VVerdoos
Log in
PN

Prateek Navani

@prateek

2 Posts0 Followers0 Following
PN
Prateek Navani@prateek· Tuesday at 7:52 AM

What does the DPDP Act actually require from your business

I've sat through a lot of "we'll deal with it later" conversations about India's data protection law. I get why. The Act passed back in 2023, the rules only showed up in November 2025, and the real deadlines still feel far off. They're not as far off as they feel. Let me walk you through what this law actually requires, and what you should be doing about it right now. Quick answer: the DPDP Act applies to any business that processes digital personal data connected to India, regardless of size, including foreign companies serving Indian customers. The rules were notified in November 2025 and roll out in three phases, with full substantive compliance required by May 13, 2027. There's no size exemption. A five-person startup and a 5,000-person company carry the same basic obligations. Penalties for serious violations can reach ₹250 crore per incident. What is the DPDP Act, and who does it apply to? It's India's first comprehensive data privacy law, and it applies to you if you handle any digital personal data connected to India, no matter how small your business is. The Act covers any organisation that determines the purpose and means of processing personal data, called a Data Fiduciary in the law's terminology. That's roughly the same role GDPR calls a "controller." If you collect a customer's name, email, or phone number digitally, you're a Data Fiduciary, full stop. Here's the part that catches foreign companies off guard. The DPDP law reaches beyond India's borders. If you're based anywhere in the world but offer goods or services to people in India and process their personal data in connection with that, you're covered too. There's no revenue threshold, no employee count cutoff, and no blanket small-business exemption that's been notified. What's the actual compliance timeline? Three phases spread across 18 months from when the rules were notified, with the real deadline landing in May 2027. Phase Date What kicks in Phase 1 November 13, 2025 Data Protection Board established, penalty framework active Phase 2 November 13, 2026 Consent Manager registration opens Phase 3 May 13, 2027 Full substantive compliance mandatory Phase 3 is where the real work lands. Notices, consent mechanisms, security safeguards, breach reporting, and data principal rights all need to be fully operational by that date. There's talk of MeitY compressing this window from 18 months to 12, which would move the deadline earlier, but that hasn't been formally confirmed as of mid-2026. My honest take here: treat 2026 as your build year regardless of whether that compression happens. Consent flows, data inventories, and vendor contracts take months to get right. Waiting for a confirmed deadline before starting is how companies end up in a scramble. 👉Must read: DPDP Compliance Checklist What do you actually have to do as a data fiduciary? The core obligations come down to five things: notice, consent, security, breach handling, and honoring individual rights. Give clear notice. Every data collection point needs a plain-language notice explaining what you're collecting and why. Get valid consent. Free, specific, informed, and unconditional. No pre-checked boxes, no bundling multiple purposes into one blanket agreement. Secure the data. Reasonable security safeguards proportionate to the sensitivity of what you're holding. Report breaches within 72 hours. Both to the Data Protection Board and to affected individuals. Honor data principal rights. Access, correction, and deletion requests need a real process behind them, not just a policy document. If you use a vendor to process data on your behalf, that vendor is a Data Processor under the Act. Using one doesn't transfer your responsibility. You still need contracts in place with adequate safeguards, and you're still accountable if that vendor mishandles the data. How is consent different under DPDP than what you're probably doing today? It's stricter than most Indian businesses are used to, and there's no fallback option if consent isn't properly obtained. This is the detail that surprises people most: unlike GDPR, the DPDP Act does not recognize "legitimate interest" as a basis for processing. Consent is essentially the primary path, alongside a narrow set of specifically defined "legitimate uses" that don't leave much room for interpretation. That means the consent banner you've been running for years, the one with a pre-checked "I agree" box or a single blanket permission covering five different purposes, almost certainly doesn't hold up under this law. Consent has to be specific to each purpose, and the person has to be able to withdraw it as easily as they gave it. What happens