Compliance Framework
DPDP Act (India's Digital Personal Data Protection Act)
India's comprehensive data protection law — directly relevant given Vajra is based in India, and increasingly relevant to any business processing Indian residents' data.
Who it applies to
Organizations processing the personal data of individuals in India, whether the organization is based in India or processes Indian residents' data from abroad — structurally similar in reach to GDPR's extraterritorial approach.
What it requires
- —Clear, specific consent from the individual ('Data Principal') before processing their personal data, for a stated purpose
- —Purpose limitation — data collected for one stated reason can't be silently repurposed
- —Breach notification to the Data Protection Board of India and affected individuals
- —Reasonable security safeguards to prevent personal data breaches
- —Specific, heightened obligations around children's data
How we approach it
As an India-based team, this is the framework we design against by default for any project handling Indian users' data — consent capture, purpose-scoped data collection, and breach-response procedures built in from the start rather than retrofitted once rules are finalized and enforced.
FAQs
How is this different from GDPR?
The core shape is similar (consent-based processing, breach notification, data-principal rights) but the specific obligations, thresholds, and enforcement mechanism (the Data Protection Board of India, rather than EU national authorities) differ — treat them as related but distinct compliance requirements, not the same law under two names.
Have a project in mind?
Tell us what you're trying to automate or build — we'll reply with next steps, not a sales pitch.