DPDP Daily

Harmeet S. Kapoor

India's data protection law, decoded - one practical episode every day. I take the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 out of the statute book and into real life: what the law demands, what businesses get wrong, what regulators will check, and what you can now demand as a citizen. From large enterprises to kirana stores, from consent managers to the ₹250 crore penalty, this is compliance without the jargon, from the author of the DPDP Act Compliance Handbook: From Law to Ground Reality. New episodes daily. Educational content, not legal advice.

  1. 1h ago

    Your Compliance Starting Line: The Nine-Question Self-Assessment

    Twelve episodes of foundations — the countdown, the constitutional history, the cast of characters, the exemptions, the penalties, the regulator, the state's wide lane. Today, theory faces you. Nine questions about your own organisation, each answerable in a minute, each revealing something the foundations arc taught — and by the end, you'll hold what organisations pay consultants lakhs to produce and still don't get straight: an honest picture of your starting line. The nine, scored green, amber or red as things are — not as they're planned: Do we actually know which of our data is digital personal data under this Act? For each data relationship, do we know which character we're playing? Could we produce a current record of what we hold, where, why and with whom it's shared? Can we name the lawful basis behind each processing activity? If a customer demanded access, correction or erasure tomorrow, could we execute? If data leaked tonight, do named people know their roles on the two clocks? Does every vendor touching our data operate under a proper contract? Is there one named human accountable for DPDP compliance? And if the Board asked us to demonstrate our efforts, what could we physically produce today? Then the tally guidance for each profile — and a worked example from advisory work: a two-hundred-person consumer services firm scoring two green, four amber, three red, why that profile is roughly the median serious Indian mid-market company in 2026, and how its first three moves wrote themselves. Why progress in compliance is rarely dramatic — it's ambers eating reds, quarter after quarter. Plus the habit that turns thirty minutes into a governance instrument: date the scorecard, re-score quarterly, file it in the evidence trail. The foundations are laid. Tomorrow, a new arc opens: the Act itself, section by section — beginning with Section 4, the two lawful bases, and the story of why India deliberately refused the "legitimate interest" ground the rest of the world relies on. DPDP Daily takes India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 out of the statute book and into real life — for compliance officers, lawyers, founders, small business owners and citizens. One practical episode every day, no jargon. I'm Harmeet Singh Kapoor, author of the DPDP Act Compliance Handbook: From Law to Ground Reality. Keywords: DPDP self-assessment, DPDP gap assessment, compliance checklist, data mapping, RoPA, lawful basis, breach readiness, vendor contracts, DPDP compliance owner, data protection audit India. Connect with me:💼 LinkedIn: https://www.linkedin.com/in/hskapoor/📄 Facebook: https://www.facebook.com/satarkintelligence▶️ YouTube: https://www.youtube.com/@DPDPdaily🎙️ Apple Podcasts: https://podcasts.apple.com/us/podcast/dpdp-daily/id6793257111𝕏 X: https://x.com/TheOtherKapoor One practical DPDP insight every morning on LinkedIn, Facebook and X — and the DPDP Act Compliance Handbook: From Law to Ground Reality coming soon. This episode is educational commentary, not legal advice. The DPDP framework is in phased implementation and positions described may evolve through notifications, Board publications and judicial interpretation. For decisions affecting your organisation or your rights, consult a qualified professional with your specific facts.

