India's Digital Personal Data Protection Act, 2023 is the reason CYVORIQ exists. Here's what it actually requires, and how our processes are built to meet it.
The Digital Personal Data Protection Act, 2023 is India's first comprehensive data protection law. It applies to any organisation that collects, stores, or processes the personal data of people in India — and that includes whatever's still sitting on a device after it's been "wiped" the ordinary way.
The individual the data is about. Someone handing over an old phone for exchange or disposal is a Data Principal.
The organisation that decides why and how personal data is processed. This is usually you, our client.
Anyone processing data on a Data Fiduciary's behalf, under contract. This is where CYVORIQ sits.
Any unauthorised or accidental exposure of personal data — including data recovered from a device that wasn't properly sanitized.
An organisation handling data at large enough scale that extra obligations apply — a dedicated DPO, regular impact assessments, and independent audits.
Penalties apply per violation, not per incident — so a single lapse involving an unsanitized device can trigger more than one of these at the same time.
| Section | What it covers | Maximum penalty |
|---|---|---|
| Sec 8(5) | Failing to implement reasonable security safeguards | ₹250 Crore |
| Sec 8(6) | Failing to report a data breach within 72 hours | ₹200 Crore |
| Sec 5 / 6 | Processing data without valid consent or notice | ₹200 Crore |
| Sec 9 | Non-compliance with children's data provisions | ₹200 Crore |
| Sec 10 | Significant Data Fiduciary failing added obligations | ₹150 Crore |
| Sec 8(7) | Failing to erase data once its purpose is fulfilled | ₹50 Crore |
| Sec 12 / 13 | Failing to honour rights or grievance requests in time | ₹50 Crore |
Compliance infrastructure like this doesn't get built overnight. With full enforcement landing on 13 May 2027, the runway to have a documented, working process in place is shorter than it looks.
| Framework | What it governs | How CYVORIQ addresses it |
|---|---|---|
| DPDP Act, 2023 | Personal data handling and accountability | Sanitization and disposal records mapped directly to Sections 8(5) and 8(7) |
| NIST SP 800-88 Rev.1 | Media sanitization methods (Clear / Purge / Destroy) | CYVRA Erase methods selected by media type and asset sensitivity, with pass/fail verification |
| RBI IT Governance Guidelines | IT asset lifecycle controls for regulated financial entities | RBI-aligned reporting formats for BFSI engagements |
| E-Waste (Management) Rules | Authorized channels for e-waste disposal | Non-recoverable assets routed through CPCB-compliant channels |
| Payment Aggregator framework | RBI regulation of digital payment intermediaries | CYVRA BidX settlement runs through licensed Payment Aggregator escrow, not an in-house wallet |
Every certificate is built to answer the questions an auditor will actually ask — not just confirm that something happened.
Already have a certificate in hand? Verify it here →
We're pursuing ISO 27001 (Information Security Management) and ISO 27701 (Privacy Information Management) certification as the next layer of our compliance posture, alongside the NIST SP 800-88 Rev.1 process alignment already built into CYVRA Erase today. We'll update this page as each certification is completed, rather than claim it ahead of time.
Large-scale trade-in and buy-back programs — from e-commerce platforms to OEM exchange schemes — collect millions of used devices every year. Under the DPDP Act, the platform accepting a device becomes responsible for the personal data on it the moment it's accepted. That responsibility doesn't go away just because a refurbisher or logistics partner handled the device next.
We're building an integration that embeds CYVRA's certified erasure directly into those buy-back workflows — turning that exposure into a documented, per-device compliance record instead of an open question.
Built on the same certification engine behind CYVRA Erase. If you run a large-scale trade-in or buy-back program, we'd like to talk about a pilot.
Talk to us about a pilotIf you have a question or a grievance about how CYVORIQ handles personal data, reach our Data Protection Officer at dpo@cyvoriq.com. We aim to acknowledge and resolve grievances within 90 days, in line with the DPDP Act, 2023.