Cloud-based applications should implement layered privacy and security controls to protect customer data throughout its lifecycle. This includes role-based access controls, encryption, secure APIs, audit logging, consent management, vulnerability management, and well-defined data retention policies
Organizations should also establish processes for handling Data Principal requests and monitoring third-party integrations. These controls help meet the DPDP Act's expectations around security safeguards, processor management, and accountability.