2 resources from Corrida Legal we point founders to, and the questions each answers.
📄 Article
✓ Link checkedIndiaFreeIntermediate
Why we picked it
This is the operational manual, not a theory piece: it lists the exact paper trail Indian courts look for (appointment letter, job description, probation appraisal form, dated manager feedback, written confirmation or extension letter) and ships sample letters plus ten drafting mistakes that get employers stuck with a deemed-confirmed employee. It nails the one thing founders miss: if you let probation lapse silently, the hire is confirmed by default, so you must issue a written confirmation OR a written extension before the clock runs out.
Why we picked it
This is the founder-facing counterpart to the DSCI summary: instead of restating the law, it turns it into an 8-step implementation roadmap for a small team, from writing a real notice to enabling deletion to logging breaches. It is honest that founders can be personally liable and that penalties run into hundreds of crores, but it also says the security safeguards need not be expensive for a small team, which is the practical read you want before you over-engineer.
Non-compliance is not just a fine: in some cases founders carry personal liability, so this is not a task you can indefinitely defer
Users need genuine, user-friendly ways to exercise access, correction, erasure, and consent withdrawal, which is a product requirement, not a legal footnote
A Data Protection Officer in India is only mandatory once you are classed a Significant Data Fiduciary (by data volume and sensitivity), so most early startups do not need one yet