エピソード

  • Section 6: The Anatomy of Valid Consent
    2026/08/06

    Somewhere in a dispute a few years from now, a company will tell the Data Protection Board: "The user consented." And the Board will ask the only question that matters: "Show me." Not the terms of service, not proof the account exists — this person's free, specific, informed, unconditional, unambiguous consent, given by a clear affirmative action, for this specified purpose. In that moment, every pre-ticked box and bundled agreement will either stand as evidence or collapse as theatre.

    This episode dissects the centrepiece of the entire statute, adjective by adjective. Free — why the pressure the law cares about is structural, the service-held-hostage test, and why employee consent is inherently suspect. Specific — the death certificate of bundled consent, the unbundling design consequence, and the necessity limit: consent operates only over data the purpose actually needs, with the Act's own telemedicine illustration showing that over-collection is collection without a basis. Informed — how notice defects corrode every consent built on them. Unconditional — no consent-as-toll-booth. Unambiguous, with clear affirmative action — why silence, inactivity, pre-ticked boxes and "continuing means agreeing" are all dead, and what lives.

    Then the provision that turns five adjectives into an engineering requirement: the burden of proving valid consent sits on the Data Fiduciary — a logging specification demanding who consented, to what purpose-version, through which notice-version, when and how, producible years later. The audit test that exposes most systems: "show me the record for a random user from eighteen months ago." Plus severability, the Consent Manager integration seam every architecture should design for today, and the closing reframe for product teams: the five adjectives as a description of a respectful product — honest, unbundled, reversible consent earning better data and fewer complaints than the dark patterns it replaces.

    DPDP Daily takes India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 out of the statute book and into real life — for compliance officers, lawyers, founders, small business owners and citizens. One practical episode every day, no jargon.

    I'm Harmeet Singh Kapoor, author of the DPDP Act Compliance Handbook: From Law to Ground Reality.

    Keywords: Section 6 DPDP, valid consent, consent requirements India, affirmative action consent, bundled consent, dark patterns, consent logging, burden of proof consent, consent manager, DPDP compliance.

    Connect with me:
    💼 LinkedIn: https://www.linkedin.com/in/hskapoor/
    📄 Facebook: https://www.facebook.com/satarkintelligence
    ▶️ YouTube: https://www.youtube.com/@DPDPdaily
    🎙️ Apple Podcasts: https://podcasts.apple.com/us/podcast/dpdp-daily/id6793257111
    𝕏 X: https://x.com/TheOtherKapoor

    One practical DPDP insight every morning on LinkedIn, Facebook and X — and the DPDP Act Compliance Handbook: From Law to Ground Reality coming soon.

    This episode is educational commentary, not legal advice. The DPDP framework is in phased implementation and positions described may evolve through notifications, Board publications and judicial interpretation. For decisions affecting your organisation or your rights, consult a qualified professional with your specific facts.

    続きを読む 一部表示
    10 分
  • Section 5: The Notice — What Your Customers Must Actually Be Told
    2026/08/05

    An uncomfortable experiment: open any app you installed this year and try to answer three questions from what it showed you at sign-up — exactly what personal data did it collect, for exactly what purposes, and where precisely would you complain if it misused that data? You agreed to something; you just couldn't say what. That experience is precisely what Section 5 exists to end.

    This episode covers the only compliance artefact every customer personally encounters. The statutory core: notice accompanying or preceding every consent request — never disclosure as an afterthought to a granted permission. The three mandatory contents, sharpened by Rule 3: an itemised description of the data ("we collect your information" fails; "name, mobile number, delivery address, order history" passes), itemised and specific purposes, and the accountability machinery — including the requirement that startles first-time readers: telling your own customers how to escalate against you to the Data Protection Board, the statute recruiting every notice in the country as civic education.

