InfraVeritas
360
DPDP
iq
DPDP Insights
All sectors
Questions
The law
Glossary
How we research
DPDP Insights
› Questions
Questions
What should our privacy notice say, and where must people see it?
Yes, at every point where you collect data
When do we need consent, and when can we rely on a legitimate use?
It depends on the use; most organisations need both
Someone withdraws consent. What has to stop, and how fast?
Stop that use quickly, across every system and vendor
Someone asks what data we hold about them. What do we send?
Yes, a clear summary, inside the published timeline
Someone asks us to delete their data. Must we?
Yes, unless a law requires you to keep it
How do we handle a privacy complaint within 90 days?
Reply within your published period, never beyond 90 days
Do we process children's data, and what changes if we do?
Check every channel; children often appear where you least expect
How long can we keep personal data?
For the legal or business period, then erase
Something has gone wrong. What happens in the first 72 hours?
Six hours for CERT-In; without delay for people and the Board; 72 hours for the detailed report
Which logs must we keep, for how long, and where?
At least one year; 180 days of ICT logs in India
Does deletion have to reach backups and test copies?
Yes, through a written backup-expiry rule
Who should be able to see personal data in our systems?
Only those who need it, reviewed every quarter
What must a vendor contract say about personal data?
Yes, every vendor that touches personal data
Can personal data be stored or accessed outside India?
Yes, unless a sector rule says otherwise
Do we need consent for employee data?
Not for employment purposes; yes for anything extra
Are contract and agency workers our responsibility?
Yes, for the data you decide about
What about CCTV, visitor registers and biometric attendance?
Yes, with notice, limits and a deletion period
Do we need a DPO?
Not required by law unless notified as an SDF, but name one person
Could we be a Significant Data Fiduciary?
Only by notification; none notified yet
Staff share personal data on WhatsApp and personal email. What do we do?
Yes, this is a common breach; give staff a safer option
Can we send offers to past customers and leads?
Only with separate consent and an easy way to stop
What about call recordings and customer service screens?
Yes, with notice, a retention period and masking
Who needs DPDP training, and what should it cover?
Everyone who handles personal data, by role
Does ISO 27001 or NIST CSF cover our DPDP duties?
They cover security, not the whole Act
Where does personal data live in our organisation?
Start with one row per system
How much effort and time will it take to be ready by 13 May 2027?
Six to nine months of steady work for most
What should the board of directors ask management about DPDP?
Five plain questions, asked every quarter
How do we put DPDP into the risk register?
One line per duty, with owner and evidence
Police, a court or a regulator asks for someone's data. What do we do?
Yes, when the request is lawful and in writing
Are we a Data Fiduciary or a Data Processor?
Often both, for different data
Can we cross-sell insurance, cards or mutual funds to existing customers?
Only with separate, specific consent
How long must we keep KYC and transaction records, and what happens after?
At least five years after the relationship ends; then erase
What can collection agents do with borrower data?
Only what is needed, under your contract and RBI conduct rules
What can our lending or banking app collect from a phone?
Need-based only, with explicit consent
One incident, many regulators: how do we meet every clock?
Six hours for CERT-In; regulator as its rules say; DPDP without delay and 72 hours
Does DPDP apply to data of foreign clients' customers?
Mostly exempt for offshore data; security still applies
How should our people access client systems?
Named, logged and removed at roll-off
A client's data is involved in an incident. Who tells whom?
Client first, within contract hours; CERT-In in six hours
How long can we keep candidate data?
For the hiring purpose, then delete unless the candidate agrees
Do we need citizens' consent to run a scheme?
Usually not; Section 7(b) or 7(c) with Rule 5 standards
What do the Second Schedule standards ask of a scheme?
Seven practical standards, each needing evidence
Must a ministry delete data when a citizen asks?
No, but correction and security still apply
How does the RTI amendment change replies about personal information?
Personal information is exempt; give reasoned orders
How should scheme systems handle Aadhaar numbers?
Vault, mask, never publish
Can we share data with states, banks or other ministries?
Yes, with a written basis, minimum fields and a log
Is our PSU 'the State' under DPDP, and what changes if it is?
Possibly, for some activities; get a written legal view
What about distributors, dealers and franchisees?
Yes, you are responsible for what they do with your consumers' data
Townships, hospitals and schools run by the PSU: what applies?
Yes, full duties for each service
Do we need DPDP consent to treat a patient?
Not for treatment; yes for extra uses
Can we share patient records with insurers and TPAs?
Yes for the patient's claim; only what it needs
Can we use patient data for research, audits or case studies?
Consent or de-identification first
Which records need extra protection under other health laws?
Yes, tighter access than other records
How do we stop staff looking at records they do not need?
Role access, flags and weekly log review
We are linked to ABDM. How does its consent fit with DPDP?
Both apply; align the wording
Imaging machines and lab analysers hold patient data. What do we do?
Separate network, controlled vendor access, wipe before disposal
How long should we keep patient records?
At least the legal minimums, with a written reason for anything longer
Explore our research-built assessment platforms
Each one comes out of the same InfraVeritas360 Foundation Layer research. Human-led, with no AI used.
Foundation Check
Foundation-layer control assessment
DPDPiq
DPDP readiness backed by evidence
Compliance Fabric
Continuous compliance discovery
DiE
Data Intelligence Engine
aiQ
AI Investment Quotient