compliance
Compliance
Everything Indian businesses need to know about the DPDP Act 2023, SEBI cybersecurity requirements, and regulatory compliance.
41 articles
Building a GRC Function in a Growing Indian Company
A practical guide to building a real GRC function for growing Indian companies: one risk register, one control set mapped to ISO 27001, SOC 2, DPDP and CERT-In.
ISO/IEC 27701:2025 Explained: India's Standalone Privacy Standard
ISO/IEC 27701:2025 is now a standalone PIMS standard, no ISO 27001 required. See what changed and how it maps to India DPDP Act compliance obligations.
DPIA Under DPDP: A Practical Guide for Indian Companies
How to run a Data Protection Impact Assessment under India DPDP Act 2023 — mandatory for Significant Data Fiduciaries, smart practice for everyone else.
ISO 27001 Internal Audit Checklist for Indian Teams (2022 Update)
A practical ISO 27001 internal audit checklist for Indian IT and SaaS teams covering all 93 Annex A controls, nonconformities, and management reviews.
DPDP Act Data Breach Notification Rules for Indian Businesses
What the DPDP Act 2023 and DPDP Rules 2025 require after a personal data breach: notification timelines to the Board and data principals, and how to prepare.
SEBI CSCRF: Cybersecurity Framework for Regulated Entities
SEBI CSCRF explained: the six-function cybersecurity framework covering governance, VAPT, SOC monitoring, and incident reporting for entities in India.
Data Classification and Discovery for DPDP in India
Data classification and discovery is the essential first step to DPDP compliance in India — inventory, tier and map personal data before you protect it.
PII in Logs: The DPDP Blind Spot in Indian Applications
PII in application logs is the DPDP Act blind spot most Indian firms overlook. Learn redaction, retention limits, and access controls that close the gap.
Sectoral CERTs and CSIRT-Fin: India's Incident Reporting Guide
Learn which body to report a cyber incident to in India — CERT-In, RBI, SEBI, CSIRT-Fin, or DoT — and how these reporting obligations stack up by sector.
DoT Telecom Cyber Security Rules 2024: India Compliance Guide
A practical breakdown of the DoT Telecom Cyber Security Rules 2024 - who they apply to, key obligations, and what Indian businesses using SMS-OTP must do now.
Data Localization Under DPDP: What Indian Businesses Must Know
A practical guide to DPDP Act 2023 data localization rules, cross-border transfer requirements, and RBI payment sector rules Indian businesses must follow.
RBI Cyber Security Framework for NBFCs: Compliance Guide
A practical guide to RBI's cyber security framework for NBFCs — IT governance, board policy, CERT-In incident reporting timelines, and IS audit steps.
PCI DSS Compliance for Indian Merchants and Payment Aggregators
A practical PCI DSS compliance guide for Indian merchants and payment aggregators, covering RBI rules, the 12 requirements, SAQ levels, and a roadmap.
CERT-In 2022 Directions Compliance: Complete Guide for India
CERT-In 2022 directions compliance is legally mandatory for all Indian businesses. Learn how 6-hour reporting, 180-day log retention, and NTP sync apply to you.
RBI Digital Lending Cybersecurity: Complete Guide for India
Learn how RBI digital lending cybersecurity rules apply to Indian fintechs and NBFCs—data localization, mandatory VAPT audits, CERT-In timelines, and LSP risk.
ISO 27001 Certification India: Step-by-Step 2022 Roadmap
Learn the complete ISO 27001 certification India roadmap: 6 phases from gap to certificate, built for Indian startups navigating DPDP and RBI requirements.
SEBI Cloud Security Framework for Indian Stock Brokers
SEBI's cloud security framework requires board approval, data localisation, and annual audits for all Indian regulated entities. Your compliance roadmap inside.
RBI Cloud Outsourcing Framework: What Indian Banks Must Do
RBI cloud outsourcing framework mandates board approval, data sovereignty, audit rights, and 6-hour CERT-In incident reporting for Indian banks and NBFCs.
Data Fiduciary Obligations Under DPDP Act: India Checklist
Every Indian business processing personal data is a Data Fiduciary under DPDP Act 2023. This checklist covers all six obligation categories to stay compliant.
DPDP Rules 2025: A Practical Guide for Indian Businesses
Draft DPDP Rules 2025 operationalise India's data protection law — covering consent, breach notification, SDF duties, and what Indian businesses must do now.
Data Retention & Deletion Under DPDP: India SMB Guide
DPDP Act 2023 mandates erasure of personal data once its purpose is served. Learn data retention rules, right to erasure, and how to build a compliant schedule.