    Then the distinctly Indian layer: availability across English and the twenty-two Eighth Schedule languages, and why your notice programme is a translation programme — professional translation of one short document, not machine translation of a sprawling policy. The Rule 3 standalone standard that ends the buried-privacy-policy era. The look-back obligation almost nobody has planned for: existing users, with consents collected under the old regime, must receive the new-style notice too. The five drafting failures I see weekly — the genre notice, the kitchen-sink purpose, the buried notice, the frozen notice, and the GDPR-template notice missing the complaints machinery entirely. What good looks like: the layered design. And the closing reframe: the notice as the one moment your data practices speak directly to a customer — compliance spend converting to brand equity for companies that treat it as craft.

    DPDP Daily takes India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 out of the statute book and into real life — for compliance officers, lawyers, founders, small business owners and citizens. One practical episode every day, no jargon.

    I'm Harmeet Singh Kapoor, author of the DPDP Act Compliance Handbook: From Law to Ground Reality.

    Keywords: Section 5 DPDP, privacy notice, DPDP notice requirements, Rule 3, itemised notice, Eighth Schedule languages, plain language notice, notice drafting, consent notice India, DPDP compliance.

    Connect with me:
    💼 LinkedIn: https://www.linkedin.com/in/hskapoor/
    📄 Facebook: https://www.facebook.com/satarkintelligence
    ▶️ YouTube: https://www.youtube.com/@DPDPdaily
    🎙️ Apple Podcasts: https://podcasts.apple.com/us/podcast/dpdp-daily/id6793257111
    𝕏 X: https://x.com/TheOtherKapoor

    One practical DPDP insight every morning on LinkedIn, Facebook and X — and the DPDP Act Compliance Handbook: From Law to Ground Reality coming soon.

    This episode is educational commentary, not legal advice. The DPDP framework is in phased implementation and positions described may evolve through notifications, Board publications and judicial interpretation. For decisions affecting your organisation or your rights, consult a qualified professional with your specific facts.

    続きを読む 一部表示
    10 分
  • Section 4: Two Lawful Bases, and Why India Refused "Legitimate Interest"
    2026/08/04

    Every data protection law on earth answers one question before all others: when is it lawful to process someone's personal data at all? Europe's answer runs six lanes wide — consent, contract, legal obligation, vital interests, public tasks, and the flexible catch-all called legitimate interests that carries most of the commercial internet. India looked at that six-lane highway and built two lanes: consent, or a closed list of legitimate uses. Nothing in between. That choice is the single most consequential design decision in the entire statute.

    Arc 2 opens here — the Act, section by section — and it begins at the foundation stone. What "lawful purpose" actually means, and why its modesty surprises people: the law doesn't police ambition; it polices authorisation. The two doors every processing activity must pass through. The absences that define the architecture: no contract basis, no legitimate-interest balancing test — and the fair account of why India refused the ground the rest of the world relies on, choosing a closed list Parliament controls over an open standard companies interpret and regulators chase.

    Then the consequences. Why consent becomes the workhorse, and consent engineering the load-bearing wall of Indian data operations. Why the product manager's instinct — "we need it to run the feature" — maps to nothing automatic here, and where the gap between "we need it" and "we have a basis for it" will surprise compliance programmes. The four-column basis-mapping exercise that converts Section 4 into a working document, and why the rows ending in shrugs are violations-in-waiting. Plus the honest note on interpretation: how the Board's early orders will calibrate the system, and the compliance-safe posture until they do.

    DPDP Daily takes India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 out of the statute book and into real life — for compliance officers, lawyers, founders, small business owners and citizens. One practical episode every day, no jargon.

    I'm Harmeet Singh Kapoor, author of the DPDP Act Compliance Handbook: From Law to Ground Reality.

    Keywords: Section 4 DPDP, lawful basis, consent, legitimate uses, legitimate interest India, GDPR comparison, lawful purpose, DPDP Act section by section, data processing grounds, DPDP compliance.

