State · Rajasthan
DPDPA Compliance in Rajasthan
From 13 May 2027 remaining DPDPA duties apply to Rajasthan firms that decide why and how digital personal data is processed: a lawful ground, a Section 5 notice, security, and a dual-clock breach runbook. Guest registers and gem-floor KYC will not wait for a Jaipur-only banner.
Last reviewed: 23 September 2026
Why DPDPA compliance matters in Rajasthan specifically
Rajasthan's files sit on tourist and factory floors. Jaipur gem and jewellery units hold buyer and artisan KYC. Udaipur and Jodhpur hotels keep guest and staff IDs. Kishangarh marble and RIICO estates hold contractor packs. Handicraft exporters keep overseas buyer lists. A municipal or e-Mitra vendor still needs a Section 8(2) contract. Processor copies stay personal data.
What Rajasthan businesses should prepare first
- Map Jaipur plus Udaipur, Jodhpur and RIICO files on one sheet — system, purpose, processor, owner.
- Give every purpose a Section 6 consent record or a named Section 7 limb. Payroll and necessary attendance can sit under Section 7(i).
- Write a breach SOP that hits CERT-In within 6 hours and the Data Protection Board under Rule 7 within 72 hours.
- Put deletion dates and an hours-based incident SLA in every Section 8(2) contract — PMS, gem ERP, e-Mitra vendor, payroll.
Frequently asked questions
We run a hotel in Udaipur, not a Jaipur IT firm. Does DPDPA apply?
Yes. Guest and staff digital files are personal data if you decide the purpose and means. The Act has no tourism carve-out. You need a ground, a notice where you rely on consent, security, and a dual-clock runbook. Section 8(5) security failures sit under the ₹250 crore Schedule slab.
If a hotel PMS or e-Mitra vendor copy leaks, who do we tell and by when?
Two clocks run together. CERT-In wants a report of covered incidents within 6 hours of noticing them. Separately, Rule 7 wants affected Data Principals intimated without delay and a detailed report to the Data Protection Board within 72 hours. Processor copies do not leave the Act.
Does every Rajasthan jeweller need a Rule 13 audit?
No. Rule 13 annual DPIA and independent audit start only after a Section 10 Significant Data Fiduciary notice. Most still owe notices, grounds, security, dual-clock reporting, erasure and processor contracts. Software is not your Section 10(2)(b) auditor.
Get a DPDPA readiness walkthrough for your Rajasthan business
Book 30 minutes to map gem-floor, hotel and RIICO files against notices and the CERT-In 6-hour plus DPB 72-hour clocks.
Book a demo
Free Gap Analysis
Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.