Introduction: Why the DPDP Act Matters for Businesses in India
Data has become a core business asset. Startups collect customer details through websites, SaaS companies process user information, e-commerce businesses maintain customer databases, employers hold employee records, and digital marketing businesses generate and analyse leads.
This is why the DPDP Act 2023, formally known as the Digital Personal Data Protection Act, 2023, matters to businesses across India.
A business does not need to be a large technology company to have data protection obligations. A startup collecting names and mobile numbers through a lead-generation form, an HR department maintaining employee records digitally, or an online store processing customer addresses may all be dealing with digital personal data covered by the statutory framework, subject to the Act's scope and exclusions.
For founders, DPDP compliance should not be treated as merely an IT or cybersecurity issue. It is also a legal, governance and business-risk issue involving how an organisation collects, uses, stores, shares, protects and ultimately erases personal data.
The law was enacted in 2023, but businesses should not assume that every provision became enforceable immediately upon enactment. The Central Government subsequently notified a phased commencement framework, while the Digital Personal Data Protection Rules, 2025 were notified on 14 November 2025. The practical compliance position therefore needs to be understood against the notified implementation timeline.
For startups, MSMEs, SaaS platforms, websites and other digital businesses, the right approach is to understand what data they handle and build compliance into their operations.
[Internal Link: DPDP Compliance Services]
What Is the DPDP Act 2023?
The full name of the law is the Digital Personal Data Protection Act, 2023.
The Act provides a legal framework for processing digital personal data in a manner that recognises both:
- the right of individuals to protect their personal data; and
- the need to process personal data for lawful purposes.
In simple business terms, the DPDP Act regulates important aspects of how covered organisations handle personal data in the digital environment.
The Act received the President's assent on 11 August 2023. However, its commencement was not a case of every substantive provision automatically becoming operational on that date. A Government notification dated 13 November 2025 brought specified provisions into force immediately, provided for certain provisions to commence one year later, and provided for the remaining major provisions to commence eighteen months from the notification date.
The current phased implementation position
The official commencement notification broadly creates three stages:
- From publication of the notification on 13 November 2025: specified provisions, including provisions relating to definitions, the Data Protection Board framework and certain rule-making and institutional provisions, came into force.
- One year from publication: section 6(9) and section 27(1)(d) are scheduled to come into force.
- Eighteen months from publication: the principal substantive provisions relating to application, notice, consent, legitimate uses, Data Fiduciary obligations, children's data, Significant Data Fiduciaries, Data Principal rights, exemptions, cross-border processing and several other provisions are scheduled to come into force.
This distinction is important. A company planning DPDP compliance in India should prepare against the notified timeline rather than incorrectly assuming that all operational obligations became immediately enforceable in August 2023.
DPDP Act 2023 and DPDP Rules 2025: What Is the Difference?
The DPDP Act 2023 and the DPDP Rules 2025 are connected, but they are not the same legal instrument.
The DPDP Act, 2023
The Act is the primary legislation. It establishes the core legal framework, including concepts such as:
- Data Principal
- Data Fiduciary
- Data Processor
- consent
- certain legitimate uses
- rights of individuals
- obligations of Data Fiduciaries
- children's personal data
- Significant Data Fiduciaries
- penalties and adjudication.
The Digital Personal Data Protection Rules, 2025
The Digital Personal Data Protection Rules, 2025 provide operational and implementation details for the statutory framework. They were notified by MeitY on 14 November 2025, with a corrigendum subsequently published by the Ministry. The Rules cover matters such as notices, Consent Managers, security safeguards, personal data breach intimation, rights-related procedures and other operational aspects.
A simple way to understand the difference
Think of the legal framework this way:
The Act answers: What does the law require and what rights and obligations exist?
The Rules answer: How are specified parts of that framework expected to operate in practice?
Phased enforcement remains important
The Rules and the Act must also be read with the official commencement notifications. The Rules themselves do not mean that every corresponding substantive obligation became immediately enforceable on 14 November 2025. Businesses should identify which provisions are currently in force and which obligations fall into the later notified commencement stages.
For this reason, a startup should not wait until the final commencement date to begin preparation. Data inventories, privacy notices, consent flows, vendor arrangements and incident-response systems can take significant time to implement.
