What is the DPDP Act? Complete Guide for Indian Businesses (2026)
Learn everything about India's Digital Personal Data Protection (DPDP) Act, including key concepts, compliance requirements, penalties, FAQs, and a practical checklist.
Read articleLearn how Indian startups can become DPDP compliant with this complete 2026 guide. Includes checklist, documents, timelines, penalties, and free readiness check.
If your startup collects customer data, employee information, or website leads in India, DPDP compliance is no longer something to postpone.
The DPDP Rules, 2025 were notified on 13 November 2025, the Data Protection Board is live, and full compliance is mandatory by 13 May 2027. This guide explains everything founders need to know — from understanding the law to building a practical compliance roadmap.
Quick links: DPDP explained simply · Compliance cost guide · Penalties explained · Compliance timeline · DPDP Act FAQs · Free readiness check · DPDPKit
The Digital Personal Data Protection (DPDP) Act, 2023 is India's primary law governing how organizations collect, process, store, share, and delete digital personal data.
Its purpose is straightforward:
Whether you're a SaaS startup, fintech company, healthcare platform, e-commerce business, or AI startup, DPDP may apply if you process personal data of individuals in India.
The DPDP Rules, 2025 (notified 13 November 2025) operationalise the Act with specific requirements for notices, consent, breach reporting, and more.
Many founders assume privacy compliance is only for large enterprises. That assumption is risky.
Almost every startup collects some form of personal data:
If you collect personal information digitally, DPDP is relevant — including B2B startups. Employee data, customer records, and lead lists all count.
Privacy is also becoming a competitive advantage. Customers increasingly prefer businesses that clearly explain what data is collected, why it is collected, how it is protected, and how they can request deletion or correction.
Enterprise buyers are starting to ask about data protection during vendor due diligence. Being DPDP-ready before May 2027 puts you ahead of competitors still copying GDPR templates.
Use this simple checklist. DPDP likely applies if you:
If you answered yes to any of these, your business should evaluate its DPDP readiness.
Take the free 50-question readiness check → — about 2 minutes, instant score and your three biggest gaps.
Any information that identifies an individual. Examples include name, mobile number, email address, IP address (depending on context), employee ID, and customer account information.
The individual whose personal data is processed — customers, employees, vendors, job applicants.
The organization deciding why and how personal data is processed. Your startup is generally the Data Fiduciary.
Personal data should generally be processed based on valid consent or another lawful basis permitted under the Act. Under DPDP, consent must be:
A named person appointed by your company to handle data-related complaints from Data Principals. Contact details must be published in your privacy policy.
Some organizations may receive additional compliance obligations based on factors determined by the Government — such as the volume and sensitivity of data processed. Not every startup will fall into this category, but you should assess your status.
A practical checklist for startups. Use this alongside the DPDPKit workbook to track progress. For the full 13-section version with checkboxes, see our dedicated DPDP compliance checklist.
Most startups require documentation such as:
| Document | Purpose |
|---|---|
| Privacy Policy | Inform users how data is collected, used, shared, and protected |
| Itemised Consent Notice | Obtain valid, specific consent with clear purpose statements |
| Employee Privacy Notice | Explain how employee and HR data is processed |
| Data Inventory | Track what personal data lives in which systems |
| Data Processing Agreement (DPA) | Govern third-party processors and subprocessors |
| Vendor Register | Record all external parties processing personal data |
| Data Retention Schedule | Define how long data is kept and when it is deleted |
| Data Breach SOP | Prepare for incidents including Board intimation within 72 hours |
| Rights Request Register | Track access, correction, and erasure requests |
| Compliance Workbook | Monitor gap assessment progress and register entries |
DPDPKit includes all of the above as Word templates plus an 8-tab Excel workbook with gap assessment, registers, and a 90-day implementation roadmap — ₹4,999, instant download.
Document:
Create a spreadsheet (or use the Data Inventory tab in DPDPKit) listing:
| Field | Example |
|---|---|
| System | Production DB, HubSpot, Razorpay |
| Data type | Email, phone, payment token |
| Owner | CTO, Head of Sales |
| Purpose | Account auth, billing, support |
| Retention | 7 years post-account closure |
| Vendor / processor | AWS, Stripe |
This becomes the foundation of every other compliance document.
Your Privacy Policy should clearly explain:
Have your counsel or CA review before publishing.
