Introduction France’s decision to prohibit unsolicited telemarketing calls from August 2026 onwards marks a significant shift in the philosophy of consumer protection. Rather than requiring consumers to register their objection to marketing calls, the French approach reverses the presumption itself, businesses must obtain consent before making the call. The distinction is important because it determines…
WhatsApp’s Age Check and the DPDP Act : What Section 9 Means for Children’s Data Compliance
- 2026-08-05
Introduction WhatsApp has started asking some users in India to confirm they are over eighteen before they can keep using the app. On its face, it looks like nothing more than another screen to tap through, the kind of prompt people barely register before moving on. But the timing tells a different story. This age…
Medical Devices and Privacy by Design: A Way to DPDPA Compliance in the Healthcare Sector
- 2026-07-22
Introduction The healthcare sector in India is witnessing a change with the advancement of technology. The use of medical devices is not limited to wards and laboratories anymore. Smart insulin pumps, fitness trackers, heart rate monitors, intelligent diagnostic applications, image processing systems, and patient monitoring applications are some of the many innovations that form part…
AI Credit Scoring in India: Data Privacy, Explainability and Algorithmic Fairness under the DPDPA
- 2026-07-17
Introduction Lenders assessed creditworthiness using traditional indicators such as repayment history, income, and existing loans, with Credit Information Companies like CIBIL converting these into a credit score. AI-driven credit scoring is transforming this approach by analysing alternative data, including mobile usage, utility bill payments, digital transactions, app behaviour, and device patterns, to assess borrowers with…
EDPB’s New Anonymization Guidelines: What They Mean for Indian Businesses under the DPDP Act
- 2026-07-15
Introduction The European Data Protection Board (“EDPB”) has issued detailed guidelines on anonymisation and web scraping in the context of generative AI. These guidelines clarify when data can be considered truly “anonymous” and therefore outside the scope of the EU General Data Protection Regulation (“GDPR”). Although the guidelines are not binding in India, they are…
Data Breach Notification under the DPDP Rules: What Every Fintech Must Know About Insider Breaches
- 2026-07-03
Introduction For years, India’s fintech ecosystem have seen a familiar script unfold. A customer success executive with database access exports a CSV with thousands of user profile names, PAN numbers, bank account details, loan histories. The internal security team logs the anomaly. HR silently suspends the employee. Legal counsel is in the loop. Then the…
Introduction The blood banking sector plays a critical but underappreciated role within the healthcare system. It handles thousands of blood samples every day, all of which are associated with particular donors and receivers. Therefore, the institutions act as custodians of highly personal and confidential information, including health-related data. In today’s technological age, they have gone…
Introduction The ongoing massive use of personal data drives the present-day digital economy. Every online transaction, whether using a mobile application, registering for a service, or making a digital payment, generates data that businesses analyse and process for a variety of uses. Although people typically give their information to a specific platform, the information rarely…
You clicked “I Agree” on a quick commerce app. That was 5 months ago. Since then, the AI has figured out you are likely pregnant. Probably diabetic. Financially stretched every third week of the month. You never consented to any of that. You consented to delivery. This is what I call “Agentic Consent Collapse” It…
Introduction In the evolving corporate environment, the transition from static software to dynamic AI agents is basically reshaping how business is conducted. No more confined to simple “if-then” logic, AI-driven automation is now powering sophisticated operations across several sectors. In customer service, intelligent agents handle complex inquiries and process refunds in real time, they conduct…
Introduction The challenge before SC centres on Section 44(3) of the DPDP Act, which amends Section 8(1)(j) of the Right to Information Act. While Section 8(1)(j) previously permitted disclosure of personal information in cases of larger public interest, the amendment under the DPDP Act now effectively bars such disclosure. We are moving away from “discretionary…
The Privacy Paradox- Debunking 14 Critical Myths of Modern Data Protection! Stop treating the DPDPA like a legal homework assignment. Dismantling misconceptions to foster a culture of proactive compliance and strategic resilience. Common Myths vs. The Reality Common Myths Myth: Our business is too small to be a target. Myth: Privacy compliance is a barrier…
The 12 Months DPDPA, When MeitY Signals!
- 2026-01-23
Most Indian boards think they have NOW full 15 months and few days, as of now, to comply with DPDPA. If MeitY compresses the runway from original 18 months to 12, transition will become a nightmare. Three uncomfortable truths I am seeing in the field: You are suffering from “Bandwidth Bankruptcy.” If your DPDPA lead…
𝐌𝐨𝐬𝐭 𝐀𝐈 𝐬𝐲𝐬𝐭𝐞𝐦𝐬 𝐚𝐫𝐞 𝐧𝐨𝐭 “𝐡𝐢𝐠𝐡-𝐫𝐢𝐬𝐤” 𝐛𝐲 𝐝𝐞𝐬𝐢𝐠𝐧. Don’t be generic in risk assessment, rather the micro level dynamics of stack of an AI System needs to be focussed upon to have actual perspective of risk assessment. Hence, if not taken care of, they become high-risk by architecture. Traditional AI, Agentic AI, and Agentic RAG…
