India sits at the centre of the global digital economy and plays a massive role in the global digital ecosystem by contributing as the largest user base for various digital platforms. It also processes a large proportion to the global financial transactions. Further, the Indian IT industry acts as data processors for various major global MNCs.
Now India's first comprehensive data protection law, the Digital Personal Data Protection Act, operationalised by the DPDP Rules 2025, is in force and rolling out in phases. Businesses are on the clock to map, implement and achieve compliance, or face penalties of up to ₹250 crore. Full compliance falls due on 13 May 2027 — under nine months away
The webinar will focus on how organisations can gear up to achieve compliance within limited time and what to expect in the future.
Why this matters for businesses?
Companies that collect, process or store personal data (which is nearly all the companies) must be compliant by 13 May 2027. The real questions are who, what, when and how: who you are under the Act, what it requires, when each obligation bites, and how to get there
The DPDP framework maps onto how data actually moves through a business. Most companies already have data-processing procedures in place; much of the work is aligning what you already do with what the law now requires, and filling the gaps. For some it will be a build from scratch. Either way, it is achievable in the window that's left, if you start now.
Key takeaways:
The nitty-gritties of privacy policies and notices
Building your consent framework before it goes operational
Developing and deploying a data governance framework
Are you a Data Fiduciary or a Data Processor — and why it matters
Engaging and managing your processors, and getting the contracts right
Speakers
Prashant Phillips, Executive Partner
Asish Philip Abraham, Executive Partner
Noorul Hassan, Executive Partner
Neelambera Sandeepan, Partner
Related Articles
Discuss this topic with our Data Protection & TMT team
Contact Us