  2. 1d ago

    The Government's Wide Lane: State Exemptions, Powers, and the Puttaswamy Shadow

    Here is the sentence that has launched a hundred editorials about India's data protection law: the government can, by notification, exempt its own instrumentalities from the Act — the same Act written to discipline how everyone handles your data. Critics call it the law's original sin. The government calls it the price of governing a nation of security threats and welfare programmes at continental scale. Both sides are arguing about something real — and this episode presents both at full strength, without caricature. First, what the provisions actually say: Section 17's two levels, the notification power and its grounds — sovereignty, security, friendly relations, public order — plus the government's power to demand information from any fiduciary, the platform-blocking power on repeat penalisation, and the state's different retention posture. Then the criticism, stated properly: elastic grounds, executive notification without per-use parliamentary process, no sunset or independent review, the conflict of a state that is both the largest data collector and the author of its own exemptions — and Justice Srikrishna's own public objections to the widening. Then the defence, equally properly: every data protection law on earth carves out national security; a welfare state at India's scale cannot let benefit delivery die at a consent screen; and notification-by-notification exemption at least creates a paper trail. Then the piece to carry away: the Puttaswamy shadow. A statutory exemption removes the Act's obligations — it cannot remove the fundamental right, and every notification remains testable against legality, legitimate aim, proportionality and safeguards. Plus the instrumentality seam where future litigation will run, the four-question checklist for every government-adjacent contract, what citizens should honestly expect, and why the best answer to the wide-lane criticism would be a state that rarely needs to drive in it. DPDP Daily takes India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 out of the statute book and into real life — for compliance officers, lawyers, founders, small business owners and citizens. One practical episode every day, no jargon. I'm Harmeet Singh Kapoor, author of the DPDP Act Compliance Handbook: From Law to Ground Reality. Keywords: Section 17 DPDP, state exemptions, government data exemption, instrumentality of state, Puttaswamy proportionality, surveillance concerns, DPDP criticism, data protection government, blocking power, DPDP Act debate. Connect with me:💼 LinkedIn: https://www.linkedin.com/in/hskapoor/📄 Facebook: https://www.facebook.com/satarkintelligence▶️ YouTube: https://www.youtube.com/@DPDPdaily🎙️ Apple Podcasts: https://podcasts.apple.com/us/podcast/dpdp-daily/id6793257111𝕏 X: https://x.com/TheOtherKapoor One practical DPDP insight every morning on LinkedIn, Facebook and X — and the DPDP Act Compliance Handbook: From Law to Ground Reality coming soon. This episode is educational commentary, not legal advice. The DPDP framework is in phased implementation and positions described may evolve through notifications, Board publications and judicial interpretation. For decisions affecting your organisation or your rights, consult a qualified professional with your specific facts.

  3. 2d ago

    Inside the Data Protection Board: India's First Digital-Native Regulator

    Every prediction about Indian data protection enforcement rests on one unstated assumption: that complaining is hard — hard enough that citizens won't bother and backlogs will swallow cases. Now consider what Parliament actually built: a regulator required by statute to function as a digital office, receiving complaints, conducting inquiries and pronouncing decisions through techno-legal means, without anyone travelling anywhere. That assumption is precisely what this design exists to destroy. This episode goes inside the Data Protection Board of India. Its structure — chairperson and members appointed by the government, the legal-expertise requirement, and the honest acknowledgment of the independence criticism carried over from the legislative journey. The three doors through which matters arrive: citizen complaints, government references, and the door companies forget — every breach intimation you file lands on the Board's desk as potential inquiry material, which means your breach report is simultaneously a compliance act and an evidentiary submission. Its powers once seized: civil-court powers to summon and compel, interim directions, urgent remedial orders mid-breach, the full penalty schedule, and the voluntary-undertaking settlement valve. The guardrails: natural justice, written reasons, expeditious timelines, and the sixty-day appeal road to TDSAT — where early DPDP jurisprudence will actually crystallise. Then Meera's complaint, walked through the machine end to end — and the fork where identical complaints produce opposite outcomes, decided years earlier by which company built the machinery and kept the records. Why the Board doesn't create your outcome; it reveals your preparation. The four facts that predict enforcement volume will surprise sceptics: near-zero filing friction, self-filling inboxes, India's complaint-culture precedents once friction drops, and a young regulator's need for visible action. And the practical close: why your grievance desk is your first line of regulatory defence, and what to build before the first hearing ever happens. DPDP Daily takes India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 out of the statute book and into real life — for compliance officers, lawyers, founders, small business owners and citizens. One practical episode every day, no jargon. I'm Harmeet Singh Kapoor, author of the DPDP Act Compliance Handbook: From Law to Ground Reality. Keywords: Data Protection Board of India, DPB, digital office regulator, DPDP complaints, TDSAT appeal, data protection enforcement, breach intimation, voluntary undertaking, grievance redressal, DPDP adjudication. Connect with me:💼 LinkedIn: https://www.linkedin.com/in/hskapoor/📄 Facebook: https://www.facebook.com/satarkintelligence▶️ YouTube: https://www.youtube.com/@DPDPdaily🎙️ Apple Podcasts: https://podcasts.apple.com/us/podcast/dpdp-daily/id6793257111𝕏 X: https://x.com/TheOtherKapoor One practical DPDP insight every morning on LinkedIn, Facebook and X — and the DPDP Act Compliance Handbook: From Law to Ground Reality coming soon. This episode is educational commentary, not legal advice. The DPDP framework is in phased implementation and positions described may evolve through notifications, Board publications and judicial interpretation. For decisions affecting your organisation or your rights, consult a qualified professional with your specific facts.

