[{"data":1,"prerenderedAt":558},["ShallowReactive",2],{"blog-\u002Fblog\u002Fbreach-notification-readiness":3,"blog-more-\u002Fblog\u002Fbreach-notification-readiness":178},{"id":4,"title":5,"author":6,"body":7,"category":156,"date":157,"description":158,"draft":159,"extension":160,"eyebrow":161,"faq":162,"h1":163,"keywords":164,"meta":168,"navigation":169,"ogTitle":161,"path":170,"readingTime":171,"relatedArticles":172,"relatedServices":173,"seo":174,"stem":175,"tags":176,"updated":157,"__hash__":177},"blog\u002Fblog\u002Fbreach-notification-readiness.md","Breach-Ready in Practice: Beyond the Policy Document","DreamyHook Consultancy Services",{"type":8,"value":9,"toc":142},"minimark",[10,23,28,55,59,70,74,79,87,91,94,98,105,109,116,120,128,136],[11,12,13,14,18,19,22],"p",{},"Plenty of organizations have a breach-notification ",[15,16,17],"em",{},"policy",". Far fewer are actually ",[15,20,21],{},"ready"," — able to detect a breach, contain it, and notify the right people in time, calmly, on a bad day. The gap between the document and the drill is where things go wrong.",[24,25,27],"h2",{"id":26},"what-the-dpdp-act-expects","What the DPDP Act expects",[11,29,30,31,35,36,39,40,45,46,49,50,54],{},"If a personal data breach occurs, you must notify the ",[32,33,34],"strong",{},"Data Protection Board of India"," and the ",[32,37,38],{},"affected Data Principals",", in the manner and timelines the ",[41,42,44],"a",{"href":43},"\u002Fdpdp-act\u002Fdpdp-rules-2025","Rules"," specify. Getting this wrong carries penalties up to ",[32,47,48],{},"₹200 crore"," — second only to the security-failure penalty itself. (",[41,51,53],{"href":52},"\u002Fdpdp-act\u002Fpenalties","See penalties.",")",[24,56,58],{"id":57},"why-a-policy-alone-fails","Why a policy alone fails",[11,60,61,62,65,66,69],{},"A policy says ",[15,63,64],{},"what"," should happen. Under pressure, teams need to know ",[15,67,68],{},"exactly who does what, with which tools, in what order",". Without that, you get delay, confusion, and missed deadlines — precisely what the Board penalizes.",[24,71,73],{"id":72},"what-real-readiness-looks-like","What real readiness looks like",[75,76,78],"h3",{"id":77},"_1-detection-you-can-trust","1. Detection you can trust",[11,80,81,82,86],{},"You can't report what you can't see. Monitoring, alerting, and audit logs (",[41,83,85],{"href":84},"\u002Fservices\u002Ftechnical-implementation","built here",") turn \"we think something happened\" into \"here's what happened, when, and to whom.\"",[75,88,90],{"id":89},"_2-a-runbook-not-a-policy","2. A runbook, not a policy",[11,92,93],{},"A step-by-step runbook: roles, decision tree, communication templates for the Board and affected users, and a clock. Everyone knows their job before the incident, not during it.",[75,95,97],{"id":96},"_3-a-tested-drill","3. A tested drill",[11,99,100,101,104],{},"Run a tabletop exercise. The first time your team walks the process should ",[32,102,103],{},"not"," be a real breach. Drills surface the gaps — a missing contact, an unclear owner, a slow approval — while they're cheap to fix.",[75,106,108],{"id":107},"_4-evidence-of-good-faith","4. Evidence of good faith",[11,110,111,112,115],{},"When the Board assesses a breach, your ",[32,113,114],{},"response and mitigation"," count. A documented, tested process is evidence you took your duties seriously — which materially affects the outcome.",[24,117,119],{"id":118},"make-it-ongoing","Make it ongoing",[11,121,122,123,127],{},"Breach readiness decays as your systems change. Keeping it current is part of ",[41,124,126],{"href":125},"\u002Fservices\u002Fmanaged-compliance","Managed Compliance",", including periodic drills.",[11,129,130,131,135],{},"Not sure how ready you are? Start with the free ",[41,132,134],{"href":133},"\u002Fquick-scan","DPDP Quick Scan",".",[137,138,139],"blockquote",{},[11,140,141],{},"General information, not legal advice.",{"title":143,"searchDepth":144,"depth":144,"links":145},"",3,[146,148,149,155],{"id":26,"depth":147,"text":27},2,{"id":57,"depth":147,"text":58},{"id":72,"depth":147,"text":73,"children":150},[151,152,153,154],{"id":77,"depth":144,"text":78},{"id":89,"depth":144,"text":90},{"id":96,"depth":144,"text":97},{"id":107,"depth":144,"text":108},{"id":118,"depth":147,"text":119},"Security","2026-04-28","A breach-notification policy isn't readiness. Here's what it actually takes to detect, respond to, and report a personal data breach under the DPDP Act.",false,"md",null,[],"Breach-ready in practice: beyond the policy document",[165,166,167],"DPDP breach notification","data breach response India","DPDP breach readiness",{},true,"\u002Fblog\u002Fbreach-notification-readiness","5 min read",[],[],{"title":5,"description":158},"blog\u002Fbreach-notification-readiness",[],"HNQ1kWiH2tfl3r2lwKClhSRirsEKjtVVze9fRe74GJ8",[179,319,471],{"id":180,"title":181,"author":6,"body":182,"category":302,"date":303,"description":304,"draft":159,"extension":160,"eyebrow":161,"faq":305,"h1":306,"keywords":307,"meta":311,"navigation":169,"ogTitle":161,"path":312,"readingTime":171,"relatedArticles":313,"relatedServices":314,"seo":315,"stem":316,"tags":317,"updated":303,"__hash__":318},"blog\u002Fblog\u002Fdpdp-for-startups-where-to-begin.md","DPDP for Startups: Where to Actually Begin",{"type":8,"value":183,"toc":295},[184,187,191,194,216,224,228,235,239,247,251,269,273,285,291],[11,185,186],{},"If you're a founder, the DPDP Act probably feels like one more thing competing for time you don't have. Good news: you don't need a privacy team or a six-figure budget to start well. You need to do a few high-leverage things in the right order.",[24,188,190],{"id":189},"start-with-what-you-actually-have","Start with what you actually have",[11,192,193],{},"Before buying anything, answer three questions:",[195,196,197,204,210],"ol",{},[198,199,200,203],"li",{},[32,201,202],{},"What personal data do we collect?"," (Sign-ups, payments, analytics, support.)",[198,205,206,209],{},[32,207,208],{},"Where does it go?"," (Your DB, plus every SaaS tool and pixel.)",[198,211,212,215],{},[32,213,214],{},"Who can touch it?"," (Team, vendors, integrations.)",[11,217,218,219,223],{},"This is a lightweight version of a ",[41,220,222],{"href":221},"\u002Fservices\u002Freadiness-audit","readiness audit"," — and it's the foundation for everything else. You can't protect what you haven't found.",[24,225,227],{"id":226},"fix-consent-early-its-cheaper-before-you-scale","Fix consent early — it's cheaper before you scale",[11,229,230,231,135],{},"Retrofitting consent across a large user base is painful. Doing it while you're small is easy. Get your notices clear and itemized, capture consent properly, and make withdrawal one tap. See ",[41,232,234],{"href":233},"\u002Fservices\u002Fconsent-management","Consent & Notice Management",[24,236,238],{"id":237},"dont-over-buy","Don't over-buy",[11,240,241,242,246],{},"A lot of \"DPDP compliance\" sales pitches push expensive SaaS you may not need yet. Early on, a clean data map, honest consent, a simple rights inbox, and basic security cover most of your risk. Spend on tooling when your scale justifies it — not before. (More on this in our ",[41,243,245],{"href":244},"\u002Fpricing","pricing philosophy",".)",[24,248,250],{"id":249},"know-if-youre-heading-toward-sdf-status","Know if you're heading toward SDF status",[11,252,253,254,258,259,263,264,268],{},"If you're in ",[41,255,257],{"href":256},"\u002Findustries\u002Ffintech","fintech",", ",[41,260,262],{"href":261},"\u002Findustries\u002Fhealthtech","healthtech",", or