King Stubb & Kasiva’s Bengaluru (Bangalore) office on Lavelle Road, where Managing Partner Jidesh Kumar is based, advises technology companies, startups and global capability centres on the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025.
Bengaluru is India’s technology hub, home to software and SaaS companies, startups and many of the global capability centres that multinationals run in India. These businesses are often Data Processors for overseas clients as well as Data Fiduciaries for their own users and employees, and they move data across borders every day.
Processing in India of personal data of people outside India, under a contract with a person outside India, is exempt from most of the Act, but the duty to take reasonable security safeguards still applies, and data about people in India is fully covered. We help Bengaluru companies work out which role they play, structure processor contracts and plan cross-border flows.
For the full picture of the law, read our one-page guide to the DPDP Act in India.
Advice on the DPDP Act and Rules from readiness through to breaches and proceedings before the Data Protection Board.
Gap assessments, data mapping, privacy notices, consent design and a compliance roadmap to 13 May 2027.
Learn moreSetting up and supporting the DPO function, including for Significant Data Fiduciaries that must appoint one.
Learn moreAnnual DPIAs, independent audits and governance for entities notified as Significant Data Fiduciaries.
Learn moreBreach intimation to the Data Protection Board and affected individuals, CERT-In reporting and regulator engagement.
Learn more1A, Lavelle Mansion, 1/2 Lavelle Road, Bengaluru 560001
Managing Partner Jidesh Kumar is based in Bengaluru. The practice’s other partners work from our New Delhi head office.
The DPDP Rules, 2025 bring the Act into force in three stages.
Yes. The DPDP Act applies across India to digital personal data, whether collected online or collected offline and later digitised. It also applies to businesses outside India that offer goods or services to people in India.
The DPDP Rules, 2025 were notified on 13 November 2025. The Consent Manager provisions apply from 13 November 2026, and the core obligations on notice, consent, security safeguards, breach intimation, data principal rights and retention apply from 13 May 2027.
Processing in India of personal data of people outside India, under a contract with a person outside India, is exempt from most of the Act under section 17(1)(d), although the duty to take reasonable security safeguards still applies. Personal data of people in India, including your own employees, is fully covered.
Complaints under the DPDP Act go to the Data Protection Board of India, and appeals from the Board go to TDSAT within 60 days. Civil courts cannot hear matters the Board can decide, but writ petitions and constitutional challenges can be brought before the Karnataka High Court.
Call the Bengaluru office on +91-80-41179111, visit us at Lavelle Road, or send an enquiry through our contact form. A member of the data privacy team will respond.
The same data privacy team advises from each King Stubb & Kasiva office.
Tell us what your organisation does with personal data and what you need. A member of the data privacy team will respond.
Last reviewed 29 September 2026. General information, not legal advice.