Most businesses meet this question in the same messy way: a customer’s procurement form asks for a SOC 2 report, a payment provider mentions PCI DSS, a European client sends a GDPR questionnaire, and somewhere underneath it all sits India’s DPDP Act with a 2027 deadline. It is genuinely hard to tell which of these you are legally required to follow, which are contractual, and which are simply things good vendors buy to win deals. This guide sorts them out: what each one is, who it actually binds, what it costs you in practice, and how they overlap.
All commencement dates, framework versions and compliance deadlines on this page are stated as of September 2026. Several of these frameworks are amended frequently; verify against the official texts linked at the bottom before relying on any date.
The Short Version
If you read nothing else, read this.
Think of it like the paperwork for a shop. Some of it is the law — the licence you must have, whether you like it or not. Some of it is a condition of doing business with someone — the mall won't give you a unit unless you follow their rules. And some of it is a certificate you put on the wall because customers trust it. All three are worth having. Only the first one gets you prosecuted.
- DPDP Act — the law on customer data. Applies to you. Obligations start 13 May 2027.
- IT Act / SPDI Rules — the older law on sensitive data. Applies to you today, until May 2027.
- CERT-In rules — if you are hacked, tell the government within six hours. Applies today.
- PCI DSS — only if card numbers pass through your own systems.
- GDPR — only if you have customers in Europe.
- HIPAA — only if you handle American patients' records for an American client.
- ISO 27001 / SOC 2 — nobody makes you. You buy them because customers ask.
Not sure which of those apply to you? The free DPDP checker asks a few questions about your business and tells you in about two minutes — no signup, no sales call.
Most small Indian businesses need the first three and nothing else. The rest arrive only when a particular customer, a card network, or a regulator brings them to your door. And here is the part that surprises people most: none of the certificates on that list make you DPDP compliant. You can hold every one of them and still be breaking Indian law, because not one of those audits ever looks at your signup form.
First, the Distinction That Explains Everything
Before comparing anything, separate the frameworks into three kinds. Almost every confusion in this area comes from treating them as interchangeable when they are not.
- Law. It binds you because a legislature said so. You cannot decline it, negotiate it, or satisfy it with a certificate. A regulator enforces it and the penalty is a statutory one. The DPDP Act is law. So is the IT Act.
- Contract. It binds you because you signed something, or because you joined a network whose rules you accepted. PCI DSS is the clearest example: no Indian statute mentions it, but every card network requires it, and your acquiring bank passes that requirement to you. A HIPAA Business Associate Agreement works the same way.
- Certification. Nobody makes you do it. You do it because customers ask, or because it shortens enterprise sales cycles. ISO 27001 and SOC 2 are here. They are evidence of good practice, not compliance with a privacy law.
The practical consequence: a certification can never discharge a legal obligation. An ISO 27001 certificate is a real asset in a procurement conversation and worth nothing as a defence before the Data Protection Board, because the Board will ask whether your consent notice met Section 5, and no ISO auditor ever looked at it.
- A Pune software company spends eight months and a large budget getting ISO 27001 certified because three enterprise customers asked for it. The certificate wins the deals. It does not change the fact that their signup form still collects phone numbers with a pre-ticked marketing box — which is a consent problem under Section 6, and the ISO auditor was never asked to look at it.
- A Coimbatore textile exporter is told by a European buyer to "be GDPR compliant." That instruction comes from a contract, not from Indian law. It is still binding — because losing the buyer is the penalty.
The Master Comparison
Every framework in this guide, side by side. Detail on each follows below.
