Skip to content
RegulensR

Compliance domain

DPDP, CERT-In and a sectoral layer on top

India’s data obligations arrive from three directions at once: the DPDP Act as horizontal law applying to everyone, CERT-In directions with a six-hour clock, and sector-specific frameworks from RBI, SEBI, IRDAI and DoT. A regulated entity meets all three; an unregulated one still meets the first two.

2,100+ obligations

maintained across Central, state and municipal levels

Applies to

Every organisation processing digital personal data — which is every organisation

2,100+
data and cyber obligations
6 hours
CERT-In clock, tracked with escalation
3 layers
horizontal, sectoral and contractual mapped together

What the domain contains

The obligation groups we maintain

Each of these decomposes into individual obligations with an actor, an action, a trigger and a deadline, cited to the section or rule it comes from.

Notice and consent

Itemised notice in English or any Eighth Schedule language, free and specific consent, withdrawal as easy as giving, and consent manager interaction where used.

Data principal rights

Access, correction, erasure and grievance redressal within prescribed timelines, with a published contact for the Data Protection Officer or authorised person.

Breach intimation

Intimation to every affected data principal and to the Data Protection Board — without the materiality threshold that most global privacy regimes provide.

CERT-In incident reporting

Six hours from noticing, across twenty categories of incident, with 180-day log retention within India and NTP synchronisation.

Significant Data Fiduciary duties

Data Protection Officer based in India, independent data audit, and Data Protection Impact Assessment for entities notified as significant.

Sectoral cyber frameworks

RBI IT Governance Directions, SEBI CSCRF, IRDAI cyber guidelines and DoT telecom cyber rules — overlapping but not identical.

Why it goes wrong

The failure modes we see most often

01

Six hours is an operational design constraint

CERT-In’s reporting window is shorter than most incident triage processes take to confirm an incident happened. It has to be designed for, not procedurally documented.

02

DPDP has no materiality threshold for breach

Unlike GDPR, every personal data breach requires intimation. Organisations that ported a GDPR-shaped process will under-report.

03

Consent for existing data

Notice must be given to data principals whose data was collected before the Act. For a consumer business with fifty million records, that is a programme, not a task.

Coverage

Principal legislation in this domain

A representative list. State variants of each are maintained separately, because they differ in ways that matter operationally.

  • DPDP Act, 2023 and Rules
  • CERT-In Directions, 2022
  • IT Act, 2000 and IT Rules, 2021
  • RBI IT Governance Directions
  • SEBI CSCRF, 2024
  • Telecom Cyber Security Rules, 2024

Explore the full library in the regulation explorer, or see the compliance calendar for what falls due next.

Across industries

This domain does not care what you manufacture

Domain obligations apply by activity, headcount, turnover and location — not by sector code. What changes between industries is how much of the domain lands on you, and which sectoral rules stack on top.

See data, privacy & cyber obligations scoped to your sites

We configure your entities, locations and states, and show you exactly which obligations in this domain land where — including the ones nobody currently owns.