Compliance & Certification

The law behind every certificate we issue

India's Digital Personal Data Protection Act, 2023 is the reason CYVORIQ exists. Here's what it actually requires, and how our processes are built to meet it.

Understanding the law

India's DPDP Act 2023, in plain terms

The Digital Personal Data Protection Act, 2023 is India's first comprehensive data protection law. It applies to any organisation that collects, stores, or processes the personal data of people in India — and that includes whatever's still sitting on a device after it's been "wiped" the ordinary way.

Full enforcement by 13 May 2027
Penalties up to ₹250 Crore per violation
Enforced by the Data Protection Board of India
Key terms

Five words worth knowing

Data Principal

The individual the data is about. Someone handing over an old phone for exchange or disposal is a Data Principal.

Data Fiduciary

The organisation that decides why and how personal data is processed. This is usually you, our client.

Data Processor

Anyone processing data on a Data Fiduciary's behalf, under contract. This is where CYVORIQ sits.

Personal Data Breach

Any unauthorised or accidental exposure of personal data — including data recovered from a device that wasn't properly sanitized.

Significant Data Fiduciary

An organisation handling data at large enough scale that extra obligations apply — a dedicated DPO, regular impact assessments, and independent audits.

What the Act actually requires

The obligations that matter most for retired devices

  • Consent has to be specific (Sections 4 & 6). A blanket "I agree to terms" checkbox isn't valid consent for a separate purpose like device data processing.
  • Clear notice is required (Section 5). People need to be told what data is collected and why, in plain language, before it's collected.
  • Liability doesn't transfer to vendors (Section 8(1)). If a logistics partner or refurbisher mishandles data, the Data Fiduciary is still the one held responsible.
  • Processor contracts must be compliant (Section 8(2)). Any third party handling data on your behalf needs a formal, DPDP-aligned agreement.
  • Reasonable security safeguards are mandatory (Section 8(5)). The single highest-penalty provision in the Act — up to ₹250 Crore for failing to protect personal data adequately.
  • Breaches must be reported within 72 hours (Section 8(6)). Both the Data Protection Board and affected individuals must be notified without delay.
  • Data must be erased once its purpose is met (Section 8(7)). Retaining personal data "just in case" after a transaction is complete isn't permitted.
  • Children's data carries extra rules (Section 9). Verifiable parental consent is required, and profiling of minors isn't allowed at all.
  • Significant Data Fiduciaries face added obligations (Section 10). A resident DPO, annual impact assessments, and an independent auditor are all mandatory.
  • People can demand correction or erasure (Sections 12 & 13). Grievances must be resolved within 90 days, with escalation to the Board if they aren't.
What non-compliance costs

The penalty schedule

Penalties apply per violation, not per incident — so a single lapse involving an unsanitized device can trigger more than one of these at the same time.

SectionWhat it coversMaximum penalty
Sec 8(5)Failing to implement reasonable security safeguards₹250 Crore
Sec 8(6)Failing to report a data breach within 72 hours₹200 Crore
Sec 5 / 6Processing data without valid consent or notice₹200 Crore
Sec 9Non-compliance with children's data provisions₹200 Crore
Sec 10Significant Data Fiduciary failing added obligations₹150 Crore
Sec 8(7)Failing to erase data once its purpose is fulfilled₹50 Crore
Sec 12 / 13Failing to honour rights or grievance requests in time₹50 Crore

Compliance infrastructure like this doesn't get built overnight. With full enforcement landing on 13 May 2027, the runway to have a documented, working process in place is shorter than it looks.

Frameworks we build against

How CYVORIQ addresses each one

FrameworkWhat it governsHow CYVORIQ addresses it
DPDP Act, 2023Personal data handling and accountabilitySanitization and disposal records mapped directly to Sections 8(5) and 8(7)
NIST SP 800-88 Rev.1Media sanitization methods (Clear / Purge / Destroy)CYVRA Erase methods selected by media type and asset sensitivity, with pass/fail verification
RBI IT Governance GuidelinesIT asset lifecycle controls for regulated financial entitiesRBI-aligned reporting formats for BFSI engagements
E-Waste (Management) RulesAuthorized channels for e-waste disposalNon-recoverable assets routed through CPCB-compliant channels
Payment Aggregator frameworkRBI regulation of digital payment intermediariesCYVRA BidX settlement runs through licensed Payment Aggregator escrow, not an in-house wallet
Certificate anatomy

What's actually on a CYVORIQ certificate

Every certificate is built to answer the questions an auditor will actually ask — not just confirm that something happened.

01 Device & asset ID
02 Method & standard used
03 Pass/fail verification result
04 Cryptographic signature
05 Timestamp
06 Operator / system ID
07 Chain-of-custody reference
08 Independent verification link

Already have a certificate in hand? Verify it here →

Building toward external certification

Where our certification program stands

We're pursuing ISO 27001 (Information Security Management) and ISO 27701 (Privacy Information Management) certification as the next layer of our compliance posture, alongside the NIST SP 800-88 Rev.1 process alignment already built into CYVRA Erase today. We'll update this page as each certification is completed, rather than claim it ahead of time.

Where we're headed next

Closing the buy-back blind spot

Large-scale trade-in and buy-back programs — from e-commerce platforms to OEM exchange schemes — collect millions of used devices every year. Under the DPDP Act, the platform accepting a device becomes responsible for the personal data on it the moment it's accepted. That responsibility doesn't go away just because a refurbisher or logistics partner handled the device next.

We're building an integration that embeds CYVRA's certified erasure directly into those buy-back workflows — turning that exposure into a documented, per-device compliance record instead of an open question.

In active development

Built on the same certification engine behind CYVRA Erase. If you run a large-scale trade-in or buy-back program, we'd like to talk about a pilot.

Talk to us about a pilot
Grievance redressal

Questions about how we handle your data

If you have a question or a grievance about how CYVORIQ handles personal data, reach our Data Protection Officer at dpo@cyvoriq.com. We aim to acknowledge and resolve grievances within 90 days, in line with the DPDP Act, 2023.

Need documentation for an upcoming audit?

We can walk your compliance team through exactly what CYVORIQ provides and how it maps to your framework.

Talk to Compliance