  4. 3d ago

    The ₹250 Crore Question: The Full Penalty Schedule, Decoded

    Two hundred and fifty crore rupees — the number in every DPDP conference deck, every consultant's opening slide, every worried WhatsApp forward between CFOs. And nine out of ten people quoting it can't answer three basic questions: what conduct does it attach to, what are the other numbers in the schedule, and what must the Board weigh before writing any figure at all? Fear of a number is not a compliance strategy. Understanding a penalty architecture absolutely is. This episode lays out the full schedule tier by tier. Up to ₹250 crore for failing reasonable security safeguards — attached to the failure of prevention, not the fact of a breach. Up to ₹200 crore for breach-notification failures and for children's data violations, and what that pairing says about what the state fears most. Up to ₹150 crore for Significant Data Fiduciaries neglecting their added obligations. The ₹50 crore general tier that makes every other provision real. And the ₹10,000 penalty on Data Principals — the asymmetry that is itself a statement about power and accountability. Then the machinery that decides where in a range you land: the mandatory factors the Board must weigh — nature, gravity and duration; the data involved; repetitiveness; gain realised or loss avoided; mitigation and its promptness; proportionality and impact. Why at least half of these are within your control before anything goes wrong, and why your evidence file is literally the difference between the top of a range and the bottom. The GDPR comparison — turnover-linked ceilings versus India's absolute caps, and who each design favours. The voluntary-undertaking exit ramp and why it will dominate the first enforcement years. The two bad reactions — paralysis and cynicism — and the rational posture between them. And a one-hour homework: mapping your organisation against each tier, one honest sentence of exposure and one of evidence. DPDP Daily takes India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 out of the statute book and into real life — for compliance officers, lawyers, founders, small business owners and citizens. One practical episode every day, no jargon. I'm Harmeet Singh Kapoor, author of the DPDP Act Compliance Handbook: From Law to Ground Reality. Keywords: DPDP penalties, 250 crore penalty, DPDP penalty schedule, data breach fine India, Data Protection Board penalties, voluntary undertaking, GDPR fines comparison, security safeguards, SDF obligations, DPDP compliance risk. Connect with me:💼 LinkedIn: https://www.linkedin.com/in/hskapoor/📄 Facebook: https://www.facebook.com/satarkintelligence▶️ YouTube: https://www.youtube.com/@DPDPdaily🎙️ Apple Podcasts: https://podcasts.apple.com/us/podcast/dpdp-daily/id6793257111𝕏 X: https://x.com/TheOtherKapoor One practical DPDP insight every morning on LinkedIn, Facebook and X — and the DPDP Act Compliance Handbook: From Law to Ground Reality coming soon. This episode is educational commentary, not legal advice. The DPDP framework is in phased implementation and positions described may evolve through notifications, Board publications and judicial interpretation. For decisions affecting your organisation or your rights, consult a qualified professional with your specific facts.

