DPDPA looks different in Infocity than it does in the Rourkela-Angul-Paradip belt.

DRMLAW LLP has no office in Odisha — DPO-as-a-Service and gap-assessment engagements run remotely from our Kolkata offices, with on-site sessions arranged as needed. This page covers where DPDPA risk actually concentrates in Odisha: Bhubaneswar's Infocity IT/BPO corridor, the Rourkela-Angul-Paradip mining, steel and port belt, and state-government/PSU data processing.

FAQ

We're a mining or steel contractor near Rourkela, not an IT company — does DPDPA even apply to us?

Yes, if you process any digital personal data — most commonly this means workforce data (biometric attendance, PF/ESI, contractor rosters) rather than customer data. A short gap assessment usually settles the question quickly.

Our Infocity IT company already has GDPR/ISO 27001 certification — is that enough?

It covers much of the technical-safeguards work, but the DPDPA has India-specific obligations that don't map onto GDPR directly — the Section 5 notice format, consent-manager architecture, and Section 8(6) breach intimation specifically to India's Data Protection Board.

Do you have an Odisha office for DPO-as-a-Service engagements?

No — DRMLAW LLP's offices are in Kolkata and Bengaluru. DPO-as-a-Service and gap assessments for Odisha clients run remotely, with in-person sessions arranged at your site or ours as an engagement needs them.

Continue to the full page at https://www.drmlaw.in/technolegal/dpdpa/bhubaneswar