What is the DPDP Act — And Why Startups Can't Afford to Ignore It

Trending

What is the DPDP Act — And Why Startups Can't Afford to Ignore It

Introduction

Most Indian startups have a data privacy policy that was copy-pasted from somewhere in 2019, has never been reviewed, and lives on a webpage nobody visits. That was fine, until now.

The Digital Personal Data Protection (DPDP) Act, 2023 establishes India’s legal framework for the processing of digital personal data. It applies to the processing of digital personal data in India and also to certain processing outside India where such processing is connected with offering goods or services to Data Principals in India.

What the DPDP Act Actually Says

After years of data misuse, ignored consent banners, and privacy policies written in font sizes only bats can read, India now has a proper legal framework around personal data.

The DPDP framework establishes a set of obligations for organisations, with the relevant provisions coming into force in phases:

  • Informed Consent Before Collection Organisations must process personal data in accordance with the lawful grounds and requirements under the DPDP Act. Where consent is the applicable basis, it must meet the requirements prescribed under the Act.
  • 🎯
    Purpose Limitation The data may only be used for the purpose for which it was gathered.
  • 👤
    Data Principal Rights The DPDP framework provides Data Principals with rights relating to their personal data, including rights concerning access to information, correction and erasure, subject to the applicable provisions and conditions.
  • 🚨
    Mandatory Breach Reporting The DPDP framework establishes obligations relating to personal data breaches, including requirements concerning notification, as the relevant provisions come into force.
  • 🏢
    Vendor Accountability Organisations will need to consider their responsibilities when engaging Data Processors and establish appropriate controls as the relevant provisions come into force.
DPDP Act framework with Data Fiduciary, Data Principal, Data Processor, and DPBI relationships

What makes the DPDP Act significant is not just the obligations themselves; it is the accountability structure behind them. For the first time, Indian organisations cannot simply publish a privacy policy and consider the matter closed. There is now an expectation of demonstrable, documented compliance.

DPDP Act, 2023 and DPDP Rules, 2025

The DPDP Act, 2023 establishes the legal framework for the processing of digital personal data in India, while the DPDP Rules, 2025 provide detailed requirements for implementing several provisions of the Act. The Act and Rules are being brought into force in phases, so organisations should assess the requirements applicable to them and prepare accordingly.

How the DPDP Act Impacts Startups

Large enterprises have legal and compliance teams built for exactly this. Most startups do not.

Product Design

Privacy should be embedded into the product architecture from the start, not as an add-on at the end. Consent mechanisms, data minimisation and purpose limitation should be considered during product design so that organisations are prepared to meet the DPDP framework as the relevant provisions come into force. Startups building apps that handle health data, financial records, or location information face particularly close scrutiny under the Act.

Operations

Every data collection activity — CRM records, app analytics, HR data, and marketing lists — needs to be documented: what is collected, from whom, why, and for how long. Maintaining a clear data inventory is an important part of preparing for the requirements of the DPDP framework. As the relevant provisions come into force, organisations will need to assess their data-processing activities and put appropriate records, controls and retention practices in place.

Customer Rights

The DPDP framework provides Data Principals with rights relating to their personal data, including rights concerning access to information, correction and erasure, subject to the applicable provisions and conditions. As the relevant provisions come into force, organisations will need to establish defined processes for receiving and responding to Data Principal requests within the applicable timelines. An informal process built around email threads and manual effort will not scale and will not hold up under regulatory scrutiny.

Diagram comparing DPDP Act requirements against typical startup compliance gaps

Interested in knowing how to handle data breaches? Check out our article — How to Handle Data Breaches Under the DPDP Act

The Compliance Challenges Startups Face

Many founders dismiss DPDP compliance as a problem for later. The issue is that "later" tends to arrive at the worst possible moment: a due diligence process, an enterprise sales cycle, or an actual data incident.

The structural challenges are real:

Unclear Ownership

Compliance ownership is unclear. In most startups, it defaults to the CTO or a developer already stretched thin across other priorities.

Consent At Every Touchpoint

Consent management across multiple touchpoints, web, app, and third-party integrations, is operationally complex and easy to get wrong.

No DSR Process

Handling Data Subject Requests requires a defined, documented process. Most startups have none.

No Audit-Ready Documentation

Audit-ready documentation is almost never in place. Regulators do not accept "it's somewhere in Notion."

Vendor Perimeter

Vendor management adds another layer: any third-party processor handling personal data on the organisation's behalf also falls within the compliance perimeter.

The Cost of Non-Compliance

The DPDP Act provides for significant financial penalties for specified contraventions, with penalties of up to ₹250 crore for certain breaches. Beyond the financial exposure, a data breach or regulatory action causes reputational damage that is significantly harder to recover from. Enterprise clients walk away. Investors ask harder questions. User trust, once broken, does not return quickly.

DPDP Act penalty tiers up to ₹250 crore per instance, shown alongside overlapping RBI and SEBI compliance obligations for fintech companies

For fintechs, the stakes are higher still. DPDP compliance does not exist in isolation; it sits alongside RBI compliance and SEBI compliance obligations that frequently overlap. Non-compliance in one area tends to create exposure across the others. Regulators communicate. Patterns get noticed.

Building a Compliance Foundation

Preparing for the DPDP framework does not require a large legal team. It takes a systematic approach and the necessary tools — built around five foundational steps that help organisations prepare for the requirements that will apply as the relevant provisions come into force.

Diagram showing the required workflow for handling Data Subject Requests under the DPDP Act
01
Complete Data Audit Conduct a complete data audit, documenting each data collection point, storage location, access controls and retention period.
02
Build Consent Workflows Create consent workflows that are clear, specific and designed to support the consent requirements of the DPDP framework where consent is applicable.
03
Create A DSR Handling Process Create a systematic mechanism for handling Data Principal requests so the organisation is prepared as the relevant rights and obligations become applicable.
04
Document Everything Keep records of data policies, processing operations, vendor agreements and incident response plans.
05
Automate Compliance Operations Implement compliance automation to save manual labour, eliminate gaps and minimise the risk of human error.

Conclusion

The startups that treat DPDP compliance as infrastructure, rather than a checkbox, are the ones that scale without disruption.

DPDP compliance, ISO 27001 certification, and strong GRC practices signal organisational maturity. They open doors in enterprise sales. They reduce friction in fundraising. They build the kind of user trust that marketing budgets cannot replicate.

The DPDP framework represents a significant shift in India's approach to digital personal data protection. As the relevant provisions of the DPDP Act and Rules come into force, organisations will need to assess which requirements apply to them and implement the necessary processes and controls. Startups that build compliance into their foundation now will be far better positioned than those scrambling to catch up later.