| Framework | Kind | Origin | Who it binds | Covers | Enforcement / ceiling |
|---|---|---|---|---|---|
| DPDP Act 2023 | Law | India | Anyone processing digital personal data of people in India, wherever located | Personal data — consent, notice, rights, breach | Data Protection Board; up to ₹250 crore per violation category |
| IT Act 2000 + SPDI Rules 2011 | Law | India | Body corporates in India handling sensitive personal data | Sensitive personal data — security practices | Compensation under Section 43A; omitted 13 May 2027 |
| CERT-In Directions 2022 | Law | India | All service providers, intermediaries, data centres, body corporates | Cyber incident reporting and logging | Section 70B(7) IT Act — up to 1 year imprisonment or fine |
| GDPR | Law | EU / EEA | Anyone offering goods or services to, or monitoring, people in the EEA | Personal data — six lawful bases, rights, transfers | National DPAs; up to €20m or 4% of global turnover |
| HIPAA | Law (+ contract) | United States | US covered entities and their business associates | Protected health information | HHS Office for Civil Rights; tiered civil and criminal penalties |
| CCPA / CPRA | Law | California, USA | Businesses meeting revenue or data-volume thresholds serving Californians | Consumer personal information, sale and sharing | California Privacy Protection Agency; per-violation penalties |
| PCI DSS 4.0.1 | Contract | Card networks | Anyone storing, processing or transmitting cardholder data | Payment card data only | Acquiring bank; fines, higher fees, loss of card acceptance |
| ISO/IEC 27001 | Certification | International | Voluntary | Information security management system | Accredited certification body; loss of certificate |
| ISO/IEC 27701 | Certification | International | Voluntary | Privacy information management system | Accredited certification body; loss of certificate |
| SOC 2 | Attestation | United States | Voluntary | Controls against five trust services criteria | CPA firm opinion; a qualified report |
| RBI directions | Law | India | Banks, NBFCs, payment system operators, lending apps | Payment data localisation, IT governance, outsourcing | RBI; monetary penalties, business restrictions |
| SEBI CSCRF | Law | India | SEBI-regulated entities — brokers, AMCs, RTAs, exchanges | Cybersecurity and cyber resilience | SEBI; penalties and regulatory action |
The India Stack: What Is Actually Law Here
Start here, because this is the part that binds an Indian business whether or not it ever sells abroad.
The DPDP Act 2023 and the DPDP Rules 2025
India’s general personal data law. It applies to processing of digital personal data within India, and, under Section 3(b), to processing outside India connected with offering goods or services to people in India. There is no revenue floor, no user-count threshold, and no requirement that anyone pay you: a free signup form counts.
The obligations that matter for most businesses are notice before collection, consent that is free, specific, informed and unconditional, the ability to honour access and erasure requests, reasonable security safeguards, and breach intimation. The DPDP Rules 2025 (G.S.R. 846(E), notified 13 November 2025) supply the procedure, and the core obligations commence on 13 May 2027. Penalties run to ₹250 crore for the most serious category; see the penalties guide for how the categories divide.
If you are unsure whether it reaches you at all, the short answer is that it almost certainly does; our guide on whether DPDP applies to your business works through the edge cases.
- A sweet shop in Madurai that takes a name and phone number for Diwali order reminders. That is digital personal data. The Act applies.
- A gym in Noida holding member names, photographs and payment history on a laptop.
- A two-person Instagram clothing business collecting addresses over DMs. There is no size below which the Act stops applying — no revenue floor, no customer-count floor.
If that describes you, the 14-step DPDP compliance checklist is the practical version of this — what to do, in order, with a free one-page PDF you can work through.
The IT Act 2000 and the SPDI Rules 2011
This is the framework that governs Indian businesses today, and it is the one most often assumed to be already dead. It is not. Section 43A of the Information Technology Act 2000, together with the Reasonable Security Practices and Procedures and Sensitive Personal Data or Information Rules 2011, requires a body corporate handling sensitive personal data (passwords, financial information, health data, biometrics, sexual orientation) to maintain reasonable security practices, and makes it liable to pay compensation for negligence that causes wrongful loss.
Section 44(2) of the DPDP Act omits Section 43A and the SPDI Rules, and that omission takes effect on 13 May 2027, the same day the core DPDP obligations commence. Until then both frameworks coexist, and the SPDI Rules remain enforceable. One practical difference worth noting: the SPDI Rules do define a category of “sensitive” personal data with stricter handling. The DPDP Act does not. It treats all personal data under one standard, with the government empowered to notify stricter treatment later.
- A diagnostic lab in Hyderabad storing test reports is holding health data — sensitive under the 2011 Rules. If those reports leak because nobody patched a server, the lab can be made to compensate the affected patients today. It does not have to wait for 2027.
- The common mistake is reading "DPDP starts in 2027" as "nothing applies until 2027." The older law has been in force since 2011 and stays in force until the day DPDP takes over.
The CERT-In Directions, April 2022
Widely under-observed, and the shortest deadline in Indian compliance. Issued on 28 April 2022 under Section 70B(6) of the IT Act, these directions require every service provider, intermediary, data centre and body corporate to:
- report listed cyber incidents to CERT-In within six hours of noticing them;
- retain ICT system logs for 180 days, stored within India;
- synchronise system clocks to the NIC or NPL network time servers;
- maintain designated points of contact for CERT-In.
