RISKFORTIS

Insights

Writing for people who will have to run this.

Operational consequences of India's data protection rules, written by practitioners. No summaries of the Act.

Breach response · 04 Aug 2026

The eleventh day: when your processor's logs move the awareness date

Rule 7 measures every deadline from awareness, and awareness is a finding of fact your own ticket system will settle. What to do when forensics hands you a date eleven days earlier than the one you filed against.

11 MIN READRead

Showing 10 articles

Consent & notice · 29 Jul 2026

Your consent tick is one artefact where the Rules want several

Bundled onboarding consent fails on purpose separation and on withdrawal. What a compliant capture record actually stores, field by field.

08 MIN

Sector: Lending · 22 Jul 2026

Three places borrower data sits that your RoPA does not list

Collections agent devices, LSP crash logs and the DLT message trail. Each is a processor relationship, and none of them signed anything.

09 MIN

Sector: GCC · 15 Jul 2026

You are a processor for the parent and a fiduciary for your own staff

Both duty sets land on the same entity and the same estate. Which obligations the global privacy programme genuinely covers, and which it never touches.

07 MIN

Breach response · 08 Jul 2026

Six hours is 8.3% of seventy-two, and your bridge call has not started

Teams rehearse the DPDP window and miss the CERT-In one. A minute-by-minute account of where the first six hours actually go.

10 MIN

SDF & governance · 01 Jul 2026

Nobody will tell you that you are a Significant Data Fiduciary

The designation turns on volume, sensitivity and risk, and the duties it brings are the expensive ones. How to write the applicability opinion before the Board writes it for you.

12 MIN

Cross-border · 24 Jun 2026

Transfer is permitted until it isn't: writing an assessment that survives a restriction

DPDP allows transfer except where Government restricts the destination. What that negative permission means for a flow you cannot unwind in a week.

08 MIN

Sector: Healthcare · 17 Jun 2026

Three consent models in one patient record

Diagnostics partners, ABDM linkage and verifiable parental consent, sitting in the same file with different bases and different retention.

09 MIN

SDF & governance · 10 Jun 2026

A documented breach plan and a tested one are not the same artifact

Only one of them survives an inquiry. What the Board is likely to ask for, and what an attestation of exercise needs to contain.

07 MIN

Consent & notice · 03 Jun 2026

Notice in twenty-two languages is a delivery problem, not a translation one

Which surfaces have to carry it, how versions are pinned to consent artefacts, and why the app is the easy part.

06 MIN

The Breach Clock

One decision, posed as a question, every Monday. The rule reference on Tuesday.

No promotion. Unsubscribe in one click.

Reading about it is cheaper than finding out during an incident.

Talk to DPDP experts

Free consultation · 45 min · in-house privacy counsel and certified fraud examiners.