King Stubb & Kasiva advises Mumbai businesses on the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 from three offices, at Nariman Point, Lower Parel and Andheri West.
Mumbai is India’s financial centre, home to the Reserve Bank of India, SEBI, the stock exchanges and the head offices of most banks, NBFCs, insurers, brokers and asset managers. For these businesses the DPDP Act sits on top of sector rules from RBI, SEBI and IRDAI, so compliance means reconciling both sets of obligations.
The city is also the centre of India’s media and entertainment industry, where subscriber, audience and talent data drive the business. We help Mumbai companies map their data, align DPDP notices and consent with sector requirements, and prepare for breach reporting.
For the full picture of the law, read our one-page guide to the DPDP Act in India.
Advice on the DPDP Act and Rules from readiness through to breaches and proceedings before the Data Protection Board.
Gap assessments, data mapping, privacy notices, consent design and a compliance roadmap to 13 May 2027.
Learn moreSetting up and supporting the DPO function, including for Significant Data Fiduciaries that must appoint one.
Learn moreAnnual DPIAs, independent audits and governance for entities notified as Significant Data Fiduciaries.
Learn moreBreach intimation to the Data Protection Board and affected individuals, CERT-In reporting and regulator engagement.
Learn moreNariman Point: Office No. 61, 6th Floor, Atlanta Building, Jamnalal Bajaj Road, Mumbai 400021
Lower Parel: 301A, 3rd Floor, Piramal Towers, Peninsula Corporate Park, Senapati Bapat Marg, Mumbai 400013
Andheri West: 802, 8th Floor, REMI Commercio, Shah Industrial Estate, Veera Desai Road, Mumbai 400053
The practice is led from New Delhi and Bengaluru and works with our Mumbai office on matters for clients here.
The DPDP Rules, 2025 bring the Act into force in three stages.
Yes. The DPDP Act applies across India to digital personal data, whether collected online or collected offline and later digitised. It also applies to businesses outside India that offer goods or services to people in India.
The DPDP Rules, 2025 were notified on 13 November 2025. The Consent Manager provisions apply from 13 November 2026, and the core obligations on notice, consent, security safeguards, breach intimation, data principal rights and retention apply from 13 May 2027.
No. The DPDP Act applies in addition to other laws and prevails only where they conflict. Stricter sector requirements, such as RBI’s rule that payment system data be stored in India, continue to apply.
Complaints under the DPDP Act go to the Data Protection Board of India, and appeals from the Board go to TDSAT within 60 days. Civil courts cannot hear matters the Board can decide, but writ petitions and constitutional challenges can be brought before the Bombay High Court.
Call the Mumbai office on +91-22-69010531, visit us at Nariman Point, Lower Parel and Andheri West, or send an enquiry through our contact form. A member of the data privacy team will respond.
The same data privacy team advises from each King Stubb & Kasiva office.
Tell us what your organisation does with personal data and what you need. A member of the data privacy team will respond.
Last reviewed 29 September 2026. General information, not legal advice.