Privacy education, consultancy & implementation, in 50+ jurisdictions.contact@vedhacon.com
Featured jurisdictionIndia, DPDP Act 2023

Notice, consent, Data Fiduciary duties, SDF obligations and breach intimation, explained.

Open the guide
Where most engagements startA readiness assessment, then a plan

We scope against the laws that actually apply to you, then sequence the work by risk.

Start the assessment
Featured whitepaperThe DPDP implementation clock

What must be operational before the substantive obligations commence in 2027.

Read the briefing
Free, no sign-upCheck your readiness in 10 minutes

Answer 18 questions and get a prioritised control roadmap instantly.

Start the assessment
Free, alwaysZero to practitioner

Track 01 assumes no prior knowledge of governance, risk and compliance.

Start Track 01
China · PIPL, DSL & CSL

China's data regime, mapped for outbound business.

China's data laws work as a stack: the Personal Information Protection Law (PIPL) governs personal information, the Data Security Law (DSL) classifies data, and the Cybersecurity Law (CSL) underpins security and localisation. Together they shape consent, classification and cross-border transfer.

Three laws, one regime

How the stack fits together

PIPL

The Personal Information Protection Law, China's comprehensive personal information statute, close in ambition to the GDPR.

DSL

The Data Security Law classifies data by importance and imposes graded security and handling duties.

CSL

The Cybersecurity Law underpins network security, critical information infrastructure and localisation.