Blog · Group 01 · Assurance & Compliance

Privacy & Data Protection articles.

Privacy programmes that stand up to scrutiny — DPDPA and GDPR alignment, DPIAs, data mapping and ISO 27701 PIMS.

Articles

Latest in Privacy & Data Protection.

Privacy & Data Protection

DPDPA Significant Data Fiduciary: What the November 2026 Deadline Means for You

India’s Digital Personal Data Protection Rules, notified in November 2025, take effect in phases — and the next major milestone, Rule 4, lands on 13 November 2026, bringing notice-and-consent requirements and Significant Data Fiduciary obligations into force.

October 8, 2026·3 min read
Read article →
Privacy & Data Protection

Privacy Meets the EU AI Act: Data Obligations for Organizations Building or Deploying AI

Teams building or deploying AI systems that touch EU users now have two overlapping regimes to satisfy — existing data protection law, and the EU AI Act’s own data-related obligations, which aren’t identical even where they look like they should be.

August 31, 2026·3 min read
Read article →
Privacy & Data Protection

Data Localization and Sovereignty: What Multi-Country Operations Need to Know

A company operating across even three or four countries is now navigating three or four distinct, independently evolving sets of expectations about where data physically lives and who can access it — and the gap between “legally allowed” and “genuinely sovereign” is widening in several major markets at once.

July 27, 2026·3 min read
Read article →
Privacy & Data Protection

Data Minimization in Practice: Cutting Collected PII Without Breaking Your Product

Every privacy framework — DPDPA, GDPR, and most sectoral regulations — names data minimization as a core principle. Almost every product team, asked to actually cut a data field, pushes back that they might need it someday. Both positions are reasonable, which is exactly why this needs a real process, not a mandate.

June 22, 2026·3 min read
Read article →
Privacy & Data Protection

Privacy by Design: Embedding DPIAs Into Your Product Development Lifecycle

A DPIA commissioned after a feature has already shipped can only tell you what you got wrong. A DPIA built into design review tells you before you’ve built anything — which is the entire point of “privacy by design” as a practice, not just a GDPR Article 25 phrase.

May 18, 2026·3 min read
Read article →
Privacy & Data Protection

DPDPA Compliance: A Practical Checklist for Indian Businesses

India’s Digital Personal Data Protection Act (DPDPA) changes what “consent” and “data handling” mean for any business processing personal data of individuals in India — and the operational work to get ready is more involved than it sounds from the headlines.

April 27, 2026·2 min read
Read article →