Regulations
Data subject rights, breach notification windows, and consent requirements under DPDPA, GDPR, and CCPA/CPRA, mapped to the Neostra modules that address them.
Neostra is designed to support any data protection regulation. Requests, consent, assessments, breach handling, and notices are all configured against a regulation library rather than hard-coded to a single law, so the same platform serves organisations operating under one regime or many.
Regulation library
Neostra ships with a library of privacy laws ready to use, including the EU GDPR, UK GDPR, India's DPDP Act, the CCPA/CPRA and other US state privacy laws, Brazil's LGPD, Canada's PIPEDA, and laws across Asia Pacific, the Middle East, and Africa. Each regulation records its jurisdictions, whether the Global Privacy Control signal applies, and its breach notification window. Most customers do not need to create regulations at all. If your organisation is subject to a law that is not in the library, or you want to track an internal policy in the same way, you can add it under Settings > Regulations and it becomes available across the modules immediately.
The rest of this page summarises the obligations Neostra helps you meet under the three regulations most customers start with, and shows where each is addressed in the platform. It is a working reference, not legal advice. Confirm requirements with your legal counsel.
Data subject rights
The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 use the terms Data Principal (the individual) and Data Fiduciary (the organization deciding purpose and means).
| Right | Where it comes from | What it means |
|---|---|---|
| Access to information | Section 11 | A summary of the personal data processed, the processing activities, and the other fiduciaries and processors it was shared with. |
| Correction, completion, updating, and erasure | Section 12 | Correct inaccurate or misleading data, complete or update it, and erase it when no longer needed for the purpose, unless retention is required by law. |
| Grievance redressal | Section 13 | A readily available means to raise a grievance with the fiduciary before approaching the Data Protection Board. |
| Nomination | Section 14 | Nominate another person to exercise these rights in the event of death or incapacity. |
| Withdraw consent | Section 6(4) to 6(6) | Withdraw consent at any time, with the ease comparable to giving it. |
The DPDP Rules, 2025 set the time to respond to a rights request at up to 90 days.
The EU GDPR and UK GDPR give data subjects the same core set of rights.
| Right | Article |
|---|---|
| Information | 13 and 14 |
| Access | 15 |
| Rectification | 16 |
| Erasure | 17 |
| Restriction of processing | 18 |
| Data portability | 20 |
| Object | 21 |
| Not to be subject to solely automated decisions | 22 |
You must respond without undue delay and within one month, extendable by two further months for complex or numerous requests (Article 12(3)).
The California Consumer Privacy Act as amended by the California Privacy Rights Act grants consumers these rights.
| Right | What it means |
|---|---|
| Know and access | Categories and specific pieces of personal information collected, sources, purposes, and third parties it was disclosed to. |
| Delete | Deletion of personal information collected from the consumer, subject to exceptions. |
| Correct | Correction of inaccurate personal information. |
| Opt out of sale or sharing | Stop the sale of personal information and its sharing for cross-context behavioral advertising. Businesses must honor opt-out preference signals such as Global Privacy Control. |
| Limit use of sensitive personal information | Restrict use and disclosure of sensitive personal information to what is necessary. |
| Non-discrimination | No retaliation for exercising rights. |
Businesses respond to know, delete, and correct requests within 45 days, extendable once by a further 45 days. Opt-out requests must be honored within 15 business days. Consumers under 16 must opt in before their personal information is sold or shared.
Breach notification windows
| Regulation | Notify the authority | Notify affected individuals |
|---|---|---|
| DPDPA 2023 and DPDP Rules 2025 | Inform the Data Protection Board without delay on becoming aware of a breach, and provide the detailed information within 72 hours, or a longer period the Board allows on request. | Inform each affected Data Principal without delay, in plain language, with the nature and consequences of the breach, the measures taken, and safety measures they can take. |
| GDPR (EU and UK) | Notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to individuals (Article 33). | Notify data subjects without undue delay when the breach is likely to result in a high risk to their rights and freedoms (Article 34). |
| CCPA/CPRA (California) | The CCPA does not itself set a regulator notification deadline. California's separate breach statute requires notice to the Attorney General when a single breach affects more than 500 California residents. | Notify affected California residents in the most expedient time possible and without unreasonable delay under California's breach notification statute. The CCPA adds a private right of action for breaches caused by a failure to maintain reasonable security. |
How Neostra applies notification windows
Every regulation in Settings > Regulations has a breach notification window in hours. When you record an incident in Breach Management and select the regulations that apply, Neostra sets a notification deadline for each one by adding that window to the time the incident was created. The Incidents list and the incident detail page show the deadline so you can see the clock for each regulator.
The regulation list ships with 72 hours for GDPR, UK GDPR, DPDP (India), CCPA/CPRA, and all other regulations except PIPA (South Korea), which is seeded at 24 hours. You can change any window for your tenant, and regulations you create use the platform default of 72 hours unless you set another value.
The seeded windows are starting points. Some laws set the clock from a different moment, use different thresholds, or expect an initial notice sooner than the detailed report. Set the value your legal team wants for each regulation.