SEBI CSCRF: What India's Regulated Entities Must Do
SEBI CSCRF mandates VAPT, SOC, cyber audit, and incident reporting for every India capital-market Regulated Entity. Here is exactly what compliance requires.
Aadhaar Data Handling: UIDAI Security Rules for Indian Businesses
Learn what UIDAI security rules require for Aadhaar data handling in India — VID, tokenization, consent, biometric prohibitions, and DPDP Act obligations.
DPDP Act Privacy Policy and Consent: India Compliance Guide
DPDP Act 2023 requires valid consent and a compliant privacy notice for Indian websites. Covers notice rules, data principal rights, and compliance steps.
IT Act Section 43A: Data Security Obligations for Indian Companies
IT Act Section 43A requires Indian companies handling sensitive personal data to implement reasonable security practices or face civil compensation claims.
GDPR Compliance Guide for Indian Companies Serving EU Customers
GDPR applies to Indian companies targeting EU residents — server location is irrelevant. Covers scope, SCCs, breach notification, and a compliance roadmap.
HIPAA vs DPDP for Indian Healthtech: Patient Data Guide
Indian healthtech companies must comply with both HIPAA and DPDP Act 2023. Learn which regime applies, when BAAs are required, and controls that satisfy both.
SOC 2 for Indian SaaS: Type I vs Type II Audit Guide
SOC 2 Type I vs Type II explained for Indian SaaS founders — AICPA Trust Services Criteria, audit timeline, and how SOC 2 complements ISO 27001 and DPDP.
Data Localization in India: RBI, DPDP and Where Data Must Live
Data localization in India varies by sector. RBI mandates payment data stays in India; DPDP allows cross-border transfers unless the government restricts it.
PCI DSS 4.0 for Indian Merchants and Payment Aggregators
PCI DSS 4.0 is now fully mandatory. Indian merchants and payment aggregators must meet 64 newly enforced requirements, expanded MFA rules, and RBI compliance.
DPDP Act Data Breach Notification: India 72-Hour Guide
DPDP Act 2023 requires breach notification to India's Data Protection Board and affected users. Here's what to do and fully document in the first 72 hours.
CERT-In 6-Hour Incident Reporting Rule: India Compliance Guide
CERT-In's 2022 Directions require Indian companies to report cyber incidents within 6 hours of detection and retain ICT logs for 180 days. Compliance guide.
ISO 27001:2022 for Indian Startups: How to Get Certified
ISO 27001:2022 brings 93 controls, 4 themes, and 11 new controls. The complete certification journey for Indian startups — gap assessment to certificate.
RBI Cyber Resilience Controls: What NBFCs Must Do in 2026
RBI's IT GRC and DPSC frameworks mandate VAPT, incident reporting, and IS audits for Indian NBFCs. Here is what cyber resilience compliance requires in 2026.
DPDP Act Compliance for Indian SMBs: Penalties, Deadlines and a Practical Checklist
India's DPDP Act 2023 is law — and most Indian SMBs are not ready. Understand your obligations as a Data Fiduciary, penalties up to ₹250 crore per instance, Data Principal rights, and a step-by-step c
DPDP Act 2023 Compliance Checklist: 47 Controls Every Indian Business Must Implement
Complete DPDP Act 2023 compliance checklist for Indian businesses. 47 controls mapped to Schedule I obligations, with penalty exposure per gap and a 14-day quick-start plan.
CERT-In VAPT Compliance: What the April 2022 Directive Actually Requires (and What It Doesn't)
CERT-In's 2022 cybersecurity directive explained for Indian businesses. Which companies must comply, what VAPT proves, and the 6-hour breach notification requirement.
RBI IT Framework Compliance for NBFCs: Step-by-Step Audit Checklist 2026
Complete RBI IT Examination Framework checklist for NBFCs and co-operative banks. Map RBI controls to security deliverables and avoid audit findings.
SEBI CSCRF Compliance for Stock Brokers and Trading Members: The Complete 2026 Audit Guide
SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) compliance guide for stock brokers, trading members, and market intermediaries. June 2026 deadline.
DPDP Act Maximum Penalty: ₹250 Crore — 5 Real Scenarios for Indian Startups
The DPDP Act maximum penalty is ₹250 crore per violation. Here are 5 real-world scenarios for Indian startups — actual penalty calculations, compliance costs, and a 14-day roadmap to reduce your risk before the Board acts.
Understanding the DPDP Act 2023: A Complete Guide for Small Businesses
What the Digital Personal Data Protection Act requires from your business, the penalties for non-compliance, and practical steps to get compliant.