City · Surat
DPDPA Compliance in Surat
The Digital Personal Data Protection Act, 2023 and its 2025 Rules fix a single deadline for Indian business: 13 May 2027. After that date, any organisation holding digital personal data must show valid consent where required, serve plain-language notices, answer data principal requests and report breaches on time. For Surat firms, the work — consent records, retention limits, job-work contracts, breach drills — has to start well before.
Why DPDPA compliance matters in Surat specifically
Surat's risk sits in two dense clusters. Varachha and Katargam diamond units run biometric attendance and payroll for a large migrant workforce, alongside KYC on overseas buyers routed through the Surat Diamond Bourse. Ring Road's textile markets and the Pandesara and Sachin GIDC mills push customer, agent and transporter data through WhatsApp order books and embroidery job-work sub-units — informal chains that still count as Data Processors under the Act.
What Surat businesses should prepare first
- Put WhatsApp buyer marketing on recorded Section 6 consent; write processor terms for job-work units.
- Document lawful grounds and consent records for each processing purpose.
- Build a breach response SOP for CERT-In's 6-hour clock and Rule 7's without-delay intimation plus 72-hour Board report.
- Review vendor contracts for processor-grade security and escalation clauses.
Frequently asked questions
We send catalogues and rate lists to buyers on WhatsApp. Do we need consent for that?
Yes. Marketing and promotional messaging is not covered by any legitimate use ground, so it runs on consent — free, specific, informed and withdrawable. A number saved from a trade enquiry is not consent to broadcast. Ask at the point of collection, keep a record of who agreed and when, and make opting out as easy as opting in. Withdrawal must stop the messages, not slow them down.
We pass karigar and order data to small job-work units. Who carries the liability?
You do. The Data Fiduciary stays accountable even when a Data Processor holds or handles the data, and the Act requires a valid contract with every processor — including the informal sub-units most Surat firms rely on. Put security, retention, sub-processing limits and immediate breach notification back to you in writing. An unwritten arrangement with a karkhana is still a processing chain in the Board's eyes.
Our accounts system was breached over a festival shutdown. When do the clocks start?
When the incident is noticed, not when the office reopens. CERT-In requires reporting of covered cyber incidents within 6 hours of noticing them. Under the DPDPA, you must inform affected Data Principals without delay, intimate the Data Protection Board without delay, and file a detailed report with the Board within 72 hours. Failure to notify is assessed separately, with penalties up to ₹200 crore under Section 8(6).
Get a DPDPA readiness walkthrough for your Surat business
Book a 30-minute call to map your consent architecture, vendor exposure, and breach posture against DPDPA.
Book a demo
Free Gap Analysis
Disclaimer: Privigo is not a law firm. This page provides operational compliance guidance only. For institution-specific obligations, work with qualified Indian legal counsel.