building toward a huge user base, you may eventually be a ",[41,265,267],{"href":266},"\u002Fdpdp-act\u002Fsignificant-data-fiduciary","Significant Data Fiduciary",". You don't need a DPO on day one — but design knowing it's coming.",[24,270,272],{"id":271},"the-one-move-that-matters-most","The one move that matters most",[11,274,275,276,280,281,284],{},"Start. The ",[41,277,279],{"href":278},"\u002Fdpdp-act\u002Ftimeline-deadlines","timeline"," runs to ",[32,282,283],{},"13 May 2027",", and compliance is sequential — early action compounds. The cheapest, calmest path is the one that begins now.",[11,286,287,288,290],{},"Take the free ",[41,289,134],{"href":133}," to see your startup's position in five minutes.",[137,292,293],{},[11,294,141],{},{"title":143,"searchDepth":144,"depth":144,"links":296},[297,298,299,300,301],{"id":189,"depth":147,"text":190},{"id":226,"depth":147,"text":227},{"id":237,"depth":147,"text":238},{"id":249,"depth":147,"text":250},{"id":271,"depth":147,"text":272},"Startups","2026-05-18","A pragmatic, founder-friendly guide to starting DPDP compliance without slowing your startup down or blowing the budget.",[],"DPDP for startups: where to actually begin",[308,309,310],"DPDP Act for startups","DPDP compliance cost India","startup data protection",{},"\u002Fblog\u002Fdpdp-for-startups-where-to-begin",[],[],{"title":181,"description":304},"blog\u002Fdpdp-for-startups-where-to-begin",[],"8g_-sFsG0qP-_cPV552yRt6owMx-tFe8zTnXW6QmWGs",{"id":320,"title":321,"author":6,"body":322,"category":454,"date":455,"description":456,"draft":159,"extension":160,"eyebrow":161,"faq":457,"h1":458,"keywords":459,"meta":463,"navigation":169,"ogTitle":161,"path":464,"readingTime":171,"relatedArticles":465,"relatedServices":466,"seo":467,"stem":468,"tags":469,"updated":455,"__hash__":470},"blog\u002Fblog\u002Fconsent-that-doesnt-kill-conversion.md","Consent That Doesn't Kill Your Conversion",{"type":8,"value":323,"toc":443},[324,331,335,353,356,360,364,371,375,378,382,390,394,397,401,408,412,427,439],[11,325,326,327,330],{},"The fear is understandable: if we ask for proper consent, won't people just say no? In practice, well-designed consent barely dents conversion — and clumsy consent hurts you twice, by annoying users ",[15,328,329],{},"and"," failing the law. Here's how to get both right.",[24,332,334],{"id":333},"what-the-dpdp-act-actually-requires","What the DPDP Act actually requires",[11,336,337,338,341,342,345,346,349,350,54],{},"Consent must be ",[32,339,340],{},"free, specific, informed, unconditional, and unambiguous",", with ",[32,343,344],{},"withdrawal as easy as giving it",". Crucially, it must be ",[32,347,348],{},"itemized"," — you can't bundle ten purposes into one take-it-or-leave-it checkbox. (",[41,351,352],{"href":43},"Full detail here.",[11,354,355],{},"That sounds restrictive. It's actually an opportunity to design something honest.",[24,357,359],{"id":358},"principles-for-high-converting-compliant-consent","Principles for high-converting, compliant consent",[75,361,363],{"id":362},"_1-ask-at-the-right-moment","1. Ask at the right moment",[11,365,366,367,370],{},"Don't front-load every permission at sign-up. Request consent ",[32,368,369],{},"in context"," — when the feature that needs it is actually used. Contextual asks convert far better than a wall of toggles on day one.",[75,372,374],{"id":373},"_2-make-the-value-obvious","2. Make the value obvious",[11,376,377],{},"People consent when they understand the benefit. \"Allow notifications so you never miss an order update\" beats \"We'd like to send you notifications.