デモを依頼する
お問い合わせ
Zscaler Cloud Portal
Zscaler Cloud Portal One
Zscaler Cloud Portal Two
Zscaler Cloud Portal Three
Zscaler Cloud Portal Beta
admin.zscloud.net
Zscaler Private Access Cloud Portal One
Zscaler Private Access Cloud Portal Two
English
Français
Deutsch
Italiano
日本語
Castellano - Mexico
Castellano - España
Portugues - Brasil
Home

Zscalerの統合型プラットフォーム

Zscalerの統合されたサイバーセキュリティ プラットフォームは、Zero Trust Exchangeを基盤としています。1つのプラットフォームで攻撃対象領域を完全に排除し、AIに合わせて拡張します。

イノベーションの詳細

Zero Trust SASE Everywhere

ゼロトラストとAI向けに構築された唯一のSASEにより、ユーザー、デバイス、ワークロード、エージェントを保護します。

イノベーションの詳細
インターネットへのセキュアなアクセス(ZIA)セキュアなプライベート アクセス(ZPA)拠点向けのゼロトラスト支社、キャンパス、工場全体でユーザーとデバイスを接続クラウド向けのゼロトラストワークロード セキュリティをファイアウォールからゼロトラストに移行します。デジタル エクスペリエンス(ZDX)アプリ、ネットワーク、デバイスの問題を迅速に検出して解決します。ゼロトラスト ブラウザークラウド サンドボックス未知のファイルベースの脅威から防御します。ゼロトラスト ファイアウォールゼロトラスト ゲートウェイあらゆるワークロードのセキュリティを管理事業継続性重大な故障時のセキュリティと稼働時間を維持しましょう。特権リモート アクセス安全で制御されたクライアントレス リモート アクセスを活用できます。Zscaler Cellularモバイル端末と通信インフラを保護

Solutions

From use cases and industries to technology partners, find the right combination of solutions for your organization.

Learn More
AI資産管理AIセキュリティ攻撃対象領域管理BYODセキュリティ継続的な脅威エクスポージャー管理データ セキュリティマイクロセグメンテーションIoT/OTのセグメンテーションVPNからの脱却AIのセキュリティB2Bの保護東西トラフィックの保護送受信トラフィックの保護IoT/OTの保護従業員の保護セキュリティコンテキストグラフゼロトラスト+AIゼロトラストSD-WAN

リソース ライブラリー

最新のサイバーセキュリティに関する知見、レポート、ガイド、ウェビナー、顧客事例などを入手して、常に最新情報を把握しましょう。

イノベーションの詳細

Zscalerがセキュリティ強化をお手伝いします。

専門家とつながり、質問への回答を得て、ドキュメントやユーザー フォーラムからライブのテクニカル サポートまで必要なサポートを受けられます。

サポートを受ける
サポートに問い合わせるチケットまたは電話で、24時間365日いつでもZscalerのテクニカルサポートチームにご連絡いただけます。お客様の導入事例Zscalerの展開を最大限に活用するためのトレーニング、ベストプラクティス、リソース。リリースノートZscaler全サービスにおける最新の製品アップデート、新機能、バグ修正。Trust Portalリアルタイムのサービス状態、稼働状況、および計画メンテナンス通知。Zenith Community374,000人以上のZscalerのユーザー、パートナー、専門家とつながることができます。Zscalerヘルプ ポータル技術文書、製品ガイド、トラブルシューティングのヒント。

Zscalerについて

Zscalerは世界最大のセキュリティ クラウドを活用することで、大手企業が脅威に先んじて対応し、業務を簡素化できるよう支援します。

イノベーションの詳細

Zscalerとは

Zscalerを支える人々、価値観、ビジョン、そして私たちという企業について知っておくべきすべて。

アナリストによる評価Gartner、ForresterがZscalerをリーダーと評価する理由をご覧ください。採用情報ビジネスをより安全に行える世界の実現を目指すチームに加わりませんか。コンプライアンスZscalerプラットフォームの認定、認可、監査レポート。企業責任Zscalerがスチュワードシップを通じて良い影響を生み出す方法。文化私たちの働き方、価値観、そして原動力について学びましょう。よくある質問Zscaler とは何か、提供するサービス、そしてプラットフォームの仕組みについて、すばやくご確認いただけます。株主、投資家情報NASDAQ: ZSの財務実績、SEC提出書類、コーポレート ガバナンス。リーダーシップ チームZscalerのビジョンと戦略を推進する経営陣や取締役会役員に会いましょう。Zenith Ventures次世代のゼロトラストとAIスタートアップへの投資。
Home
デモを依頼するお問い合わせ