    Connect with me:
    💼 LinkedIn: https://www.linkedin.com/in/hskapoor/
    📄 Facebook: https://www.facebook.com/satarkintelligence
    ▶️ YouTube: https://www.youtube.com/@DPDPdaily
    🎙️ Apple Podcasts: https://podcasts.apple.com/us/podcast/dpdp-daily/id6793257111
    𝕏 X: https://x.com/TheOtherKapoor

    One practical DPDP insight every morning on LinkedIn, Facebook and X — and the DPDP Act Compliance Handbook: From Law to Ground Reality coming soon.

    This episode is educational commentary, not legal advice. The DPDP framework is in phased implementation and positions described may evolve through notifications, Board publications and judicial interpretation. For decisions affecting your organisation or your rights, consult a qualified professional with your specific facts.

    続きを読む 一部表示
    10 分
  • Your Compliance Starting Line: The Nine-Question Self-Assessment
    2026/08/03

    Twelve episodes of foundations — the countdown, the constitutional history, the cast of characters, the exemptions, the penalties, the regulator, the state's wide lane. Today, theory faces you. Nine questions about your own organisation, each answerable in a minute, each revealing something the foundations arc taught — and by the end, you'll hold what organisations pay consultants lakhs to produce and still don't get straight: an honest picture of your starting line.

    The nine, scored green, amber or red as things are — not as they're planned: Do we actually know which of our data is digital personal data under this Act? For each data relationship, do we know which character we're playing? Could we produce a current record of what we hold, where, why and with whom it's shared? Can we name the lawful basis behind each processing activity? If a customer demanded access, correction or erasure tomorrow, could we execute? If data leaked tonight, do named people know their roles on the two clocks? Does every vendor touching our data operate under a proper contract? Is there one named human accountable for DPDP compliance? And if the Board asked us to demonstrate our efforts, what could we physically produce today?

    Then the tally guidance for each profile — and a worked example from advisory work: a two-hundred-person consumer services firm scoring two green, four amber, three red, why that profile is roughly the median serious Indian mid-market company in 2026, and how its first three moves wrote themselves. Why progress in compliance is rarely dramatic — it's ambers eating reds, quarter after quarter. Plus the habit that turns thirty minutes into a governance instrument: date the scorecard, re-score quarterly, file it in the evidence trail.

    The foundations are laid. Tomorrow, a new arc opens: the Act itself, section by section — beginning with Section 4, the two lawful bases, and the story of why India deliberately refused the "legitimate interest" ground the rest of the world relies on.

    DPDP Daily takes India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 out of the statute book and into real life — for compliance officers, lawyers, founders, small business owners and citizens. One practical episode every day, no jargon.

    I'm Harmeet Singh Kapoor, author of the DPDP Act Compliance Handbook: From Law to Ground Reality.

    Keywords: DPDP self-assessment, DPDP gap assessment, compliance checklist, data mapping, RoPA, lawful basis, breach readiness, vendor contracts, DPDP compliance owner, data protection audit India.

    Connect with me:
    💼 LinkedIn: https://www.linkedin.com/in/hskapoor/
    📄 Facebook: https://www.facebook.com/satarkintelligence
    ▶️ YouTube: https://www.youtube.com/@DPDPdaily
    🎙️ Apple Podcasts: https://podcasts.apple.com/us/podcast/dpdp-daily/id6793257111
    𝕏 X: https://x.com/TheOtherKapoor

    One practical DPDP insight every morning on LinkedIn, Facebook and X — and the DPDP Act Compliance Handbook: From Law to Ground Reality coming soon.

    This episode is educational commentary, not legal advice. The DPDP framework is in phased implementation and positions described may evolve through notifications, Board publications and judicial interpretation. For decisions affecting your organisation or your rights, consult a qualified professional with your specific facts.

