Chandrasekar Rathinam logo
Back to all articles
Compliance6 Aug 20269 min read

DPDP Act and Website Compliance: What Indian Sites Must Fix

A pragmatic mapping of India's Digital Personal Data Protection Act to the concrete changes a website needs: consent, notices, retention, breach reporting and vendor controls.

Chandrasekar Rathinam

Chandrasekar Rathinam

Cyber Security Consultant · Chennai

Share:

Compliance is an engineering programme, not a policy page

India's Digital Personal Data Protection Act applies to any site processing the personal data of individuals in India. Publishing a privacy policy satisfies almost none of it. The obligations land in forms, cookies, databases, logs and vendor contracts.

Consent and notice

  • Free, specific, informed, unconditional and unambiguous consent — no pre-ticked boxes, no bundling
  • An itemised notice at collection stating purposes, rights and the grievance channel
  • Withdrawal must be as easy as giving consent, and must propagate to processors
  • Verifiable parental consent for users under 18, with no behavioural advertising to children

Data minimisation and retention

Collect only what the stated purpose requires, and delete when the purpose ends. That means real retention schedules enforced by scheduled jobs — including backups, analytics warehouses and log stores, which are where "deleted" data usually survives.

Data principal rights

Build workflows, not inboxes: access and summary of processing, correction and erasure, nomination, and grievance redressal with a published response window. Every request needs identity verification and an audit trail.

Security safeguards and breach reporting

Reasonable security safeguards are mandatory: encryption in transit and at rest, access control, logging, and tested backups. Personal data breaches must be reported to the Data Protection Board and to affected principals — so detection and an executable incident runbook are compliance controls, not nice-to-haves.

Vendors and transfers

Every processor — analytics, CRM, email, hosting, AI APIs — needs a contract binding it to your purposes, security standards, deletion duties and breach notification. Maintain a live processor inventory with data categories and locations.

Practical first sprint

  1. Complete a data inventory and flow map for the website
  2. Rebuild the consent banner to gate scripts before they load
  3. Publish an itemised notice plus a working rights request form
  4. Define and automate retention and deletion
  5. Paper the processors and rehearse the breach runbook

Related Topics & Tags

#DPDP Act#website compliance#data protection India#consent management#breach reporting

Have Questions? Get in Touch!

Whether you need an architecture review, a penetration test, or a security programme built from scratch — let's talk about where you are and what comes next.

Contact Me