Note how this interacts with DPDP. The statutory duty to report a personal data breach sits in Section 8(6) of the Act; Rule 7 of the DPDP Rules 2025 supplies the procedure — tell affected individuals without delay, give the Board an initial intimation without delay, then detailed particulars within 72 hours. A breach at an Indian company can therefore trigger both a six-hour CERT-In report and, from May 2027, the Section 8(6) and Rule 7 obligations. They are separate filings to separate authorities on separate clocks. Our breach notification guide covers the DPDP side in detail.
- A Chennai e-commerce firm discovers at 11pm on Saturday that its customer database was copied. The CERT-In clock starts at 11pm — not Monday morning when the founder reads the email. Six hours later it is 5am Sunday, and the report is already late.
- This is why the useful preparation is not a policy document. It is knowing, before anything happens, who writes the report and what their login is. Most businesses fail this one on logistics, not on intent.
Sector regulators: RBI, SEBI, IRDAI
If you are regulated, your regulator’s rules sit on top of everything above and are usually stricter.
RBI. The April 2018 circular on Storage of Payment System Data requires payment system operators to store end-to-end transaction data only in India. This is unaffected by the DPDP Act’s comparatively permissive approach to cross-border transfers, because Section 16(2) expressly preserves stricter sectoral requirements. RBI also runs separate directions on IT governance, outsourcing of IT services, and digital lending.
SEBI. The Cybersecurity and Cyber Resilience Framework (CSCRF) consolidated SEBI’s earlier cyber circulars into one graded framework for regulated entities, with compliance dates through 2025 that were extended more than once by category of entity. It brings structured audit reporting and mandatory security operations arrangements.
IRDAI. Insurers and intermediaries follow IRDAI’s information and cyber security guidelines, including audit and reporting obligations.
- A payments startup reads that DPDP allows data to leave India and concludes it can move transaction records to a cheaper server abroad. It cannot. RBI's 2018 circular requires end-to-end payment data to stay in India, and Section 16(2) of the DPDP Act expressly leaves that requirement standing.
- The general rule: where two rulebooks cover the same data, you follow the tighter one. A permissive national law never overrides a strict sectoral one.
The Global Privacy Laws
GDPR — the European baseline
The most influential privacy law in the world, and the one the DPDP Act is most often measured against. It applies if you are established in the EEA, or if you offer goods or services to people there, or if you monitor their behaviour.
Two differences matter most to an Indian business. First, lawful basis: the GDPR offers six, and legitimate interests carries a great deal of ordinary marketing and analytics. The DPDP Act offers consent plus a narrow list of legitimate uses in Section 7, with no general legitimate-interests basis, so a European programme does not port over unchanged. Second, penalty structure: GDPR fines scale to 4% of global turnover, while DPDP penalties are fixed rupee ceilings that fall much harder on a small company in relative terms. The full DPDP vs GDPR comparison works through all eight material differences.
- A Jaipur handicrafts exporter sells to customers in Germany through its own website. GDPR applies — not because the company is European, but because the customers are.
- A Bengaluru SaaS company copies its European privacy policy into its Indian product and assumes it is covered. It is not. The European version leans on "legitimate interests" for marketing emails; that basis does not exist under the DPDP Act, so those emails need consent in India.
HIPAA — United States health data
HIPAA is narrow and frequently misunderstood in India. It is US federal law covering protected health information held by covered entities (US health plans, health care clearinghouses, and providers who transmit health information electronically for billing) and by the business associates who process that information for them.
An Indian hospital treating Indian patients is not a HIPAA covered entity. What brings HIPAA to India is service work for US healthcare: medical transcription, revenue-cycle management, coding, teleradiology, clinical SaaS. In those cases the obligation reaches you through a Business Associate Agreement, which is a contract. Since the HITECH Act, business associates also face direct statutory liability. Its Security Rule requires administrative, physical and technical safeguards; its Breach Notification Rule sets a 60-day outer limit for notifying affected individuals, which is a far longer clock than either CERT-In or DPDP.
Indian healthcare providers are instead governed by the DPDP Act, the IT Act and SPDI Rules, and clinical record-keeping requirements under National Medical Commission regulations. Our healthcare DPDP guide covers what an Indian clinic or hospital actually needs.
