DPDP Act FAQ

Short, specific answers to what Indian organisations actually ask about the Digital Personal Data Protection Act. Each question has its own page.

Who must appoint a Data Protection Officer under the DPDP Act?

What is a RoPA?

What is the difference between a RoPA and a data inventory?

What is a Significant Data Fiduciary under the DPDP Act?

What is a Data Fiduciary under the DPDP Act?

What is a Data Principal under the DPDP Act?

What rights do Data Principals have under the DPDP Act?

Who is a Consent Manager under the DPDP Act?

What is a consent management platform?

What makes consent valid under the DPDP Act?

What language must a DPDP notice be in?

What is a Data Protection Impact Assessment (DPIA)?

When does the DPDP Act apply?

Does the DPDP Act apply to startups and small businesses?

What are the penalties under the DPDP Act?

What is the breach notification requirement under the DPDP Act?

How long do we have to respond to a data principal request?

How much does DPDP compliance cost in India?

Does ISO 27001 or SOC 2 make us DPDP compliant?

Where should we start with DPDP compliance?

What is the full form of DPDP?

Can a customer ask us to delete their data under the DPDP Act?

When did the DPDP Act come into force?

Does the DPDP Act apply to companies outside India?

Can we transfer personal data outside India under the DPDP Act?

What is verifiable parental consent under the DPDP Act?

How long can we retain personal data under the DPDP Act?

Do we need consent to process employee data?

Is the DPDP Act the same as GDPR?

Who enforces the DPDP Act?

Do we need a privacy policy under the DPDP Act?

Does the DPDP Act cover B2B and business contact data?

What happens if we ignore a data principal request?

What is a consent artefact?

What is the difference between a DPIA and a PIA?

What is the grievance redressal timeframe under the DPDP Rules?