Zscaler and India’s Data Protection Laws

Introduction

After a long (seven-year) gestation period, India has enacted the Digital Personal Data Protection Act of 2023 (“DPDPA”), a comprehensive data protection law that provides a framework for regulating the collection, processing and storage of personal data. While the DPDPA was signed into law on August 12, 2023, implementing regulations for the DPDPA have not yet been issued. The DPDPA will replace the privacy rules applicable under Section 43A of India’s Information Technology Act.

This overview describes key provisions of the DPDPA and how Zscaler will comply with it.

  • Definition of personal data. Personal data is broadly defined to include any data relating to a natural person who is either (i) identifiable or (ii) could be made identifiable through direct or indirect means. This encompasses a wide range of information, including names, addresses, financial data, online identifiers, and geolocation data.
  • Legal basis for processing. The DPDPA allows data processing only for "lawful purposes" based on consent or other specific grounds. Consent must be "free, specific, informed, unconditional, and unambiguous," with clear affirmative action signifying consent. Additional lawful bases include public interest, legal obligations, contractual necessity, and vital interests of the data subject.
  • Individual rights. The DPDPA grants individuals (referred to as “data principals”) extensive rights over their personal data. These rights (which align with the rights granted to data subjects under the GDPR) include: (i) right to access (individuals can request a copy of their personal data held by an entity); (ii) right to correction (individuals can request that inaccuracies in their data be corrected; (iii) right to erasure (individuals can request deletion of their data in certain circumstances); (iv) right to restrict processing (individuals can object to or restrict the processing of their data); and (v) right to data portability (individuals can request transfer of their data to another entity).
  • Security measures. The DPDPA imposes obligations on "data fiduciaries" (entities that control and process personal data, similar to “controllers” under the GDPR) to implement appropriate security measures to protect personal data from unauthorized access, disclosure, or destruction. These measures must be commensurate with the nature of the data and the risks involved.
  • Security breach requirements. In case of a data breach, data fiduciaries must notify the Data Protection Board of India and affected individuals without undue delay. They must also take necessary steps to contain the breach and mitigate its potential harm. Details as to what breaches trigger the notification requirement, and the timeframe for reporting breaches, will follow in the DPDPA regulations.
  • Extraterritorial scope. The DPDPA applies to the processing of personal data of individuals in India, regardless of the location of the data fiduciary. This extraterritorial application extends to entities offering goods or services in India, even if they are not physically present in the country.
  • Outsourcing. In recognition of the importance of the Business Processing Outsourcing (“BPO”) industry in India, the DPDPA provides certain exemptions in the context of cross-border BPO activities. In particular, when personal data of individuals not within India is processed by an India-based entity pursuant to a contract entered into with an entity outside of India, that processing is not subject to obligations imposed on data fiduciaries (including Significant Data Fiduciaries) or with respect to cross-border transfers or individual rights; however, the security measure obligations remain applicable.

Concept of “Significant Data Fiduciaries”

The DPDPA introduces the novel concept of Significant Data Fiduciaries (“SDFs”). SDFs are data fiduciaries that process a large volume of personal data, particularly sensitive data, that may pose significant risks to the rights and freedoms of individuals. The India Government has the power to designate any data fiduciary (or class of fiduciaries) as an SDF based on various factors, including: (i) volume and sensitivity of personal data processed; (ii) nature of the processing activities; (iii) risk of harm to data subjects; (iv) financial turnover or market share of the fiduciary; and (v) impact of the processing on national security or public order.

SDFs face additional obligations compared to regular data fiduciaries, such as:

  • Appointing a Data Protection Officer (“DPO”): SDFs must have a dedicated DPO responsible for data protection compliance.
  • Conducting Data Protection Impact Assessments (“DPIAs”): SDFs must conduct DPIAs for high-risk processing activities to identify and mitigate potential risks.
  • Appointing an independent data auditor: SDFs must appoint an independent auditor to regularly assess their data protection practices.
  • Implementing stricter security measures: SDFs must implement stronger security measures commensurate with the risks involved in their processing activities.

These additional obligations ensure that SDFs, which handle particularly sensitive and large amounts of data, prioritize data protection and minimize risks to individuals' privacy.