- A children's clinic in Kochi treating local families: HIPAA does not apply. Indian law does.
- A Kochi company doing medical transcription for a hospital in Texas: HIPAA does apply, through the Business Associate Agreement it signed. The work is identical in character; the customer is what changes the answer.
- Vendors selling "HIPAA compliance" to Indian hospitals with no American clients are selling something that hospital does not need.
CCPA and CPRA — California
California’s consumer privacy law, amended by the CPRA, applies to for-profit businesses that serve California residents and cross one of its thresholds: broadly, large annual revenue, large-scale handling of consumer personal information, or deriving substantial revenue from selling or sharing it. Its distinctive feature is the right to opt out of the sale or sharing of personal information, which is why “Do Not Sell or Share My Personal Information” links appear on US sites. It is an opt-out regime by default, where the DPDP Act and the GDPR are opt-in. Several other US states now run comparable laws.
- Under Indian and European law, silence means no. You must ask first.
- Under California's law, the default runs the other way for sale and sharing: you may proceed until the customer tells you to stop, which is why American websites carry a "Do Not Sell" link and Indian ones do not.
- Practical effect for an Indian company: the thresholds are high enough that most SMBs never reach them. Do not build for CCPA until a Californian customer base actually exists.
COPPA — American children's data
Worth knowing if you build anything used by children. COPPA is US federal law regulating online services directed at children under 13, or general services that knowingly collect data from them. It requires verifiable parental consent before collection, enforced by the Federal Trade Commission.
Note the mismatch with India: the DPDP Act treats everyone under 18 as a child, and prohibits behavioural tracking and targeted advertising at them outright. So an Indian ed-tech company serving both markets is running two different age lines at once — 13 for its American users, 18 for its Indian ones — and the Indian rule is the stricter of the two.
- A Hyderabad ed-tech app with students in both India and the United States cannot pick one age threshold. It needs parental consent for a 15-year-old in Chennai (Indian law) but not for the same-aged student in Chicago (American law) — while a 12-year-old triggers both.
- A coaching centre in Kota with only Indian students ignores COPPA entirely and applies the under-18 rule.
The Security Frameworks
PCI DSS — payment cards
PCI DSS is not a law anywhere. It is the Payment Card Industry Data Security Standard, maintained by the PCI Security Standards Council on behalf of the card networks, and it reaches you through your acquiring bank or payment provider. If you store, process or transmit cardholder data, it applies in India exactly as it does in the United States.
The current version is 4.0.1, published June 2024; the future-dated requirements introduced in v4.0 became mandatory on 31 March 2025. Its twelve requirement areas are concrete and technical: network segmentation, no vendor-default passwords, encryption of cardholder data in transit and at rest, vulnerability management, access control, logging, testing, and a security policy.
Scope is the whole game here. If your checkout hands the customer to a gateway’s hosted page or iframe and card numbers never touch your systems, your obligations shrink to the lightest self-assessment questionnaire, mostly confirming that your provider is compliant and that card numbers never leak into your logs, emails or support tickets. If your own page collects the card number first, you are in scope properly. Note also that PCI DSS says nothing about consent, notice or erasure. It secures card data; it does not make you DPDP compliant.
- Does a card number ever touch something you own — a server, a spreadsheet, a WhatsApp message, a support ticket?
- A Delhi boutique whose website sends customers to Razorpay's own payment page: card numbers never reach them, so their obligations are minimal.
- A travel agency that takes card details over the phone and writes them on a booking form: fully in scope, and almost certainly unaware of it. A card number in a WhatsApp thread or a paper register is the most common breach of this standard among small Indian businesses.
ISO/IEC 27001 and ISO/IEC 27701
ISO/IEC 27001 is the international standard for an information security management system. You are certified by an accredited body after an audit, in a three-year cycle with annual surveillance. It is a management-system standard rather than a control checklist: it asks whether you have identified your risks, chosen controls deliberately, assigned ownership, and review the whole thing on a schedule.
ISO/IEC 27701 is the privacy counterpart. This one has changed materially and it is worth being current: the 2019 edition was an extension you could only apply on top of ISO 27001, and it has been withdrawn. The 2025 edition is a standalone standard. You can now certify a privacy information management system without holding ISO 27001 first, and it adds modern guidance on cloud, AI-related processing, biometrics and health data.