if there's a data breach? You have 72 hours to notify affected people, and the notification has to include specific details, not a vague acknowledgment that something happened. Once a breach occurs, the clock starts immediately. Your notification to affected Data Principals needs to cover what happened in plain language, what data was exposed, what protective steps they can take, and how to reach you with questions. The Data Protection Board also needs to be notified, and the completeness and speed of your report directly affects the penalty you might face. This is worth testing before you need it. A breach response plan that only exists on paper tends to fall apart in the first real incident. Run through it once with your team so the 72-hour clock doesn't catch anyone off guard. Are you a significant data fiduciary? Possibly, if you process data at real scale or in sensitive categories, and the government hasn't published the official list yet, so the safest move is to prepare as if you might qualify. The Central Government designates Significant Data Fiduciaries, or SDFs, based on the volume and sensitivity of data processed, the risk to individuals, and broader considerations like national security or impact on electoral processes. If you're designated, the obligations step up meaningfully: Appoint a Data Protection Officer based in India, reporting to your board Appoint an independent data auditor Conduct regular Data Protection Impact Assessments Undergo more frequent, more formal audits As of mid-2026, that official SDF list still hasn't been published. High-volume platforms, fintechs, healthtechs, and large consumer businesses should assume they're likely candidates and prepare accordingly. What can cross-border data transfer actually look like? More flexible than you might expect. India didn't copy the strict data localization model some other countries use. The DPDP Act runs on a negative-list approach. Transfers are allowed to any country except ones the government specifically restricts. No such restricted list has been published yet, so cross-border transfers are currently permitted broadly, subject to safeguards specified later. This flexibility isn't permanent. SDFs may face additional restrictions on specific categories of data down the line, so map your cross-border data flows now. What happens if you don't comply? The penalties are steep enough to change how seriously most businesses treat this, and they stack per violation. Violation type Maximum penalty Failure to maintain reasonable security safeguards ₹250 crore Failure to notify a breach ₹200 crore Children's data violations ₹200 crore Significant Data Fiduciary obligation failures ₹150 crore General non-compliance ₹50 crore These aren't caps per company. They're per violation, and they can stack if multiple failures occur from the same incident. What should you actually do right now? Work through this in order, and you'll be in a genuinely strong position well before May 2027. Map your data. Know what personal data you collect, where it lives, and who touches it, including vendors. Appoint a responsible person. Even before you know if you'll be designated an SDF, someone needs clear ownership of this program. Rebuild your consent flows. Audit every collection point for pre-checked boxes, bundled permissions, or vague language, and fix them now rather than in a rush later. Put processor contracts in place. Confirm every vendor touching personal data has a contract with real security obligations attached. Draft and test your breach response plan. Don't wait for an actual incident to find out it doesn't work. What mistakes are businesses making with DPDP prep? A few patterns show up again and again, and they're all avoidable with a bit of early effort. Waiting for the SDF list before preparing. By the time it's published, you may already be behind. Prepare as if you qualify. Treating consent as a one-time banner fix. Real compliance means every collection point, not just your homepage cookie notice. Assuming vendor contracts are optional. Using a processor doesn't reduce your liability. It just adds another party you need a solid contract with. Underestimating how long consent flow rebuilds actually take. This is engineering and legal work combined, and it rarely finishes in a sprint. The bottom line The DPDP Act isn't a distant regulation to worry about later. It applies broadly, the deadlines are real, and the penalties are large enough to matter to businesses of every size. Start with your data map and your consent flows. Everything else on this list gets easier once those two are actually done. And given how much of this touches legal risk directly, it's worth having your compliance program reviewed by legal counsel familiar with the Act rather than relying on any single guide, including this one.

