City · Nagpur
DPDPA Compliance in Nagpur
The Digital Personal Data Protection Act, 2023 and its 2025 Rules give every Indian business one fixed date: 13 May 2027. From then, any organisation processing digital personal data must show valid consent where required, issue plain-language notices, act on data principal requests and report breaches on time. For Nagpur businesses, the groundwork — consent records, retention limits, vendor contracts, breach drills — starts now.
Why DPDPA compliance matters in Nagpur specifically
Nagpur's exposure follows its role as a central-India hub. MIHAN SEZ hosts IT and BPO units processing client records as Data Processors for principals elsewhere, alongside cargo and express operators whose consignee databases carry names, phone numbers and delivery addresses at volume. AIIMS Nagpur and the Wardha Road private hospital belt draw patients from Vidarbha and adjoining states, while Sitabuldi's NBFCs and orange-and-agri traders hold KYC on farmer and dealer networks.
What Nagpur businesses should prepare first
- Clean consignee and franchise partner access to logistics databases; set delivery-purpose retention limits.
- Document lawful grounds and consent records for each processing purpose.
- Build a breach response SOP for CERT-In's 6-hour clock and Rule 7's without-delay intimation plus 72-hour Board report.
- Review vendor contracts for processor-grade security and escalation clauses.
Frequently asked questions
We are a logistics firm holding lakhs of consignee names, numbers and addresses. Does that count as personal data?
Yes. Anything identifying an individual — name, phone, delivery address, shipment history — is personal data, and volume raises the stakes rather than the threshold. You need a notice explaining what you collect and why, retention that ends when the delivery and statutory purpose is done, and access controls so field staff and franchise partners see only what they need. Old consignee databases sitting in spreadsheets are the usual weak point.
Our MIHAN unit only processes data on instructions from a client. Are we a Data Fiduciary?
Probably not — you are likely a Data Processor, and your duties flow from the contract with the Data Fiduciary, which the Act requires to be in place. That contract should cover security safeguards, retention, sub-processing limits and immediate breach notification back to the client. Note that for your own employee and vendor records you are a Data Fiduciary in your own right, with the full set of obligations.
Our systems were compromised overnight. What must we do and by when?
Two clocks run in parallel from the moment the incident is noticed. CERT-In requires reporting of covered cyber incidents within 6 hours. Under the DPDPA, you must inform affected Data Principals without delay, intimate the Data Protection Board without delay, and file a detailed report with the Board within 72 hours. Failure to notify is assessed separately from a security lapse, carrying penalties up to ₹200 crore under Section 8(6).
Get a DPDPA readiness walkthrough for your Nagpur business
Book a 30-minute call to map your consent architecture, vendor exposure, and breach posture against DPDPA.
Book a demo
Free Gap Analysis
Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.