Compliance is an engineering programme, not a policy page
India's Digital Personal Data Protection Act applies to any site processing the personal data of individuals in India. Publishing a privacy policy satisfies almost none of it. The obligations land in forms, cookies, databases, logs and vendor contracts.
Consent and notice
- Free, specific, informed, unconditional and unambiguous consent — no pre-ticked boxes, no bundling
- An itemised notice at collection stating purposes, rights and the grievance channel
- Withdrawal must be as easy as giving consent, and must propagate to processors
- Verifiable parental consent for users under 18, with no behavioural advertising to children
Data minimisation and retention
Collect only what the stated purpose requires, and delete when the purpose ends. That means real retention schedules enforced by scheduled jobs — including backups, analytics warehouses and log stores, which are where "deleted" data usually survives.
Data principal rights
Build workflows, not inboxes: access and summary of processing, correction and erasure, nomination, and grievance redressal with a published response window. Every request needs identity verification and an audit trail.
Security safeguards and breach reporting
Reasonable security safeguards are mandatory: encryption in transit and at rest, access control, logging, and tested backups. Personal data breaches must be reported to the Data Protection Board and to affected principals — so detection and an executable incident runbook are compliance controls, not nice-to-haves.
Vendors and transfers
Every processor — analytics, CRM, email, hosting, AI APIs — needs a contract binding it to your purposes, security standards, deletion duties and breach notification. Maintain a live processor inventory with data categories and locations.
Practical first sprint
- Complete a data inventory and flow map for the website
- Rebuild the consent banner to gate scripts before they load
- Publish an itemised notice plus a working rights request form
- Define and automate retention and deletion
- Paper the processors and rehearse the breach runbook
Related Topics & Tags
Related Articles
View allIndia's DPDP Act: A Practical Technical Readiness Checklist for CISOs
With India's Digital Personal Data Protection (DPDP) Act enforceable across sectors, compliance requires translating legal obligations into tangible technical safeguards and data governance architectures.
SOC 2 Type II vs. ISO 27001: Which Security Framework Should You Target First?
Navigating security compliance certifications can overwhelm technology leaders. Analyze the structural differences, audit processes, and business positioning between SOC 2 Type II and ISO/IEC 27001:2022.
DPDP Act Compliance Guide for Startups
A practical, engineering-first DPDP Act compliance roadmap for Indian startups: consent and notice, data inventory, deletion flows, vendor contracts, security safeguards, breach reporting, penalties and a 30-60-90 day plan.
