Your data register
is now a legal register.
Every company, society, trust, LLP and professional practice that touches an Indian's personal data is a Data Fiduciary under the DPDP Act — whether or not it ever meant to be. JurisTatva builds the notices, consent architecture, registers, policies and SOPs that turn that exposure into a documented, defensible compliance file.
The Act does not ask what kind of entity you are.
It asks whether you determine the purpose and means of processing digital personal data in India. A "person" under Sec. 2(s) includes companies, societies, trusts, LLPs, sole proprietors and unincorporated associations alike — for-profit or not.
Employee & HR Records
Payroll, PF/ESI, appraisals and contact data of staff and consultants — Sec. 5's notice duty applies to every Data Principal, including employees.
Members, Donors & Investors
Governing body, shareholder, donor and funder contact details — a not-for-profit or society structure gives no exemption.
Website, App & Event Data
Visitors, newsletter subscribers, webinar and training participants — every intake channel is a processing activity.
Vendor & Client Contacts
Any personal data shared with, or received from, processors and sub-processors under a service contract.
The Flagship Portals
The advisory company & compliance partner behind every platform below.
Our Specialised Venture Platforms
Non-compliance is priced in crores, not notices.
The Data Protection Board of India can impose these amounts directly.
DPDP Act, 2023 — the questions people actually ask.
Any person — including a company, LLP, society, trust or sole proprietor — that determines the purpose and means of processing digital personal data in India is a Data Fiduciary under Section 2(i), regardless of whether it is for-profit or not-for-profit.
A Data Fiduciary must notify the Data Protection Board of India and each affected Data Principal without delay, with a detailed report generally expected within 72 hours of becoming aware of the breach.
The Data Protection Board can impose penalties of up to ₹250 crore for failing to take reasonable security safeguards, with separate bands of up to ₹200 crore and ₹50 crore for other categories of non-compliance.
Entities generally build their grievance redressal SOP around a 90-day outer limit for resolving a Data Principal's rights request or grievance.
A defensible compliance file typically includes a data mapping register, consent notices and logs, a master privacy policy, retention and breach policies, vendor DPAs, and SOPs for breach, grievance and rights-request handling — JurisTatva's framework organises 44 such instruments across 7 layers.
Find out exactly which of the 44 instruments you're missing.
A short diagnostic call maps your data flows against the DPDP checklist and tells you precisely where your exposure sits — before we quote a single rupee of fee.
