Privacy & Data Protection articles.
Privacy programmes that stand up to scrutiny — DPDPA and GDPR alignment, DPIAs, data mapping and ISO 27701 PIMS.
Latest in Privacy & Data Protection.
DPDPA Significant Data Fiduciary: What the November 2026 Deadline Means for You
India’s Digital Personal Data Protection Rules, notified in November 2025, take effect in phases — and the next major milestone, Rule 4, lands on 13 November 2026, bringing notice-and-consent requirements and Significant Data Fiduciary obligations into force.
Read article →Privacy Meets the EU AI Act: Data Obligations for Organizations Building or Deploying AI
Teams building or deploying AI systems that touch EU users now have two overlapping regimes to satisfy — existing data protection law, and the EU AI Act’s own data-related obligations, which aren’t identical even where they look like they should be.
Read article →Data Localization and Sovereignty: What Multi-Country Operations Need to Know
A company operating across even three or four countries is now navigating three or four distinct, independently evolving sets of expectations about where data physically lives and who can access it — and the gap between “legally allowed” and “genuinely sovereign” is widening in several major markets at once.
Read article →Data Minimization in Practice: Cutting Collected PII Without Breaking Your Product
Every privacy framework — DPDPA, GDPR, and most sectoral regulations — names data minimization as a core principle. Almost every product team, asked to actually cut a data field, pushes back that they might need it someday. Both positions are reasonable, which is exactly why this needs a real process, not a mandate.
Read article →Privacy by Design: Embedding DPIAs Into Your Product Development Lifecycle
A DPIA commissioned after a feature has already shipped can only tell you what you got wrong. A DPIA built into design review tells you before you’ve built anything — which is the entire point of “privacy by design” as a practice, not just a GDPR Article 25 phrase.
Read article →DPDPA Compliance: A Practical Checklist for Indian Businesses
India’s Digital Personal Data Protection Act (DPDPA) changes what “consent” and “data handling” mean for any business processing personal data of individuals in India — and the operational work to get ready is more involved than it sounds from the headlines.
Read article →