The regulatory landscape, translated into operations
India's Digital Personal Data Protection Act, 2023 changes what 'disposed of' has to mean. This page summarizes the law, the principles, the penalties — and how each maps to what we actually deliver.
What the law is, and why devices are in scope
The DPDP Act is India's comprehensive personal data protection law. It applies to any organization — or platform — that processes personal data, and its erasure obligations follow the data wherever it lives, including on retired laptops, phones, servers, and drives. Any entity that accepts a used device, whether through internal IT retirement or a consumer trade-in program, inherits fiduciary responsibility for the data on it.
- Consent management with auditable withdrawal handling
- Clear, itemized privacy notices to data principals
- Personal data breach reporting to the Data Protection Board and affected principals
- Erasure and retention rules tied to purpose completion
- Significant Data Fiduciary obligations: DPO, independent audits, DPIAs
- Data-principal rights: access, correction, erasure, grievance redressal
- Conditions governing cross-border transfer of personal data
What we actually deliver
Device-level, cryptographically signed certificates (SHA-256 + RSA-2048)
Full chain-of-custody documentation — geo-tagged, time-stamped, digitally signed
Audit-ready reporting mapped to DPDP, RBI guidance, and CPCB requirements
Ready to make device retirement your most documented process?
Talk to our compliance team. Every question answered with evidence, not assurance.
