Breach and enforcement
Is a privacy policy enough for DPDP compliance?
- Short answer
- No. A privacy policy is a statement of what you intend to do. Compliance is the system that proves you actually did it. Publishing a policy you do not follow is worse than useless, because it becomes evidence of what you promised.
The Act's duties are operational. Erasing data when the purpose ends, answering a grievance within ninety days, notifying a breach, honouring a rights request, binding your processors by contract: none of these are satisfied by a document.
The specific trap is a policy that describes practices you do not have. A notice claiming that data is deleted after twelve months, on a system that deletes nothing, states your obligation and simultaneously evidences your failure to meet it.
Start from what your systems actually do, fix the gaps that matter, and let the policy describe the result.
Where this comes from
- Section 8, DPDP Act 2023
The mistake people make
Buying a policy, publishing it unread, and treating the project as finished.