Back to blog
Compliance

What is the DPDP Act? Complete Guide for Indian Businesses (2026)

Learn everything about India's Digital Personal Data Protection (DPDP) Act, including key concepts, compliance requirements, penalties, FAQs, and a practical checklist.

Bilal Shaikh
July 23, 2026
12 min read

What is the DPDP Act?

The Digital Personal Data Protection (DPDP) Act, 2023 is India's primary law governing how organizations collect, use, store, share, and delete digital personal data.

Its objective is to protect the privacy of individuals while enabling organizations to process personal data for lawful purposes.

If your business collects customer details, employee information, website enquiries, payment information, or any other personal data digitally, the DPDP Act is likely relevant to your operations.

The DPDP Rules, 2025 were notified on 13 November 2025. The Data Protection Board is operational, and full compliance is mandatory by 13 May 2027.

Related guides: DPDP explained simply (beginners) · DPDP compliance checklist · Ultimate DPDP compliance guide (2026) · Deadline-focused startup guide · Free readiness check · DPDPKit


Table of contents


Why Was the DPDP Act Introduced?

India has become one of the world's largest digital economies. Every day, millions of people share personal information through mobile apps, websites, banking platforms, e-commerce stores, healthcare applications, education platforms, digital payments, and government portals.

Before the DPDP Act, privacy obligations were spread across multiple regulations and sector-specific rules. The DPDP Act establishes a dedicated legal framework for digital personal data.

Its goals include:

  • Protecting individual privacy
  • Promoting responsible data handling by Data Fiduciaries
  • Building trust in digital services
  • Supporting innovation with clear rules
  • Strengthening cybersecurity and breach accountability

Who Does the DPDP Act Apply To?

The Act applies to organizations that process digital personal data in circumstances covered by the law — including B2B startups, not just consumer apps.

Examples of businesses in scope:

  • SaaS companies
  • E-commerce businesses
  • Healthcare and health-tech startups
  • FinTech companies
  • HR software providers
  • EdTech platforms
  • AI startups
  • Marketing agencies
  • Mobile application developers
  • Online marketplaces

If your business collects names, email addresses, phone numbers, customer accounts, employee records, payment information, or website enquiries, you should evaluate your DPDP obligations.

Quick self-check: Take the free 50-question DPDP readiness check →


What is Personal Data?

Personal data is information that relates to an identifiable individual.

Examples include:

  • Full name, email address, and phone number
  • Residential or billing address
  • Customer ID or employee ID
  • Government-issued identifiers where applicable
  • Profile photographs and account credentials
  • IP addresses and device identifiers (depending on context)

Businesses should understand what personal data they collect — across all systems, not just the website — before designing compliance processes.


Important DPDP Terms

Data Principal

The individual whose personal data is processed — customers, employees, vendors, job applicants, and website users.

Data Fiduciary

An organization that determines why and how personal data is processed. Most startups and businesses collecting customer information are Data Fiduciaries.

Data Processor

A third party that processes data on behalf of a Data Fiduciary — cloud hosting, CRM platforms, payroll software, customer support tools, email marketing platforms, payment gateways.

Data Fiduciaries remain accountable for processor compliance. DPAs (Data Processing Agreements) are essential.

Consent

Where consent is the lawful basis, it must be:

  • Free, specific, informed, and unambiguous
  • Backed by an itemised notice explaining what data is collected and why
  • As easy to withdraw as it was to give

Users should understand exactly why their information is being collected — not buried in Terms of Service.

Grievance Officer

A named person appointed by the Data Fiduciary to handle data-related complaints from Data Principals. Contact details must be published in your privacy policy.

Significant Data Fiduciary (SDF)

The Government may designate certain organizations as Significant Data Fiduciaries based on factors such as volume and sensitivity of data processed. SDFs face additional compliance obligations. Not every startup will qualify, but you should assess your status.


Core Principles of the DPDP Act

While implementation depends on your business, these principles provide a useful foundation.

1. Purpose limitation

Collect personal data only for legitimate and clearly communicated purposes. Avoid collecting information "just in case."

2. Data minimization

Collect only what your business genuinely needs. If a newsletter signup only requires an email address, asking for date of birth may be unnecessary.

3. Accuracy

Take reasonable steps to keep personal data accurate and updated where appropriate.

4. Security

Protect personal data using appropriate technical and organizational measures — access controls, encryption in transit, secure backups, MFA, and employee awareness.

5. Storage limitation

Avoid retaining personal data longer than necessary. Create documented retention schedules and deletion triggers.

