How to implement the DPDP Act
When you visit many global websites, you will instantly be prompted to accept or reject cookies. That’s for you to tell the company whether you are ok with them collecting and using your data. If it’s a website you frequent, there are advantages in accepting the cookies, because you may then not have to key in information about yourself every time, it’ll offer you personalised recommendations and ads, pages may open faster. But then you may have to deal with frequent marketing messages, including maybe from the company’s partners.
If you reject the cookies, you forego the advantages, but you will be saved from a lot of spam and marketing calls and messages.
The European Union’s General Data Protection Regulation (GDPR) is the current gold standard in rules for collecting, processing, and storing personal data of individuals. India in 2023 passed a similar law – Digital Personal Data Protection Act (DPDPA) – and published detailed rules around it last year. Every entity handling personal data is mandated to implement it fully by May, 2027.
We had a discussion on what this entails for organisations, and we would urge you to listen to it on our Facebook or YouTube page – because it deeply impacts every organisation that collects personal data.
The discussion was in association with ManageEngine, the division of Zoho Corporation that offers a comprehensive IT management portfolio. Sreedharan K S, director of compliance at Zoho Corp, noted that India’s law, unlike the EU one, is only for digital data. He said the focus is on informed consent as the basis for processing of data. The govt, he said, has specified some situations where data can be processed without consent – like during disasters or public health emergencies.
Shreyashi Sengupta, partner for digital trust technology risk automation at KPMG, said the Act really empowers users. “I’m allowed to exercise my consent, I need to be told what my information is being used for, and I have the right to terminate my consent and ask that my data be erased,” she said. If there’s a data breach, the law demands that affected parties be informed immediately.
The Act also imposes strict, mandatory compliance requirements for the continued processing and storage of historical data. And organisations that have been around a long time will have lots of legacy data.
Enabling and dealing with all of this will require substantial effort, which explains why the govt has given some time to organisations to comply. Sreedharan noted that the effort will have to start with asset management – “you have to first discover where the data is, and then you have to map which data is personal, how important it is, whether it is required.” This part will be painful. Shreyashi noted that the IT landscape in enterprises today is vast, and data would be in multiple places. “You need to track the content not only on one application, but what the effects of it are on downstream and upstream applications,” she said.
Given how long the exercise would be, Shreyashi recommended that organisations focus first on customer facing applications, and user consent preference management. “Once that gets going, then look at things like breach notification. The data discovery process is a lifelong exercise, and that can keep happening in parallel,” she said. Companies can build their own consent management platforms, or connect to independent consent managers that are emerging to provide centralised dashboards for users to give, manage, and withdraw consent across multiple platforms.
Multi-language capabilities will be essential on websites to guarantee informed consent. “Bhashini APIs could be used for this as a start,” Sreedharan said, referring to the govt’s AI-powered multilingual platform.
Israel Iran War
The European Union’s General Data Protection Regulation (GDPR) is the current gold standard in rules for collecting, processing, and storing personal data of individuals. India in 2023 passed a similar law – Digital Personal Data Protection Act (DPDPA) – and published detailed rules around it last year. Every entity handling personal data is mandated to implement it fully by May, 2027.
The discussion was in association with ManageEngine, the division of Zoho Corporation that offers a comprehensive IT management portfolio. Sreedharan K S, director of compliance at Zoho Corp, noted that India’s law, unlike the EU one, is only for digital data. He said the focus is on informed consent as the basis for processing of data. The govt, he said, has specified some situations where data can be processed without consent – like during disasters or public health emergencies.
Shreyashi Sengupta, partner for digital trust technology risk automation at KPMG, said the Act really empowers users. “I’m allowed to exercise my consent, I need to be told what my information is being used for, and I have the right to terminate my consent and ask that my data be erased,” she said. If there’s a data breach, the law demands that affected parties be informed immediately.
