How every rule maps to Vashix architecture. Designed for Indian enterprise from day one.
This page describes how Vashix architecture maps to DPDP Rules 2025. Full compliance alignment is in progress as regulations are finalized. Core security safeguards (encryption at rest and in transit) are live. India-only data residency is in progress.
| DPDP Rule | Requirement | How Vashix Addresses It |
|---|---|---|
| Rule 3 | Clear consent notice before data collection | SDK consent screen shown before every capture. Itemised list of data collected (GPS, timestamp, device ID, motion). Plain language. |
| Rule 6(1)(a) | Encryption of personal data | Encryption at rest and in transit. Hardware-bound private key never exported. |
| Rule 6(1)(b) | Access controls on computer resources | Role-based dashboard access. API key scoping. No adjuster can access another adjuster's captures. |
| Rule 6(1)(c) | Logs and monitoring for unauthorised access | Full audit log per capture. Every API call logged with timestamp, IP, and user. |
| Rule 6(1)(d) | Data backups for continued processing | Redundant cloud storage with availability targets per service plan. |
| Rule 6(1)(e) | Retain logs for minimum 1 year | Logs retained 1 year minimum. Configurable up to 7 years on Enterprise. |
| Rule 6(1)(f) | Contract must require security safeguards | Standard DPA included with all paid plans. |
| Rule 7 | Breach notification within 72 hours | Dashboard breach detection. Export-ready incident report for DPB notification. |
| Rule 13 | Data Principal rights (access + erasure) | Erasure request support via dashboard. Data export for access requests. |
| Rule 14 | Data must not leave India | Processing on secure cloud infrastructure. Migration to India-only data residency is in progress. |
Under the DPDP Rules 2025, Vashix acts as a Data Processor processing personal data strictly on the instructions of your organisation (the Data Fiduciary). We determine nothing about the purpose of processing — you do. This means your DPDP obligations are reduced when using Vashix versus building an in-house solution, where your team would assume full Fiduciary liability.
Read Rule 6(1)(f) — Processor Contract Requirements →Insurance companies face dual requirements: DPDP Rules 2025 AND IRDAI data governance guidelines. Vashix helps insurance companies meet photo documentation requirements. DPDP mandates that documentation be lawfully collected with consent, securely stored, and deletable on request. Vashix is architected for all three.
IRDAI Data Guidelines →Enterprise clients receive a custom DPA reviewed by our legal counsel. Contact hello@vashix.com
The Data Protection Board is operational as of November 2025. They have inquiry powers and can impose penalties immediately. The 2027 deadline is for full compliance — enforcement can begin now.