King Stubb & Kasiva advises Hyderabad businesses on the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 from our office in Banjara Hills.
Hyderabad is a major centre for IT services, global capability centres, and pharmaceuticals and life sciences, and it is where the insurance regulator IRDAI is headquartered. Pharma and clinical research businesses handle patient and trial data, and capability centres process data for group companies abroad.
That mix raises processor, cross-border and sector questions under the DPDP Act. We help Hyderabad companies define their role for each data flow, align DPDP obligations with IRDAI and other sector rules, and prepare security safeguards and breach response.
For the full picture of the law, read our one-page guide to the DPDP Act in India.
Advice on the DPDP Act and Rules from readiness through to breaches and proceedings before the Data Protection Board.
Gap assessments, data mapping, privacy notices, consent design and a compliance roadmap to 13 May 2027.
Learn moreSetting up and supporting the DPO function, including for Significant Data Fiduciaries that must appoint one.
Learn moreAnnual DPIAs, independent audits and governance for entities notified as Significant Data Fiduciaries.
Learn moreBreach intimation to the Data Protection Board and affected individuals, CERT-In reporting and regulator engagement.
Learn more404, Shangrila Plaza, Road No. 2, Banjara Hills, Opposite KBR Park, Hyderabad 500034
The practice is led from New Delhi and Bengaluru and works with our Hyderabad office on matters for clients here.
The DPDP Rules, 2025 bring the Act into force in three stages.
Yes. The DPDP Act applies across India to digital personal data, whether collected online or collected offline and later digitised. It also applies to businesses outside India that offer goods or services to people in India.
The DPDP Rules, 2025 were notified on 13 November 2025. The Consent Manager provisions apply from 13 November 2026, and the core obligations on notice, consent, security safeguards, breach intimation, data principal rights and retention apply from 13 May 2027.
Yes, for personal data of people in India, such as their employees. Where a centre processes personal data of people outside India under a contract with its overseas parent, most obligations do not apply under section 17(1)(d), although the duty to take reasonable security safeguards still does.
Complaints under the DPDP Act go to the Data Protection Board of India, and appeals from the Board go to TDSAT within 60 days. Civil courts cannot hear matters the Board can decide, but writ petitions and constitutional challenges can be brought before the Telangana High Court.
Call the Hyderabad office on +91-40-48516011, visit us at Banjara Hills, or send an enquiry through our contact form. A member of the data privacy team will respond.
The same data privacy team advises from each King Stubb & Kasiva office.
Tell us what your organisation does with personal data and what you need. A member of the data privacy team will respond.
Last reviewed 29 September 2026. General information, not legal advice.