As India brings the Digital Personal Data Protection Act, 2025 into effect, organisations must strengthen their data governance, security controls, and compliance mechanisms to meet the evolving regulatory landscape. With phased enforcement beginning this year, the responsibilities and expectations for Data Fiduciaries, Significant Data Fiduciaries, and Consent Managers have increased substantially.
Key Highlights:
• Key obligations under the DPDPA and DPDP Rules, 2025
• The phased enforcement timelines organisations must prepare for
• Minimum security safeguards and breach-notification requirements
• Applicable exemptions and their implications for compliance strategies
Read our insights
The New ICC 2026 Arbitration Rules
August 12, 2026
The ICC's new 2026 Arbitration Rules are the biggest update since 2021, bringing faster timelines and tighter disclosure rules. Here's what it means for experts working on ICC cases.
The Dual Mandate: AI for IA & IA for AI
August 7, 2026
Alvarez & Marsal hosted The Dual Mandate: AI for IA & IA for AI, bringing together senior Internal Audit leaders for an evening of practical discussion on how organizations are navigating AI adoption while strengthening governance and assurance.
The £3.3 Million Legal Victory Protecting the House That Hosted a Tudor King
August 3, 2026
Alvarez & Marsal senior director Mohammad Yadollahi’s expert testimony recently helped claimants win £3.3 million pounds in damages for a historic building where King Henry VIII once stayed.
Third-Party Risk Management: You Can Outsource the Task — Not the Risk
August 3, 2026
Third-party relationships create efficiency, but the risk stays with you. In this Raising the Bar piece, Eduardo Magalhaes, Isabela Dauger, and Clara Jordão break down why regulators are holding companies accountable for their vendors' failures.