What is the DPDP Act? Complete Guide for Indian Businesses (2026)
Learn everything about India's Digital Personal Data Protection (DPDP) Act, including key concepts, compliance requirements, penalties, FAQs, and a practical checklist.
Read articleFind answers to the most common questions about India's Digital Personal Data Protection (DPDP) Act. Learn who it applies to, compliance requirements, and practical guidance.
The Digital Personal Data Protection (DPDP) Act, 2023 raises many questions for startups, SaaS companies, e-commerce businesses, HR teams, founders, and product managers.
Does it apply to small businesses? Do you need customer consent? Is a Privacy Policy enough? What documents should you prepare?
This guide answers 40 of the most frequently asked questions in plain language. For deeper guides, see What is the DPDP Act?, the Ultimate compliance guide, and the DPDP Rules 2025 explained.
Disclaimer: This article is for educational purposes and is not legal advice. Compliance requirements vary by organisation. Have your counsel or CA review your customised documents.
Quick links: Free readiness check · Compliance checklist · DPDPKit
The Digital Personal Data Protection (DPDP) Act, 2023 is India's primary law governing how organizations collect, use, store, share, and delete digital personal data. The DPDP Rules, 2025 were notified on 13 November 2025 to operationalise the Act.
The Act was introduced to protect personal privacy, increase transparency, improve accountability, encourage responsible data handling, and strengthen trust in India's digital economy.
No. GDPR applies primarily within the European Union (and in certain extra-territorial contexts). DPDP is India's privacy law. International businesses may need to comply with both. See DPDP vs GDPR in our pillar guide.
Digital personal data is personal information that exists in digital form — names, email addresses, phone numbers, customer accounts, employee records, online orders, mobile app profiles, IP addresses (depending on context), and support ticket data.
Yes. If your startup processes digital personal data in circumstances covered by the Act, you should evaluate your compliance obligations — regardless of headcount.
Business size alone does not determine applicability. The key factor is whether and how your organisation processes digital personal data.
Yes, if your website collects personal data through contact forms, newsletter signups, user registration, checkout pages, or customer accounts.
Yes. Mobile apps often process account details, contact information, device identifiers, purchase history, and support requests.
Generally, yes. E-commerce companies process customer information for orders, payments, shipping, and support.
Yes. Most SaaS businesses process customer and employee data — accounts, billing, usage logs, support tickets — and should assess their obligations under the Act.
Yes. B2B is not an exemption. Your customers' employees, your own employees, and your marketing leads are all Data Principals under the Act.
Consent is the primary lawful basis for most startup processing activities, but the Act also permits processing in certain specified situations (such as certain legitimate uses). Evaluate the legal basis for each processing activity separately — don't assume one basis covers everything.
Yes. Where consent is the basis for processing, withdrawal must be as easy as giving consent. Establish a documented workflow and log withdrawals.
No. Avoid pre-selected checkboxes for marketing or non-essential processing. Consent must be free, specific, informed, and unambiguous.
Separate different purposes. Users should understand what they're agreeing to for product use versus marketing communications. Consent bundling is a common compliance failure.
Under DPDP, consent must be backed by a notice that itemises what data is collected and for what specific purposes — not buried in Terms of Service. See the DPDP Rules 2025 explained.
If your business collects personal data through its website, app, or services, an accurate Privacy Policy is essential for transparency — and must include Grievance Officer contact details under DPDP.
No. Your Privacy Policy must reflect your own data practices, systems, vendors, retention periods, and rights-handling processes. Copied GDPR templates are the most common failure we see in readiness checks.
At minimum: data categories collected, processing purposes, sharing and processors, retention periods, Data Principal rights, Grievance Officer contact, security practices, and cross-border transfers (if applicable).
No. DPDP requires India-specific elements GDPR policies typically miss — itemised consent notices, Grievance Officer, under-18 child threshold, and 72-hour Board breach reporting. See our deadline-focused guide.
The Act requires reasonable security safeguards appropriate to the nature of the data. Encryption in transit (TLS 1.2+) and encryption at rest for sensitive data are widely expected.
Yes. MFA is a strong baseline control for systems that access personal data.
You must have an incident response process covering identification, investigation, documentation, user notification (without undue delay where required), Data Protection Board intimation without delay, and a detailed report within 72 hours.
Yes. DPDP requires Data Fiduciaries to appoint a named Grievance Officer and publish contact details in your Privacy Policy.
