Data protection & privacy
Handle personal data the way the law now expects
Practical privacy advice under the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000, from consent notices and policies to data-principal rights, breach response and cross-border transfers.
Free 15-minute consultation. Your idea is confidential from the very first hello, protected whether or not you go on to instruct us.
What's included
Everything your data protection & privacy needs
India's privacy regime has moved from a narrow set of rules under the IT Act to a full statute in the DPDP Act, 2023. We help organisations work out what applies to them and put workable processes in place, rather than paperwork that sits unread.
DPDP Act readiness review
We map what personal data you collect, why, where it sits and who you share it with, then assess your position against the DPDP Act, 2023 and the IT Act, 2000 together with the SPDI Rules, 2011, and set out the gaps in order of priority.
Notices, consent & policies
We draft the notice given to data principals, the consent mechanics that sit behind it, privacy policies, employee and vendor privacy terms, and the data processing clauses in your contracts with processors.
Data-principal rights & grievances
We build the process for handling data-principal requests, access, correction, erasure, grievance redressal and nomination, and advise on the role of the data protection officer and consent manager where those obligations apply.
Breach response & transfers
We prepare a breach response plan, advise in real time when an incident occurs, including notification obligations, and advise on transferring personal data outside India within the framework the Act allows.
Simple, transparent, fast
How it works
- 01
Understand your data
A free, confidential conversation about what personal data your business handles and how it flows through your systems and vendors.
- 02
Gap assessment
We assess your current notices, consents, contracts and security practice against the DPDP Act and the IT Act, and prioritise what needs to change.
- 03
Draft & implement
We prepare notices, policies, contract clauses and internal procedures, and work with your product and engineering teams so they are actually usable.
- 04
Stay ready
We keep you current as the rules and enforcement practice develop, and stand by for breach response and data-principal escalations.
Why Soni & Soni
Authority you can rely on, a process you can see.
- 0+
- Marks granted
- 0+
- Active clients
- 0+
- Jurisdictions
- 0%
- Client retention
Privacy alongside IP
Data and intellectual property sit close together in most digital businesses. We advise on both, so your terms, licences and privacy commitments say the same thing.
Built for how you operate
Advice shaped around your product and vendor stack, not a generic policy pack that nobody in the business can follow.
Calm in an incident
A prepared plan and a lawyer on the line matters most in the first hours after a suspected breach, when decisions are hardest to reverse.
Practising since 2008
Offices in Ahmedabad and Jodhpur, with a first response to new enquiries within ten minutes.
Talk to an attorney
Not sure where you stand on privacy?
Tell us what your business does with personal data and we'll come back with a clear view of your obligations and where to start, confidentially, at no cost for the first conversation.
Free 15-minute consultation. Your idea is confidential from the very first hello, protected whether or not you go on to instruct us.
Data Protection & Privacy, your questions, answered
Does the Digital Personal Data Protection Act, 2023 apply to my business?
The Act applies to the processing of digital personal data within India, and to processing outside India where it relates to offering goods or services to data principals in India. Whether and how it applies to you depends on what data you handle and in what role, and that is the first thing we work out.
What is the difference between a data fiduciary and a data processor?
Under the DPDP Act, the data fiduciary is the person who determines the purpose and means of processing personal data and carries the primary obligations. A data processor processes data on the fiduciary's behalf under a contract. The distinction drives who owes what, and it needs to be reflected properly in your agreements.
Do the older IT Act rules still matter?
Yes, they remain part of the picture. Section 43A of the IT Act, 2000 and the SPDI Rules, 2011 have governed sensitive personal data for years, and Section 72A addresses wrongful disclosure. We advise on how these sit alongside the DPDP Act as it is brought into force.
What rights do individuals have over their data?
The DPDP Act gives data principals rights including access to information about processing, correction and erasure of their data, a route to grievance redressal, and the ability to nominate another person to exercise their rights. Your business needs a practical process for receiving and answering those requests.
What should we do if we suffer a data breach?
Contain the incident, preserve the evidence and take advice immediately, because the DPDP Act requires a personal data breach to be notified to the Data Protection Board and to affected data principals in the manner prescribed. Having a response plan agreed in advance is what makes those first hours manageable.
Can we transfer personal data outside India?
The DPDP Act permits transfer of personal data outside India subject to restrictions the Central Government may notify, and sector regulators may impose their own localisation requirements. We advise on the current position for your sector and on structuring vendor arrangements accordingly.
Let's protect what you've built.
Book your free, confidential consultation and talk through your privacy obligations with a lawyer.
