HomeAbout Us
Our Advisory TeamBlogs & UpdatesContactCareers
Get in Touch +91-8368623272

Every business today collects personal data — of customers, employees, vendors and website visitors. With India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Digital Personal Data Protection Rules, 2025 now in force on a phased basis, how that data is collected, used, stored and shared has become a legal obligation, not just good practice. Businesses that deal with clients in Europe or other jurisdictions must also meet the requirements of laws such as the EU General Data Protection Regulation (GDPR).

Lawnut helps organisations understand their obligations, close the gaps and build privacy compliance into everyday operations — in a practical, documented and audit-ready way.

Understanding the DPDP Framework

The DPDP Act governs the processing of digital personal data in India, and of personal data processed outside India in connection with offering goods or services to individuals in India. The DPDP Rules, 2025 were notified on 14 November 2025 and provide for an 18-month phased compliance timeline. Key requirements include:

  • Notice and consent: a clear, standalone notice explaining what personal data is collected and why, and valid consent for processing (subject to specified legitimate uses).
  • Purpose limitation: personal data may be used only for the purpose for which it was collected.
  • Security safeguards: reasonable security measures to protect personal data and prevent breaches.
  • Breach intimation: personal data breaches must be reported to the Data Protection Board and to the affected individuals.
  • Rights of individuals: access, correction, erasure, grievance redressal and nomination — with requests to be addressed within prescribed timelines.
  • Retention: personal data must be erased once the purpose is served, subject to legal retention requirements.
  • Children's data: verifiable consent of the parent or lawful guardian before processing a child's personal data.
  • Significant Data Fiduciaries: entities so notified have additional obligations, including a Data Protection Officer, independent data audits and data protection impact assessments.

Non-compliance can attract significant financial penalties imposed by the Data Protection Board of India.

Our Data Privacy Services

DPDP Act Compliance

  • Assessing the applicability of the DPDP Act and Rules to your business.
  • Data mapping — what personal data you collect, where it is stored, who can access it and with whom it is shared.
  • Gap assessment against the requirements of the Act and Rules.
  • Drafting consent notices and consent flows for websites, apps and forms.
  • Setting up processes for rights requests, grievance redressal and breach intimation.
  • A prioritised implementation roadmap aligned with the phased compliance timeline.

GDPR & Global Privacy

  • Applicability assessment for Indian businesses serving clients in the EU, UK and other jurisdictions.
  • Guidance for foreign companies with operations or processing activities in India.
  • Aligning privacy programmes across DPDP, GDPR and client contractual requirements.
  • Support with cross-border data transfer considerations and client privacy questionnaires.

Privacy Audits & Documentation

  • Privacy policies and notices for websites and applications.
  • Internal data protection policies, retention schedules and records of processing.
  • Data processing agreements and privacy clauses in vendor and client contracts.
  • Periodic privacy audits and compliance health-checks.
  • Board and management reporting on privacy compliance.

Our Approach

1. Assess

We understand your business, the personal data you handle and the laws that apply to you.

2. Map

We document your data flows — collection, storage, access, sharing and deletion.

3. Identify Gaps

We compare current practices against the DPDP Act, Rules and other applicable laws, and rate each gap by risk.

4. Implement

We prepare the notices, policies, contracts and processes needed to close the gaps, working with your teams.

5. Review

Periodic audits and updates keep your privacy programme current as the law and your business evolve.

Why Lawnut for Data Privacy

  • Legal and process expertise together: our team combines regulatory, legal and audit experience.
  • Practical documentation: policies and notices that your teams can actually follow.
  • Audit-ready approach: every step documented, so you can demonstrate compliance.
  • Integrated support: privacy compliance that works alongside your contracts, IT systems and AI initiatives.

Contact us for a data privacy applicability and gap assessment for your business.

Get in Touch

Ready to take the next step?

Schedule your free consultation — let's discuss how we can help you achieve your goals.