City · Kochi
DPDPA Compliance in Kochi
The Digital Personal Data Protection Act, 2023 and its 2025 Rules set one deadline for every Indian business: 13 May 2027. From then, any organisation handling digital personal data must demonstrate valid consent where required, serve plain-language notices, act on data principal requests and report breaches on time. For Kochi businesses, the build-out — consent capture, retention limits, processor contracts, breach drills — has to begin well ahead.
Why DPDPA compliance matters in Kochi specifically
Kochi's data flows cross borders more than most Indian cities'. Infopark and SmartCity units process client records as Data Processors for US and European principals. Gold loan NBFCs and co-operative banks hold KYC for a customer base heavily made up of Gulf NRIs. Aster, Amrita and Lisie draw medical-tourism patients from abroad, while Fort Kochi homestays, houseboat operators and Ayurveda centres copy foreign passports and file Form C.
What Kochi businesses should prepare first
- Map cross-border transfers (NRI KYC, Infopark client data, medical tourism) against Section 16 and sectoral localisation rules.
- Document lawful grounds and consent records for each processing purpose.
- Build a breach response SOP for CERT-In's 6-hour clock and Rule 7's without-delay intimation plus 72-hour Board report.
- Review vendor contracts for processor-grade security and escalation clauses.
Frequently asked questions
Half our customers are NRIs in the Gulf and our client is in the US. Can we still transfer data abroad?
Yes, by default. Section 16 works on a negative list — transfers are permitted unless the Central Government restricts a specific country, and no such list has been notified yet. But sectoral rules (RBI's payment data localisation, for instance) may still bind you, and a foreign client's own law, such as the GDPR, can apply to you through contract. Map where your data actually sits before assuming you are clear.
We are a hospital treating foreign and domestic patients. Does health data get special treatment?
The DPDPA has no separate sensitive personal data tier — health records carry the same obligations as any other personal data. What changes is the practical risk: a breach of patient histories invites the higher end of penalties, up to ₹250 crore under Section 8(5) for failing reasonable security safeguards. Keep clinical records under retention rules tied to medical law, and hold consent evidence for anything used beyond treatment, such as marketing or research.
Our IT vendor spotted unauthorised access on a Sunday. When does our clock start?
When the incident is noticed, not when your office reopens. CERT-In requires reporting covered cyber incidents within 6 hours of noticing them. Under the DPDPA, you must inform affected Data Principals without delay, intimate the Data Protection Board without delay, and file a detailed report with the Board within 72 hours. Build an out-of-hours escalation path with your processor — the contract should oblige them to alert you immediately.
Get a DPDPA readiness walkthrough for your Kochi business
Book a 30-minute call to map your consent architecture, vendor exposure, and breach posture against DPDPA.
Book a demo
Free Gap Analysis
Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.