  5. 4d ago

    The Phased Timeline Decoded: What's Law Today Versus May 2027

    Somewhere in India today, a company lawyer is telling a boardroom: "The DPDP Act isn't really in force yet — we have time." Somewhere else, a consultant is telling a different boardroom: "You're already violating a live statute." Both are pointing at the same Gazette notifications, both are half-right, and each half-truth is dangerous alone. This episode decodes the phased commencement precisely. Why an Act passed in August 2023 stayed dormant for over two years, and what actually happened in November 2025. Wave one, live today: the definitions, the Data Protection Board, its digital-office design and the appeal architecture to TDSAT. Wave two, this November: the Consent Manager registration framework activates. Wave three, 13 May 2027: everything else — notices, consent, security safeguards, breach reporting clocks, retention, children's data, rights and grievance machinery. Then what the calendar actually means for behaviour. Why "largely not enforceable yet" comes with three corrections: the IT Act ecosystem, CERT-In directions and sectoral regulators never paused; enterprise contracts are already writing DPDP-readiness into vendor agreements, making the standard commercially binding regardless of the Gazette; and every unmapped database you accumulate now is remediation work bought at tomorrow's prices. Why the eighteen-month runway is a preparation period, not a grace period — and why "we started in April" will be an aggravating fact before the Board, not a defence. The three myths, named and dismantled. Per-audience quarterly actions for enterprises and SMEs, including the contract-clause check I'll wager at least one of your three largest customer agreements fails. And the four-channel regulatory watch that hears the next wave before your competitors do. DPDP Daily takes India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 out of the statute book and into real life — for compliance officers, lawyers, founders, small business owners and citizens. One practical episode every day, no jargon. I'm Harmeet Singh Kapoor, author of the DPDP Act Compliance Handbook: From Law to Ground Reality. Keywords: DPDP timeline, DPDP enforcement date, May 2027 deadline, DPDP Rules commencement, phased implementation, Consent Manager November 2026, Data Protection Board, CERT-In, DPDP compliance deadline, data protection India. Connect with me:💼 LinkedIn: https://www.linkedin.com/in/hskapoor/📄 Facebook: https://www.facebook.com/satarkintelligence▶️ YouTube: https://www.youtube.com/@DPDPdaily🎙️ Apple Podcasts: https://podcasts.apple.com/us/podcast/dpdp-daily/id6793257111𝕏 X: https://x.com/TheOtherKapoor One practical DPDP insight every morning on LinkedIn, Facebook and X — and the DPDP Act Compliance Handbook: From Law to Ground Reality coming soon. This episode is educational commentary, not legal advice. The DPDP framework is in phased implementation and positions described may evolve through notifications, Board publications and judicial interpretation. For decisions affecting your organisation or your rights, consult a qualified professional with your specific facts.

