India’s digital personal data protection regime turns questions that were once IT policy into questions of statutory obligation. Which data a business may collect, on what notice, kept for how long, shared with whom, and answered for before which authority. The regime is young, its delegated legislation is still arriving, and businesses must build now for rules that will harden later.
The work
The practice maps how the statute applies to a specific business. What personal data it actually processes, in which role, under which lawful basis, and which obligations follow in notices, consent, retention, security and grievance handling. It drafts the documents that carry compliance, including privacy notices, consent language, data-processing and sharing agreements, and the internal policies that make them true.
When something goes wrong, the practice supports incident response. Establishing what happened, what the statute requires to be reported and to whom, and how to communicate without creating liability the facts do not require.
How the practice approaches it
Data-protection advice fails when it is written for an imaginary company. The practice works from the client’s real data flows, verifies each obligation in the statute and the rules as actually notified, and marks clearly which requirements are in force, which await delegated legislation, and which are prudent practice rather than law. Compliance built on that honesty survives audits and incidents alike.