Category Archives: Data Protection & Compliance

DPDP Act Contract Compliance in India: Which Agreements to Update, Which Clauses to Change

Written by: Prakhar Rai, Advocate | Founder, My Legal Pal | Enrolled with the Bar Council of India | Contracts and data protection lawyer in India Last reviewed: 6 October 2026, against the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 Quick answer If your business handles personal data in India, a […]

Standard Contractual Clauses (SCCs): How Businesses Legally Export EU Personal Data to Non-Adequate Countries

Written by: Prakhar Rai, Founder, My Legal Pal | Bar Council of India | LL.B, NLSIU Bangalore | Master of Business Laws | Advises on GDPR, UK GDPR, and cross-border data transfer compliance Quick answer The GDPR restricts moving personal data out of the EEA unless the destination has specific legal cover. Standard Contractual Clauses, […]

Data Mapping Under DPDP: A Practical Guide for Indian Businesses (2026)

Written by: Prakhar Rai, Founder, My Legal Pal | Bar Council of India | LL.B, NLSIU Bangalore | Master of Business Laws | Advises on DPDP, GDPR, and CCPA compliance for businesses operating in and outside India Quick answer Data mapping is the exercise of finding out, in specific and current terms, what personal data […]

Data Protection Law in Argentina: How It Differs From GDPR and CCPA (2026)

TL;DR: Argentina’s data protection framework, Ley 25.326, predates both GDPR and CCPA by well over a decade, and it holds something neither of those frameworks has with each other: an active EU adequacy decision, reconfirmed by the European Commission as recently as January 2024, making Argentina the only Latin American jurisdiction with that status. But […]

What Is a DPIA, and When Does Your Company Need One Under DPDP? (2026)

TL;DR: A Data Protection Impact Assessment, or DPIA, is a structured review of how your company processes personal data, what risks that creates for the people whose data it is, and whether your safeguards are actually adequate. Under India’s DPDP Rules, 2025, a DPIA is not required for every business, it is a specific, mandatory […]

Data Breach Response: The Legal Playbook for the First 72 Hours (2026)

 TL;DR: A breach doesn’t wait for you to figure out who to call. If your business handles sensitive data across multiple countries, a single incident can trigger CERT-In’s 6-hour window, GDPR’s 72-hour window, and separate obligations under the US, Australia, and India’s DPDP Act simultaneously, on independent clocks that don’t wait for each other. Most […]

You Have International Users. That Means You Have International Legal Obligations.

You Have International Users. That Means You Have International Legal Obligations.

Here is something most founders discover too late: data protection law does not follow your company. It follows your users. You might be incorporated in India, operating from Dubai, with your servers on AWS in Singapore. But the moment a user in Germany signs up for your product, the EU’s General Data Protection Regulation applies […]

Consent Management Rules under the Digital Personal Data Protection Act (DPDPA), 2023:

Consent Management Rules under the Digital Personal Data Protection Act (DPDPA), 2023:

TL;DR: Consent management under India’s DPDP Act is not a policy document, it is something you build: a notice shown before you collect data, a consent mechanism that captures a genuine yes per purpose, a system that logs what was consented to and when, a withdrawal path as easy as the original consent, and a […]

DPDP Act 2023: The Complete 2026 Compliance Guide for Data Fiduciaries and Processors

DPDP Act

TL;DR: The Digital Personal Data Protection Act, 2023 governs how anyone, anywhere, handles the digital personal data of people in India. Its Rules were notified on 14 November 2025, and full compliance is due by 13 May 2027. The Act covers not just Indian companies but any business in the world that processes an Indian […]

Data Protection Laws Around the World: Understanding Global Regulations

TL;DR: Data protection laws govern how organisations collect, use, store, and share personal data, and they now exist almost everywhere. As of 2026, more than 170 countries have enacted data protection legislation, covering around 79% of the world’s population. The EU’s GDPR remains the global benchmark, and most newer laws, including India’s DPDP Act, Brazil’s […]