For an Indian business preparing for DPDP, ISO 27701 is the closest available certification to the Act’s subject matter, and its control set maps well onto DPDP’s security and governance obligations. It still does not certify DPDP compliance, and nothing does, because the Act creates no certification scheme.
- No such thing as a "DPDP certificate" exists. The Act creates no certification scheme and appoints no certifying bodies. Anyone selling you one is selling their own opinion.
- What ISO 27001 genuinely buys you is a shorter enterprise sales cycle and a documented answer when a regulator asks whether you took reasonable security measures. Those are real benefits. Neither is the same as compliance.
SOC 2
Not a certification and not a law: a SOC 2 report is an attestation written by a CPA firm under AICPA standards, describing your controls against the trust services criteria: security, and optionally availability, processing integrity, confidentiality and privacy. A Type I report tests design at a point in time; a Type II tests operating effectiveness across a period, typically three to twelve months, and is the one enterprise buyers actually want.
SOC 2 is prevalent in Indian SaaS because US buyers ask for it. It is the fastest way to satisfy enterprise procurement and, unlike ISO, produces a detailed report rather than a certificate, which is why it is shared under NDA rather than displayed on a website.
- A Bengaluru SaaS company loses two deals because procurement asked for a SOC 2 report and it had none. That is the signal to start — a real cost you can point at.
- A company with no enterprise customers buying SOC 2 "to look serious" has bought an expensive document nobody has asked to read. It is a sales tool. Buy it when sales need it.
Where They Overlap, and Where They Do Not
The good news for anyone facing several of these at once: the operational core is shared. Build it once and it serves nearly everything.
| Control | DPDP | GDPR | HIPAA | PCI DSS | ISO 27001 | SOC 2 |
|---|---|---|---|---|---|---|
| Data inventory / mapping | Needed in practice | Required (Art. 30) | Required | Required (scoping) | Required | Required |
| Access control | Rule 6 | Art. 32 | Security Rule | Req. 7–8 | Annex A | Security criteria |
| Encryption | Rule 6 | Art. 32 | Addressable | Req. 3–4 | Annex A | Security criteria |
| Logging and monitoring | Rule 6 | Art. 32 | Required | Req. 10 | Annex A | Security criteria |
| Vendor / processor contracts | Section 8(2) | Art. 28 | BAA | Req. 12 | Annex A | Required |
| Breach notification | Rule 7 | 72 hours | 60 days | To acquirer | Process only | Process only |
| Consent before collection | Core | One of six bases | Not the model | No | No | No |
| Notice in local languages | Section 5(3) | Plain language | Notice of practices | No | No | No |
| Erasure on withdrawal | Section 12(3) | Art. 17 | Limited | No | No | No |
That middle row — notice in the individual's chosen language — is the one businesses most often discover late. Section 5(3) gives every customer the option of English or any of the 22 Eighth Schedule languages, and no ISO or SOC 2 audit will ever mention it. Our free consent notice generator writes one for your business in 23 languages; it runs entirely in your browser, so nothing you type is sent to us.
Read the bottom three rows carefully, because they are the reason a security certificate does not carry you. Consent before collection, notice in the individual’s chosen language, and erasure on withdrawal are the heart of the DPDP Act, and no security framework on this page asks for any of them. A company with ISO 27001, SOC 2 Type II and PCI DSS in hand can still be squarely non-compliant with the DPDP Act on 13 May 2027, because none of those audits ever looked at its signup form.
The breach row deserves the same attention, because the clocks do not agree with each other. One incident can start several at once, and they run at different speeds.
- An Indian company with American healthcare clients discovers a breach on Friday evening. CERT-In wants a report in six hours. From May 2027, the Board wants an initial intimation without delay and full particulars within 72 hours. HIPAA gives its 60-day outer limit for notifying affected individuals.
- The dangerous instinct is to wait for the investigation to finish and then notify everyone at once. That comfortably meets the 60-day rule and badly misses the six-hour one.
- The fix is to separate the two jobs: report early on what you know, keep investigating afterwards. You are not expected to have all the answers within six hours — you are expected to have told them.
So Which Ones Apply to You?
