Data Privacy & Cyber Law Hub: Q&A Library: practical Indian finance and law guidance from Finin2min.
Scope, Territorial Reach and ExclusionsWhat is the Finin2min conclusion on Scope, Territorial Reach and Exclusions?
Map whether data is digital, processed in India or connected with offering goods or services to individuals in India, then test exclusions.
Scope, Territorial Reach and ExclusionsWhich legal anchor applies to Scope, Territorial Reach and Exclusions?
DPDP Act ss.2–3
Scope, Territorial Reach and ExclusionsWhat evidence is most important for Scope, Territorial Reach and Exclusions?
data inventory and processing register; privacy notice and consent artefacts; processor contracts and security schedules; retention and deletion logs
Scope, Territorial Reach and ExclusionsWhat is the recommended action for Scope, Territorial Reach and Exclusions?
Create a jurisdiction and data-flow memo.
DPDP Commencement RoadmapWhat is the Finin2min conclusion on DPDP Commencement Roadmap?
Operational planning must separate provisions already commenced from those due in November 2026 and May 2027.
DPDP Commencement RoadmapWhich legal anchor applies to DPDP Commencement Roadmap?
Notification dated 13 November 2025
DPDP Commencement RoadmapWhat evidence is most important for DPDP Commencement Roadmap?
data inventory and processing register; privacy notice and consent artefacts; processor contracts and security schedules; retention and deletion logs
DPDP Commencement RoadmapWhat is the recommended action for DPDP Commencement Roadmap?
Maintain a section-level commencement matrix.
Data Principal, Fiduciary, Processor and Consent ManagerWhat is the Finin2min conclusion on Data Principal, Fiduciary, Processor and Consent Manager?
Correct role classification drives notices, contracts, rights, breach and accountability.
Data Principal, Fiduciary, Processor and Consent ManagerWhich legal anchor applies to Data Principal, Fiduciary, Processor and Consent Manager?
DPDP Act definitions and Rules
Data Principal, Fiduciary, Processor and Consent ManagerWhat evidence is most important for Data Principal, Fiduciary, Processor and Consent Manager?
data inventory and processing register; privacy notice and consent artefacts; processor contracts and security schedules; retention and deletion logs
Data Principal, Fiduciary, Processor and Consent ManagerWhat is the recommended action for Data Principal, Fiduciary, Processor and Consent Manager?
Map role per processing activity, not per legal entity only.
Notice, Consent and Lawful ProcessingWhat is the Finin2min conclusion on Notice, Consent and Lawful Processing?
Consent should be informed, specific, clear and withdrawable, supported by the prescribed notice architecture.
Notice, Consent and Lawful ProcessingWhich legal anchor applies to Notice, Consent and Lawful Processing?
DPDP Act ss.4–6; DPDP Rules
Notice, Consent and Lawful ProcessingWhat evidence is most important for Notice, Consent and Lawful Processing?
data inventory and processing register; privacy notice and consent artefacts; processor contracts and security schedules; retention and deletion logs
Notice, Consent and Lawful ProcessingWhat is the recommended action for Notice, Consent and Lawful Processing?
Redesign notices and consent records by purpose.
Certain Legitimate UsesWhat is the Finin2min conclusion on Certain Legitimate Uses?
Non-consent processing is limited to statutory categories and must not become a generic convenience basis.
Certain Legitimate UsesWhich legal anchor applies to Certain Legitimate Uses?
DPDP Act s.7
Certain Legitimate UsesWhat evidence is most important for Certain Legitimate Uses?
data inventory and processing register; privacy notice and consent artefacts; processor contracts and security schedules; retention and deletion logs
Certain Legitimate UsesWhat is the recommended action for Certain Legitimate Uses?
Document the exact clause, facts and proportionality.
Children and Persons with DisabilityWhat is the Finin2min conclusion on Children and Persons with Disability?
Age assurance, verifiable parental consent and restricted tracking/advertising require product-level controls, subject to notified exceptions.
Children and Persons with DisabilityWhich legal anchor applies to Children and Persons with Disability?
DPDP Act s.9; DPDP Rules
Children and Persons with DisabilityWhat evidence is most important for Children and Persons with Disability?
data inventory and processing register; privacy notice and consent artefacts; processor contracts and security schedules; retention and deletion logs
Children and Persons with DisabilityWhat is the recommended action for Children and Persons with Disability?
Create a child-user flow and exception register.
Significant Data FiduciaryWhat is the Finin2min conclusion on Significant Data Fiduciary?
Notification as an SDF adds DPO, audit, assessment and governance obligations.
Significant Data FiduciaryWhich legal anchor applies to Significant Data Fiduciary?