Who Does the DPDP Act Apply To?
The Act applies, subject to its provisions and exclusions, to the processing of digital personal data:
- within India, where personal data is collected in digital form; or
- collected in non-digital form and subsequently digitised.
It also applies to the processing of digital personal data outside India if the processing is in connection with an activity related to offering goods or services to Data Principals within India.
Practical examples
A startup collecting customer details
A startup collecting names, email addresses and mobile numbers through its website may be processing digital personal data.
An e-commerce website
An online store may process customer names, addresses, contact information, account details and transaction-related personal data.
An HR department
A company storing employee records, contact details, payroll information and other identifiable information in digital systems may need to assess those processing activities under the DPDP framework.
A SaaS platform
A SaaS company may process account information, user profiles, usage information and other personal data through its digital platform.
A company using online lead-generation forms
A business collecting prospect information through advertisements, landing pages, webinars or online enquiry forms should examine why the data is collected, the applicable statutory ground for processing and how the information is used or shared.
Important exclusions
The Act contains exclusions and exemptions, including exclusions concerning personal data processed by an individual for personal or domestic purposes and personal data made publicly available in specified circumstances. It also contains exemptions for particular situations and classes of processing under section 17.
These exclusions should not be reduced to a simplistic statement that publicly available data or any business-related information is automatically outside the law. Applicability depends on the precise statutory wording and the particular processing activity.
Key Definitions Under the DPDP Act
What Is Personal Data?
Under the Act, personal data means any data about an individual who is identifiable by or in relation to that data.
Examples may include:
- name
- mobile number
- email address
- customer account information
- employee information
- an online identifier where it identifies an individual in context.
The key issue is whether the data relates to an identifiable individual.
Who Is a Data Principal?
A Data Principal is the individual to whom the personal data relates.
For example:
- a customer whose details are held by an online store;
- an employee whose information is maintained by a company;
- a user registered on a SaaS platform.
For a child or a person with a disability in circumstances covered by the Act, the statutory framework recognises the relevant parent, lawful guardian or other authorised person in the manner provided by the legislation.
Who Is a Data Fiduciary?
A Data Fiduciary is a person who, alone or together with other persons, determines the purpose and means of processing personal data.
In practical terms, this is often the organisation that decides:
- what data to collect;
- why it is needed;
- how it will be used;
- how long it will be retained.
A startup operating a customer platform may therefore be a Data Fiduciary in relation to personal data processed for its business purposes.
What Is a Data Processor?
A Data Processor processes personal data on behalf of a Data Fiduciary.
For example, a company may engage:
- a cloud service provider;
- a payroll service provider;
- a customer-support platform;
- a technology vendor.
The fact that a processor performs processing does not remove the Data Fiduciary's statutory accountability for obligations applicable to it under the Act.
What Is a Consent Manager?
A Consent Manager is a person registered with the Data Protection Board who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform.
The Rules provide operational requirements concerning Consent Managers, including registration and other conditions. Consent Manager compliance should therefore be understood by reference to the Act and the notified Rules, rather than simply treating any consent-management software as a statutory Consent Manager.
What Is a Significant Data Fiduciary?
A Significant Data Fiduciary is a Data Fiduciary, or class of Data Fiduciaries, notified by the Central Government under section 10.
The Act identifies relevant factors including:
- volume and sensitivity of personal data processed;
- risk to the rights of Data Principals;
- potential impact on sovereignty and integrity of India;
- risk to electoral democracy;
- security of the State;
- public order; and
- other factors as may be considered necessary.
A company does not become a Significant Data Fiduciary merely because it is large. The statutory status depends on Government notification.
What Are the Lawful Grounds for Processing Personal Data?
The DPDP Act provides that personal data may be processed for a lawful purpose where the Data Principal has given consent, or for certain legitimate uses specified under the statutory framework.
Consent-based processing
Consent is a central ground for processing personal data under the Act.
Certain legitimate uses
Section 7 recognises specified situations described as certain legitimate uses. These include statutory categories such as voluntary provision of personal data for a specified purpose, certain functions of the State, compliance with legal obligations, medical emergencies and other situations expressly provided by the Act.
