Solutions

Same Act. Different collisions.
One page per sector.

The DPDP Act reads the same for everyone. What actually breaks is where it meets the rules your sector already lives under — PMLA, IRDAI's retention slabs, RBI's lending directions, the Third Schedule's deletion clock. Each page below starts from a problem we verified against the instrument itself, not from a template with your industry's name swapped in.

BUILT FROM A PRIMARY-SOURCE PROBLEM REGISTER · SWEEP DATED 2 SEPTEMBER 2026 · CORRECTIONS LISTED OPENLY

BANKING & FIs

The erasure you must refuse — and prove

PMLA holds KYC for five years after the relationship ends; DPDP hands the same person an erasure right. The law resolves the conflict in the bank’s favour. The workflow that evidences that refusal, request by request, is what nobody has.

Read the banking page →
NBFC & FINTECH

One loan, four copies, no owner

Originator, co-lender, lending-service provider, collections agent and four credit bureaus each hold the borrower’s record. A correction accepted by one leaves stale copies everywhere else — and no instrument says which copy answers the request.

Read the NBFC & fintech page →
INSURANCE

Ten years, twelve for a death claim

IRDAI’s 2025 regulations keep records ten years from the last transaction and large claims for twelve. A nominee can exercise a deceased policyholder’s erasure right on exactly those records. Most answers are a lawful partial refusal that must itself be evidenced.

Read the insurance page →
EDUCATION & EDTECH

Lifetime access means rights that never expire

A course that never ends has no moment when “the purpose is served.” Every account stays a live obligation forever — and under-18 learners need verifiable parental consent through a mechanism whose infrastructure isn’t built yet.

Read the education page →
ECOMMERCE & RETAIL

Three years, then delete — with 48 hours’ notice

Above two crore users the Third Schedule sets a three-year inactivity clock with a 48-hour notice before each erasure — while GST keeps the invoice for seventy-two months and the same order record sits, un-clocked, with every seller who exported it.

Read the ecommerce page →
HEALTHCARE & HEALTHTECH

The clinical record stays; everything around it must be justified

Regulation keeps an inpatient record three years and defensive practice keeps it far longer. What DPDP demands is the unregulated middle — marketing, engagement and app data no named law protects — plus a second consent regime from ABDM and a claims chain through insurers and TPAs.

Read the healthcare page →
TELECOM

Two years of call records, and a right to erase them

Licence conditions protect the two-year archive and nothing built from it; one incident reports to three regulators on three clocks; and the industry’s own asks on breach reporting, SIM parental consent and consent managers went unaddressed at notification.

Read the telecom page →
SAAS & B2B SOFTWARE

You hold the data; your customer holds the liability

The fiduciary answers “irrespective of any agreement to the contrary,” with no direct statutory duty on the processor — so the allocation lands as an indemnity fight in every renewal, behind a sub-processor chain the customer cannot see and a cross-border regime repointable any quarter.

Read the SaaS page →
REAL ESTATE & PROPTECH

One enquiry, fifty brokers who dial

A distribution model built on onward transfer nobody consented to; RERA records that shield the agreement’s PAN but not the CRM, across thirty-odd unmapped state rule sets; and Aadhaar mandated at the registry and photocopied at the sales office.

Read the real-estate page →
HR, STAFFING & GIG

“Purposes of employment” assumes an employee

The legitimate-use ground covers current employees and silently excludes candidates, contractors, gig workers and alumni — everyone HR processes hardest. Background checks run on consent collected by someone else, for an employer who carries the whole liability.

Read the HR page →
NOT YET

Travel & hospitality; gaming & media

Both were swept. Neither cleared this site’s bar of four confirmed collisions once the register’s reporting about single named companies was set aside — travel has two, gaming has one. No page until the evidence supports one; we would rather you find nothing than a thin one. The demo conversation uses what there is.

How these pages were built

A problem register first.
Product fit second.

In September 2026 we swept eight sectors for the places a DPDP obligation collides with an operational fact of the business, or with a sectoral mandate that already applies. Eighty-five problems, each carrying the instrument it rests on and the source it was checked against. Every page here is a slice of that register — and the register was finished before anyone was allowed to ask what our product does about it.

THE BAR

Confirmed means two sources, one of them real

A problem is marked confirmed only with two independent sources, at least one being the instrument itself — the section, the regulation, the gazette notification — or a practitioner record: a consultation submission, an enforcement order, a procurement document. Law-firm and vendor explainers are context. They never count as confirmation.

THE HONESTY

Hypotheses are labelled. Unknowns stay unknown.

Where a collision follows from the text but nobody is on record feeling it yet, the page says hypothesised. Where a fact could not be established from a primary source, the page says so rather than picking the number an AI draft offered. Three of our own AI research drafts disagreed on how long a bank keeps KYC; the register settled it from the statute. That correction is on the banking page.

THE RULES

No scan numbers, no penalty arithmetic, no roadmap

Nothing here is a measured prevalence — those belong to the Sector Pulse, under its own floors. No fine-amount headlines: the penalty schedule is a matter of record, stated plainly once, not a threat repeated per sector. And every Consent Tree capability named on these pages is live today. Things we are still building are not on them.

Where these pages stop

Four things they will not do.

They are not legal advice.

Each page cites the provision it relies on so your counsel can read it. Where the register flagged a clause as named-but-not-read, that item was left off the page rather than paraphrased.

They do not characterise any organisation.

Only public instruments, published consultation submissions, published enforcement orders and public procurement documents are cited. No inference about any named company’s internal state is drawn from them.

They do not do countdown clocks.

The dates are stated once, as the notifications state them: Rules notified in mid-November 2025; Consent-Manager registration opening in mid-November 2026; the substantive duties, the rights and the penalty powers in mid-May 2027. Nothing on these pages is presented as in force before it is.

They age visibly.

Every register fact carries its sweep date. When a regulator acts, a Board is appointed or a class of fiduciary is notified, the relevant line changes and the date with it — the page never quietly reads as newer than its evidence.