Skip to main content

Consently Blog

Expert insights on DPDPA 2023 compliance, data protection, and privacy best practices

Technical
AI Chatbot
LLM

DPDP Compliance for AI Chatbots and LLM Apps Built in India

Your chatbot is a data collection surface with a text box. Users paste Aadhaar numbers, medical histories, and card details into it, your prompts go to a model provider abroad, and every conversation is logged. Here is what the DPDP Act requires of an LLM application built in India — and the architecture that satisfies it.

28 July 202610 min read
Technical
DSAR
Data Principal Rights

DSAR Automation in 2026: Running Data Principal Rights Requests at Volume

The first Data Principal rights request is a curiosity. The five hundredth is an operational crisis. Under the DPDP Act you must verify identity, search every system, respond within your published timeline, and prove you did. Here is how to build a rights workflow that survives volume.

23 July 20269 min read
Technical
Data Retention
Erasure

Data Retention and Erasure Under the DPDP Rules: The Three-Year Clock and How to Automate It

The DPDP Rules attach a hard erasure clock to specified classes of data fiduciary: three years of Data Principal inactivity and the data must go, with 48 hours' notice before deletion. Most Indian companies have never deleted anything. Here is what the rule requires and how to build the machinery.

18 July 20269 min read
Compliance Guides
Consent Manager
DPDPA

DPDP Consent Manager Registration: Eligibility, the ₹2 Crore Net Worth Bar, and the Application Checklist

The Consent Manager framework goes live on 13 November 2026. Registration requires incorporation in India, a minimum net worth of ₹2 crore, and demonstrated technical capability to run consent across fiduciaries. Here is who qualifies, what the application needs, and — importantly — why most businesses should not apply.

14 July 20269 min read
Compliance Guides
HR
Employee Data

Employee Data Under the DPDP Act: What Indian HR Teams Must Fix Before 2027

HR holds more sensitive personal data than marketing ever will — Aadhaar, bank details, medical records, background checks, CCTV, and now productivity monitoring. The DPDP Act covers all of it. The good news: much of it does not need consent. The bad news: most HR teams have no idea which parts do.

10 July 20269 min read
Compliance Guides
SDF
Significant Data Fiduciary

Significant Data Fiduciary Under DPDP: Obligations, DPO Requirements, Audits and Cross-Border Rules

Being designated a Significant Data Fiduciary adds four obligations no ordinary Data Fiduciary has: a resident DPO, an independent data auditor, annual Data Protection Impact Assessments, and algorithmic due diligence. MeitY has also signalled cross-border restrictions for SDFs. Here is what the designation means and how to prepare.

6 July 202610 min read
Industry Insights
AI Governance
MeitY

India's AI Governance Guidelines and the DPDP Act: What the Seven Sutras Mean for Data Fiduciaries

India chose voluntary AI governance and binding data protection. The AI Governance Guidelines released at the AI Impact Summit 2026 set seven principles and three new institutions — but the enforceable obligations on AI systems still come from the DPDP Act. Here is how the two fit together, and what a data fiduciary should actually do.

30 June 20269 min read
Compliance Guides
AI
DPDPA

Can You Train AI on Indian Customer Data? What the DPDP Act Says About AI Training Data

India's DPDP Act has no research exemption for commercial AI, no legitimate-interests basis, and no concept of anonymised-enough. If you are fine-tuning a model on customer support transcripts or building a RAG index over user records, here is what the law actually requires — and what breaks.

23 June 202610 min read
Technical
Google Consent Mode
GTM

Google Consent Mode v2 and the DPDP Act: How Indian Websites Should Configure Tags in 2026

Consent Mode v2 is a Google Ads requirement. The DPDP Act is Indian law. They are not the same thing, and configuring one does not satisfy the other. A practical setup guide for Indian websites running GA4, Google Ads, and Tag Manager under DPDP.

16 June 202610 min read
Compliance Guides
DPDPA
DPDP Rules 2025

The DPDP Act Deadline Calendar: Every Date Between Now and 13 May 2027

The DPDP Rules 2025 set two hard dates: 13 November 2026 for the Consent Manager framework and 13 May 2027 for every core obligation. MeitY has proposed compressing that further. Here is the month-by-month readiness calendar Indian businesses should be working to — with what to finish in each quarter.

10 June 202610 min read
Buyer Guides
DPDPA
Enterprise

Enterprise DPDPA Privacy Platform: What Large Indian Organisations Should Demand in 2026

Enterprise DPDPA compliance is a different problem from installing a banner on one website. Dozens of digital properties, multiple brands, SSO, on-premise mandates, DSAR volume, and vendor risk — a practical requirements guide for large Indian organisations evaluating a DPDPA privacy platform.

5 June 202610 min read
Compliance Guides
DPBI
Data Protection Board

What Is the Data Protection Board of India (DPBI)? Powers, Penalties, and How to Be Ready for It

The Data Protection Board of India is the body that will actually fine you under the DPDP Act — up to ₹250 crore per instance. Yet most Indian businesses can't say what it is, how it works, or what it will ask for. A plain-language explainer on the DPBI: composition, powers, penalty schedule, appeals, and the evidence you should be able to produce.

5 June 20269 min read