Work down this list. Each answer is independent of the others.
| If this is true of you | You need |
|---|---|
| You collect any personal data from people in India | DPDP Act; IT Act and SPDI Rules until 13 May 2027 |
| You run any ICT system in India | CERT-In directions — 6-hour reporting, 180-day logs |
| Your own systems touch card numbers | PCI DSS |
| You have customers in the EU or EEA | GDPR |
| You process US patient data for a US healthcare client | HIPAA, through a Business Associate Agreement |
| You serve California residents above the thresholds | CCPA / CPRA |
| You are an RBI, SEBI or IRDAI regulated entity | Your regulator’s framework, on top of everything else |
| Enterprise buyers keep asking for proof | SOC 2 Type II, or ISO 27001 — optional, commercially useful |
| You want a privacy-specific certificate | ISO/IEC 27701:2025 — optional |
For most Indian SMBs the honest answer is short: the DPDP Act, the SPDI Rules until 2027, and the CERT-In directions. Everything else arrives only if a customer, a card network or a regulator brings it.
If you sell software across borders and the question is the other way round — which of the world's privacy regimes your product triggers — our companion guide comparing global data privacy laws: GDPR, DPDP, CCPA, LGPD, PIPL and the rest puts twelve of them side by side, with the consent defaults, breach clocks and transfer rules that differ between them.
A Sensible Order of Work
If several of these apply, do not run them as separate projects. They share too much.
- Know what you hold. One inventory of personal data: what you collect, why, where it lives, who you share it with, how long you keep it. Every framework here starts from this, and doing it once serves all of them.
- Satisfy Indian law first. It is the one you cannot decline. Notice and consent for DPDP — the consent notice generator gives you the notice itself — security practices for the SPDI Rules, and a CERT-In reporting process with someone named to run it.
- Add contractual obligations as they arrive. PCI DSS when card data enters your systems; a BAA when a US healthcare client signs; GDPR work when European customers do.
- Buy certification when it is being asked for. SOC 2 or ISO 27001 when procurement forms start blocking deals. Not before, and never as a substitute for step two.
- A 20-person Shopify seller in Surat: write down what customer data you hold and why, fix the signup consent, publish a way for customers to ask for their data or its deletion, and name the person who reports a breach. That is the whole job. No certificate, no consultant, no ISO audit.
- The same business three years later, selling to a European retailer and taking card payments on its own checkout: now add GDPR and PCI DSS, because the customer and the payment flow changed. Not before.
Three Free Tools to Start With
All three are free, need no signup, and are built for the step they name.
- DPDP checker — answer a few questions, get the list of obligations that actually apply to your business. About two minutes.
- 14-step compliance checklist — the work itself, in order, with a one-page PDF to keep.
- Consent notice generator — a DPDP consent notice for your business in any of 23 languages, generated in your browser.
References & Sources
- India Code — Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023), official consolidated text (Sections 3, 5, 7, 8, 12, 16, 44).
- Ministry of Electronics & IT — Data Protection Framework, including the Digital Personal Data Protection Rules 2025 (G.S.R. 846(E), notified 13 November 2025).
- Ministry of Electronics & IT — Information Technology Act, 2000 and the Reasonable Security Practices and Procedures and Sensitive Personal Data or Information Rules, 2011.
- CERT-In — Directions under Section 70B(6) of the IT Act, 2000, dated 28 April 2022 (six-hour incident reporting, 180-day log retention, NTP synchronisation).
- Reserve Bank of India — Storage of Payment System Data, circular DPSS.CO.OD No. 2785/06.08.005/2017-2018, 6 April 2018.
- Securities and Exchange Board of India — Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities, and subsequent circulars extending compliance timelines.
- European Union — Regulation (EU) 2016/679 (General Data Protection Regulation), official text (Articles 3, 6, 17, 28, 30, 32, 83).
- U.S. Department of Health & Human Services — HIPAA for Professionals, covering the Privacy, Security and Breach Notification Rules and business associate obligations.
- California Privacy Protection Agency — California Consumer Privacy Act regulations, as amended by the CPRA.
- PCI Security Standards Council — PCI DSS v4.0.1 (June 2024) and guidance confirming the 31 March 2025 effective date for future-dated requirements.
- ISO — ISO/IEC 27001 Information security management systems.
- ISO — ISO/IEC 27701:2025 Privacy information management systems, the standalone second edition superseding ISO/IEC 27701:2019.
- AICPA — SOC 2 and the Trust Services Criteria.
This article is general information comparing Indian and international data protection, security and compliance frameworks. It is not legal advice, and it is not a substitute for advice on your own circumstances. Several frameworks named here are amended frequently and some obligations commence on future dates; verify against the current official texts, and consult a qualified professional before relying on any of it.