A business should therefore not assume that every legitimate commercial purpose qualifies as a "legitimate use" under section 7. The processing activity must fall within the statutory framework.
The Indian DPDP model should also not be treated as identical to the GDPR. While the two frameworks both address personal data protection, their terminology, structure and legal grounds for processing differ.
Consent Under the DPDP Act
Where processing is based on consent, the Act requires consent to be:
- free;
- specific;
- informed;
- unconditional;
- unambiguous; and
- based on clear affirmative action.
Consent must signify agreement to the processing of personal data for the specified purpose and must be limited to the personal data necessary for that specified purpose.
Consent requests and notices
The Act's notice and consent framework is important for websites and applications.
A practical website example:
A visitor submits a form requesting a product demonstration. The company should consider:
- what personal data is requested;
- why each category of data is required;
- what notice should be provided;
- whether the proposed processing is based on consent or another statutory ground;
- whether additional marketing use requires separate consideration.
The Rules provide additional operational detail for notices, including requirements aimed at making relevant information clear and understandable.
Withdrawal of consent
The Act also provides for withdrawal of consent. The process of withdrawal should be as easy as the process used to give consent.
For businesses, this means consent cannot simply be collected and then forgotten. Systems should be capable of recording and operationalising withdrawal where consent is the basis of processing.
[Internal Link: Privacy Policy Drafting]
Data Principal Rights Under the DPDP Act
Right to Access Information About Personal Data
A Data Principal has statutory rights concerning information about personal data processed by the Data Fiduciary, subject to the Act's provisions.
For the individual: This supports transparency regarding how their personal data is being processed.
For the business: A practical rights-request process should be designed so requests can be received, verified, routed to relevant teams and answered appropriately.
Right to Correction and Erasure
The Act provides for rights relating to correction, completion, updating and erasure of personal data, subject to the statutory framework.
For the individual: Incorrect or unnecessary personal data may be capable of being addressed through the applicable process.
For the business: Data systems should not make correction or deletion operationally impossible. Organisations should know where relevant data exists, including in key internal systems and processor-managed environments.
Right of Grievance Redressal
The Data Principal has a right to readily available grievance redressal by the Data Fiduciary or Consent Manager, as applicable.
For the individual: There should be a meaningful channel to raise concerns.
For the business: A company should establish a contact mechanism and an internal process for receiving and addressing grievances.
Right to Nominate
A Data Principal has a right to nominate another individual who may exercise relevant rights in the event of the Data Principal's death or incapacity, subject to the Act.
Businesses should consider how their rights-management procedures will address such situations.
Duties of Data Principals
The Act also places certain duties on Data Principals.
These include duties not to:
- register false or frivolous grievances or complaints;
- furnish false particulars or suppress material information when providing personal data for a specified purpose;
- impersonate another person while providing personal data;
- suppress information in specified circumstances; or
- otherwise act in a manner contrary to the duties set out in section 15.
The Schedule provides that breach of duties under section 15 may attract a penalty of up to ₹10,000.
Obligations of a Data Fiduciary
For businesses, the obligations of a Data Fiduciary form the operational core of DPDP compliance.
Lawful processing
A business should identify the purpose of each significant processing activity and the applicable statutory ground.
Notice requirements
Where required under the applicable framework, the Data Principal should receive the prescribed notice concerning the relevant personal data and purpose of processing.
Consent management
Where consent is relied upon, organisations should maintain appropriate mechanisms to obtain, record and honour consent and withdrawal.
Accuracy and completeness
Where personal data is likely to be used to make a decision affecting a Data Principal or disclosed to another Data Fiduciary, the Act requires reasonable efforts to ensure that the personal data is complete, accurate and consistent.
Reasonable security safeguards
A Data Fiduciary must protect personal data in its possession or under its control by taking reasonable security safeguards to prevent personal data breaches.
This is not necessarily a single cybersecurity product or checklist. Security safeguards should be appropriate to the processing environment and risks involved.
Personal data breach obligations
A Data Fiduciary must comply with the applicable statutory and Rules-based breach-intimation requirements.
Erasure and retention
The Act requires erasure of personal data where consent is withdrawn or the specified purpose is no longer being served, unless retention is necessary for compliance with law. The Rules provide further operational detail for specified situations and periods.
