Frequently Asked Questions

Last updated: 20 August 2026

Short answers to questions that come up often, with a link to a fuller explainer for each. This page is for general information only and is not legal advice.

Data protection (DPDP Act)

When does the DPDP Act take effect?

The Digital Personal Data Protection Rules, 2025 were notified on 14 November 2025, and the framework takes effect in stages. The main compliance obligations are due to apply around May 2027. Read more →

What rights do I have over my personal data under the DPDP Act?

The Act gives individuals rights including access to information about their data, correction and erasure, grievance redressal, and the right to nominate another person to exercise their rights. Read more →

What makes consent valid under the DPDP Act?

Consent must be free, specific, informed, unconditional and unambiguous, given through a clear affirmative action, and limited to the stated purpose. It can be withdrawn at any time. Read more →

Who is a Data Fiduciary and who is a Data Principal?

A Data Fiduciary is the person or organisation that decides why and how personal data is processed; a Data Principal is the individual the data is about. Read more →

How is children's data treated under the DPDP Act?

Processing a child's personal data generally requires verifiable consent from a parent or lawful guardian, and tracking, behavioural monitoring and targeted advertising directed at children are restricted. Read more →

What is the Data Protection Board of India?

It is the body established under the DPDP Act to oversee compliance, inquire into breaches and complaints, and impose penalties. Appeals from its decisions go to the Appellate Tribunal (TDSAT). Read more →

Cyber crime & fraud

How do I report online financial fraud in India?

Call the toll-free helpline 1930 as soon as possible and file a complaint on cybercrime.gov.in. Reporting quickly gives the best chance of stopping the transfer of the funds. Read more →

What should I do first if I have been defrauded online?

Act quickly: report to 1930 and the cyber crime portal, inform your bank, and preserve evidence such as transaction details and screenshots. Read more →

What is the Information Technology Act, 2000?

It is India's primary law on electronic activity and cyber offences, enacted in 2000 and substantially amended in 2008. It recognises electronic records and signatures and defines offences such as identity theft and cheating by personation. Read more →

GDPR & international

Does the GDPR apply to my business in India?

It can. Even without an establishment in the EU, the GDPR may apply if you offer goods or services to individuals in the EU, or monitor their behaviour in the EU. Read more →

How does the GDPR differ from the DPDP Act?

Both protect personal data, but they differ in scope, terminology, the lawful bases for processing, and their penalty regimes. Read more →

AI & emerging technology

What is the EU AI Act?

It is a European Union law that regulates artificial intelligence using a risk-based approach, with four tiers from unacceptable risk (prohibited) to minimal risk. It entered into force in 2024 and applies in phases. Read more →

About this website

Is the information on this website legal advice?

No. It is general information only and does not create a lawyer–client relationship. Legal issues turn on their specific facts, and formal legal advice should be obtained before acting on any information here.

Where can I read about the areas of practice?

The areas the practice works in are set out on the Areas of Practice page.