    続きを読む 一部表示
    11 分
  • The Government's Wide Lane: State Exemptions, Powers, and the Puttaswamy Shadow
    2026/08/02

    Here is the sentence that has launched a hundred editorials about India's data protection law: the government can, by notification, exempt its own instrumentalities from the Act — the same Act written to discipline how everyone handles your data. Critics call it the law's original sin. The government calls it the price of governing a nation of security threats and welfare programmes at continental scale. Both sides are arguing about something real — and this episode presents both at full strength, without caricature.

    First, what the provisions actually say: Section 17's two levels, the notification power and its grounds — sovereignty, security, friendly relations, public order — plus the government's power to demand information from any fiduciary, the platform-blocking power on repeat penalisation, and the state's different retention posture. Then the criticism, stated properly: elastic grounds, executive notification without per-use parliamentary process, no sunset or independent review, the conflict of a state that is both the largest data collector and the author of its own exemptions — and Justice Srikrishna's own public objections to the widening. Then the defence, equally properly: every data protection law on earth carves out national security; a welfare state at India's scale cannot let benefit delivery die at a consent screen; and notification-by-notification exemption at least creates a paper trail.

    Then the piece to carry away: the Puttaswamy shadow. A statutory exemption removes the Act's obligations — it cannot remove the fundamental right, and every notification remains testable against legality, legitimate aim, proportionality and safeguards. Plus the instrumentality seam where future litigation will run, the four-question checklist for every government-adjacent contract, what citizens should honestly expect, and why the best answer to the wide-lane criticism would be a state that rarely needs to drive in it.

    DPDP Daily takes India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 out of the statute book and into real life — for compliance officers, lawyers, founders, small business owners and citizens. One practical episode every day, no jargon.

    I'm Harmeet Singh Kapoor, author of the DPDP Act Compliance Handbook: From Law to Ground Reality.

    Keywords: Section 17 DPDP, state exemptions, government data exemption, instrumentality of state, Puttaswamy proportionality, surveillance concerns, DPDP criticism, data protection government, blocking power, DPDP Act debate.

    Connect with me:
    💼 LinkedIn: https://www.linkedin.com/in/hskapoor/
    📄 Facebook: https://www.facebook.com/satarkintelligence
    ▶️ YouTube: https://www.youtube.com/@DPDPdaily
    🎙️ Apple Podcasts: https://podcasts.apple.com/us/podcast/dpdp-daily/id6793257111
    𝕏 X: https://x.com/TheOtherKapoor

    One practical DPDP insight every morning on LinkedIn, Facebook and X — and the DPDP Act Compliance Handbook: From Law to Ground Reality coming soon.

    This episode is educational commentary, not legal advice. The DPDP framework is in phased implementation and positions described may evolve through notifications, Board publications and judicial interpretation. For decisions affecting your organisation or your rights, consult a qualified professional with your specific facts.

    続きを読む 一部表示
    12 分
  • Inside the Data Protection Board: India's First Digital-Native Regulator
    2026/08/01

    Every prediction about Indian data protection enforcement rests on one unstated assumption: that complaining is hard — hard enough that citizens won't bother and backlogs will swallow cases. Now consider what Parliament actually built: a regulator required by statute to function as a digital office, receiving complaints, conducting inquiries and pronouncing decisions through techno-legal means, without anyone travelling anywhere. That assumption is precisely what this design exists to destroy.

    This episode goes inside the Data Protection Board of India. Its structure — chairperson and members appointed by the government, the legal-expertise requirement, and the honest acknowledgment of the independence criticism carried over from the legislative journey. The three doors through which matters arrive: citizen complaints, government references, and the door companies forget — every breach intimation you file lands on the Board's desk as potential inquiry material, which means your breach report is simultaneously a compliance act and an evidentiary submission. Its powers once seized: civil-court powers to summon and compel, interim directions, urgent remedial orders mid-breach, the full penalty schedule, and the voluntary-undertaking settlement valve. The guardrails: natural justice, written reasons, expeditious timelines, and the sixty-day appeal road to TDSAT — where early DPDP jurisprudence will actually crystallise.

