users is not HDFC Bank. The baseline, the SDF line, and the retention clocks you reconcile on paper. 29 Jun 2026 · 4 min EdTech EdTech: the children's data twist from day one Children's data changes the baseline itself: verifiable parental consent, and an absolute ban on behavioural targeting of minors. 29 Jun 2026 · 4 min E-commerce E-commerce: the 2 crore user line that changes everything Three triggers people blur: the Third Schedule retention regime, SDF notification, and the day one transaction log duty. 29 Jun 2026 · 5 min SaaS & Cloud SaaS and cloud: when a processor becomes a Fiduciary Process on a client's behalf and you are usually a processor. Use that data for your own purposes and the law re-classifies you. 29 Jun 2026 · 4 min HR HR and employee data: the sector everybody is in Holding employee data alone puts the full baseline on you, with no size gate. Why consent is the wrong basis for staff data. 29 Jun 2026 · 4 min AI & ML AI and ML: can you prove a basis for every record? "The training data is public, so we are fine" is the most expensive assumption in AI. Why publicly available is narrower than reachable. 29 Jun 2026 · 5 min

General awareness

The misconceptions that affect almost every organisation
Awareness The bank that linked strangers to your account Staff attached strangers' phone numbers to customer accounts to hit an app target. Nobody broke in. Encryption stops outsiders; the Act governs what insiders may do with data they already hold. 27 Jul 2026 · 4 min Awareness Your startup is not a Consent Manager, and that is fine A consent banner and a grievance form make you a compliant Data Fiduciary. A Consent Manager is a registered Rule 4 role with Rs 2 crore net worth and a data blind platform. 14 Jul 2026 · 4 min Awareness Nine DPDP misconceptions that will not die Too small to be a Fiduciary, consent for everything, 72 hours to report, two crore makes an SDF. Nine assumptions the Act does not actually support, each corrected. 6 Jul 2026 · 5 min Awareness "72 hours" is the most misread number in DPDP breach reporting Two clocks and two audiences, not one deadline. Without delay is the starting gun; 72 hours is only the detailed report to the Board; and availability incidents count too. 6 Jul 2026 · 5 min Awareness Most privacy notices list three rights. The Act gives four. The nomination right and the sharing map limb of access are the two most notices drop, because they cost a system to honour, not just a sentence. 6 Jul 2026 · 4 min Awareness Significant Data Fiduciary is not a size threshold SDF status is conferred by Government notification on sensitivity and risk, not a user count. Size shortens the odds; it does not pull the trigger. 3 Jul 2026 · 5 min Awareness The DPDP Act does not ban cross border transfers A blocked list, not a guest list. Under Section 16 transfer abroad is allowed until the Government restricts a destination. But a stricter sectoral law still wins. 2 Jul 2026 · 4 min Awareness The biggest mistake when outsourcing processing Treating the vendor contract as a transfer of liability. You can outsource the processing. You cannot outsource the accountability. 1 Jul 2026 · 4 min Awareness A Privacy Policy alone is not DPDP compliance A privacy policy tells people what you intend to do. Compliance is whether you can do it, and prove it. One is a paragraph, the other is a system. 30 Jun 2026 · 5 min Awareness Who is actually a Data Fiduciary? The Act does not ask how big your company is. It asks who decided the purpose and means of processing. Why size is the wrong question. 29 Jun 2026 · 5 min Awareness Consent is not the default: understanding Section 7 Consent is the main road. Section 7 gives a few marked exits. There is no lane marked "because it makes commercial sense." 29 Jun 2026 · 5 min

Get DPDP ready in hours, not weeks

Take the readiness assessment and generate your compliance documents from your answers.

Assess My Readiness