\" Plain language, stated benefit.",[75,379,381],{"id":380},"_3-default-to-off-honestly","3. Default to off, honestly",[11,383,384,385,389],{},"Optional purposes should be off by default. Counter-intuitively, this builds trust — and trust converts. Our own ",[41,386,388],{"href":387},"\u002Fcookie-policy","cookie banner"," does exactly this.",[75,391,393],{"id":392},"_4-make-no-painless","4. Make \"no\" painless",[11,395,396],{},"If declining feels punishing, you'll get resentment, not consent. A clean \"not now\" keeps the relationship intact for a later, better-timed ask.",[75,398,400],{"id":399},"_5-respect-withdrawal","5. Respect withdrawal",[11,402,403,404,407],{},"Withdrawal must be as easy as consent — and your systems must actually stop processing. A ",[41,405,406],{"href":233},"preference center"," makes this simple for users and provable for you.",[24,409,411],{"id":410},"the-hidden-upside","The hidden upside",[11,413,414,415,418,419,422,423,426],{},"Honest consent produces a ",[32,416,417],{},"cleaner, more engaged audience"," and a ",[32,420,421],{},"defensible consent ledger",". You lose a few low-intent opt-ins and gain users who actually want to hear from you — plus the evidence you'd need if the ",[41,424,425],{"href":52},"Board"," ever asked.",[11,428,429,430,432,433,435,436,135],{},"Want consent flows that are compliant ",[15,431,329],{}," convert? See ",[41,434,234],{"href":233},", or ",[41,437,438],{"href":133},"scan your current setup",[137,440,441],{},[11,442,141],{},{"title":143,"searchDepth":144,"depth":144,"links":444},[445,446,453],{"id":333,"depth":147,"text":334},{"id":358,"depth":147,"text":359,"children":447},[448,449,450,451,452],{"id":362,"depth":144,"text":363},{"id":373,"depth":144,"text":374},{"id":380,"depth":144,"text":381},{"id":392,"depth":144,"text":393},{"id":399,"depth":144,"text":400},{"id":410,"depth":147,"text":411},"Design","2026-05-10","DPDP-compliant consent and conversion aren't enemies. Here's how to design consent flows that meet the law and keep your funnel healthy.",[],"Consent that doesn't kill your conversion",[460,461,462],"DPDP consent design","consent management DPDP","consent conversion",{},"\u002Fblog\u002Fconsent-that-doesnt-kill-conversion",[],[],{"title":321,"description":456},"blog\u002Fconsent-that-doesnt-kill-conversion",[],"pyFcR_kBWDY8hPubQJaNJ2UUCQLxoGxzZY4NZZapUow",{"id":4,"title":5,"author":6,"body":472,"category":156,"date":157,"description":158,"draft":159,"extension":160,"eyebrow":161,"faq":551,"h1":163,"keywords":552,"meta":553,"navigation":169,"ogTitle":161,"path":170,"readingTime":171,"relatedArticles":554,"relatedServices":555,"seo":556,"stem":175,"tags":557,"updated":157,"__hash__":177},{"type":8,"value":473,"toc":540},[474,480,482,494,496,502,504,506,510,512,514,516,520,522,526,528,532,536],[11,475,13,476,18,478,22],{},[15,477,17],{},[15,479,21],{},[24,481,27],{"id":26},[11,483,30,484,35,486,39,488,45,490,49,492,54],{},[32,485,34],{},[32,487,38],{},[41,489,44],{"href":43},[32,491,48],{},[41,493,53],{"href":52},[24,495,58],{"id":57},[11,497,61,498,65,500,69],{},[15,499,64],{},[15,501,68],{},[24,503,73],{"id":72},[75,505,78],{"id":77},[11,507,81,508,86],{},[41,509,85],{"href":84},[75,511,90],{"id":89},[11,513,93],{},[75,515,97],{"id":96},[11,517,100,518,104],{},[32,519,103],{},[75,521,108],{"id":107},[11,523,111,524,115],{},[32,525,114],{},[24,527,119],{"id":118},[11,529,122,530,127],{},[41,531,126],{"href":125},[11,533,130,534,135],{},[41,535,134],{"href":133},[137,537,538],{},[11,539,141],{},{"title":143,"searchDepth":144,"depth":144,"links":541},[542,543,544,550],{"id":26,"depth":147,"text":27},{"id":57,"depth":147,"text":58},{"id":72,"depth":147,"text":73,"children":545},[546,547,548,549],{"id":77,"depth":144,"text":78},{"id":89,"depth":144,"text":90},{"id":96,"depth":144,"text":97},{"id":107,"depth":144,"text":108},{"id":118,"depth":147,"text":119},[],[165,166,167],{},[],[],{"title":5,"description":158},[],1780230336780]