DPDP Act s.10; DPDP Rules
Significant Data FiduciaryWhat evidence is most important for Significant Data Fiduciary?
data inventory and processing register; privacy notice and consent artefacts; processor contracts and security schedules; retention and deletion logs
Significant Data FiduciaryWhat is the recommended action for Significant Data Fiduciary?
Build an SDF-readiness file.
Data Principal Rights and DutiesWhat is the Finin2min conclusion on Data Principal Rights and Duties?
Access, correction, erasure, grievance and nomination need authenticated, traceable workflows; users also have statutory duties.
Data Principal Rights and DutiesWhich legal anchor applies to Data Principal Rights and Duties?
DPDP Act ss.11–15; DPDP Rules
Data Principal Rights and DutiesWhat evidence is most important for Data Principal Rights and Duties?
data inventory and processing register; privacy notice and consent artefacts; processor contracts and security schedules; retention and deletion logs
Data Principal Rights and DutiesWhat is the recommended action for Data Principal Rights and Duties?
Implement ticket, identity, decision and closure evidence.
Personal Data Breach ResponseWhat is the Finin2min conclusion on Personal Data Breach Response?
DPDP and CERT-In may require parallel assessment, communications and records with different triggers.
Personal Data Breach ResponseWhich legal anchor applies to Personal Data Breach Response?
DPDP Act and DPDP Rules; CERT-In overlay
Personal Data Breach ResponseWhat evidence is most important for Personal Data Breach Response?
data inventory and processing register; privacy notice and consent artefacts; processor contracts and security schedules; retention and deletion logs
Personal Data Breach ResponseWhat is the recommended action for Personal Data Breach Response?
Activate legal, security, communications and evidence tracks immediately.
Cross-Border Data TransfersWhat is the Finin2min conclusion on Cross-Border Data Transfers?
The framework permits transfers subject to notified restrictions and other Indian or foreign sectoral rules.
Cross-Border Data TransfersWhich legal anchor applies to Cross-Border Data Transfers?
DPDP Act s.16 and government directions
Cross-Border Data TransfersWhat evidence is most important for Cross-Border Data Transfers?
data inventory and processing register; privacy notice and consent artefacts; processor contracts and security schedules; retention and deletion logs
Cross-Border Data TransfersWhat is the recommended action for Cross-Border Data Transfers?
Maintain country, vendor and sector restriction mapping.
Retention, Erasure and Purpose CompletionWhat is the Finin2min conclusion on Retention, Erasure and Purpose Completion?
Data should not be retained indefinitely after purpose completion unless law requires it.
Retention, Erasure and Purpose CompletionWhich legal anchor applies to Retention, Erasure and Purpose Completion?
DPDP Act s.8; DPDP Rules
Retention, Erasure and Purpose CompletionWhat evidence is most important for Retention, Erasure and Purpose Completion?
data inventory and processing register; privacy notice and consent artefacts; processor contracts and security schedules; retention and deletion logs
Retention, Erasure and Purpose CompletionWhat is the recommended action for Retention, Erasure and Purpose Completion?
Define legal holds, deletion jobs and backup treatment.
Processor Contracts and AccountabilityWhat is the Finin2min conclusion on Processor Contracts and Accountability?
The fiduciary remains accountable and needs enforceable instructions, security, breach and deletion terms.
Processor Contracts and AccountabilityWhich legal anchor applies to Processor Contracts and Accountability?
DPDP Act s.8 and Rules
Processor Contracts and AccountabilityWhat evidence is most important for Processor Contracts and Accountability?
data inventory and processing register; privacy notice and consent artefacts; processor contracts and security schedules; retention and deletion logs
Processor Contracts and AccountabilityWhat is the recommended action for Processor Contracts and Accountability?
Use a data-processing schedule with audit and subprocessor controls.
Data Protection Board and EnforcementWhat is the Finin2min conclusion on Data Protection Board and Enforcement?
The Board is digital by design and can inquire into breaches and non-compliance, issue directions and impose penalties under the statutory framework.
Data Protection Board and EnforcementWhich legal anchor applies to Data Protection Board and Enforcement?
DPDP Act ss.18–34; DPDP Rules
Data Protection Board and EnforcementWhat evidence is most important for Data Protection Board and Enforcement?
data inventory and processing register; privacy notice and consent artefacts; processor contracts and security schedules; retention and deletion logs
Data Protection Board and EnforcementWhat is the recommended action for Data Protection Board and Enforcement?
Establish authorised receipt, preservation and response governance.
DPDP Rules, 2025 Operating MapWhat is the Finin2min conclusion on DPDP Rules, 2025 Operating Map?
The Rules translate the Act into notice, breach, rights, child, SDF, consent-manager and Board procedures.
DPDP Rules, 2025 Operating MapWhich legal anchor applies to DPDP Rules, 2025 Operating Map?
