Chandrasekar Rathinam logo
Back to all articles
Compliance10 Aug 202610 min read

DPDP Act Compliance Guide for Startups

A practical, engineering-first DPDP Act compliance roadmap for Indian startups: consent and notice, data inventory, deletion flows, vendor contracts, security safeguards, breach reporting, penalties and a 30-60-90 day plan.

Chandrasekar Rathinam

Chandrasekar Rathinam

Cyber Security Consultant · Chennai

Share:

India''s Digital Personal Data Protection Act, 2023 (DPDP Act) applies to almost every startup that processes the digital personal data of people in India — whether you run a SaaS product, a D2C store, a fintech app or a two-person MVP. This guide is a practical, engineering-first roadmap for founders and CTOs who need to get compliant without hiring a full privacy team.

Who the DPDP Act applies to

If you decide why and how personal data is processed, you are a Data Fiduciary. Your users are Data Principals. Vendors that process data on your instructions (analytics, email, cloud, CRM) are Data Processors. The Act covers digital personal data processed in India, and also processing outside India where you offer goods or services to people in India.

There is no revenue or headcount exemption. A seed-stage startup with 500 signups carries the same core obligations as an enterprise — only the additional "Significant Data Fiduciary" duties are reserved for larger, higher-risk operators notified by the government.

The seven obligations that matter most for startups

  1. Lawful basis — process personal data only with free, specific, informed and unambiguous consent, or under a recognised legitimate use (for example, when the user voluntarily provides data for a purpose they clearly asked for, or for employment purposes).
  2. Notice — give a clear, standalone notice at or before collection: what data, for what purpose, how to withdraw consent, how to exercise rights, and how to complain to the Data Protection Board.
  3. Purpose and storage limitation — collect only what the purpose needs and delete data when the purpose is served or consent is withdrawn.
  4. Security safeguards — take reasonable technical and organisational measures to prevent a personal data breach. This is the clause with the highest penalty exposure (up to ₹250 crore).
  5. Breach notification — notify affected users and the Data Protection Board of every personal data breach, without a materiality threshold.
  6. Data Principal rights — support access, correction, erasure, grievance redressal and nomination requests within a defined timeline.
  7. Children''s data — verifiable parental consent for users under 18, with no tracking, behavioural monitoring or targeted advertising directed at children.

A 30-60-90 day compliance plan

Days 1–30: see your data

  • Build a data inventory: every form, SDK, table, bucket, log stream and third-party tool that touches personal data.
  • Map each field to a purpose and a retention period. Anything you cannot justify, stop collecting.
  • List your processors (Stripe/Razorpay, AWS/GCP, Mixpanel, Intercom, HubSpot, Sentry) and check what personal data each one receives.
  • Appoint an accountable owner and publish a contact for privacy queries — for smaller fiduciaries this can be a founder or a designated grievance officer.

Days 31–60: fix consent and contracts

  • Rewrite signup, checkout and newsletter notices in plain language; unbundle marketing consent from service consent and remove pre-ticked boxes.
  • Log consent as an auditable record: user ID, purpose, notice version, timestamp, IP and the exact text shown.
  • Ship a self-serve withdraw consent and delete my account flow — withdrawal must be as easy as giving consent.
  • Put data processing agreements in place with every vendor, covering security, sub-processing, breach reporting and deletion on termination.

Days 61–90: harden and rehearse

  • Enforce encryption in transit and at rest, least-privilege IAM, MFA for admin consoles, and separate prod/non-prod data. Never restore production data into staging.
  • Mask or tokenise personal data in logs, error reports and LLM prompts. AI features are a common leak path — see our AI security guide for LLM features.
  • Automate retention: scheduled deletion jobs, expiring backups, and TTLs on analytics events.
  • Write and rehearse a breach runbook: detection, containment, user notification, Board notification, evidence retention.
  • Validate the whole surface with a vulnerability assessment and penetration test and fix findings before an incident makes them public.

Penalties: what non-compliance actually costs

Financial penalties under the Act''s schedule reach up to ₹250 crore for failing to take reasonable security safeguards, up to ₹200 crore for failures around children''s data or breach notification, and up to ₹50 crore for breaching other duties. The Data Protection Board decides penalties after an inquiry, considering the nature of the breach, its impact, and whether you took mitigating action — which is why documented evidence of your controls is worth as much as the controls themselves.

Startup mistakes we see most often

  • Copy-pasting a GDPR privacy policy and never mapping it to actual systems.
  • Treating a cookie banner as the whole compliance programme.
  • Unlimited employee access to the production database "because we''re small".
  • Personal data sitting forever in Slack exports, Google Sheets and analytics warehouses.
  • No deletion path, so consent withdrawal is impossible to honour.
  • Shipping an AI assistant that sends customer records to a third-party model with no contract or redaction.

Frequently asked questions

Is the DPDP Act already enforceable?

The Act was enacted in August 2023 and is being operationalised through the DPDP Rules, with phased timelines for different obligations. Build now: consent, deletion and security controls take months of engineering, not weeks.

Do we need to store Indian users'' data in India?

The DPDP Act permits cross-border transfers except to countries restricted by the government, so it is far more permissive than a hard localisation mandate — but sector regulators (for example in payments) may impose stricter rules on you.

Are B2B contact details covered?

Yes. A work email that identifies an individual is still personal data.

Where to start this week

Pick the two highest-risk items — an accurate data inventory and a working delete-my-data path — and finish them end to end. If you want an outside review of your consent flows, vendor exposure and security safeguards, get in touch for a DPDP readiness assessment, or read our DPDP Act overview and website compliance essentials.

Related Topics & Tags

#dpdp act compliance#dpdp act for startups#data protection india#dpdp act 2023#startup privacy compliance#consent management india

Have Questions? Get in Touch!

Whether you need an architecture review, a penetration test, or a security programme built from scratch — let's talk about where you are and what comes next.

Contact Me