Grievance redressal
Businesses should maintain an accessible process for handling grievances.
Data Processor management
A Data Fiduciary may engage a Data Processor to process personal data on its behalf for the relevant purpose. Vendor and processor arrangements should therefore be reviewed from both a contractual and operational perspective.
Accountability
Using an external vendor does not automatically transfer the Data Fiduciary's statutory responsibilities. A founder should know:
- who processes the company's data;
- where key data is stored;
- what processors can do with it;
- what security obligations apply;
- how incidents will be reported.
Personal Data Breach: What Should a Company Do?
The Act defines a personal data breach broadly to include unauthorised processing or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data that compromises confidentiality, integrity or availability.
A company should therefore not treat a breach as limited only to a traditional "hack". Accidental exposure, unauthorised sharing or loss of availability may also require legal assessment under the applicable framework.
A practical incident-response approach
A business should have a documented process covering:
- identification of the incident;
- containment;
- preservation of relevant evidence;
- assessment of affected data and individuals;
- internal escalation;
- legal assessment;
- notifications where required;
- remediation and prevention of recurrence.
The notified Rules provide that, upon becoming aware of a personal data breach, the Data Fiduciary must intimate affected Data Principals without delay with specified information. The Rules also require intimation to the Board without delay and detailed information within 72 hours of becoming aware of the breach, unless the Board allows a longer period upon a written request. These operational requirements must be read with the notified phased commencement timeline.
The key business lesson is simple: do not wait for a breach to decide who is responsible for handling one.
Processing Children's Personal Data
The Act defines a child as an individual who has not completed 18 years of age.
A Data Fiduciary must, before processing personal data of a child or a person with a disability, obtain verifiable consent of the parent or lawful guardian, as applicable, in accordance with the statutory and Rules-based framework.
The Act also restricts:
- tracking or behavioural monitoring of children; and
- targeted advertising directed at children.
However, the Act also permits the Central Government to notify exemptions or specified classes of Data Fiduciaries or purposes subject to statutory conditions. Businesses should therefore check the latest notified position rather than assuming that every activity involving a person below 18 is governed without any statutory exception.
Significant Data Fiduciary: Who Can Be Classified as One?
A Significant Data Fiduciary is not a self-selected label. The Central Government may notify a Data Fiduciary or class of Data Fiduciaries as a Significant Data Fiduciary.
Additional obligations under the Act include, as applicable:
- appointment of a Data Protection Officer;
- appointment of an independent data auditor;
- periodic Data Protection Impact Assessment;
- periodic audit; and
- other measures as may be prescribed.
The Act requires the relevant designation to be based on statutory factors. Therefore, not every startup with substantial user numbers, and not every large company, should automatically be described as a Significant Data Fiduciary.
DPDP Compliance for Startups and MSMEs
For a startup, DPDP compliance should be proportionate to the nature and scale of processing while remaining aligned with the applicable law.
A practical framework is:
1. Identify what personal data you collect
List customer, employee, vendor, prospect and user information.
2. Map where the data comes from
For example:
- website forms;
- mobile apps;
- advertisements;
- CRM systems;
- email campaigns;
- recruitment platforms;
- third-party integrations.
3. Identify why the data is being processed
Document the business purpose for each major processing activity.
4. Review the lawful basis or statutory ground
Assess whether processing is based on consent or another applicable statutory ground.
5. Update privacy notices
Generic copied privacy policies are not a reliable compliance strategy.
[Internal Link: Privacy Policy Drafting]
6. Review consent mechanisms
Examine:
- forms;
- app onboarding;
- marketing opt-ins;
- newsletter subscriptions;
- account registration flows.
7. Review contracts with third-party processors and vendors
Identify cloud providers, payroll vendors, CRM tools, marketing platforms and other processors.
8. Implement reasonable security safeguards
Security should cover people, processes and technology, not only software.
9. Establish grievance and rights-request processes
Decide who receives requests and how the organisation responds.
10. Create a personal data breach response plan
Assign responsibility before an incident occurs.
11. Review data retention and deletion practices
Do not retain data indefinitely simply because storage is inexpensive.
12. Monitor phased implementation and further notifications
DPDP compliance is a legal and operational programme, not a single document.
