THE PRIVACY LABS BLOG

DPDP compliance, minus the legalese.

Practical guides to the DPDP Act for Indian founders and engineers, plus teardowns of real Indian brand privacy policies against the exact sections they meet and miss.

24 articles13 teardowns11 guides

We read their privacy policies so you don't have to.

Real Indian brands, read against the exact sections of the DPDP Act they meet and miss. Brands we work with never become teardowns.

FlipkartTeardown

Flipkart's Privacy Policy vs the DPDP Act: 500 Million Users, Zero Mentions

  • Prescription data with no health-specific safeguard (§8, Rule 6)
  • KYC and financial data under blanket consent (§6)
  • Retention with no schedule (Rule 8)
6 min read
TeardownTeardown

Bombay Shaving Company's Privacy Policy vs the DPDP Act: A Template With the Seams Showing

6 min read
TeardownTeardown

Lenskart's Privacy Policy vs the DPDP Act: Someone Read the Act. Someone Else Wrote the Consent Clause.

7 min read
TeardownTeardown

Rapido's Privacy Policy vs the DPDP Act: Can a Gig Worker Freely Refuse Consent?

7 min read
Bombay Shaving CompanyTeardown

Bombay Shaving Company's Privacy Policy Vs the DPDP Act: A Templated Clause and No Retention Schedule

  • A templated clause describing a product this isn't
  • No retention clause at all (Rule 8)
  • One blanket consent sentence for five actions (§6)
  • Business-transfer clause moves data without fresh consent
5 min read
ZeptoTeardown

Zepto's Privacy Policy vs the DPDP Act: A Section-by-Section Teardown

  • Retention with no number (Rule 8)
  • Consent by usage (§6)
  • The Act is never named
6 min read
SwiggyTeardown

Swiggy's Privacy Policy vs the DPDP Act: One Clause That Won't Survive November

  • Prescription data, general-purpose safeguards (§8, Rule 6)
  • AI data sharing without separate consent (§6)
  • No retention periods (Rule 8)
6 min read
ZomatoTeardown

Zomato, Blinkit, and the DPDP Act: When a Household Profile Becomes a Liability

  • Blinkit and Zomato: two datasets, one household
  • Three gaps the 2021 breach made visible
6 min read
CREDTeardown

CRED and the DPDP Act: What Happens When Your Business Model Is a Consent Transaction

  • Itemised or bundled: the §6 question
  • Withdrawal without detriment
5 min read
MobiKwikTeardown

MobiKwik's 8.2TB Breach and the DPDP Act's 72-Hour Clock

  • When does the 72-hour clock start? (Rule 7)
  • KYC data at the top of the harm scale (§8, Rule 6)
5 min read
boAtTeardown

boAt's Privacy Policy vs the DPDP Act: The Best Policy We've Read Still Has Two Gaps

  • No retention period (Rule 8)
  • English only (§5(3))
5 min read
BigBasketTeardown

BigBasket's 2020 Breach and the Household Profile Hiding in a Grocery Order

  • Retention without a purpose end-date (Rule 8)
  • No layered consent for inferred profiling (§6)
  • Breach timeline opacity (Rule 7)
5 min read
Domino's IndiaTeardown

Domino's India Delivered 180 Million Orders. It Also Delivered Them to a Dark-Web Marketplace.

  • Retention without a purpose ceiling (Rule 8)
  • No breach disclosure (Rule 7)
  • The GPS problem (§6)
5 min read

Start here

New to the DPDP Act? Read these in order and you will know what applies to you, and what you have to do about it.

Compliance Score

Reading about gaps is one thing. Knowing yours is another.

Run the same scan we use in these teardowns on your own website: privacy policy, cookie consent, and retention posture, scored against the DPDP Act in 60 seconds. No signup.

Run a free Compliance Score