Consent requirements
Consent must be free, specific, informed, unconditional, and unambiguous, given by a clear affirmative action, and limited to the personal data necessary for the specified purpose (Section 6). Every request for consent must be accompanied by, or preceded by, a notice describing the personal data, the purpose, how to exercise rights, and how to complain to the Board (Section 5). The Data Principal can withdraw consent as easily as it was given, and withdrawal stops processing based on that consent. Processing a child's data (under 18) requires verifiable parental consent, and tracking, behavioral monitoring, and targeted advertising directed at children are prohibited (Section 9). The Data Fiduciary must be able to prove that notice was given and consent obtained.
Consent is one of six lawful bases and must be freely given, specific, informed, and unambiguous, given by a statement or clear affirmative action (Articles 4(11) and 7). Pre-ticked boxes and inactivity do not count. Consent must be as easy to withdraw as to give, and the controller must be able to demonstrate it was obtained. Explicit consent is required for special category data (Article 9). Storing or reading cookies and similar identifiers on a user's device requires consent under the ePrivacy rules in each member state and in the UK, except where strictly necessary for the service the user requested. Children below the digital consent age (16 by default, member states may set 13 to 16) need parental consent for online services.
California uses an opt-out model for adults. Businesses that sell or share personal information must offer a clear Do Not Sell or Share My Personal Information mechanism, honor browser opt-out preference signals such as Global Privacy Control, and give consumers a way to limit use of sensitive personal information. Opt-in consent is required before selling or sharing the personal information of consumers under 16 (with parental consent under 13). Businesses may not use dark patterns to obtain consent and must offer a symmetrical choice between accepting and declining.
Obligations mapped to Neostra modules
| Obligation | Regulations | Neostra module and feature |
|---|---|---|
| Receive rights requests through a public channel | DPDPA s.11 to 14, GDPR Art. 12, CCPA | Privacy Rights Manager: published intake forms, the Integration API, and the data subject portal |
| Verify the identity of the requester | GDPR Art. 12(6), CCPA verification rules, DPDP Rules | Privacy Rights Manager: email verification with a configurable timeout, optional affidavit and captcha |
| Route, fulfil, and respond within the statutory time | DPDPA (90 days), GDPR (1 month), CCPA (45 days) | Privacy Rights Manager: workflows, tasks, request queue, response templates, deadline extension on tasks |
| Let the data subject track and receive the response | GDPR Art. 12, CCPA | Privacy Rights Manager: request portal with email plus request ID sign in and a one time access code |
| Collect valid consent and honor withdrawal | DPDPA s.6, GDPR Art. 7, ePrivacy | Consent Management: collection points, banners, cookie categories and cookies, purposes, preference centers |
| Honor opt-out and Global Privacy Control signals | CCPA/CPRA and other US state laws | Consent Management: the consent modal captures the browser GPC signal; regulations flag whether GPC applies |
| Keep evidence of notice and consent | DPDPA s.6, GDPR Art. 7(1) | Consent Management: Consent Records, Receipts, Data Subjects |
| Publish notices and a privacy center | DPDPA s.5, GDPR Art. 13 and 14, CCPA notice at collection | Privacy Center: privacy center builder, privacy notice pages, translations, published versions |
| Maintain a record of processing activities | GDPR Art. 30, implied by DPDPA | Data Inventory: data systems, processing activities, vendors, RoPA Reports |
| Register purposes for personal data | DPDPA s.5 and s.6 | Data Inventory: DPDPA Purpose Registry |
| Know where personal data is stored | All | Data Inventory: scheduled scanning of databases and object storage, data flow, inventory |
| Assess readiness and run impact assessments | DPDPA s.10 (Significant Data Fiduciaries), GDPR Art. 35 | Governance: DPDP Readiness Assessment in the Scanner; Assessments: DPIA (GDPR), DPIA (DPDPA), and RoPA templates |
| Detect, assess, and notify breaches on time | DPDPA s.8(6) and Rule 7, GDPR Art. 33 and 34, California breach statute | Breach Management: breach intake forms, breach types, breach workflows, tasks, per regulation notification deadlines |
| Restrict access by role and brand | All (security and accountability) | Settings: Users, Groups, Brands, roles, tenant level two-factor authentication |
| Serve users and data subjects in their language | DPDPA s.5(3) (English or any language in the Eighth Schedule), GDPR Art. 12(1) (clear and plain language) | Settings > Tenant Active Languages; translations on forms, banners, and privacy centers |
Configurable timelines
Neostra does not hard code statutory deadlines. The following are set per tenant:
- Breach notification window per regulation, in hours, under Settings > Regulations.
- Intake form email verification timeout, per form, with a minimum of 30 minutes.
- Workflow stages, tasks, and assignees per workflow, including deadline extension on individual tasks.
- Request types and their translations under Privacy Rights Manager > Request Types.
The retention period for request and consent data is shown under Settings > Tenant.
Where a law sets a fixed period, configure the matching value in Neostra and review it when the law or its rules change.