[Internal Link: Startup Legal Services]
DPDP Compliance Checklist for Companies
- Identify all major categories of personal data collected.
- Prepare a data inventory.
- Map how personal data moves across the organisation.
- Identify data collected through websites and mobile applications.
- Review website and lead-generation forms.
- Review the applicable statutory ground for processing.
- Review privacy notices.
- Review consent language and consent flows.
- Create a process for withdrawal of consent where applicable.
- Review cookies and tracking technologies where relevant.
- Identify employee and HR data processing.
- Identify customer and prospect data processing.
- Identify third-party vendors and Data Processors.
- Review data-processing arrangements and relevant contracts.
- Implement reasonable security safeguards.
- Create and test a breach-response procedure.
- Establish a grievance-redressal mechanism.
- Prepare procedures for rights-related requests.
- Review retention and deletion practices.
- Maintain appropriate internal governance and documentation.
- Monitor Government notifications and the phased implementation timeline.
This DPDP compliance checklist should be treated as a starting framework, not a substitute for reviewing the specific data practices of a particular business.
DPDP Act Penalties: What Are the Financial Risks?
The penalty framework is set out in the Schedule to the DPDP Act.
The maximum penalties include:
| Nature of breachMaximum statutory penalty | |
| Failure to take reasonable security safeguards to prevent a personal data breach | May extend to ₹250 crore |
| Failure to give required notice of a personal data breach to the Board or affected Data Principal | May extend to ₹200 crore |
| Breach of obligations relating to children's personal data | May extend to ₹200 crore |
| Breach of additional obligations of a Significant Data Fiduciary | May extend to ₹150 crore |
| Breach of duties of a Data Principal | May extend to ₹10,000 |
| Breach of a voluntary undertaking accepted by the Board | Up to the extent applicable to the underlying breach |
| Breach of any other provision of the Act or Rules | May extend to ₹50 crore |
Maximum penalty is not automatic
It is important not to state that every violation automatically results in the maximum amount.
The Act provides for penalties that may extend to the specified limits. The actual outcome depends on the statutory adjudicatory process and the circumstances of the particular non-compliance.
For founders, the correct takeaway is not "every mistake will cost ₹250 crore". It is that serious categories of non-compliance can carry significant statutory financial exposure.
DPDP Act vs GDPR: Key Differences
| IssueDPDP Act, 2023GDPR | ||
| Primary jurisdiction | India-focused statutory framework | European Union and EEA data protection framework |
| Core scope | Processing of digital personal data within the statutory scope | Processing of personal data within its own territorial and material scope |
| Legal grounds | Consent and certain legitimate uses under the Act | Multiple lawful bases expressly structured under GDPR |
| Consent | Defined within the DPDP statutory framework | Detailed GDPR-specific consent requirements |
| Individual rights | Rights expressly provided by the DPDP Act | Broader GDPR rights framework with different terminology and structure |
| Regulator | Data Protection Board of India framework | Supervisory authorities in EU/EEA jurisdictions |
| Penalties | Schedule-based maximum penalties | GDPR-specific administrative fine framework |
| Business approach | Indian statutory and Rules-based compliance model | GDPR accountability and compliance framework |
The two frameworks should not be treated as identical.
A company that has invested heavily in GDPR compliance may already have useful privacy processes, but it should still conduct a separate assessment of Indian DPDP requirements.
How Should a Startup Prepare for DPDP Compliance?
Step 1: Conduct a Data Audit
Identify what personal data exists and where it is stored.
Step 2: Identify Data Processing Activities
Document key activities involving collection, storage, use, sharing and deletion.
Step 3: Review Consent and Notices
Review whether the current user journey aligns with the applicable statutory framework.
Step 4: Review Website and App Compliance
Check:
- enquiry forms;
- sign-up flows;
- account creation;
- marketing opt-ins;
- privacy information;
- user communication processes.
[Internal Link: Terms and Conditions for Websites]
Step 5: Review Third-Party Vendors
Create a vendor register for processors and significant service providers.
Step 6: Strengthen Data Security
Assess access controls, authentication, backups, incident detection and internal data-handling practices.
Step 7: Create Internal Policies and Procedures
Document how the organisation handles personal data in practice.
