Law & Legal

Data Protection and Privacy

Indian data protection has moved from a policy question to an operational one, and most organisations are still answering the policy question.

What we do

We advise on the Digital Personal Data Protection Act, 2023 and the rules made under it, and we do it at the level of what has to change in the business rather than at the level of what the statute says. Gap assessment against current processing. Notice and consent architecture, including consent that can be withdrawn as easily as it was given, which is where most implementations fail. Data principal rights and the machinery to answer them within time. Processor contracting and the flow-down obligations. Cross-border transfer. Breach assessment and reporting, and the decisions that have to be taken in the first day. Governance, being the appointment and positioning of the person responsible, the grievance mechanism and the audit trail. For international groups we map the Indian obligations against an existing General Data Protection Regulation programme and identify only the delta, which is usually far smaller than feared and different in the places that matter.

Experience

The matters below are described without identifying the client, unless the client has consented in writing to being named.

Matter lines to be added from the group's work in this area. No client name without written consent on file.

Matters are described at the level of transaction type, sector and outcome rather than identifying detail.

Further entries to be populated at launch.

Key Contacts

John

Partner

John

Partner

Latest Insights

Scroll to Top