Yes. Employee records — payroll, attendance, performance, recruitment — are personal data and often overlooked by startups.
Yes. Review recruitment tools, payroll systems, attendance trackers, performance platforms, and employee record storage as part of your data inventory.
Many vendors process personal data on your behalf — payment gateways, cloud hosting, CRM, email, analytics, support tools. You remain accountable as the Data Fiduciary.
Yes. Track every processor, the data they handle, DPA status, and cross-border storage locations. DPDPKit includes a Vendor Register tab in the workbook.
Yes, before sharing personal data with processors. DPDPKit includes a DPA template aligned to the notified Rules.
Common documentation includes:
See the full document list and 13-section checklist.
A record of what personal data you collect, why, where it is stored, who can access it, and how long it is retained. It is the foundation of almost every other compliance activity.
A documented policy describing how long different categories of personal data are retained and when they are deleted.
A log to record and track Data Principal requests — access, correction, erasure, and consent withdrawal — with response timelines and outcomes.
13 May 2027 for full compliance under the Act and notified Rules. The Data Protection Board has been operational since 13 November 2025, and complaints can be filed today.
Penalties can reach up to ₹250 crore per violation depending on the nature and gravity of the breach. Examples:
| Violation type | Maximum penalty |
|---|---|
| General contraventions | Up to ₹250 crore |
| Breach of obligations re: children's data | Up to ₹200 crore |
| Failure to implement reasonable security | Up to ₹250 crore |
| Failure to notify Board of breach | Up to ₹200 crore |
Yes. Penalties apply based on the violation, not company size. A missing consent notice or unreachable Grievance Officer can trigger a Board complaint.
Many early-stage startups begin with documented processes and templates. Consulting firms often quote ₹3–5 lakh; DPDPKit starts at ₹4,999 with an 8-tab workbook and 11 Word templates for self-implementation.
For many startups, a focused implementation takes 4–12 weeks depending on complexity and engineering work for consent and rights flows. DPDPKit includes a 90-day roadmap.
Yes. Spreadsheets, document templates, vendor registers, and internal checklists work well at early stage. DPDPKit's workbook is designed for this.
Start with a data inventory. Understanding what personal data you process is the foundation for policies, consent flows, vendor reviews, and retention schedules.
Take the free 50-question readiness check → to identify your biggest gaps automatically.
Yes. Where consent is relied upon, maintain records of who consented, to what purposes, which notice version applied, and when.
Yes. Review integrations that process or transfer personal data between systems — including third-party SDKs in mobile apps.
Encryption is an appropriate safeguard for backups containing personal data, especially sensitive categories.
Yes. Engineering teams implement consent flows, deletion endpoints, access controls, and logging — privacy training reduces implementation gaps.
Yes. Regular access reviews ensure employees only access personal data needed for their role. Quarterly reviews are a good baseline.
Review your privacy program at least annually, after launching new products, when adding vendors, following operational changes, and after security incidents. Schedule quarterly reviews through May 2027.
Before you finish, ask yourself:
If any answer is no, work through our full compliance checklist.
Want to see how prepared your business is?
Take our free DPDP readiness check — 50 questions, about 2 minutes, instant score with your top three gaps. No signup required.
DPDPKit includes everything referenced in these FAQs as ready-to-customise templates — drafted against the DPDP Rules notified 13 November 2025:
₹4,999 — instant download after payment.
The DPDP Act introduces an important framework for protecting digital personal data in India. While the law may seem complex at first, most startups make meaningful progress by understanding what data they process, documenting their practices, and building governance processes over time.
Rather than aiming for perfection on day one, focus on a structured program that evolves as your business grows — and hit 80%+ on your gap assessment before the 13 May 2027 deadline.
Keep learning:
This guide is for informational purposes only and does not constitute legal advice.
Written by
Founder, UXLaunch Lab
11+ years across fintech, Web3, and SaaS. Shipped RoleGrowth — an AI-powered career platform — end-to-end in 8 weeks.
Frequently asked questions
Learn everything about India's Digital Personal Data Protection (DPDP) Act, including key concepts, compliance requirements, penalties, FAQs, and a practical checklist.
Read articleUnderstand the DPDP Rules 2025 with this practical guide for Indian startups and businesses. Learn key requirements, compliance steps, FAQs, and best practices.
Read articleLearn about DPDP Act penalties, how financial penalties are determined, common compliance mistakes, and practical steps businesses can take to reduce privacy risks.
Read article