DPDP Rules, 2025
DPDP Rules, 2025 Operating MapWhat evidence is most important for DPDP Rules, 2025 Operating Map?
data inventory and processing register; privacy notice and consent artefacts; processor contracts and security schedules; retention and deletion logs
DPDP Rules, 2025 Operating MapWhat is the recommended action for DPDP Rules, 2025 Operating Map?
Create a rule-to-control-to-evidence register.
IT Act and SPDI TransitionWhat is the Finin2min conclusion on IT Act and SPDI Transition?
Legacy privacy and cybersecurity duties may continue during the phased transition and in areas not displaced.
IT Act and SPDI TransitionWhich legal anchor applies to IT Act and SPDI Transition?
IT Act, SPDI Rules and DPDP consequential amendments
IT Act and SPDI TransitionWhat evidence is most important for IT Act and SPDI Transition?
data inventory and processing register; privacy notice and consent artefacts; processor contracts and security schedules; retention and deletion logs
IT Act and SPDI TransitionWhat is the recommended action for IT Act and SPDI Transition?
Run a transition analysis, not a replacement assumption.
CERT-In Six-Hour Incident ReportingWhat is the Finin2min conclusion on CERT-In Six-Hour Incident Reporting?
Specified cyber incidents should be reported within six hours of noticing, with available information supplemented later.
CERT-In Six-Hour Incident ReportingWhich legal anchor applies to CERT-In Six-Hour Incident Reporting?
CERT-In directions and FAQs
CERT-In Six-Hour Incident ReportingWhat evidence is most important for CERT-In Six-Hour Incident Reporting?
data inventory and processing register; privacy notice and consent artefacts; processor contracts and security schedules; retention and deletion logs
CERT-In Six-Hour Incident ReportingWhat is the recommended action for CERT-In Six-Hour Incident Reporting?
Pre-authorise contacts, templates and clock-start rules.
Intermediary and Synthetic Content DutiesWhat is the Finin2min conclusion on Intermediary and Synthetic Content Duties?
Platforms need due diligence, grievance, takedown and specified synthetic-content controls based on their role and scale.
Intermediary and Synthetic Content DutiesWhich legal anchor applies to Intermediary and Synthetic Content Duties?
IT Intermediary Rules, including 2026 changes
Intermediary and Synthetic Content DutiesWhat evidence is most important for Intermediary and Synthetic Content Duties?
data inventory and processing register; privacy notice and consent artefacts; processor contracts and security schedules; retention and deletion logs
Intermediary and Synthetic Content DutiesWhat is the recommended action for Intermediary and Synthetic Content Duties?
Map product features to intermediary obligations.
Cybersecurity Governance and AuditWhat is the Finin2min conclusion on Cybersecurity Governance and Audit?
Security needs governance, asset ownership, logging, testing, access control and incident exercises.
Cybersecurity Governance and AuditWhich legal anchor applies to Cybersecurity Governance and Audit?
IT Act, CERT-In and sectoral standards
Cybersecurity Governance and AuditWhat evidence is most important for Cybersecurity Governance and Audit?
data inventory and processing register; privacy notice and consent artefacts; processor contracts and security schedules; retention and deletion logs
Cybersecurity Governance and AuditWhat is the recommended action for Cybersecurity Governance and Audit?
Adopt control, evidence, exception and remediation registers.
Cloud, SaaS and Vendor Privacy ReviewWhat is the Finin2min conclusion on Cloud, SaaS and Vendor Privacy Review?
Vendor onboarding should cover data role, location, subprocessors, security, breach, continuity and exit.
Cloud, SaaS and Vendor Privacy ReviewWhich legal anchor applies to Cloud, SaaS and Vendor Privacy Review?
DPDP, contract and sector rules
Cloud, SaaS and Vendor Privacy ReviewWhat evidence is most important for Cloud, SaaS and Vendor Privacy Review?
data inventory and processing register; privacy notice and consent artefacts; processor contracts and security schedules; retention and deletion logs
Cloud, SaaS and Vendor Privacy ReviewWhat is the recommended action for Cloud, SaaS and Vendor Privacy Review?
Use risk-tiered procurement gates.
Privacy Impact and Product ReviewWhat is the Finin2min conclusion on Privacy Impact and Product Review?
High-risk products should assess necessity, user impact, safeguards, residual risk and approvals before launch.
Privacy Impact and Product ReviewWhich legal anchor applies to Privacy Impact and Product Review?
DPDP governance and SDF assessment concepts
Privacy Impact and Product ReviewWhat evidence is most important for Privacy Impact and Product Review?
data inventory and processing register; privacy notice and consent artefacts; processor contracts and security schedules; retention and deletion logs
Privacy Impact and Product ReviewWhat is the recommended action for Privacy Impact and Product Review?
Integrate privacy review into product approval.