The same Act, different exposure
The obligations are uniform. What varies is the volume of personal data, the sensitivity of it, and how much of it was collected before anyone asked.
- DPDP Compliance for Startups
18 September 2026
The startup exemption exists. It has not been granted to you.
Sec. 17(3) lets the government exempt notified startups from five provisions. Until a notification names you, every duty applies — in this order.
- DPDP Compliance for HR and Employers
18 September 2026
Most of HR does not run on consent, and that is the point
Sec. 7(i) makes employment a legitimate use, so most HR processing is not consent-based. Safeguards, breach duties and your vendor chain still apply.
- DPDP Compliance for Schools and Colleges
18 September 2026
A school roll is almost entirely children under this Act
A school roll is almost entirely children under the Act. What Rule 12 exempts, where it stops, and why colleges cannot assume they have no children.
- DPDP Compliance for EdTech Companies
18 September 2026
The exemption schools have does not travel to their vendors
EdTech processes children's data at scale. What Sec. 9 forbids, and why the Fourth Schedule exemption a school holds does not travel to its vendors.
- DPDP Compliance for E-commerce
18 September 2026
The consent is easy. The erasure clock is the surprise.
Marketing consent, cookie and SDK tracking, and the Third Schedule's three-year erasure rule for platforms above two crore registered users.
- DPDP Compliance for Banks and BFSI
16 September 2026
You already collect consent. The Act asks a different question.
Financial services already run KYC and RBI consent regimes. Where the DPDP Act overlaps with them, and where it asks for something those regimes never did.
- DPDP Compliance for Healthcare Providers
28 August 2026
Health data, and an Act with no sensitive category
Health data is personal data under the DPDP Act, with no sensitive category. What hospitals and diagnostics chains must change before 13 May 2027.