ThreatLabZ
Storie di successo dei clienti
Carriere
Partner
Supporto
Contattaci
1-408-533-0288
Zscaler Cloud Portal | Admin
Zscaler Cloud Portal | Admin
Zscaler Cloud Portal | Admin
Zscaler Cloud Portal | Admin
Zscaler Cloud Portal | Admin
admin.zscloud.net
Zscaler Private Access Cloud Portal One | Admin
Portale di Zscaler Private Access Cloud | Amministratore
Home
Scopri il prodottoRichiedi una dimostrazione
Proteggi la forza lavoro

Offri agli utenti un accesso fluido, sicuro e affidabile alle applicazioni e ai dati..

Proteggi il cloud

Sviluppa ed esegui app cloud sicure, abilita la connettività zero trust al cloud e proteggi i carichi di lavoro dal data center al cloud.

Proteggi gli ambienti IoT e OT

Fornisci una connettività zero trust ai dispositivi IoT e OT e un accesso remoto sicuro ai sistemi OT.

Proteggi il B2B

Fornisci ai tuoi partner una connettività zero trust site-to-site e un accesso affidabile alle app B2B.

Zscaler Platform
Perché scegliere Zscaler?
Leadership nell settore dell'AI
SASE di Zscaler
Zscaler SSE
Riconoscimenti degli analisti
Automazione Zero Trust
Storie dei clienti
Ecosistema di partner
Riduci il tuo impatto ambientale

Resoconto di settore

Zscaler: una leader nel Magic Quadrant™ di Gartner® 2025 per il Security Service Edge (SSE)

nvaigation-gartner-report-2025
SASE Zero Trust
Accesso sicuro a Internet (ZIA)
Accesso privato sicuro (ZPA)
Esperienza digitale (ZDX)
Firewall zero trust
Cloud Sandbox
Zero Trust Browser
Zero Trust Branch
SD-WAN zero trust
Segmentazione IoT/OT
Accesso remoto con privilegi
Zscaler Cellular
Sicurezza dell'AI
Gestione delle risorse IA
AI Access Security
AI Red Teaming
Limitazioni dell'AI
Zero Trust Cloud
Secure Ingress and Egress Traffic
Secure East-West Traffic
Microsegmentazione
Zero Trust Gateway
Sicurezza dei dati
DLP per web e e-mail
DLP dell'endpoint
Sicurezza dei dispositivi personali (BYOD)
Multi-Mode CASB
Sicurezza SaaS unificata
DSPM
Microsoft Copilot Data Protection
Operazioni di sicurezza
Risk360
Tecnologia di deception
Asset Exposure Management
Gestione unificata delle vulnerabilità
Ricerca gestita delle minacce
Managed Detection & Response
Data Fabric for Security
CASI D'USO
Zero trust + AI
Business Insights
Sostituire la VPN
Protezione dalle minacce informatiche
Blocca i ransomware
Alternativa alla VDI
Proteggere i dati
Ottimizza le esperienze digitali
Distribuisci i dispositivi personali in modo sicuro
Riduci il rischio informatico
Security Operations
Continuous Threat Exposure Management
Accelerare fusioni, acquisizioni e cessioni
Soluzioni per l'industria e il mercato
Assistenza sanitaria
Servizi finanziari e bancari
Settore manifatturiero
Istruzione
Retail
Governo australiano
Governo cinese
Settore pubblico degli Stati Uniti
Governo federale degli Stati Uniti
Amministrazione statale e locale degli Stati Uniti
APJ Mid-Market / Commercial
Partner
Esplora i nostri partner
Diventa un partner
Portale partner
PARTNER TECNOLOGICI
Scopri i partner per la tecnologia
Microsoft
CrowdStrike
AWS
Okta
Rubrik
SAP
Zero trust + AI
Business Insights
Sostituire la VPN
Protezione dalle minacce informatiche
Blocca i ransomware
Alternativa alla VDI
Proteggere i dati
Ottimizza le esperienze digitali
Distribuisci i dispositivi personali in modo sicuro
Riduci il rischio informatico
Security Operations
Continuous Threat Exposure Management
Accelerare fusioni, acquisizioni e cessioni
Assistenza sanitaria
Servizi finanziari e bancari
Settore manifatturiero
Istruzione
Retail
Governo australiano
Governo cinese
Settore pubblico degli Stati Uniti
Governo federale degli Stati Uniti
Amministrazione statale e locale degli Stati Uniti
APJ Mid-Market / Commercial
Esplora i nostri partner
Diventa un partner
Portale partner
Scopri i partner per la tecnologia
Microsoft
CrowdStrike
AWS
Okta
Rubrik
SAP
Centro risorse
Libreria delle risorse
Blog
Storie di successo dei clienti
Webinar
Zpedia
Eventi e formazione
Prossimi eventi
Zenith Live
Zscaler Academy
Ricerca e servizi di sicurezza
Analisi di ThreatLabz
Aggiornamenti degli avvisi di sicurezza
Strumenti
Anteprima della sicurezza
Security and Risk Assessment
Divulga una vulnerabilità
Executive Insights App
Calcolatore del ROI della protezione dai ransomware
Community e assistenza
Customer Success Center
Zenith Community
Portale di assistenza Zscaler
Libreria delle risorse
Blog
Storie di successo dei clienti
Webinar
Zpedia
Prossimi eventi
Zenith Live
Zscaler Academy
Analisi di ThreatLabz
Aggiornamenti degli avvisi di sicurezza
Anteprima della sicurezza
Security and Risk Assessment
Divulga una vulnerabilità
Executive Insights App
Calcolatore del ROI della protezione dai ransomware
Customer Success Center
Zenith Community
Portale di assistenza Zscaler
Informazioni su Zscaler

