AravaliStack and India's Digital Personal Data Protection Act.
The DPDP Act 2023 creates a technical obligation, not just a legal one. Here's exactly how AravaliStack's architecture satisfies each key requirement โ with evidence templates your DPO can use directly.
DPDP Act obligations โ AravaliStack controls
The Digital Personal Data Protection Act, 2023 is India's comprehensive data protection legislation. It came into force in August 2023 and establishes rights for data principals, obligations for data fiduciaries, consent requirements, data localisation mandates for certain categories of data, and penalties of up to โน250 crore per violation. Every enterprise that processes personal data of Indian citizens is covered.
A 12-page template your DPO can complete to demonstrate DPDP Act readiness โ with AravaliStack control references pre-filled.
- Personal data of Indian citizens must not be transferred outside India without consent or legal basis
- AravaliStack runs on-premise. Data never leaves your infrastructure. No cross-border transfers occur by design. Zero configuration required.
- Purpose Limitation
- Data must only be processed for the purpose for which it was collected
- AravaliStack's policy engine enforces namespace-level data purpose controls. ML workloads are blocked from accessing data beyond their declared purpose. Audit trail captures every data access with declared purpose.
- Storage Limitation
- Data must not be retained beyond the period necessary for the stated purpose
- Automated data lifecycle policies enforce retention schedules at the storage layer. Data past its retention period is automatically deleted with cryptographic erasure confirmation. Retention schedule reports are generated on demand.
- Security Safeguards
- Appropriate technical and organisational measures to protect personal data
- AES-256 encryption at rest, mTLS in transit, Vault for key management, zero-trust network policies via Istio, RBAC enforced by Keycloak, immutable audit logs in tamper-evident storage.
- Breach Notification
- Data fiduciaries must report breaches to the Data Protection Board and affected individuals
- AravaliStack's AIOps layer detects anomalous data access patterns in real time. Automated incident workflow triggers notification drafts within 30 minutes of a confirmed breach โ pre-formatted for DPDP Board notification requirements.
- Right to access, correction, erasure, and grievance redressal
- AravaliStack's API gateway includes a Data Subject Rights workflow โ accept deletion and access requests via API, log them, and track their execution with automated evidence generation for compliance reporting.