  6. 5d ago

    What the Act Does NOT Cover: The Exemptions Map

    A compliance riddle: an Indian IT company processes ten million French customers' data for a European client — largely exempt from the DPDP Act. The same company's two thousand employee records, on the same servers — fully covered. A bank chasing a defaulter needs no consent. A court processing your data answers to no notice requirement at all. None of this is scandal; it's design — and knowing the edges of a law matters as much as knowing its centre. This episode maps everything outside the DPDP Act's reach, starting with the distinction people constantly confuse: matters outside the Act's scope altogether versus processing inside scope but exempted by Section 17 — conditional, purpose-bound, and narrower than the headlines. The offshore processing carve-out that shapes India's biggest industry, and why it covers the delivery work but never the house: your employees, Indian customers and vendors remain fully in scope. The enforcement cluster — legal rights and claims, courts, and investigation of offences — and the purpose-boundedness that keeps an exemption from becoming a loophole. The research and statistics exemption and its conditions. The merger and amalgamation exemption almost nobody discusses, why it moves data across a transaction without sanctifying what the buyer does afterwards, and why data due diligence is becoming standard M&A hygiene. Plus the startup notification power, and a worked example — a lending fintech with four data streams and four different answers — showing why exemption strategy is mostly data architecture wearing a legal hat. The episode closes with the practitioner's four-question method for any exemption claim: scope or exemption? Which provision? What purpose bounds it? And what happens at the edges? An exemption you can cite, bound and evidence is a legal position. An exemption you merely feel entitled to is a finding waiting to happen. DPDP Daily takes India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 out of the statute book and into real life — for compliance officers, lawyers, founders, small business owners and citizens. One practical episode every day, no jargon. I'm Harmeet Singh Kapoor, author of the DPDP Act Compliance Handbook: From Law to Ground Reality. Keywords: DPDP Act exemptions, Section 17, offshore processing exemption, IT BPO data processing, legal rights enforcement, merger data transfer, M&A data due diligence, research exemption, startup exemption, DPDP scope, data protection India. Connect with me:💼 LinkedIn: https://www.linkedin.com/in/hskapoor/📄 Facebook: https://www.facebook.com/satarkintelligence▶️ YouTube: https://www.youtube.com/@DPDPdaily🎙️ Apple Podcasts: https://podcasts.apple.com/us/podcast/dpdp-daily/id6793257111𝕏 X: https://x.com/TheOtherKapoor One practical DPDP insight every morning on LinkedIn, Facebook and X — and the DPDP Act Compliance Handbook: From Law to Ground Reality coming soon. This episode is educational commentary, not legal advice. The DPDP framework is in phased implementation and positions described may evolve through notifications, Board publications and judicial interpretation. For decisions affecting your organisation or your rights, consult a qualified professional with your specific facts.

  7. 6d ago

    What Counts as Personal Data: The Definition That Decides Everything

    A shopkeeper keeps his customers' udhaar entries in a paper register. His neighbour keeps the same entries in a phone app. Same names, same amounts, same purpose — and under the DPDP Act, one of them is processing regulated personal data while the other, for that register at least, sits outside the Act entirely. Before any talk of consent or penalties, every situation must pass through one gate: is this personal data, in digital form, within the Act's scope? This episode unpacks the definition phrase by phrase. "Any data" — why India rejected the old closed-list approach, and why your health record and your food preferences now sit in the same legal category, though flattened categories never meant flattened risk. "About an individual" — including the expensive myth that B2B companies are outside this law, when every business email and vendor contact is personal data. "Identifiable" — the singling-out test, why customer IDs with a mapping table are pseudonymisation rather than anonymisation, and why genuine anonymisation is a higher bar than most teams assume. Then the digital-only boundary that surprises everyone: what the paper carve-out really covers, why it's narrower than it looks when every process eventually digitises, and why retreating to paper is choosing the wrong century. The exclusions map — personal and domestic use, publicly available data and the edges of that carve-out. And the borderline cases that fill my inbox: CCTV footage as personal data, biometric attendance machines and why a leaked fingerprint can't be changed like a password, and the WhatsApp boundary — where the family group ends and the business broadcast list begins, because the device doesn't determine the law; the purpose does. The episode closes with a five-minute scoping drill on your own organisation's data — the map everything else in this series operates inside. DPDP Daily takes India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 out of the statute book and into real life — for compliance officers, lawyers, founders, small business owners and citizens. One practical episode every day, no jargon. I'm Harmeet Singh Kapoor, author of the DPDP Act Compliance Handbook: From Law to Ground Reality. Keywords: personal data definition, DPDP Act scope, digital personal data, identifiability, anonymisation, pseudonymisation, CCTV personal data, biometric data, WhatsApp business data, paper records exemption, data protection India. Connect with me:💼 LinkedIn: https://www.linkedin.com/in/hskapoor/📄 Facebook: https://www.facebook.com/satarkintelligence▶️ YouTube: https://www.youtube.com/@DPDPdaily🎙️ Apple Podcasts: https://podcasts.apple.com/us/podcast/dpdp-daily/id6793257111𝕏 X: https://x.com/TheOtherKapoor One practical DPDP insight every morning on LinkedIn, Facebook and X — and the DPDP Act Compliance Handbook: From Law to Ground Reality coming soon. This episode is educational commentary, not legal advice. The DPDP framework is in phased implementation and positions described may evolve through notifications, Board publications and judicial interpretation. For decisions affecting your organisation or your rights, consult a qualified professional with your specific facts.