Photo shared by Prateek Navani: I've sat through a lot of "we'll deal with it later" conversations about India's data protection law
PN
Prateek Navani@prateek· August 7 at 1:17 PM

AI hardware costs in 2026: what's driving GPU prices up

If you have priced out a GPU recently, whether for gaming, a workstation, or an AI project, you already know something has changed. Prices are continuously rising. In short: GPU prices are surging in 2026 because massive AI data center demand has triggered a global memory shortage. AI infrastructure absorbs a huge share of high-end memory, including HBM, GDDR6, GDDR7, and DDR5, leaving far less supply for consumer and enterprise hardware and pushing manufacturing costs up sharply. This is not a short-term blip caused by one product launch or one bad quarter. It is a structural shift in how memory gets made and who gets it first. AI data centers are eating the memory supply Every GPU, whether it is a gaming card or a data center accelerator, needs memory to function. For years, memory manufacturers split their factory output between commodity memory for PCs and consoles, and higher-end memory for servers and specialized hardware. That balance has broken down. Samsung, SK Hynix, and Micron are the three companies that make the vast majority of the world's DRAM. In 2026, all three have been shifting factory capacity toward high bandwidth memory, or HBM, the memory format that powers AI accelerators. HBM is significantly more profitable per wafer than standard DDR5. When a manufacturer has to choose between a highly profitable product with guaranteed demand from hyperscalers and a lower-margin product for the consumer market, the choice is not close. Industry estimates suggest AI data centers could absorb around 70% of global high-end memory output in 2026, up from roughly 20 to 30% just a few years ago. The result is a squeeze that started in enterprise memory and spread into gaming GPUs, laptops, and even game consoles, because they all draw from the same limited fabs. Core drivers of higher GPU prices AI memory squeeze This is the primary driver. AI infrastructure providers are willing to pay a premium for guaranteed memory supply, and manufacturers are prioritizing that demand over consumer-facing products. Every wafer redirected to HBM production is a wafer that does not become standard GPU or system memory. Rising component costs Memory now represents a much larger share of total GPU production cost than it did even a year ago. Contract pricing for both DDR5 and HBM has climbed sharply through 2026, and fixed-price memory agreements that GPU makers relied on in prior years have expired, exposing them to current market rates. When the input cost rises this much, manufacturers pass at least part of that increase on to buyers. Extended lead times Manufacturing allocation has become unpredictable. Lead times for high-demand GPU architectures have stretched well beyond historical norms, in some cases reaching several months from order to delivery. Longer lead times make planning harder for both individual buyers and businesses trying to provision infrastructure on a schedule. Stretched product roadmaps Planned refreshes and next-generation consumer GPU releases have faced delays. When fewer new products enter the market on schedule, there is less competitive pressure to bring prices down, and older inventory stays priced higher for longer than it normally would. What this means if you are planning AI infrastructure For businesses building or scaling AI workloads, this shortage changes the calculation around buying versus renting compute. High-end accelerators built for AI training and inference carry large amounts of premium memory by design. A single data-center-grade accelerator can include well over 100GB of HBM, which is part of why enterprise AI hardware has been hit especially hard by the same shortage affecting consumer cards. If you are planning capacity around a specific accelerator like the H200 GPU, it is worth checking current, real pricing directly rather than budgeting off numbers from even a few months ago, since this market is moving quickly. For many businesses, the more practical path in 2026 is not buying hardware outright. Renting GPU capacity from a cloud provider avoids the upfront capital cost of hardware whose price could still be climbing when it arrives, and it avoids the multi-month wait that direct purchases now often involve. There is also a depreciation risk worth considering. Hardware bought today at an inflated price does not become cheaper to have owned if prices ease later. A rented or reserved cloud allocation shifts that risk to the provider, who can adjust capacity and pricing across a much larger pool of customers than a single business managing its own hardware refresh cycle. How to plan around rising GPU and memory costs Budget for volatility, not a fixed number: Get current pricing before finalizing any hardware budget. A quote from even two or three months ago may already be outdated. Separate your always-on needs from your burst needs: If your AI workload runs steadily, a dedicated or reserved allocation can be more cost-predictable than pure on-demand pricing during a period of rising rates. If your workload spikes occasionally, on-demand or rented capacity avoids overcommitting to hardware you will not use consistently. Ask about lead times before committing to a purchase date: If a project timeline depends on receiving specific hardware, confirm current lead times with the vendor directly rather than assuming they match what was normal a year ago. Reconsider memory requirements realistically: Not every workload needs the newest, highest-memory card available. Right-sizing memory to the actual workload can meaningfully reduce cost exposure during a period when memory itself is the most expensive component. Watch supplier announcements, not just price trackers: Manufacturer decisions, like shifting production priorities or retiring certain consumer product lines, tend to signal where prices are headed before that shows up in retail pricing. The bottom line The GPU price increases in 2026 are not about one company raising prices for its own reasons. They trace back to a single, structural cause: AI infrastructure needs more high-end memory than the world's fabs can currently produce, and consumer and enterprise GPU buyers are competing for what is left. Understanding that root cause helps you plan better, whether that means budgeting for volatility, timing a purchase, or shifting toward rented cloud capacity instead of owned hardware while the market works through this shortage.

Photo shared by Prateek Navani: If you have priced out a GPU recently, whether for gaming, a workstation, or an AI project, you alre