Overview
India's Digital Personal Data Protection Act 2023 marks a watershed moment in the country's regulatory landscape, introducing enforceable obligations on Data Fiduciaries — including consent requirements, purpose limitation, data minimisation, security safeguards, breach notification, and Data Principal rights — with penalties of up to ₹250 crore per violation. For most organisations, DPDP compliance requires a fundamental review of how personal data is collected, processed, stored, transferred, and deleted across the enterprise.
At Anjani Kripa, we assist clients in understanding their obligations as Data Fiduciaries and Data Processors, structuring appropriate governance and management frameworks, and ensuring compliance readiness before enforcement begins. Our advisory spans gap assessments, framework design, consent architecture, vendor management, regulatory proceedings, and ongoing monitoring — enabling our clients to stay ahead of a rapidly evolving regulatory landscape across both the DPDP Act and applicable sectoral data regulations.
Our Services
End-to-end advisory across the full data governance and DPDP compliance lifecycle.
Regulatory Landscape
Key laws and frameworks shaping India's data protection obligations.
DPDP Act 2023
India's principal data protection law — consent obligations, data fiduciary duties, breach notification to the Data Protection Board, Data Principal rights, and penalties up to ₹250 crore per instance of non-compliance.
DPDP Rules (Under Development)
The implementing rules to the DPDP Act are under active development, addressing consent manager frameworks, Significant Data Fiduciary obligations, cross-border data transfer permitted countries, and the Data Protection Board's functioning.
RBI / SEBI Data Norms
Reserve Bank of India and SEBI data localisation, storage, and privacy requirements applicable to banks, NBFCs, payment aggregators, brokers, and other regulated financial entities — running parallel to DPDP obligations.
Global Privacy Alignment
For organisations with cross-border operations or international data transfers, advisory on aligning Indian DPDP obligations with global privacy frameworks including GDPR and other applicable international standards.
How We Work
A structured advisory process from assessment through to ongoing compliance.
Assessment & Gap Analysis
We conduct a comprehensive review of your current data processing activities, governance structures, vendor arrangements, and existing policies against DPDP Act obligations and applicable sectoral requirements — producing a detailed gap analysis with prioritised remediation recommendations.
Framework Design & Documentation
We design and implement your data governance framework — consent management architecture, data processing policies, vendor contracts, privacy notices, data retention schedules, and internal training programmes — providing implementation-ready documents your team can deploy immediately.
Regulatory Monitoring & Representation
We provide continuing advisory as the DPDP regulatory framework evolves — including implementing rules, Data Protection Board guidance, and international developments — along with representation support during regulatory interactions, investigations, and Board proceedings.
