State · Kerala

DPDPA Compliance in Kerala

Kerala organisations that process digital personal data face remaining DPDPA duties from 13 May 2027: a lawful ground, a Section 5 notice, security, and a dual-clock breach runbook. Gulf-linked KYC and plantation rolls will not wait for a Kochi-only banner. Map the state once.

Last reviewed: 23 September 2026

Why DPDPA compliance matters in Kerala specifically

Kerala's exposure is coastal and inland. Kochi IT and port seats process client and sailor files; processor copies stay personal data. Spice and cashew exporters hold buyer and labour KYC. Plantation estates keep seasonal Aadhaar. NBFCs serving Gulf-returnee families hold remittance KYC. Akshaya and municipal vendors process citizen applications and need a Section 8(2) contract.

What Kerala businesses should prepare first

  • Map Kochi plus Kozhikode, Kollam and estate files on one sheet — system, purpose, processor, owner.
  • Give every purpose a Section 6 consent record or a named Section 7 limb. Payroll and necessary attendance can sit under Section 7(i).
  • Write a breach SOP that hits CERT-In within 6 hours and the Data Protection Board under Rule 7 within 72 hours.
  • Put deletion dates and an hours-based incident SLA in every Section 8(2) contract — port CFS, exporter ERP, Akshaya vendor, payroll.

Frequently asked questions

We only export from Kollam or run an estate, not a Kochi IT firm. Does DPDPA apply?

Yes. The Act has no sector or pin-code floor. If you decide the purpose and means for digital personal data — labour IDs, buyer KYC, remittance files — you are a Data Fiduciary. Section 8(5) security failures sit under the ₹250 crore Schedule slab.

If an Akshaya vendor or port CFS copy leaks, who do we tell and by when?

Two clocks run together. CERT-In wants a report of covered incidents within 6 hours of noticing them. Separately, Rule 7 wants affected Data Principals intimated without delay and a detailed report to the Data Protection Board within 72 hours. Processor copies do not leave the Act.

Do Kerala schools need a Rule 13 pack because they hold children's data?

Not unless the Central Government notifies you as a Significant Data Fiduciary under Section 10. Rule 13 is SDF-only. You still owe notices, grounds, security, dual-clock reporting, erasure and processor contracts. Children's data needs verifiable parental consent — that is not Rule 13.

Official sources

Get a DPDPA readiness walkthrough for your Kerala business

Book 30 minutes to map Kochi, exporter and Akshaya-adjacent files against notices and the CERT-In 6-hour plus DPB 72-hour clocks.

Book a demo Free Gap Analysis

Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.