The Act also imposes strict, mandatory compliance requirements for the continued processing and storage of historical data. And organisations that have been around a long time will have lots of legacy data.
Enabling and dealing with all of this will require substantial effort, which explains why the govt has given some time to organisations to comply. Sreedharan noted that the effort will have to start with asset management – “you have to first discover where the data is, and then you have to map which data is personal, how important it is, whether it is required.” This part will be painful. Shreyashi noted that the IT landscape in enterprises today is vast, and data would be in multiple places. “You need to track the content not only on one application, but what the effects of it are on downstream and upstream applications,” she said.
Given how long the exercise would be, Shreyashi recommended that organisations focus first on customer facing applications, and user consent preference management. “Once that gets going, then look at things like breach notification. The data discovery process is a lifelong exercise, and that can keep happening in parallel,” she said. Companies can build their own consent management platforms, or connect to independent consent managers that are emerging to provide centralised dashboards for users to give, manage, and withdraw consent across multiple platforms.
Popular from Technology
- Amazon sends letter to FCC saying: Reject application of Elon Musk's Spacex for Space data centers; gives three reasons to dismiss
- Mark Zuckerberg's Meta acquires AI agent social network Moltbook that rival Sam Altman made ‘fun of’ by saying …
- OpenAI loses 1.5 million subscribers in less than 48 hours after CEO Sam Altman says yes to the deal that Anthropic rejected
- Sam Altman replies to Nvidia CEO Jensen Huang’s expanded 'Like Mad' for OpenAI comment on stage; says ‘very …’
- Tesla investor shares video of Nvidia-backed Figure’s Humanoid robot cleaning living room; gets a query from Elon Musk
end of article
Trending Stories
- US-Israel-Iran War News Live Updates: UAE embassy in Iraq attacked, Hezbollah drones target Israel
- Made-in-India bullet train to run on Ahmedabad-Mumbai route in 2027
- Flagging dangers of social media, SC to hear Centre plea on fact-check units
- 'Brain-dead' woman jolted back to life by pothole in UP
- UCC key to end gender bias in laws: SC
- India considering naval escort for ships in Strait of Hormuz amid Iran war: Report
- 'Ispe mein kya bolun?': Ishan Kishan gets annoyed after winning T20 World Cup 2026 title - Watch
Featured in technology
- Elon Musk responds to report claiming Amazon to hold engineering meeting today following outages; says: Proceed with ...
- Redmi Pad 2 Pro review: Steps up the game
- OpenAI and Google employees file Amicus brief in support of Anthropic; say: We are engineers, researchers, scientists employed at American AI labs who ...
- Google supercharges Docs, Sheets, Slides and Drive with Gemini AI-powered features: What is changing
- Mark Zuckerberg acquires AI agent social network Moltbook that rival Sam Altman made ‘fun of’ by saying …
- Tesla Robotaxi backend director Thomas Dmytryk bids goodbye to the company after eleven years; writes 'why now' in a long LinkedIn post
Photostories
- Colon cancer is rising in younger adults: Doctors explain how sedentary lifestyles, poor bowel habits and diet increase risk and the daily habits that help prevent it
- Meet Marta Ortega Pérez: The billionaire heiress redefining the Zara empire
- How to make Street-Style Chowmein at home
- 10 countries with the most cultural influence in the world
- LPG Gas Cylinder Shortage: 7 popular gas-stove dishes you can make in a microwave
- Rashmika Mandanna and Vijay Deverakonda’s Pradhanam-Mehendi festivities were a kaleidoscope of couture and tradition | See photos
- Fake turmeric powder in the market? How to check the purity of turmeric powder at home and 5 ways to consume it
- Interstellar, Einstein and the strange elasticity of time
- Rumoured couple Trisha Krishnan and Vijay Thalapathy step out in matching style – is this twinning intentional?
- Inside Mohammed Siraj’s Car Collection: 5 luxury cars owned by the Indian fast bowler
Up Next
Start a Conversation
Post comment