Which DPDP sections bite hardest for your industry, which sectoral rules layer on top, and what the Data Protection Board is likely to open its first inquiries on. Every guide cross-referenced to primary sources.
Banks, NBFCs, insurers, brokers. RBI KYC retention conflicts with DPDP erasure. Sec. 8(5) security cap sits alongside RBI IT baselines. Payment localisation under RBI 6 April 2018 remains binding.
SectorHospitals, diagnostics, telemedicine, health insurers. ABDM Health Data Management Policy layers on top. Consent artefact for every cross-facility record fetch. Sensitive data category means stricter safeguards.
SectorMarketplaces, D2C brands, quick commerce, loyalty. DPDP consent hygiene stacks with CCPA dark-pattern prohibitions. Personalisation and dynamic pricing under new scrutiny.
SectorSmall businesses under 20 employees. There is no MSME exemption. Same duty as larger companies, same Rs. 250 crore cap. What phased enforcement gives you and how to use the runway.
The four guides above cover roughly 70 percent of the queries we see. The next tranche will land through the second half of 2026:
Sec. 9 children's data plus Rule 10 VPC. K-12 platforms need this first.
Processor contracts under Sec. 8(4). Cross-border under Sec. 16 with EU/US customers.
Behavioural targeting risk. Sec. 9(3) children ban. Consent architecture across the stack.
Loyalty programs, delivery data, physical touchpoints. QR consent under Rule 3.
Employee data, background checks, payroll processors. Sec. 7 legitimate uses.
Broker platforms, property listings, buyer identity verification.
Delivery data, driver identity, warehouse worker records. Cross-border for global operators.
Beneficiary data, donor records, cross-border funding disclosures.