Restrictions on Cross-Border Data Transfers

The DPDPA regulates the cross-border transfer of personal data, seeking to ensure adequate levels of protection in the receiving country. While cross-border transfers are generally permitted (i.e., the DPDPA contains no data localization requirements), the India Government has the power to restrict them to certain countries or territories through notification. Further regulations are expected to clarify the criteria and procedures for such restrictions.

Zscaler Compliance with India’s Data Protection Laws

In its role as a processor of customer data that may be subject to India’s data protection laws, Zscaler is committed to meeting its compliance obligations, including as follows:

  1. Legal basis for personal data processing. Zscaler ensures that it satisfies the requirements of the DPDPA for personal data processing, including by requiring its customers to obtain all necessary consents and only processing personal data for the purpose of providing its services and products to the customer.
  2. Security measures. Zscaler has adopted reasonable security safeguards to prevent personal data breaches. These safeguards include establishing internal personal data management policies and procedures, applying appropriate technical security measures such as cryptography and anonymization, conducting training, and creating contingency plans.
  3. Data breaches. In the event of a data breach, Zscaler will promptly notify its customers as well as the Data Protection Board of India as required under the DPDPA and any applicable regulations.
  4. Rights of data subjects. Consistent with the requirements of the DPDPA, Zscaler assists its customers in fulfilling their obligations to allow data principals to exercise their data protection rights, including rights of access, correction, and erasure of personal data.
  5. Cross-border transfers. Zscaler will continue to comply with its obligations to protect personal data under the DPDPA with respect to any transfers of personal data from India to a third country. Further, Zscaler will monitor and comply with any country-specific restrictions that may be imposed by the Data Protection Board of India.
  6. Outsourcing exemptions. To the extent that Zscaler outsources any personal data processing to an India-based service provider, Zscaler is aware of and will take advantage of the BPO exemptions specified in the DPDPA. In any event, Zscaler will take appropriate steps to ensure that its India-based service providers maintain the security of any outsourced personal data.
  7. Significant Data Fiduciaries. If any Zscaler client is designated as an SDF, Zscaler will take reasonable measures to assist that client in complying with its SDF obligations.

Zscaler will update this overview once the DPDPA’s implementing regulations and enforcement mechanisms have been approved and issued.

Helpful Links Regarding India Data Protection Laws

Text of the DPDPA: https://dpdpa.co.in/ 

India Ministry of Electronics and Information Technology: http://www.cac.gov.cn/2016-11/07/c_1119867116.htm

NOTE: While this site is designed to help organizations understand India’s data protection laws in connection with Zscaler's services and products, the information contained herein should not be construed as legal advice. Organizations should consult with their own legal counsel with respect to interpreting their unique obligations under India’s data protection laws.

Zscaler Platform
AIセキュリティ
データ セキュリティ
SecOps
製品とソリューション
Product Tours
業界
パートナー
カーボン
Zscalerについて
Zscaler FAQ
リーダーシップ
採用情報
Investors
プレス
責務
お問い合わせ
価格設定
Red Canary
コミュニティ
Analysts
ニュース
Zenith Live
イベント
Executive Insightsアプリ
ThreatLabzリサーチ
リソース ライブラリー
ブログ
ウェビナー
Zpedia
サイバーアカデミー
お客様の成功事例
お客様の導入事例
サポートに問い合わせる
ヘルプポータル
セキュリティ アドバイザリー
脆弱性の開示
Security Risk Assessments
コンプライアンス
パートナー ポータル
Home

ゼロトラストのリーダーとして世界的に認知されているZscalerは、世界最大のセキュリティ クラウドを活用して、ビジネスの簡素化と保護を実現するソリューションを世界中の大手企業に提供しています。

Facebookを見る(opens in a new tab)LinkedInで検索する(opens in a new tab)Xをフォロー(opens in a new tab)YouTubeチャンネルを登録(opens in a new tab)Instagramをフォロー(opens in a new tab)
サイトマッププライバシー法的事項セキュリティCookieの設定
© 2026 Zscaler, Inc.

All rights reserved. Zscaler™およびzscaler.com/jp/legal/trademarksに記載されたその他の商標は、米国および/または各国のZscaler, Inc.における(i)登録商標またはサービス マーク、または(ii)商標またはサービス マークです。その他の商標はすべて、それぞれの所有者に帰属します。