Skip to content

Adjacent India requirements

DPDP is not the only rule set. OpenDPDP stores each overlay independently, with entity/activity scope and conflict review.

Existing law — provision-specific transition

The Information Technology Act, 2000 and the 2011 SPDI Rules remain part of the current analysis. DPDP section 44 amends/repeals connected provisions in a phased commencement. Do not assert that section 43A/SPDI disappeared merely because the DPDP Act was enacted; verify the specific section 44 cohort and any later repeal instrument at the time of advice.

Until transition is legally complete for the relevant provision, customers may need controls for SPDI privacy policy, consent, purpose, disclosure, transfer and reasonable security. The legal configuration supports effective periods so the same record is not double-counted after transition.

Adjacent India law — in force

The 2022 Directions apply to specified broad classes and include:

  • time synchronisation to authorised sources;
  • six-hour reporting for listed cyber incidents;
  • information/cooperation duties;
  • secure maintenance of ICT logs for a rolling 180 days within India;
  • additional subscriber/customer information duties for identified provider classes.

Use the official FAQ and extension. A security incident record can have separate CERT_IN, DPDP, sector and contract decisions.

The Consumer Protection Act/e-commerce framework and CCPA Dark Patterns Guidelines affect consumer interfaces. Consent and withdrawal designs prohibit disguised advertisements, false urgency, basket sneaking, confirmshaming, forced action, subscription traps, interface interference, drip-pricing and other notified practices where applicable. The product review records screenshots, journey steps and remediation, not only text approval.

Regulatory advisory

The CCPA’s 5 June 2025 advisory asked e-commerce platforms to self-audit within three months and remediate dark patterns. Store it as an advisory overlay with its own scope/evidence; do not convert it into a universal DPDP duty or a software-issued “dark-pattern-free” certification.

Role-specific adjacent law

The IT Intermediary Rules apply only after a legal role/category assessment. Configure relevant grievance, due-diligence, preservation, disclosure and cooperation tasks separately from DPDP. April 2026 proposed amendments located in this pass remain labelled draft. Never infer that every SaaS product, marketplace or customer forum is an intermediary.

The Aadhaar Act and UIDAI regulations govern authentication/offline verification roles, consent, purpose, storage, security and audit. OpenDPDP supports pluggable identity assurance and stores a provider token/outcome rather than Aadhaar numbers or XML by default. Voluntary DPBI portal approval is not a universal basis for private customer use.

DigiLocker, eSign, KYC and Account Aggregator artefacts each have their own programme and legal contracts. They can supply evidence or consent instructions through an adapter but are not collapsed into DPDP consent.

The consolidated TCCCPR framework governs senders, headers/templates, customer preferences, consents, DLT and complaints for commercial communication. A DPDP marketing consent does not by itself satisfy TCCCPR registration/template/preference requirements. Maintain linked but distinct receipts and suppression outcomes.

Evidence, employment and public-sector context

Section titled “Evidence, employment and public-sector context”

The Bharatiya Sakshya Adhiniyam’s electronic-record provisions require more than a hash: preserve source, system-operation, custody and certificate inputs and obtain case-specific counsel on admissibility. Contract terms can allocate processor performance but cannot contract out of a Fiduciary’s statutory accountability. Companies Act, tax, labour, limitation, employment, public-record and litigation rules may require record-class retention; record the exact provision and trigger instead of applying a generic “corporate” hold. RTI/public authority and State processing need a separate role/exemption analysis.

National security and critical infrastructure

Section titled “National security and critical infrastructure”

NCIIPC and sector critical-infrastructure controls apply only to notified protected systems and covered organisations. The product can enable the pack after recording the notification and authority; it cannot self-designate a system as legally protected.

Avoid using consent/identity metadata to create an unrelated market profile, discriminatory access or a closed transfer gate. Export source, control, consent and case records in documented formats; support customer-controlled keys and connector portability; publish deprecation and migration periods.

TopicDPDPAdjacent/sectorResolution behavior
incident clockwithout delay + 72-hour Board detail (future)CERT-In six hours; sector clocksrun every applicable clock
logsRule 6 one year for stated purpose (future)CERT-In 180 days in India; sector rulespurpose-tagged rule per log class
erasurepurpose/withdrawal subject to lawKYC, transaction, claims, trial, tax, litigationrestrict use; retain only scoped record
marketingconsent/s7 analysisTCCCPR and consumer rulesrequire both applicable control sets
identityauthenticated rights routeAadhaar/UIDAI, KYC, programme termsleast-intrusive lawful method
localisationnotified/order-dependentactivity/entity-specific sector rulesmost restrictive applicable rule, with rationale