6. Accountability

Demonstrate responsible data handling through policies, registers, documented processes, and a compliance workbook that tracks progress.


Rights of Individuals

The Act gives Data Principals greater control over their personal data. Depending on applicable provisions, individuals may have the right to:

  • Receive information about how their data is processed
  • Request correction of inaccurate data
  • Request erasure where appropriate
  • Withdraw consent
  • Nominate another individual to exercise rights in certain circumstances
  • Seek grievance redressal through your Grievance Officer

Businesses should establish workflows to respond to these requests efficiently and log them in a rights request register.


Responsibilities of Businesses

Organizations processing personal data should implement practices such as:

Maintain a privacy policy

Explain what information is collected, why it is collected, how it is used, how long it is retained, Data Principal rights, and Grievance Officer contact details.

Obtain valid consent

Where consent is the basis for processing, ensure users understand what they are agreeing to. Avoid vague or bundled consent requests.

Secure personal data

Security measures should reflect the sensitivity of the information — encryption, secure hosting, role-based access, logging, and regular software updates.

Manage vendors

Maintain a vendor inventory, review how third parties handle personal data, and execute DPAs before sharing data with processors.

Respond to user requests

Prepare workflows for access, correction, erasure, and consent withdrawal. Define response timelines and assign an owner.

Report breaches

In the event of a personal data breach, notify affected Data Principals without undue delay where required, intimate the Data Protection Board without delay, and file a detailed report within 72 hours.


Essential Compliance Documents

A practical compliance program often includes:

Document Purpose
Privacy Policy Explain data handling practices to the public
Itemised Consent Notice Inform users before collecting data; obtain valid consent
Employee Privacy Notice Cover employee and HR data processing
Data Inventory Identify what personal data is held and where
Vendor Register Track third-party processors and DPA status
Data Processing Agreement Define processor responsibilities and safeguards
Data Retention Schedule Specify retention periods and deletion triggers
Rights Request Register Record and track Data Principal requests
Data Breach Response Plan Prepare for incidents including Board reporting
Grievance Officer Appointment Formalise the named contact for complaints
Compliance Workbook Monitor gap assessment and implementation progress

DPDPKit includes all of the above as templates plus an 8-tab workbook — ₹4,999, instant download.

For a full implementation walkthrough, see the Ultimate DPDP Compliance Guide (2026).


Practical Compliance Roadmap

A focused 3-week starting point for early-stage teams. Larger or more complex stacks may need 8–12 weeks — DPDPKit includes a 90-day roadmap for that.

Week 1

  • Identify all personal data across systems
  • Prepare a data inventory
  • Review website forms and signup flows
  • Draft or update Privacy Policy

Week 2

  • Review vendors and send DPAs
  • Draft internal policies (retention, breach, rights SOP)
  • Appoint and publish Grievance Officer details
  • Prepare itemised consent notices

Week 3

  • Test rights request and deletion workflows
  • Train employees on data handling basics
  • Re-run gap assessment — target 80%+ complete
  • Schedule quarterly reviews through May 2027

Penalties Under the DPDP Act

Non-compliance carries significant financial risk. The Data Protection Board has been operational since 13 November 2025.

Violation type Maximum penalty
General contraventions Up to ₹250 crore
Breach of obligations re: children's data Up to ₹200 crore
Failure to implement reasonable security Up to ₹250 crore
Failure to notify Board of breach Up to ₹200 crore

Penalties depend on the nature and gravity of the violation. The Board is already accepting complaints — enforcement risk is not limited to the May 2027 deadline.


Common DPDP Mistakes

Businesses frequently:

  • Copy privacy policies from US or EU competitors
  • Store unnecessary personal information
  • Forget employee and HR data
  • Ignore third-party vendors and DPAs
  • Never document retention periods
  • Lack incident response procedures
  • Cannot quickly locate a customer's data when asked
  • Assume GDPR compliance is sufficient for India

Building structured processes early helps avoid these issues. See the full compliance checklist in our pillar guide.


Benefits of DPDP Compliance

Compliance supports more than legal readiness. It can also help organizations:

  • Build customer and enterprise buyer trust
  • Improve data governance and operational discipline
  • Strengthen security practices
  • Streamline internal processes
  • Support enterprise sales and vendor due diligence
  • Improve vendor oversight
  • Prepare for future certifications (ISO 27001, SOC 2)

DPDP vs GDPR

DPDP GDPR
Jurisdiction India European Union (+ EEA)
Scope Digital personal data Broader personal data scope
Child threshold Under 18 Under 16 (member states may lower to 13)
Grievance Officer / DPO Grievance Officer mandatory DPO required in certain cases
Breach reporting Board intimation + 72-hour detailed report 72 hours to DPA where applicable
Legal framework India's digital ecosystem Established EU privacy regulation

Organizations operating internationally may need to comply with both. A GDPR privacy policy alone is not sufficient for DPDP.

