A written rule means nothing if your computer doesn't follow it.
Imagine you wrote a rule: 'Only the HR person can see salary slips.' Good rule. But if your computer lets everyone open that folder — the rule is useless. DPDPA does not just want rules on paper. It wants your systems to actually stop the wrong people. If your IT is not set up right, you are already breaking the law — even if you didn't mean to.
Say your shop keeps customer Aadhaar copies in a shared Google Drive folder. Your delivery boy, accountant, and owner can all open it. That is a problem under DPDPA. Only the person who needs it should see it. Same with salary slips — only HR should open them. Your IT person must set passwords and permissions. If someone leaks data, the law will ask: did your system stop them? If the answer is no, you are in trouble.
Ask your IT person who can open salary slips and Aadhaar files right now.
Delete old customer phone numbers and scanned ID copies you no longer need.
Check if your business is ready. Takes 3 minutes. Visit saralprivacy.com/assessment
“Policy without controls is wallpaper.”
Free — takes 3 minutes
Answer a few simple questions. Get your free Readiness Score — sent to your email or WhatsApp.
Check My Readiness →Take our free 3–5 minute industry assessment to find out your compliance risk level.
Take Free Assessment →Free Download
The Complete DPDPA Compliance Guide
Plain English. Everything your business needs to understand the DPDP Rules 2025 — written for founders, not lawyers. Now in 7 Indian languages.
Download the Guide →5 Ready-to-Use Templates
Start complying — not just reading
Privacy Notice, Consent Language, Data Inventory, DSR SOP, Vendor Register. Delivered free to your email.
2-min reads, plain English, every morning. Free forever.