Ensure users understand what they're agreeing to, why data is needed, and how consent can be withdrawn. Remove consent bundling — don't force marketing consent to use your product.
Identify all vendors processing personal data:
Maintain a vendor register and send DPAs for signature.
Users may ask to access their information, correct inaccuracies, delete data where applicable, or withdraw consent. Have a documented workflow, response timelines, and a register to log each request.
Prepare for data breaches before they happen. Your plan should include:
Run a tabletop drill once — even a 1-hour exercise surfaces gaps.
Many startups:
These gaps become operational problems long before they become regulatory ones.
Non-compliance is not theoretical. The Data Protection Board has been operational since 13 November 2025 and can impose significant penalties.
| Violation type | Maximum penalty |
|---|---|
| General contraventions | Up to ₹250 crore |
| Breach of obligations re: children's data | Up to ₹200 crore |
| Failure to implement reasonable security | Up to ₹250 crore |
| Failure to notify Board of breach | Up to ₹200 crore |
Penalties depend on the nature and gravity of the violation. The Board is already accepting complaints — you do not need to wait until May 2027 for enforcement risk to materialise.
Full compliance deadline: 13 May 2027. There is no announced grace period beyond this date.
A practical 3-week sprint for early-stage teams. For larger or more complex stacks, extend to 8–12 weeks using the 90-day roadmap in DPDPKit.
| DPDP | GDPR | |
|---|---|---|
| Jurisdiction | India | European Union (+ EEA) |
| Scope | Digital personal data | Broader personal data scope |
| Child threshold | Under 18 | Under 16 (member states may lower to 13) |
| Consent | Itemised notice required | Specific, informed consent |
| Regulator | Data Protection Board of India | National DPAs in each EU state |
| Breach reporting | Board intimation + 72-hour detailed report | 72 hours to DPA (where applicable) |
| Grievance Officer | Mandatory appointment | DPO required in certain cases |
Organizations operating internationally may need to comply with both. A GDPR privacy policy alone is not sufficient for DPDP — India-specific elements like the Grievance Officer, itemised consent notices, and Board breach reporting must be addressed separately.
Compliance is not only about reducing legal risk. It also helps:
If your startup processes digital personal data in circumstances covered by the Act, you should assess and implement the compliance measures that apply to your business.
Size alone does not determine applicability. The key factor is whether and how personal data is processed.
No. Privacy documentation should accurately reflect your own data practices, systems, vendors, and retention periods.
Many SaaS businesses process personal data and should evaluate their obligations under the Act.
Typical documentation may include a Privacy Policy, consent notices, data inventory, vendor register, rights request register, retention schedule, breach SOP, Grievance Officer appointment, and DPAs for processors. Exact requirements depend on your activities.
For many early-stage startups, a focused implementation project can often be completed in 4–12 weeks. Timing varies based on business complexity, engineering work for consent and rights flows, and whether you start from templates or from scratch.
Not sure where your startup stands?
Take our free DPDP readiness check — 50 questions, about 2 minutes, instant results with your score and top three gaps. No signup required.
If you'd rather not create policies, registers, and compliance documents from scratch, DPDPKit provides a practical compliance OS for Indian startups.
It includes:
₹4,999 — instant download after payment.
DPDP compliance is not a one-time legal exercise — it is an ongoing business capability. Startups that build privacy into their operations early are better positioned to earn customer trust, streamline internal processes, and adapt as regulatory expectations evolve.
Whether you're launching a new SaaS product, scaling an e-commerce business, or growing an AI startup, taking a structured approach now can save significant effort before the 13 May 2027 deadline.
Next steps:
This guide is for informational purposes only and does not constitute legal advice. Have your counsel or CA review your customised documents before you rely on them.
Written by
Founder, UXLaunch Lab
11+ years across fintech, Web3, and SaaS. Shipped RoleGrowth — an AI-powered career platform — end-to-end in 8 weeks.
Frequently asked questions
Learn everything about India's Digital Personal Data Protection (DPDP) Act, including key concepts, compliance requirements, penalties, FAQs, and a practical checklist.
Read articleUnderstand the DPDP Rules 2025 with this practical guide for Indian startups and businesses. Learn key requirements, compliance steps, FAQs, and best practices.
Read articleLearn about DPDP Act penalties, how financial penalties are determined, common compliance mistakes, and practical steps businesses can take to reduce privacy risks.
Read article