Compliance domain
DPDP, CERT-In and a sectoral layer on top
2,100+ obligations
maintained across Central, state and municipal levels
Applies to
Every organisation processing digital personal data — which is every organisation
- 2,100+
- data and cyber obligations
- 6 hours
- CERT-In clock, tracked with escalation
- 3 layers
- horizontal, sectoral and contractual mapped together
What the domain contains
The obligation groups we maintain
Each of these decomposes into individual obligations with an actor, an action, a trigger and a deadline, cited to the section or rule it comes from.
Notice and consent
Itemised notice in English or any Eighth Schedule language, free and specific consent, withdrawal as easy as giving, and consent manager interaction where used.
Data principal rights
Access, correction, erasure and grievance redressal within prescribed timelines, with a published contact for the Data Protection Officer or authorised person.
Breach intimation
Intimation to every affected data principal and to the Data Protection Board — without the materiality threshold that most global privacy regimes provide.
CERT-In incident reporting
Six hours from noticing, across twenty categories of incident, with 180-day log retention within India and NTP synchronisation.
Significant Data Fiduciary duties
Data Protection Officer based in India, independent data audit, and Data Protection Impact Assessment for entities notified as significant.
Sectoral cyber frameworks
RBI IT Governance Directions, SEBI CSCRF, IRDAI cyber guidelines and DoT telecom cyber rules — overlapping but not identical.
Why it goes wrong
The failure modes we see most often
Six hours is an operational design constraint
CERT-In’s reporting window is shorter than most incident triage processes take to confirm an incident happened. It has to be designed for, not procedurally documented.
DPDP has no materiality threshold for breach
Unlike GDPR, every personal data breach requires intimation. Organisations that ported a GDPR-shaped process will under-report.
Consent for existing data
Notice must be given to data principals whose data was collected before the Act. For a consumer business with fifty million records, that is a programme, not a task.
Coverage
Principal legislation in this domain
A representative list. State variants of each are maintained separately, because they differ in ways that matter operationally.
- DPDP Act, 2023 and Rules
- CERT-In Directions, 2022
- IT Act, 2000 and IT Rules, 2021
- RBI IT Governance Directions
- SEBI CSCRF, 2024
- Telecom Cyber Security Rules, 2024
Explore the full library in the regulation explorer, or see the compliance calendar for what falls due next.
Across industries
This domain does not care what you manufacture
Domain obligations apply by activity, headcount, turnover and location — not by sector code. What changes between industries is how much of the domain lands on you, and which sectoral rules stack on top.
Other domains
The rest of the stack
Corporate & Secretarial
The obligations that attach to the entity, whatever it makes
11,200+ obligations across statesLabour & Employment
Four Codes, thirty-six sets of state rules, one payroll
4,600+ obligationsEHS & Environment
Consents, waste, emissions and the compensation formula
3,300+ obligationsTax, GST & Customs
One company, many GSTINs, and a re-sectioned Income-tax Act
2,800+ obligationsProduct Standards & Quality
QCOs, labelling and the six-month window before your product is illegal
5,400+ obligationsSectoral Licensing
The licence conditions nobody reads after the licence is granted
900+ obligationsCompetition & Consumer
Dark patterns, deal value thresholds and endorser liability
See data, privacy & cyber obligations scoped to your sites
We configure your entities, locations and states, and show you exactly which obligations in this domain land where — including the ones nobody currently owns.