Gurugram is India's densest concentration of global capability centres, insurers and consumer-finance businesses. The characteristic problem here is not ignorance of privacy but the assumption that a parent company's global programme already covers India — GCCs frequently discover their group GDPR framework was never mapped to DPDP at all.
Where processing is performed in India for a group entity abroad, the fiduciary/processor split has to be settled in writing before anything else. Getting it wrong means applying processor logic to data you are actually accountable for.
Insurance and consumer lending add the retention-versus-erasure tension in its sharpest form, because policy and underwriting records carry their own statutory retention periods.
ProtectComply is built by Exuverse, whose team sits in Noida. We work with organisations across India — remotely for most of a programme, in person when discovery or a workshop genuinely needs it.
Not automatically. There is real overlap, but DPDP has its own definitions, lawful bases, notice-language expectations and Significant Data Fiduciary regime. Assuming coverage is the most common and expensive error in this sector.
Usually a processor for the group's data and a fiduciary for its own employee, recruitment and vendor data. Settling that split in writing is the first step.
Jupinder Bedi — Jupinder writes on data protection practice at ProtectComply, with a focus on how obligations translate into system behaviour.
Take the free readiness check and find out in 10 minutes.
Start free readiness check →