Getting StartedRegulations

Regulations

Data subject rights, breach notification windows, and consent requirements under DPDPA, GDPR, and CCPA/CPRA, mapped to the Neostra modules that address them.

Neostra is designed to support any data protection regulation. Requests, consent, assessments, breach handling, and notices are all configured against a regulation library rather than hard-coded to a single law, so the same platform serves organisations operating under one regime or many.

Regulation library

Neostra ships with a library of privacy laws ready to use, including the EU GDPR, UK GDPR, India's DPDP Act, the CCPA/CPRA and other US state privacy laws, Brazil's LGPD, Canada's PIPEDA, and laws across Asia Pacific, the Middle East, and Africa. Each regulation records its jurisdictions, whether the Global Privacy Control signal applies, and its breach notification window. Most customers do not need to create regulations at all. If your organisation is subject to a law that is not in the library, or you want to track an internal policy in the same way, you can add it under Settings > Regulations and it becomes available across the modules immediately.

The rest of this page summarises the obligations Neostra helps you meet under the three regulations most customers start with, and shows where each is addressed in the platform. It is a working reference, not legal advice. Confirm requirements with your legal counsel.

Data subject rights

The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 use the terms Data Principal (the individual) and Data Fiduciary (the organization deciding purpose and means).

RightWhere it comes fromWhat it means
Access to informationSection 11A summary of the personal data processed, the processing activities, and the other fiduciaries and processors it was shared with.
Correction, completion, updating, and erasureSection 12Correct inaccurate or misleading data, complete or update it, and erase it when no longer needed for the purpose, unless retention is required by law.
Grievance redressalSection 13A readily available means to raise a grievance with the fiduciary before approaching the Data Protection Board.
NominationSection 14Nominate another person to exercise these rights in the event of death or incapacity.
Withdraw consentSection 6(4) to 6(6)Withdraw consent at any time, with the ease comparable to giving it.

The DPDP Rules, 2025 set the time to respond to a rights request at up to 90 days.

Breach notification windows

RegulationNotify the authorityNotify affected individuals
DPDPA 2023 and DPDP Rules 2025Inform the Data Protection Board without delay on becoming aware of a breach, and provide the detailed information within 72 hours, or a longer period the Board allows on request.Inform each affected Data Principal without delay, in plain language, with the nature and consequences of the breach, the measures taken, and safety measures they can take.
GDPR (EU and UK)Notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to individuals (Article 33).Notify data subjects without undue delay when the breach is likely to result in a high risk to their rights and freedoms (Article 34).
CCPA/CPRA (California)The CCPA does not itself set a regulator notification deadline. California's separate breach statute requires notice to the Attorney General when a single breach affects more than 500 California residents.Notify affected California residents in the most expedient time possible and without unreasonable delay under California's breach notification statute. The CCPA adds a private right of action for breaches caused by a failure to maintain reasonable security.

How Neostra applies notification windows

Every regulation in Settings > Regulations has a breach notification window in hours. When you record an incident in Breach Management and select the regulations that apply, Neostra sets a notification deadline for each one by adding that window to the time the incident was created. The Incidents list and the incident detail page show the deadline so you can see the clock for each regulator.

The regulation list ships with 72 hours for GDPR, UK GDPR, DPDP (India), CCPA/CPRA, and all other regulations except PIPA (South Korea), which is seeded at 24 hours. You can change any window for your tenant, and regulations you create use the platform default of 72 hours unless you set another value.

The seeded windows are starting points. Some laws set the clock from a different moment, use different thresholds, or expect an initial notice sooner than the detailed report. Set the value your legal team wants for each regulation.

Consent must be free, specific, informed, unconditional, and unambiguous, given by a clear affirmative action, and limited to the personal data necessary for the specified purpose (Section 6). Every request for consent must be accompanied by, or preceded by, a notice describing the personal data, the purpose, how to exercise rights, and how to complain to the Board (Section 5). The Data Principal can withdraw consent as easily as it was given, and withdrawal stops processing based on that consent. Processing a child's data (under 18) requires verifiable parental consent, and tracking, behavioral monitoring, and targeted advertising directed at children are prohibited (Section 9). The Data Fiduciary must be able to prove that notice was given and consent obtained.

Obligations mapped to Neostra modules

ObligationRegulationsNeostra module and feature
Receive rights requests through a public channelDPDPA s.11 to 14, GDPR Art. 12, CCPAPrivacy Rights Manager: published intake forms, the Integration API, and the data subject portal
Verify the identity of the requesterGDPR Art. 12(6), CCPA verification rules, DPDP RulesPrivacy Rights Manager: email verification with a configurable timeout, optional affidavit and captcha
Route, fulfil, and respond within the statutory timeDPDPA (90 days), GDPR (1 month), CCPA (45 days)Privacy Rights Manager: workflows, tasks, request queue, response templates, deadline extension on tasks
Let the data subject track and receive the responseGDPR Art. 12, CCPAPrivacy Rights Manager: request portal with email plus request ID sign in and a one time access code
Collect valid consent and honor withdrawalDPDPA s.6, GDPR Art. 7, ePrivacyConsent Management: collection points, banners, cookie categories and cookies, purposes, preference centers
Honor opt-out and Global Privacy Control signalsCCPA/CPRA and other US state lawsConsent Management: the consent modal captures the browser GPC signal; regulations flag whether GPC applies
Keep evidence of notice and consentDPDPA s.6, GDPR Art. 7(1)Consent Management: Consent Records, Receipts, Data Subjects
Publish notices and a privacy centerDPDPA s.5, GDPR Art. 13 and 14, CCPA notice at collectionPrivacy Center: privacy center builder, privacy notice pages, translations, published versions
Maintain a record of processing activitiesGDPR Art. 30, implied by DPDPAData Inventory: data systems, processing activities, vendors, RoPA Reports
Register purposes for personal dataDPDPA s.5 and s.6Data Inventory: DPDPA Purpose Registry
Know where personal data is storedAllData Inventory: scheduled scanning of databases and object storage, data flow, inventory
Assess readiness and run impact assessmentsDPDPA s.10 (Significant Data Fiduciaries), GDPR Art. 35Governance: DPDP Readiness Assessment in the Scanner; Assessments: DPIA (GDPR), DPIA (DPDPA), and RoPA templates
Detect, assess, and notify breaches on timeDPDPA s.8(6) and Rule 7, GDPR Art. 33 and 34, California breach statuteBreach Management: breach intake forms, breach types, breach workflows, tasks, per regulation notification deadlines
Restrict access by role and brandAll (security and accountability)Settings: Users, Groups, Brands, roles, tenant level two-factor authentication
Serve users and data subjects in their languageDPDPA s.5(3) (English or any language in the Eighth Schedule), GDPR Art. 12(1) (clear and plain language)Settings > Tenant Active Languages; translations on forms, banners, and privacy centers

Configurable timelines

Neostra does not hard code statutory deadlines. The following are set per tenant:

  • Breach notification window per regulation, in hours, under Settings > Regulations.
  • Intake form email verification timeout, per form, with a minimum of 30 minutes.
  • Workflow stages, tasks, and assignees per workflow, including deadline extension on individual tasks.
  • Request types and their translations under Privacy Rights Manager > Request Types.

The retention period for request and consent data is shown under Settings > Tenant.

Where a law sets a fixed period, configure the matching value in Neostra and review it when the law or its rules change.