What Are the Key Rules Under DPDPA India You Must Know
India’s Digital Personal Data Protection Act (DPDPA India) sets a new baseline for how organisations collect, store, and process personal data. As data volumes grow and cyber risks intensify, enterprises face rising DPDPA compliance challenges—from governance gaps to evolving consent requirements. Understanding the core rules is now essential for every IT and security leader. Core Provisions of DPDPA India The DPDPA establishes numerous specific rules governing how a business may collect and use data. Examples include: Purpose limitation: A business may collect personal information only for clearly defined, lawful purposes. Data minimisation: A business may keep only the minimum amount of personal information necessary to conduct its business. Storage limitation: A business cannot keep personal information longer than is necessary for business purposes. Lawful processing: Every data processing activity must either be based on the owner’s consent or carried out for legitimate business...