What the Digital Personal Data Protection Act means
The Digital Personal Data Protection Act, 2023 (DPDP Act) is India’s central framework for regulating the processing of digital personal data. It applies a consent-and-accountability model: individuals, called Data Principals, receive defined rights, while organisations, called Data Fiduciaries, must process data for lawful purposes and protect it with reasonable safeguards.
For founders, product teams and public-facing institutions, the Act is not just a privacy-policy exercise. It affects onboarding, analytics, advertising, customer support, AI development, vendor contracts, security controls and data-retention decisions. As of 2026, teams should track the Act alongside the rules and implementation guidance issued by the government, rather than relying on summaries written before the operating framework is finalised.
Who the Act covers
The DPDP Act generally applies when digital personal data is processed in India, whether the data was collected online or collected offline and later digitised. It can also apply to processing outside India when connected with offering goods or services to people in India, subject to the Act’s conditions and any notified restrictions.
It is relevant to:
- Data Fiduciaries: organisations that decide why and how personal data is processed.
- Data Processors: vendors that process data for a Data Fiduciary, such as cloud providers, CRM platforms, payroll vendors and analytics services.
- Data Principals: individuals to whom the personal data relates.
- Significant Data Fiduciaries: notified entities that may face additional governance, impact-assessment and audit obligations.
A company does not avoid responsibility simply because a third-party SaaS provider stores or analyses the data. The business choosing the purpose and means of processing must understand its vendor chain and allocate responsibilities contractually and operationally.
Core obligations for organisations
Establish a lawful purpose
An organisation should identify the specific purpose for each material processing activity. The Act permits processing based on consent or certain legitimate uses recognised in the legislation. Avoid broad, indefinite statements such as “for all business purposes”. A purpose register should connect each data field to a business need, legal basis, retention period and responsible owner.
Give clear notices
Notices should explain what personal data is being collected, why it is needed and how a person can exercise rights or raise a grievance. Make notices readable at the point of collection, especially in mobile apps, forms and assisted-service settings. Separate optional marketing or personalisation from information necessary to deliver the core service.
This matters particularly for AI products. Teams building data veracity infrastructure for high-stakes AI should document data provenance, validation and access controls, not merely add a generic privacy paragraph to a model card.
Use consent properly
Consent must be free, specific, informed and unambiguous, and it should be as easy to withdraw as it was to give. Maintain evidence of the notice shown, the consent captured, its timestamp, the purpose selected and any later withdrawal. Do not make a person accept unrelated processing as a condition of receiving a service unless the processing is genuinely necessary.
Protect personal data
The Act requires reasonable security safeguards and imposes consequences for breaches. A proportionate baseline includes encryption in transit and at rest, role-based access, secure secrets management, logging, vulnerability management, backups, incident-response procedures and employee training. Security controls should cover development and testing environments, where teams often copy production data without adequate masking.
Manage retention and deletion
Create retention schedules based on purpose, contractual needs and legal requirements. When a purpose ends, delete or anonymise data unless another valid obligation requires retention. Deletion should include operational databases, caches, exports, backups where technically feasible, and downstream processors. Keep an auditable record of what was deleted and why.
Control processors and suppliers
Before sharing data with a vendor, assess its security, sub-processors, breach-notification process, access model, deletion commitments and data-location arrangements. Contracts should define permitted purposes, confidentiality, security measures, assistance with rights requests and exit procedures. A vendor inventory is essential for startups using multiple analytics, marketing and AI APIs.
Rights of Data Principals
Individuals can request information about their personal data and processing activities, seek correction or completion of inaccurate data, request erasure where applicable, and use the prescribed grievance mechanism. They may also nominate another person to exercise rights in certain circumstances.
Organisations should make requests easy to submit and verify without collecting excessive new information. Set internal service levels, route requests to accountable owners and preserve evidence of the response. A privacy inbox alone is not a process: customer support, engineering, legal and security teams need a shared workflow.
The Act also places duties on Data Principals, including providing authentic information and not filing false or frivolous grievances. These duties do not remove an organisation’s obligation to respond fairly and transparently.
Children’s data and consent management
The DPDP Act gives children enhanced protection. Processing a child’s data requires verifiable parental consent, and organisations must not undertake prohibited tracking, behavioural monitoring or targeted advertising directed at children under the applicable requirements.
Products used by schools, edtech companies, gaming platforms, healthcare providers and family services should design age assurance and parental-consent flows early. Do not treat a date-of-birth field as a complete control. Document how the organisation handles uncertain age, revocation, account deletion and data shared with processors.
Penalties and breach readiness
The Board established under the Act can impose significant monetary penalties, with the schedule allowing penalties of up to ₹250 crore for certain breaches. The actual exposure depends on the contravention and applicable proceedings; organisations should not describe the Act as imposing a blanket percentage of global turnover, a claim sometimes carried over from other regimes.
Prepare a breach playbook covering detection, containment, investigation, decision rights, communications, regulator engagement where required and support for affected individuals. Run tabletop exercises at least annually. A breach register should capture near misses as well as confirmed incidents so recurring control failures are visible.
A practical compliance roadmap
Start with a six-step programme:
- Map data: inventory systems, fields, collection points, users, processors and cross-border flows.
- Classify purpose: document why each dataset is processed and whether it is necessary.
- Fix notices and consent: rewrite user-facing language and build reliable consent records.
- Strengthen controls: close gaps in access, encryption, logging, deletion and incident response.
- Operationalise rights: create intake, verification, fulfilment and escalation workflows.
- Measure continuously: track deletion completion, vendor reviews, unresolved requests, incidents and training coverage.
Analytics can help identify duplicate records and retention gaps, but teams should avoid creating new privacy risks while measuring compliance. For example, no-code data analytics platforms in India may accelerate reporting, but access permissions, export controls and processor terms still require human review.
What startups should do first
A small company does not need an elaborate privacy department to begin. Assign one accountable owner, maintain a plain-language data inventory, remove unnecessary collection, secure production access and review every external API that receives personal data. Build privacy requirements into product discovery and vendor procurement rather than retrofitting them after launch.
For AI teams, avoid training or fine-tuning on scraped, customer or employee data without documenting provenance, purpose and permissions. The practical standard is simple: know what you collected, why you collected it, where it went, who can access it and when it will be deleted.
FAQ
Is the DPDP Act the same as GDPR?
No. Both regulate personal-data processing, but their definitions, rights, lawful bases, institutions and penalties differ. An organisation compliant with GDPR should still perform an India-specific gap assessment.
Does the Act apply to companies outside India?
It can apply to processing outside India when the activity is connected with offering goods or services to Data Principals in India, subject to the Act and applicable notifications.
Is a privacy policy enough for compliance?
No. A policy explains practices but does not replace consent records, security safeguards, processor controls, retention schedules, rights workflows or breach readiness.
What should a founder do this month?
Map personal-data flows, stop unnecessary collection, review vendors, update notices, assign an owner and test an incident-response and deletion process. Then monitor official rules and guidance as the framework develops in 2026.