    Then Meera's complaint, walked through the machine end to end — and the fork where identical complaints produce opposite outcomes, decided years earlier by which company built the machinery and kept the records. Why the Board doesn't create your outcome; it reveals your preparation. The four facts that predict enforcement volume will surprise sceptics: near-zero filing friction, self-filling inboxes, India's complaint-culture precedents once friction drops, and a young regulator's need for visible action. And the practical close: why your grievance desk is your first line of regulatory defence, and what to build before the first hearing ever happens.

    DPDP Daily takes India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 out of the statute book and into real life — for compliance officers, lawyers, founders, small business owners and citizens. One practical episode every day, no jargon.

    I'm Harmeet Singh Kapoor, author of the DPDP Act Compliance Handbook: From Law to Ground Reality.

    Keywords: Data Protection Board of India, DPB, digital office regulator, DPDP complaints, TDSAT appeal, data protection enforcement, breach intimation, voluntary undertaking, grievance redressal, DPDP adjudication.

    Connect with me:
    💼 LinkedIn: https://www.linkedin.com/in/hskapoor/
    📄 Facebook: https://www.facebook.com/satarkintelligence
    ▶️ YouTube: https://www.youtube.com/@DPDPdaily
    🎙️ Apple Podcasts: https://podcasts.apple.com/us/podcast/dpdp-daily/id6793257111
    𝕏 X: https://x.com/TheOtherKapoor

    One practical DPDP insight every morning on LinkedIn, Facebook and X — and the DPDP Act Compliance Handbook: From Law to Ground Reality coming soon.

    This episode is educational commentary, not legal advice. The DPDP framework is in phased implementation and positions described may evolve through notifications, Board publications and judicial interpretation. For decisions affecting your organisation or your rights, consult a qualified professional with your specific facts.

    続きを読む 一部表示
    11 分
  • The ₹250 Crore Question: The Full Penalty Schedule, Decoded
    2026/07/31

    Two hundred and fifty crore rupees — the number in every DPDP conference deck, every consultant's opening slide, every worried WhatsApp forward between CFOs. And nine out of ten people quoting it can't answer three basic questions: what conduct does it attach to, what are the other numbers in the schedule, and what must the Board weigh before writing any figure at all? Fear of a number is not a compliance strategy. Understanding a penalty architecture absolutely is.

    This episode lays out the full schedule tier by tier. Up to ₹250 crore for failing reasonable security safeguards — attached to the failure of prevention, not the fact of a breach. Up to ₹200 crore for breach-notification failures and for children's data violations, and what that pairing says about what the state fears most. Up to ₹150 crore for Significant Data Fiduciaries neglecting their added obligations. The ₹50 crore general tier that makes every other provision real. And the ₹10,000 penalty on Data Principals — the asymmetry that is itself a statement about power and accountability.

    Then the machinery that decides where in a range you land: the mandatory factors the Board must weigh — nature, gravity and duration; the data involved; repetitiveness; gain realised or loss avoided; mitigation and its promptness; proportionality and impact. Why at least half of these are within your control before anything goes wrong, and why your evidence file is literally the difference between the top of a range and the bottom. The GDPR comparison — turnover-linked ceilings versus India's absolute caps, and who each design favours. The voluntary-undertaking exit ramp and why it will dominate the first enforcement years. The two bad reactions — paralysis and cynicism — and the rational posture between them. And a one-hour homework: mapping your organisation against each tier, one honest sentence of exposure and one of evidence.

    DPDP Daily takes India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 out of the statute book and into real life — for compliance officers, lawyers, founders, small business owners and citizens. One practical episode every day, no jargon.

    I'm Harmeet Singh Kapoor, author of the DPDP Act Compliance Handbook: From Law to Ground Reality.