  8. Jul 27

    The Cast of Characters: Who's Who in the DPDP Framework

    Order food on any delivery app tonight and you've just set five legal roles in motion. You're one of them. The app is another. The cloud company hosting your order history is a third. A platform you've never heard of may soon manage your consent as a fourth. And standing over the whole transaction is a regulator that works entirely through a digital office. The entire DPDP Act is written as duties attached to roles — miscast any of them and every compliance decision downstream goes wrong. This episode makes the full cast concrete through one running example. The Data Principal — why India's law calls you a principal rather than a "user" or "data subject," and what that one word announces about who the data belongs to. The Data Fiduciary — the entity deciding purpose and means, carrying nearly every obligation in the Act, and why Parliament chose a relationship word loaded with duty over Europe's neutral "controller." The Data Processor — executing on instructions, with accountability routed through the fiduciary, which is exactly why your vendors' discipline is now your liability. The Consent Manager — the Board-registered dashboard whose registration window opens this November. And the Data Protection Board itself, with the Significant Data Fiduciary designation as the promotion that doubles your compliance burden. Then the harder drills: role-mapping a mid-sized hospital, where the diagnostic lab is a processor, the insurer is a second fiduciary, the telemedicine platform wears both hats depending on which door the patient entered through — and the hospital is a fiduciary all over again for its own two thousand employees. Plus a direct word to processors: why "the fiduciary carries the obligations" is not a holiday, how compliance is becoming a sales asset in the vendor market, and the fifteen-minute placement exercise that produces more clarity than most workshops. DPDP Daily takes India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 out of the statute book and into real life — for compliance officers, lawyers, founders, small business owners and citizens. One practical episode every day, no jargon. I'm Harmeet Singh Kapoor, author of the DPDP Act Compliance Handbook: From Law to Ground Reality. Keywords: Data Fiduciary, Data Principal, Data Processor, Consent Manager, Significant Data Fiduciary, SDF, Data Protection Board of India, DPDP Act roles, DPDP compliance, data protection India. Connect with me:💼 LinkedIn: https://www.linkedin.com/in/hskapoor/📄 Facebook: https://www.facebook.com/satarkintelligence▶️ YouTube: https://www.youtube.com/@DPDPdaily🎙️ Apple Podcasts: https://podcasts.apple.com/us/podcast/dpdp-daily/id6793257111𝕏 X: https://x.com/TheOtherKapoor One practical DPDP insight every morning on LinkedIn, Facebook and X — and the DPDP Act Compliance Handbook: From Law to Ground Reality coming soon. This episode is educational commentary, not legal advice. The DPDP framework is in phased implementation and positions described may evolve through notifications, Board publications and judicial interpretation. For decisions affecting your organisation or your rights, consult a qualified professional with your specific facts.

About

India's data protection law, decoded - one practical episode every day. I take the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 out of the statute book and into real life: what the law demands, what businesses get wrong, what regulators will check, and what you can now demand as a citizen. From large enterprises to kirana stores, from consent managers to the ₹250 crore penalty, this is compliance without the jargon, from the author of the DPDP Act Compliance Handbook: From Law to Ground Reality. New episodes daily. Educational content, not legal advice.