Achieving and maintaining compliance with the DPDP Act involves implementing robust technical and organisational controls. While the Act is about legal principles, proving compliance is an operational challenge. It requires a systematic way to manage, evidence, and audit your data protection practices.
At Securion.ai, our platform is designed to automate the collection of evidence for controls like those required under Rule 6 of the DPDPA. By turning compliance frameworks into agentic workflows, we help you prove that you have the right processes in place for consent management, data retention, and user rights requests, making you audit-ready, continuously.
Navigating the complexities of the DPDPA can be challenging. If you need help understanding your obligations and implementing the right controls, talk to us.
Frequently Asked Questions
1. What about consent collected before the DPDP Act came into force?
You must provide a notice to these users as soon as reasonably practicable, informing them of the data you hold and its purpose, and giving them an easy way to withdraw consent. If they do not withdraw, you can continue processing, but the burden is on you to prove the original consent was valid.
2. Can I use a single checkbox for my Terms of Service and Privacy Policy?
No. This is known as 'bundling' and is not compliant. Consent for processing personal data must be separate from agreeing to general terms and conditions. Each distinct data processing purpose requires its own specific, un-ticked checkbox.
3. What is a Consent Manager? Do I need one?
A Consent Manager is a licensed entity registered with the Data Protection Board that can act as a single point of contact for users to manage their consent across multiple platforms. While you can use one, a Data Fiduciary is perfectly entitled to manage its own consent collection directly, provided it meets all the Act's requirements.
4. What happens if a user withdraws consent? Do I have to delete all their data?
Not necessarily. You must stop processing their data for the purpose for which consent was withdrawn. However, you may be required to retain some of their data to comply with other legal obligations (e.g., financial transaction records for tax purposes).