Blog & updates
DPDP, in plain English.
News, deadline reminders and guides for Indian website owners working through the DPDP Act.
Showing 7–12 of 30
Page 2 of 5
- Guide
DPDP consent-banner requirements — exactly what your Indian website needs
Section 6 and Section 7 of the DPDP Act define what 'consent' actually means under Indian law — and almost every Indian website's cookie banner fails at least one of the criteria. Here is a banner-by-banner spec, with concrete examples of what passes and what does not.
Read article
- Guide
How much could a DPDP violation actually cost your business?
The DPDP Act's Schedule lists five graded penalty bands up to ₹250 crore. The Board does not pick the headline number by default — Section 33(2) gives it a six-factor framework that scales the actual fine. Here is the practical math for an Indian SMB, mid-market and SDF.
Read article
- Guide
DPDP Section 8 security headers — the exact HTTP-header stack Indian websites should ship
Section 8(5) carries the highest penalty band in the Act — ₹250 crore. A surprising chunk of that exposure is closeable with seven HTTP headers any backend can emit in one config change. Here is the exact stack, the configured values, and the order to roll it out without breaking your site.
Read article
- Guide
DPDP for Indian edtech — verifiable parental consent, Section 9 prohibitions, and what compliance looks like
Indian edtech sits at the worst-case intersection of the DPDP Act — children's data at scale, Section 9 prohibitions on tracking and targeted ads, mandatory verifiable parental consent. Here is the actual compliance stack for an edtech startup or platform.
Read article
- Guide
How websites quietly defraud Indian users — and 5 checks every Data Principal should run
Indian websites are taking your data in ways the DPDP Act now forbids — dark-pattern consent, ghost trackers, fake withdrawal links, silent profile sales. Here are the five 60-second checks that tell you if a site is safe before you hand over a number, address or payment.
Read article
- Guide
The Indian data breaches you can still get hit by — and the steps every user should take this week
Air India, BigBasket, AIIMS Delhi, BoAt — millions of Indian records have been on sale on the open web since 2021. Here's what was leaked, what fraudsters do with it, and the seven concrete steps to take right now to limit your exposure.
Read article