City · Indore

DPDPA Compliance in Indore

The Digital Personal Data Protection Act, 2023 and its 2025 Rules give Indian businesses a single deadline: 13 May 2027. From that date, any organisation processing digital personal data must show valid consent where required, issue plain-language notices, answer data principal requests and report breaches promptly. For Indore businesses, the preparation — consent records, retention limits, vendor contracts, breach drills — needs to start now.

Why DPDPA compliance matters in Indore specifically

Indore's exposure spans sectors that all run on personal data. Crystal IT Park and Super Corridor units process client records as Data Processors for principals elsewhere. The city's dense mutual fund distributor and NBFC base holds KYC, PAN and bank details. Vijay Nagar and Rau coaching institutes enrol minors, private hospitals on AB Road keep patient histories from across Malwa, and Pithampur's auto and pharma plants hold worker and vendor files.

What Indore businesses should prepare first

  • Reconcile RBI/SEBI KYC retention with DPDPA notice, consent and rights obligations.
  • Document lawful grounds and consent records for each processing purpose.
  • Build a breach response SOP for CERT-In's 6-hour clock and Rule 7's without-delay intimation plus 72-hour Board report.
  • Review vendor contracts for processor-grade security and escalation clauses.

Frequently asked questions

We already collect KYC under RBI and SEBI rules. Isn't that enough?

No. Sectoral KYC rules tell you what to collect and how long to keep it; the DPDPA governs the consent, notice and rights layer on top. You still need a clear notice at collection, a record of consent you can produce later, a way to honour access, correction and erasure requests, and a published grievance contact. Where a sectoral law mandates retention, keep the data — but document the legal basis.

Our customer data sits with an outside CRM or IT vendor. Who is liable?

You are. The Data Fiduciary remains accountable even when a Data Processor holds the data, so a written contract is mandatory — covering security, retention, sub-processing and breach notification back to you. Ask vendors where the data is hosted and how fast they can alert you, because your reporting clock starts when the incident is noticed, not when the vendor gets around to telling you.

If our systems are hit, how quickly must we report it?

Two separate clocks run together. CERT-In requires reporting of covered cyber incidents within 6 hours of noticing them. Under the DPDPA, you must inform affected Data Principals without delay, intimate the Data Protection Board without delay, and file a detailed report with the Board within 72 hours. Failure to notify carries penalties up to ₹200 crore under Section 8(6), assessed separately from security lapses.

Get a DPDPA readiness walkthrough for your Indore business

Book a 30-minute call to map your consent architecture, vendor exposure, and breach posture against DPDPA.

Book a demo Free Gap Analysis

Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.