Consent, notice and the 72-hour breach rule under DPDP
Notice must stand on its own
Under Rule 3, the notice that precedes consent has to be understandable by itself, with an itemised description of the personal data, the specified purpose, and the means to withdraw consent, exercise rights and complain to the Board — offered in English or a scheduled Indian language. A privacy policy buried behind a link does not cut it.
Consent must be real — and easy to take back
Consent must be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and no broader than the purpose needs. Withdrawing it must be as easy as giving it, and when someone withdraws, you must stop — and make your processors stop too. If a dispute arises, you must be able to prove valid notice and consent were obtained.
Every breach, within 72 hours
DPDP has no harm or materiality threshold. Every personal data breach is notifiable — to each affected person without delay, and to the Board with a detailed report within 72 hours.
That is a higher bar than the GDPR's risk-based trigger, and it means your detection-to-notification pipeline has to be fast, rehearsed and evidenced. A 72-hour clock is not something to assemble by hand after the fact.
See it on your own frameworks
Book a 30-minute walkthrough and we'll map Compliance One to your environment.