Step 8: Train Relevant Teams
Founders, HR, marketing, technology, customer support and sales teams may all handle personal data.
Step 9: Establish a Breach-Response Process
Create an escalation matrix before an incident occurs.
Step 10: Monitor Legal Developments and Implementation Deadlines
The DPDP framework has a notified phased commencement structure. Businesses should track further notifications, guidance and developments rather than relying permanently on an old compliance memo.
Common DPDP Compliance Mistakes Businesses Should Avoid
Copying a generic privacy policy
A privacy policy copied from another website may not reflect the company's actual processing practices.
Collecting more data than necessary
Every additional category of personal data increases governance and security responsibilities.
Using vague consent language
Consent requests should not leave users guessing what data is being processed and for what purpose.
Failing to map third-party data sharing
Many businesses know what data is in their CRM but do not know every platform to which that data is transmitted.
Ignoring employee and HR data
Privacy compliance is not only about customers.
Having no breach-response plan
The first serious incident should not be the first time the company decides who handles a breach.
Treating compliance as a one-time documentation exercise
Data practices change as products, vendors and business models evolve.
Assuming GDPR compliance automatically means DPDP compliance
The frameworks overlap in some areas but are legally distinct.
Frequently Asked Questions About the DPDP Act 2023
1. What is the DPDP Act 2023?
The DPDP Act 2023 is India's Digital Personal Data Protection Act, which establishes a framework for processing digital personal data while recognising individual data rights and the need for lawful processing.
2. When was the DPDP Act enacted?
The Act received Presidential assent on 11 August 2023. Its provisions have a separately notified phased commencement timeline.
3. What are the DPDP Rules 2025?
The Digital Personal Data Protection Rules, 2025 provide operational details for implementing parts of the DPDP framework. They were notified on 14 November 2025.
4. Who needs to comply with the DPDP Act?
Businesses and other persons processing digital personal data within the Act's scope should assess their obligations, subject to statutory exclusions and exemptions.
5. Does the DPDP Act apply to startups?
Yes, a startup can fall within the Act's scope if its processing activities satisfy the statutory application provisions. Size alone does not determine applicability.
6. What is a Data Fiduciary under the DPDP Act?
A Data Fiduciary is a person who determines the purpose and means of processing personal data.
7. What is the difference between a Data Principal and a Data Fiduciary?
The Data Principal is the individual to whom the personal data relates. The Data Fiduciary determines the purpose and means of processing that data.
8. What are the penalties under the DPDP Act?
Depending on the category of breach, the statutory maximum penalties range up to ₹250 crore. The maximum is not automatically imposed in every case.
9. Does the DPDP Act apply to employee data?
Digital employee data may fall within the statutory framework, subject to the Act's application provisions, exemptions and the particular processing activity.
10. How can a company become DPDP compliant?
A company should conduct a data audit, map processing activities, review applicable statutory grounds, update notices and consent processes, strengthen security, manage vendors, establish rights and grievance procedures, and monitor the phased implementation timeline.
11. Is the DPDP Act the same as GDPR?
No. Both are data protection frameworks, but their legal structures, terminology, rights, grounds for processing, regulatory systems and penalty frameworks differ.
12. What should a startup do first for DPDP compliance?
Start with a data inventory and data-mapping exercise. A company cannot effectively manage legal obligations if it does not know what personal data it collects, where it is stored and who receives it.
Conclusion
The DPDP Act 2023 is a major development in India's data protection law, but businesses should approach it with legal precision. The Act, the Digital Personal Data Protection Rules, 2025, and the officially notified phased commencement timeline must be read together.
For founders, the most practical starting point is to understand their actual data practices. Identify the personal data being collected, why it is processed, where it travels, who has access to it, how it is secured and how the organisation will respond when a Data Principal exercises a right or a security incident occurs.
DPDP compliance should be treated as an ongoing governance and operational process, not merely as a privacy policy placed on a website.
If your startup or business collects, stores or processes personal data and needs help understanding its DPDP compliance obligations, the legal team at Founders Legal Desk can assist with assessing your data practices and developing an appropriate compliance framework.
Get in Touch with Founders Legal Desk
Website: www.founderslegaldesk.com
WhatsApp: +91 97117 52388
Email: legal@founderslegaldesk.com
