Last updated: 20 August 2026
Short answers to questions that come up often, with a link to a fuller explainer for each. This page is for general information only and is not legal advice.
The Digital Personal Data Protection Rules, 2025 were notified on 14 November 2025, and the framework takes effect in stages. The main compliance obligations are due to apply around May 2027. Read more →
The Act gives individuals rights including access to information about their data, correction and erasure, grievance redressal, and the right to nominate another person to exercise their rights. Read more →
Consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and limited to the stated purpose. It can be withdrawn at any time. Read more →
A Data Fiduciary is the person or organisation that decides why and how personal data is processed; a Data Principal is the individual the data is about. Read more →
Processing a child's personal data generally requires verifiable consent from a parent or lawful guardian, and tracking, behavioural monitoring and targeted advertising directed at children are restricted. Read more →
It is the body established under the DPDP Act to oversee compliance, inquire into breaches and complaints, and impose penalties. Appeals from its decisions go to the Appellate Tribunal (TDSAT). Read more →
Call the toll-free helpline 1930 as soon as possible and file a complaint on cybercrime.gov.in. Reporting quickly gives the best chance of stopping the transfer of the funds. Read more →
Act quickly: report to 1930 and the cyber crime portal, inform your bank, and preserve evidence such as transaction details and screenshots. Read more →
It is India's primary law on electronic activity and cyber offences, enacted in 2000 and substantially amended in 2008. It recognises electronic records and signatures and defines offences such as identity theft and cheating by personation. Read more →
It can. Even without an establishment in the EU, the GDPR may apply if you offer goods or services to individuals in the EU, or monitor their behaviour in the EU. Read more →
Both protect personal data, but they differ in scope, terminology, the lawful bases for processing, and their penalty regimes. Read more →
It is a European Union law that regulates artificial intelligence using a risk-based approach, with four tiers from unacceptable risk (prohibited) to minimal risk. It entered into force in 2024 and applies in phases. Read more →
No. It is general information only and does not create a lawyer–client relationship. Legal issues turn on their specific facts, and formal legal advice should be obtained before acting on any information here.
The areas the practice works in are set out on the Areas of Practice page.