Scopri come tutto è iniziato e le previsioni per il futuro

Partner

Incontra i nostri partner ed esplora gli integratori di sistema e le alleanze tecnologiche

Notizie e annunci

Non perdere gli aggiornamenti sulle ultime novità

Team di leadership

Incontra il nostro team di gestione

Integrazioni con i partner

Esplora le integrazioni con i nostri partner per la tecnologia

Rapporti con gli investitori

Scopri le ultime notizie, le informazioni sulle azioni e i report trimestrali

Carriere

Unisciti alla nostra missione

Conformità

Scopri di più sui nostri rigorosi standard

Centro stampa

Trova tutto ciò di cui hai bisogno per parlare di Zscaler

Culture

Our values, leadership principles, and ways of working

Zenith Ventures

Scopri di più sui nostri rigorosi standard

Environmental, Social and Governance

Scopri il nostro approccio ESG

Home
Scopri il prodottoRichiedi una dimostrazione

Zscaler and India’s Data Protection Laws

Introduction

After a long (seven-year) gestation period, India has enacted the Digital Personal Data Protection Act of 2023 (“DPDPA”), a comprehensive data protection law that provides a framework for regulating the collection, processing and storage of personal data. While the DPDPA was signed into law on August 12, 2023, implementing regulations for the DPDPA have not yet been issued. The DPDPA will replace the privacy rules applicable under Section 43A of India’s Information Technology Act.

This overview describes key provisions of the DPDPA and how Zscaler will comply with it.

  • Definition of personal data. Personal data is broadly defined to include any data relating to a natural person who is either (i) identifiable or (ii) could be made identifiable through direct or indirect means. This encompasses a wide range of information, including names, addresses, financial data, online identifiers, and geolocation data.
  • Legal basis for processing. The DPDPA allows data processing only for "lawful purposes" based on consent or other specific grounds. Consent must be "free, specific, informed, unconditional, and unambiguous," with clear affirmative action signifying consent. Additional lawful bases include public interest, legal obligations, contractual necessity, and vital interests of the data subject.
  • Individual rights. The DPDPA grants individuals (referred to as “data principals”) extensive rights over their personal data. These rights (which align with the rights granted to data subjects under the GDPR) include: (i) right to access (individuals can request a copy of their personal data held by an entity); (ii) right to correction (individuals can request that inaccuracies in their data be corrected; (iii) right to erasure (individuals can request deletion of their data in certain circumstances); (iv) right to restrict processing (individuals can object to or restrict the processing of their data); and (v) right to data portability (individuals can request transfer of their data to another entity).
  • Security measures. The DPDPA imposes obligations on "data fiduciaries" (entities that control and process personal data, similar to “controllers” under the GDPR) to implement appropriate security measures to protect personal data from unauthorized access, disclosure, or destruction. These measures must be commensurate with the nature of the data and the risks involved.
  • Security breach requirements. In case of a data breach, data fiduciaries must notify the Data Protection Board of India and affected individuals without undue delay. They must also take necessary steps to contain the breach and mitigate its potential harm. Details as to what breaches trigger the notification requirement, and the timeframe for reporting breaches, will follow in the DPDPA regulations.
  • Extraterritorial scope. The DPDPA applies to the processing of personal data of individuals in India, regardless of the location of the data fiduciary. This extraterritorial application extends to entities offering goods or services in India, even if they are not physically present in the country.
  • Outsourcing. In recognition of the importance of the Business Processing Outsourcing (“BPO”) industry in India, the DPDPA provides certain exemptions in the context of cross-border BPO activities. In particular, when personal data of individuals not within India is processed by an India-based entity pursuant to a contract entered into with an entity outside of India, that processing is not subject to obligations imposed on data fiduciaries (including Significant Data Fiduciaries) or with respect to cross-border transfers or individual rights; however, the security measure obligations remain applicable.

Concept of “Significant Data Fiduciaries”

The DPDPA introduces the novel concept of Significant Data Fiduciaries (“SDFs”). SDFs are data fiduciaries that process a large volume of personal data, particularly sensitive data, that may pose significant risks to the rights and freedoms of individuals. The India Government has the power to designate any data fiduciary (or class of fiduciaries) as an SDF based on various factors, including: (i) volume and sensitivity of personal data processed; (ii) nature of the processing activities; (iii) risk of harm to data subjects; (iv) financial turnover or market share of the fiduciary; and (v) impact of the processing on national security or public order.

