Overview
India's data protection law is no longer a draft. The Digital Personal Data Protection Act, 2023 has been brought into force in phases: the Data Protection Board from November 2025, consent-manager provisions from 14 November 2026, and every remaining obligation on data fiduciaries from 13 May 2027. Penalties run to ₹250 crore per contravention.
Most organisations in Lucknow that hold personal data, from hospitals and coaching institutes to e-commerce sellers and housing societies, have never mapped what they collect or why. Our data-protection practice does that mapping and builds the documents and habits the law expects, in proportion to the size of the organisation.
How We Work With Data Privacy Clients
We begin with a gap assessment: what personal data you collect, on what basis, where it sits, who processes it for you and how long it stays. From that we produce a short, prioritised roadmap rather than a hundred-page report, and we draft the artefacts that matter first: the notice, the consent mechanism, the processor agreements, the breach procedure and the record of processing.
For sectors with specific exposure, such as healthcare, education and financial services, we layer the sector rules on top and train the people who actually handle the data. Where a matter becomes contentious, we represent you before the Data Protection Board and the courts.
Core Data Privacy Services
DPDP readiness assessment
Data mapping, gap analysis and a prioritised roadmap against the Act and the 2025 Rules.
Privacy notices & consent
Plain-language notices, consent flows, withdrawal mechanisms and verifiable parental consent for children's data.
Data processing agreements
Contracts with vendors, cloud providers and processors that allocate DPDP obligations correctly.
Breach response
Incident playbooks, intimation to the Board and affected persons within the prescribed timelines, and post-incident review.
Sector playbooks
Hospitals and clinics, schools and coaching institutes, e-commerce and fintech: the specific obligations, drafted for each.
Cross-border transfers
Advice on transfers, restricted countries and contractual safeguards for group companies and SaaS vendors.
Training & awareness
Short sessions for management and front-line staff on what the law requires of them day to day.
Representation
Before the Data Protection Board, in appeals and in related consumer and IT Act proceedings.
Who We Help
Hospitals, diagnostic labs and clinics
Schools, universities and coaching institutes
E-commerce sellers, D2C brands and marketplaces
NBFCs, fintech and lending apps
Housing societies, clubs and membership bodies
Why Choose Sarvā Nyāy For Data Protection & DPDP Compliance
Research depth.
Our founder's doctoral research is on data protection and its ethical dimensions; the practice is built on that foundation.
Proportionate advice.
A twenty-person clinic does not need an enterprise programme. We size the work to the risk.
Litigation-ready documents.
Every notice and contract is drafted with the possibility that a Board or a court will one day read it.
Testimonial
“We were sent a two-page roadmap, not a policy manual. The notice went live on our website in a week and the staff session took an afternoon.”
When To Call Sarvā Nyāy
If your organisation collects personal data from patients, students, customers or members, the 14 November 2026 and 13 May 2027 deadlines apply to you. An initial assessment tells you how far you are from compliance and what to do first.
Response within 24 hours · Advocate-client confidentiality · Mon – Sat, 10:00 – 19:00 IST

