City · Chandigarh

DPDPA Compliance in Chandigarh

The Digital Personal Data Protection Act, 2023 and its 2025 Rules set one hard date for every Indian business: 13 May 2027. After that, any organisation handling digital personal data must prove valid consent where required, serve clear notices, honour data principal rights and report breaches on schedule. For firms in Chandigarh, the groundwork — consent capture, vendor contracts, retention rules, breach drills — has to begin now.

Why DPDPA compliance matters in Chandigarh specifically

Chandigarh's data risk sits in its service economy rather than factories. Rajiv Gandhi IT Park exporters process client data as Data Processors for overseas principals, inheriting obligations by contract. The PGIMER-anchored private hospital and diagnostics belt across Sectors 8 to 34 holds health records for patients travelling from Punjab, Haryana and Himachal. Sector 34's competitive-exam coaching cluster enrols minors, and tricity firms run one customer database across three jurisdictions.

What Chandigarh businesses should prepare first

  • Unify consent and retention policy across Chandigarh–Mohali–Panchkula operations.
  • Document lawful grounds and consent records for each processing purpose.
  • Build a breach response SOP for CERT-In's 6-hour clock and Rule 7's without-delay intimation plus 72-hour Board report.
  • Review vendor contracts for processor-grade security and escalation clauses.

Frequently asked questions

We operate across Chandigarh, Mohali and Panchkula. Do the rules differ in each?

No. The DPDPA is a central law and applies uniformly across the Union Territory and both states, so one compliance framework covers the whole tricity operation. What matters is the entity processing the data, not where the office sits. Keep a single consent record and retention policy rather than three, and make sure branch staff follow the same notice and grievance process.

Do we need a Data Protection Officer, DPIA and annual audits?

Only if the Central Government notifies your organisation as a Significant Data Fiduciary. Those extra duties — an India-based DPO, periodic Data Protection Impact Assessment, independent audit and algorithmic due diligence — sit under Rule 13 and apply to SDFs alone. Every other Data Fiduciary still needs consent, notices, security safeguards, breach reporting and a grievance redressal contact.

Our IT Park company only processes data for a foreign client. Are we covered?

Likely yes, as a Data Processor. Your obligations flow from your contract with the Data Fiduciary, which must bind you on security, retention and breach notification. If a breach occurs, the dual clock still runs: CERT-In within 6 hours of noticing a covered incident, and under the DPDPA, affected Data Principals and the Data Protection Board without delay, with a detailed report to the Board within 72 hours.

Get a DPDPA readiness walkthrough for your Chandigarh business

Book a 30-minute call to map your consent architecture, vendor exposure, and breach posture against DPDPA.

Book a demo Free Gap Analysis

Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.