SDFs face additional obligations compared to regular data fiduciaries, such as:

  • Appointing a Data Protection Officer (“DPO”): SDFs must have a dedicated DPO responsible for data protection compliance.
  • Conducting Data Protection Impact Assessments (“DPIAs”): SDFs must conduct DPIAs for high-risk processing activities to identify and mitigate potential risks.
  • Appointing an independent data auditor: SDFs must appoint an independent auditor to regularly assess their data protection practices.
  • Implementing stricter security measures: SDFs must implement stronger security measures commensurate with the risks involved in their processing activities.

These additional obligations ensure that SDFs, which handle particularly sensitive and large amounts of data, prioritize data protection and minimize risks to individuals' privacy.

Restrictions on Cross-Border Data Transfers

The DPDPA regulates the cross-border transfer of personal data, seeking to ensure adequate levels of protection in the receiving country. While cross-border transfers are generally permitted (i.e., the DPDPA contains no data localization requirements), the India Government has the power to restrict them to certain countries or territories through notification. Further regulations are expected to clarify the criteria and procedures for such restrictions.

Zscaler Compliance with India’s Data Protection Laws

In its role as a processor of customer data that may be subject to India’s data protection laws, Zscaler is committed to meeting its compliance obligations, including as follows:

  1. Legal basis for personal data processing. Zscaler ensures that it satisfies the requirements of the DPDPA for personal data processing, including by requiring its customers to obtain all necessary consents and only processing personal data for the purpose of providing its services and products to the customer.
  2. Security measures. Zscaler has adopted reasonable security safeguards to prevent personal data breaches. These safeguards include establishing internal personal data management policies and procedures, applying appropriate technical security measures such as cryptography and anonymization, conducting training, and creating contingency plans.
  3. Data breaches. In the event of a data breach, Zscaler will promptly notify its customers as well as the Data Protection Board of India as required under the DPDPA and any applicable regulations.
  4. Rights of data subjects. Consistent with the requirements of the DPDPA, Zscaler assists its customers in fulfilling their obligations to allow data principals to exercise their data protection rights, including rights of access, correction, and erasure of personal data.
  5. Cross-border transfers. Zscaler will continue to comply with its obligations to protect personal data under the DPDPA with respect to any transfers of personal data from India to a third country. Further, Zscaler will monitor and comply with any country-specific restrictions that may be imposed by the Data Protection Board of India.
  6. Outsourcing exemptions. To the extent that Zscaler outsources any personal data processing to an India-based service provider, Zscaler is aware of and will take advantage of the BPO exemptions specified in the DPDPA. In any event, Zscaler will take appropriate steps to ensure that its India-based service providers maintain the security of any outsourced personal data.
  7. Significant Data Fiduciaries. If any Zscaler client is designated as an SDF, Zscaler will take reasonable measures to assist that client in complying with its SDF obligations.

Zscaler will update this overview once the DPDPA’s implementing regulations and enforcement mechanisms have been approved and issued.

Helpful Links Regarding India Data Protection Laws

Text of the DPDPA: https://dpdpa.co.in/ 

India Ministry of Electronics and Information Technology: http://www.cac.gov.cn/2016-11/07/c_1119867116.htm

NOTE: While this site is designed to help organizations understand India’s data protection laws in connection with Zscaler's services and products, the information contained herein should not be construed as legal advice. Organizations should consult with their own legal counsel with respect to interpreting their unique obligations under India’s data protection laws.

Piattaforma Zero Trust
AI Security
Sicurezza dei dati
SecOps
Prodotti e soluzioni
Scopri il prodotto
Settori
Partner
Carbonio
Informazioni su Zscaler
FAQ su Zscaler
Leadership
Carriere
Investitore
Stampa
Responsabilità
Contatti
Prezzi
Red Canary
Community
Analysts
News
Zenith Live
Eventi
Executive Insights App
Attività di ricerca di Threatlabz
Libreria delle risorse
Blog
Webinar
Zpedia
Cyber Academy
Storie di successo dei clienti
Customer Success Center
Contatta l'assistenza
Portale di Assistenza
Avvisi di sicurezza
Divulga una vulnerabilità
Analisi dei rischi per la sicurezza
Conformità
Portale partner
Home

Zscaler è universalmente riconosciuta come leader nel settore dello zero trust. Sfruttando il security cloud più grande del pianeta, Zscaler anticipa le esigenze delle aziende, nonché protegge e semplifica il business delle realtà più affermate del mondo. 

Visita la nostra pagina Facebook(opens in a new tab)Trovaci su LinkedIn(opens in a new tab)Seguici su X(opens in a new tab)Iscriviti al nostro canale Youtube(opens in a new tab)Seguici su Instagram(opens in a new tab)
Mappa del sitoPrivacyLegaleSicurezzaPreferenze sui cookie
© 2026 Zscaler, Inc.

Tutti i diritti riservati. Zscaler™ e gli altri marchi commerciali presenti su zscaler.it/legal/trademarks sono (I) marchi commerciali o marchi di servizio registrati o (II) marchi commerciali o marchi di servizio di Zscaler, Inc. negli Stati Uniti e/o in altri Paesi. Tutti gli altri marchi commerciali sono di proprietà dei rispettivi titolari.