    Keywords: DPDP penalties, 250 crore penalty, DPDP penalty schedule, data breach fine India, Data Protection Board penalties, voluntary undertaking, GDPR fines comparison, security safeguards, SDF obligations, DPDP compliance risk.

    Connect with me:
    💼 LinkedIn: https://www.linkedin.com/in/hskapoor/
    📄 Facebook: https://www.facebook.com/satarkintelligence
    ▶️ YouTube: https://www.youtube.com/@DPDPdaily
    🎙️ Apple Podcasts: https://podcasts.apple.com/us/podcast/dpdp-daily/id6793257111
    𝕏 X: https://x.com/TheOtherKapoor

    One practical DPDP insight every morning on LinkedIn, Facebook and X — and the DPDP Act Compliance Handbook: From Law to Ground Reality coming soon.

    This episode is educational commentary, not legal advice. The DPDP framework is in phased implementation and positions described may evolve through notifications, Board publications and judicial interpretation. For decisions affecting your organisation or your rights, consult a qualified professional with your specific facts.

    続きを読む 一部表示
    11 分
  • The Phased Timeline Decoded: What's Law Today Versus May 2027
    2026/07/30

    Somewhere in India today, a company lawyer is telling a boardroom: "The DPDP Act isn't really in force yet — we have time." Somewhere else, a consultant is telling a different boardroom: "You're already violating a live statute." Both are pointing at the same Gazette notifications, both are half-right, and each half-truth is dangerous alone.

    This episode decodes the phased commencement precisely. Why an Act passed in August 2023 stayed dormant for over two years, and what actually happened in November 2025. Wave one, live today: the definitions, the Data Protection Board, its digital-office design and the appeal architecture to TDSAT. Wave two, this November: the Consent Manager registration framework activates. Wave three, 13 May 2027: everything else — notices, consent, security safeguards, breach reporting clocks, retention, children's data, rights and grievance machinery.

    Then what the calendar actually means for behaviour. Why "largely not enforceable yet" comes with three corrections: the IT Act ecosystem, CERT-In directions and sectoral regulators never paused; enterprise contracts are already writing DPDP-readiness into vendor agreements, making the standard commercially binding regardless of the Gazette; and every unmapped database you accumulate now is remediation work bought at tomorrow's prices. Why the eighteen-month runway is a preparation period, not a grace period — and why "we started in April" will be an aggravating fact before the Board, not a defence. The three myths, named and dismantled. Per-audience quarterly actions for enterprises and SMEs, including the contract-clause check I'll wager at least one of your three largest customer agreements fails. And the four-channel regulatory watch that hears the next wave before your competitors do.

    DPDP Daily takes India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 out of the statute book and into real life — for compliance officers, lawyers, founders, small business owners and citizens. One practical episode every day, no jargon.

    I'm Harmeet Singh Kapoor, author of the DPDP Act Compliance Handbook: From Law to Ground Reality.

    Keywords: DPDP timeline, DPDP enforcement date, May 2027 deadline, DPDP Rules commencement, phased implementation, Consent Manager November 2026, Data Protection Board, CERT-In, DPDP compliance deadline, data protection India.

    Connect with me:
    💼 LinkedIn: https://www.linkedin.com/in/hskapoor/
    📄 Facebook: https://www.facebook.com/satarkintelligence
    ▶️ YouTube: https://www.youtube.com/@DPDPdaily
    🎙️ Apple Podcasts: https://podcasts.apple.com/us/podcast/dpdp-daily/id6793257111
    𝕏 X: https://x.com/TheOtherKapoor

    One practical DPDP insight every morning on LinkedIn, Facebook and X — and the DPDP Act Compliance Handbook: From Law to Ground Reality coming soon.

    This episode is educational commentary, not legal advice. The DPDP framework is in phased implementation and positions described may evolve through notifications, Board publications and judicial interpretation. For decisions affecting your organisation or your rights, consult a qualified professional with your specific facts.

    続きを読む 一部表示
    10 分