Apple spent a decade making privacy feel obvious.
- App Tracking Transparency
- Nutrition labels on the App Store
- On-device processing
- “Privacy. That’s iPhone.”
It was not a policy PDF. It was product. Users started noticing. Ad tech had to rebuild. Privacy stopped being a footnote and became a market force.
India’s DPDP story is the next chapter of that same shift with a different instrument.
Apple used platform power. India used statute. Consent, purpose limitation, Data Principal rights, Significant Data Fiduciary duties, penalties that actually sting.
The Rules are now live in phases, with the hard operating obligations marching toward May 2027. Companies do not get to treat this as a brand campaign. They have to treat it as how personal data moves through the firm.
That is the parallel worth holding onto.
Apple proved privacy can change behaviour when it sits inside the product. DPDP says privacy has to sit inside the operating system of the company - notices, consent, retention, deletion, vendor chains, audit trails. Dashboards that summarise the Act will not be enough. The work is in the daily practice of CAs, CSs and DPOs who have to make it real for the clients they advise.
At Obedien, that is the lane we are building for: privacy as a working layer, not another slide in the compliance pack.
Apple made users expect control.
DPDP makes organisations prove they can deliver it.
The open question for Indian firms is simple. Will privacy stay a policy note on the website or become part of how the business actually runs before the enforcement clock stops being abstract?

