Consently Blog
Expert insights on DPDPA 2023 compliance, data protection, and privacy best practices
DPDP Compliance for AI Chatbots and LLM Apps Built in India
Your chatbot is a data collection surface with a text box. Users paste Aadhaar numbers, medical histories, and card details into it, your prompts go to a model provider abroad, and every conversation is logged. Here is what the DPDP Act requires of an LLM application built in India — and the architecture that satisfies it.
DSAR Automation in 2026: Running Data Principal Rights Requests at Volume
The first Data Principal rights request is a curiosity. The five hundredth is an operational crisis. Under the DPDP Act you must verify identity, search every system, respond within your published timeline, and prove you did. Here is how to build a rights workflow that survives volume.
Data Retention and Erasure Under the DPDP Rules: The Three-Year Clock and How to Automate It
The DPDP Rules attach a hard erasure clock to specified classes of data fiduciary: three years of Data Principal inactivity and the data must go, with 48 hours' notice before deletion. Most Indian companies have never deleted anything. Here is what the rule requires and how to build the machinery.
DPDP Consent Manager Registration: Eligibility, the ₹2 Crore Net Worth Bar, and the Application Checklist
The Consent Manager framework goes live on 13 November 2026. Registration requires incorporation in India, a minimum net worth of ₹2 crore, and demonstrated technical capability to run consent across fiduciaries. Here is who qualifies, what the application needs, and — importantly — why most businesses should not apply.
Employee Data Under the DPDP Act: What Indian HR Teams Must Fix Before 2027
HR holds more sensitive personal data than marketing ever will — Aadhaar, bank details, medical records, background checks, CCTV, and now productivity monitoring. The DPDP Act covers all of it. The good news: much of it does not need consent. The bad news: most HR teams have no idea which parts do.
Significant Data Fiduciary Under DPDP: Obligations, DPO Requirements, Audits and Cross-Border Rules
Being designated a Significant Data Fiduciary adds four obligations no ordinary Data Fiduciary has: a resident DPO, an independent data auditor, annual Data Protection Impact Assessments, and algorithmic due diligence. MeitY has also signalled cross-border restrictions for SDFs. Here is what the designation means and how to prepare.
India's AI Governance Guidelines and the DPDP Act: What the Seven Sutras Mean for Data Fiduciaries
India chose voluntary AI governance and binding data protection. The AI Governance Guidelines released at the AI Impact Summit 2026 set seven principles and three new institutions — but the enforceable obligations on AI systems still come from the DPDP Act. Here is how the two fit together, and what a data fiduciary should actually do.
Can You Train AI on Indian Customer Data? What the DPDP Act Says About AI Training Data
India's DPDP Act has no research exemption for commercial AI, no legitimate-interests basis, and no concept of anonymised-enough. If you are fine-tuning a model on customer support transcripts or building a RAG index over user records, here is what the law actually requires — and what breaks.
Google Consent Mode v2 and the DPDP Act: How Indian Websites Should Configure Tags in 2026
Consent Mode v2 is a Google Ads requirement. The DPDP Act is Indian law. They are not the same thing, and configuring one does not satisfy the other. A practical setup guide for Indian websites running GA4, Google Ads, and Tag Manager under DPDP.
The DPDP Act Deadline Calendar: Every Date Between Now and 13 May 2027
The DPDP Rules 2025 set two hard dates: 13 November 2026 for the Consent Manager framework and 13 May 2027 for every core obligation. MeitY has proposed compressing that further. Here is the month-by-month readiness calendar Indian businesses should be working to — with what to finish in each quarter.
Enterprise DPDPA Privacy Platform: What Large Indian Organisations Should Demand in 2026
Enterprise DPDPA compliance is a different problem from installing a banner on one website. Dozens of digital properties, multiple brands, SSO, on-premise mandates, DSAR volume, and vendor risk — a practical requirements guide for large Indian organisations evaluating a DPDPA privacy platform.
What Is the Data Protection Board of India (DPBI)? Powers, Penalties, and How to Be Ready for It
The Data Protection Board of India is the body that will actually fine you under the DPDP Act — up to ₹250 crore per instance. Yet most Indian businesses can't say what it is, how it works, or what it will ask for. A plain-language explainer on the DPBI: composition, powers, penalty schedule, appeals, and the evidence you should be able to produce.