The DPDP Act, 2023: what it actually requires
The obligations the Act places on anyone who decides why and how personal data is processed — notice, consent, security, breach reporting, children's data and grievance redressal.
Read the noteWriting a consent notice that meets Section 5
The four items a DPDP notice must contain, the language requirement, and the drafting habits that cause a notice to fail.
Read the noteCookies and trackers: what Indian law actually says
India has no dedicated cookie law. The obligation comes from the DPDP Act where a cookie processes personal data, and from the dark-pattern guidelines where the banner is designed to push a choice.
Read the noteIT Rules, 2021: what an intermediary must publish and when it must act
Publication duties, the Grievance Officer, the 24-hour and 15-day timelines, and the take-down obligations that attach to a website hosting third-party content.
Read the noteSPDI Rules, 2011: the older regime that still applies
Section 43A of the IT Act and the 2011 Rules on sensitive personal data — the privacy-policy contents, written consent, disclosure and the ISO 27001 security benchmark.
Read the noteCERT-In Directions, 2022: six hours to report, 180 days of logs
The reporting, log-retention, clock-synchronisation and KYC directions issued under Section 70B(6) of the IT Act, and who they bind.
Read the noteE-commerce disclosure and the 2023 dark-pattern guidelines
What an online seller must display, the consumer grievance timelines, and the thirteen specified dark patterns a platform may not use.
Read the noteA personal data breach in India: who you must tell, and how fast
Two separate reporting duties run in parallel — CERT-In within six hours and the Data Protection Board under the DPDP Act — plus sector rules for regulated entities.
Read the noteSee how your own site measures up
The audit checks a live website against the same provisions these notes describe.