For a deeper comparison, see the DPDP vs GDPR section in our pillar guide.


Frequently Asked Questions

Is the DPDP Act mandatory?

If your organization processes digital personal data in situations covered by the Act, you should assess and implement the obligations that apply to your business.

Does the DPDP Act apply to startups?

Yes. Many startups process customer, employee, or website visitor data and should evaluate their compliance responsibilities.

Do small businesses need DPDP compliance?

Business size alone does not determine applicability. The key consideration is whether and how personal data is processed.

What documents should every startup prepare?

Common documents include a Privacy Policy, consent notices, data inventory, vendor register, rights request register, retention schedule, breach SOP, Grievance Officer appointment, and DPAs for processors. Exact requirements depend on your operations.

Can I copy another company's Privacy Policy?

No. Your Privacy Policy should accurately reflect your own data collection, processing, storage, and retention practices.

Is the DPDP Act only about websites?

No. The Act is relevant wherever your organization processes digital personal data — internal systems, HR processes, customer support platforms, mobile apps, and cloud services.


Free DPDP Readiness Check

Unsure whether your business is ready?

Take our free DPDP readiness check — 50 questions, about 2 minutes, instant score with your top three gaps. No signup required.

Start your free assessment →


Get DPDPKit

If you want a practical starting point instead of creating every document from scratch, DPDPKit includes:

  • Privacy Policy template (DPDP-aligned)
  • Itemised Consent Notice
  • Cookie and Tracking Consent Notice
  • Data Principal Rights Request SOP
  • Grievance Officer Appointment and Charter
  • Data Breach Notification SOP (72-hour Board reporting)
  • Data Processing Agreement (DPA) Template
  • Employee and HR Data Privacy Notice
  • Vendor and Third-Party Processor Checklist
  • Children's Data Processing Policy
  • Data Retention and Deletion Schedule
  • 8-tab Compliance Workbook with gap assessment and 90-day roadmap

₹4,999 — instant download after payment.

Get DPDPKit →


Final thoughts

The DPDP Act represents an important step in strengthening privacy and responsible data handling in India's digital economy. For startups and growing businesses, compliance should not be viewed as a one-time legal exercise, but as an opportunity to build customer trust, improve internal processes, and establish a strong foundation for future growth.

Rather than waiting until the 13 May 2027 deadline becomes urgent, assess your current practices now, document how personal data is handled, and implement practical governance measures over time.

Next steps:

  1. Take the free readiness check to find your gaps
  2. Read the Ultimate DPDP Compliance Guide (2026) for the full checklist and step-by-step plan
  3. Get DPDPKit if you want templates, workbook, and a 90-day roadmap

This guide is for informational purposes only and does not constitute legal advice. Have your counsel or CA review your customised documents before you rely on them.

Written by

Bilal Shaikh

Founder, UXLaunch Lab

11+ years across fintech, Web3, and SaaS. Shipped RoleGrowth — an AI-powered career platform — end-to-end in 8 weeks.

Frequently asked questions

Quick answers.

What is the DPDP Act?
The Digital Personal Data Protection (DPDP) Act, 2023 is India's primary law governing how organizations collect, use, store, share, and delete digital personal data. The DPDP Rules, 2025 were notified on 13 November 2025, with full compliance mandatory by 13 May 2027.
Is the DPDP Act mandatory?
If your organization processes digital personal data in situations covered by the Act, you should assess and implement the obligations that apply to your business — regardless of company size.
Does the DPDP Act apply to startups?
Yes. Many startups process customer, employee, or website visitor data and should evaluate their compliance responsibilities under the Act.
Do small businesses need DPDP compliance?
Business size alone does not determine applicability. The key consideration is whether and how personal data is processed.
Can I copy another company's Privacy Policy?
No. Your Privacy Policy must accurately reflect your own data collection, processing, storage, retention, and vendor relationships.
Is the DPDP Act only about websites?
No. The Act applies wherever your organization processes digital personal data — internal HR systems, CRM, mobile apps, cloud services, and vendor platforms included.

Related articles