Draft Digital Personal Data Protection Rules, 2025
Released on January 3, 2025 by MeitY for public consultation, these draft rules provide the operational framework for implementing the DPDP Act, including provisions for consent managers, data retention periods, security measures, breach notifications within 72 hours, and children’s data protection. Download PDF
UK GDPR (UK General Data Protection Regulation, Post-Brexit)
Following Brexit, the UK incorporated GDPR into domestic law as the UK GDPR, maintaining largely the same provisions while allowing for future divergence. Effective from January 1, 2021, it works alongside the Data Protection Act 2018 to form the UK’s data protection framework. Key differences include the ICO as the sole supervisory authority, specific provisions […]
CPRA (California Privacy Rights Act, 2020)
The California Privacy Rights Act, approved by voters in November 2020 and effective from January 1, 2023, significantly expands and strengthens the CCPA. It creates new consumer rights including the right to correct inaccurate information, right to limit use of sensitive personal information, and extends the “look-back” period for data access requests to 12 months. […]
CCPA (California Consumer Privacy Act, 2018)
The California Consumer Privacy Act, effective from January 1, 2020, is a landmark US state privacy law granting California residents comprehensive rights over their personal information. It applies to for-profit businesses that collect California residents’ personal information, meet specific thresholds (annual revenues over $25 million, data of 50,000+ consumers, or 50%+ revenue from selling data), […]
GDPR (General Data Protection Regulation, 2016)
The General Data Protection Regulation is the European Union’s comprehensive data protection law that came into force on May 25, 2018. It establishes strict rules for how organizations collect, process, store, and transfer personal data of EU residents. Key provisions include requiring explicit consent for data processing, mandatory data breach notifications within 72 hours, right […]
Digital Personal Data Protection Act, 2023
This official document outlines India’s Digital Personal Data Protection Act, 2023, a comprehensive law enacted to regulate the processing of digital personal data. The Act aims to balance individual data protection rights with the necessity of processing such data for lawful purposes. It defines key terms like Data Fiduciary and Data Principal, establishes the Data Protection Board of India to oversee compliance, and […]