Questions
What counts as “personal data” under the DPDP Act?
Any data about an individual that makes them identifiable - Section 2(t) doesn't require a name or ID number specifically. That's why pseudonymized fields like hashed mobile numbers still count: hashing changes the label, not the identifiability.
What's the difference between a Data Fiduciary and a Data Processor?
A Data Fiduciary decides why and how personal data is processed - the Act's obligations sit with them. A Data Processor handles data on a fiduciary's instructions and carries contractual obligations, not direct statutory liability.
Can someone withdraw consent after giving it?
Yes, at any time. Section 4(7) requires withdrawal to be as easy as giving consent was. Once withdrawn, processing must stop and the data erased, unless another law requires retention.
What rights does a Data Principal (the individual) have?
Access to their data, correction of inaccurate data, erasure, grievance redressal, and the right to nominate someone to act on their behalf if they die or are incapacitated. Notably, the Act does not include a GDPR-style right to data portability.
Are there special rules for children's data?
Processing a minor's (under-18) personal data requires verifiable parental consent, and the Act bars behavioural monitoring, tracking, and targeted advertising directed at children.
What happens if there's a data breach?
The Data Fiduciary must notify the Data Protection Board and every affected Data Principal within 72 hours of becoming aware - describing what happened, what data was affected, and the remediation underway.
How large are the penalties?
Up to ₹250 crore for failing to implement reasonable security safeguards where that leads to a breach, up to ₹200 crore for breach-notification failures or violations involving children's data, and up to ₹10,000 against a Data Principal who files a frivolous complaint.
When does full enforcement kick in?
The DPDP Rules were notified 13 November 2025. Phase 1 stood up the Data Protection Board immediately; Phase 2 (13 November 2026) activates the Consent Manager framework; Phase 3 (13 May 2027) brings full compliance obligations into force for every Data Fiduciary - the same date on RegVision's homepage ticker.
Does RegVision replace our DPO or legal counsel?
No. Decision-support only - your DPO holds final authority on every finding.
What happens when a finding is wrong?
It doesn't guess. When evidence is insufficient, RegVision returns “cannot determine” and a human reviews it.
Do you cover every regulation yet?
Not yet, and we won't pretend otherwise. See what's live on the Product page.
How does RegVision integrate with our workflow?
Findings surface at PR-time and through scheduled sweeps, routed to the owning team - no separate console required for the day-to-day.
Where does our data live?
On your infrastructure. RegVision never runs as central SaaS for production data. See the Trust page for the full boundary.
Is RegVision ISO 27001 certified?
Certification is in progress. We share status openly through your vendor assessment.
Is our data used to train any model?
No. Customer code, schemas, policies and uploads are never used to train or fine-tune any model.
How long is data retained?
Evidence is workspace-scoped and held only as long as its purpose requires, then purged. Assessment submissions are deleted on request.
What does RegVision cost?
We're taking a small number of design partners before we take payment terms. See the Pricing page.