These posts cover the compliance side of application security for Indian product teams: DPDP Act obligations, SOC 2 and ISO 27001 preparation, CERT-In expectations, and how to answer an enterprise security questionnaire honestly without losing the deal.
Compliance work goes wrong when it is treated as paperwork bolted on at the end. These posts are about the engineering half — the evidence, the controls and the honest answers that make an audit or a vendor review uneventful.
The Act is short, and most of what it asks a product team for is engineering work you can do in a sprint: know what you hold, prove consent, delete on request, notice a breach.