Core Applicability FAQs
Understand how the DPDP Act applies to your business, obligations, and compliance responsibilities.
What data does the DPDP Act cover?
+
It regulates digital personal data about identifiable individuals, including digitized offline data like scanned IDs.
Who must comply?
+
Data fiduciaries processing data in India or targeting Indian users, including foreign firms, startups, and enterprises—no blanket exemptions for MSMEs.
What are the penalties for non-compliance?
+
The Act introduces heavy financial penalties for various contraventions. Failure to take reasonable security safeguards to prevent data breaches can result in penalties up to ₹250 Crores.
What are a "Data Principal" and a "Data Fiduciary"?
+
Data Principal: The individual to whom the personal data relates (your customer or employee).
Data Fiduciary: The entity that determines the purpose and means of processing personal data (your company).
Data Fiduciary: The entity that determines the purpose and means of processing personal data (your company).
Do you offer consulting alongside the software?
+
Absolutely. KavachOne is a Techno-Audit firm. We don't just provide the tools; our team of PCI DSS QSA, ISO 27001, and CIPP/E certified experts provides hands-on gap assessments and implementation guidance.
How long does the platform maintain audit logs?
+
KavachOne maintains a tamper-proof, secure audit trail for 7 years. This ensures that your organization can provide historical evidence of consent and processing activities during regulatory audits or legal disputes.