Compliance & Risk Advisory
Gap assessments, policies and playbooks aligned with RBI, SEBI CSCRF, CERT-In, IRDAI, PCI DSS and DPDP.
Learn more about Compliance & Risk Advisory →The Digital Personal Data Protection (DPDP) Act, 2023 is India's law on processing digital personal data. It sets duties for Data Fiduciaries — organisations that decide why and how personal data is processed — and rights for Data Principals, the individuals the data is about.
The DPDP Rules were notified in November 2025, with obligations coming into force in phases. Organisations should use the transition period to map their data, fix consent and prepare for breach notification.
Process personal data for a lawful purpose with free, specific, informed and unambiguous consent, or on another legitimate use.
Give clear notice describing the personal data and the purpose of processing.
Protect personal data with reasonable security safeguards to prevent a breach.
Inform the Data Protection Board and each affected Data Principal of a personal data breach.
Support rights to access, correction, erasure and grievance redressal.
Erase personal data when the purpose is served, unless retention is required by law.
Appoint a Data Protection Officer, an independent data auditor, and carry out periodic Data Protection Impact Assessments.
Aligned with, not endorsed by any regulator. This page is a plain-English summary for awareness — confirm obligations against the latest official circulars or with your compliance officer.
Gap assessments, policies and playbooks aligned with RBI, SEBI CSCRF, CERT-In, IRDAI, PCI DSS and DPDP.
Learn more about Compliance & Risk Advisory →Call us when it matters: triage, containment, recovery and regulator reporting support.
Learn more about 24/7 Incident Response →Senior security leadership, policies and vendor risk management without a full-time CISO.
Learn more about vCISO, Governance & Third-Party Risk →The Act is law, and the Rules notified in November 2025 bring obligations into force in phases. Organisations should prepare now rather than wait for the final deadline.
The Data Protection Board of India and each affected Data Principal, in the form and manner set out in the Rules.
The Government notifies Significant Data Fiduciaries based on factors like the volume and sensitivity of data. We help you assess your exposure.
We assess where you stand, close the gaps and prepare the evidence your auditors and regulator will ask for.
support@trustnetsecure.com · +91 93229 37312 · +91 88300 61438
Under attack right now? Go to emergency help →
📍 Location not reported
📍 Location not reported
📍 Location not reported
📍 Location not reported
📍 Location not reported
📍 Location not reported
Source: The Hacker News — headlines only, each linking to the original article.