King Stubb & Kasiva advises Chennai businesses on the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 from our office at Raheja Towers on Anna Salai.
Chennai’s economy spans automotive and manufacturing, IT and financial services operations, and healthcare. Manufacturers and IT services companies here hold personal data on large workforces and customer bases, and hospitals and diagnostics businesses handle patients’ health data.
We help Chennai companies map employee and customer data, decide where consent is needed and where a legitimate use applies, set retention periods, and put vendor contracts and breach response plans in place before 13 May 2027.
For the full picture of the law, read our one-page guide to the DPDP Act in India.
Advice on the DPDP Act and Rules from readiness through to breaches and proceedings before the Data Protection Board.
Gap assessments, data mapping, privacy notices, consent design and a compliance roadmap to 13 May 2027.
Learn moreSetting up and supporting the DPO function, including for Significant Data Fiduciaries that must appoint one.
Learn moreAnnual DPIAs, independent audits and governance for entities notified as Significant Data Fiduciaries.
Learn moreBreach intimation to the Data Protection Board and affected individuals, CERT-In reporting and regulator engagement.
Learn more211, Alpha Wing, Second Floor, Raheja Towers, 177 Anna Salai, Chennai 600002
The practice is led from New Delhi and Bengaluru and works with our Chennai office on matters for clients here.
The DPDP Rules, 2025 bring the Act into force in three stages.
Yes. The DPDP Act applies across India to digital personal data, whether collected online or collected offline and later digitised. It also applies to businesses outside India that offer goods or services to people in India.
The DPDP Rules, 2025 were notified on 13 November 2025. The Consent Manager provisions apply from 13 November 2026, and the core obligations on notice, consent, security safeguards, breach intimation, data principal rights and retention apply from 13 May 2027.
Not always. Section 7 of the DPDP Act allows processing for employment purposes, including protecting the employer from loss or liability, without consent. Employers still have to secure the data, keep it accurate and meet the other obligations of a Data Fiduciary.
Complaints under the DPDP Act go to the Data Protection Board of India, and appeals from the Board go to TDSAT within 60 days. Civil courts cannot hear matters the Board can decide, but writ petitions and constitutional challenges can be brought before the Madras High Court.
Call the Chennai office on +91-44-28605955, visit us at Anna Salai, or send an enquiry through our contact form. A member of the data privacy team will respond.
The same data privacy team advises from each King Stubb & Kasiva office.
Tell us what your organisation does with personal data and what you need. A member of the data privacy team will respond.
Last reviewed 29 September 2026. General information, not legal advice.