Chandrasekar Rathinam logo
Back to all articles
Compliance10 Aug 202610 min read

DPDP Act Compliance Guide for Startups

A practical, engineering-first DPDP Act compliance roadmap for Indian startups: consent and notice, data inventory, deletion flows, vendor contracts, security safeguards, breach reporting, penalties and a 30-60-90 day plan.

Chandrasekar Rathinam

Chandrasekar Rathinam

Cyber Security Consultant · Chennai

Share:

Why the DPDP Act matters for startups now

India's Digital Personal Data Protection Act, 2023 changes how every startup that handles digital personal data must design products, choose vendors and respond to incidents. Compliance is not a privacy-policy exercise. It is an operating model spanning product, engineering, security, legal and customer support.

The seven core obligations

  1. Know your data: inventory personal data, purposes, systems, owners and processors.
  2. Provide clear notice: explain what is collected, why, and how people exercise rights.
  3. Use valid consent or another permitted basis: keep evidence and make withdrawal as easy as giving consent.
  4. Limit and delete: collect only what is needed and enforce retention schedules.
  5. Protect data: apply reasonable security safeguards proportionate to risk.
  6. Handle rights: provide reliable correction, access and erasure workflows.
  7. Prepare for breaches: detect, contain, investigate and notify through a rehearsed process.

A 30-60-90 day roadmap

Days 1–30: discover and prioritise

  • Create a data inventory and system map
  • Identify high-risk stores, public exposure and privileged access
  • Review notices, consent capture and third-party trackers
  • Assign accountable owners across product, security and legal

Days 31–60: implement controls

  • Build withdrawal, correction and deletion workflows
  • Apply retention rules and verify deletion in backups and vendors
  • Strengthen access control, encryption, logging and vulnerability management
  • Update processor contracts and vendor review criteria

Days 61–90: prove and rehearse

  • Test rights requests end to end
  • Run a personal-data breach tabletop exercise
  • Review evidence and remediate control gaps
  • Establish recurring audits and privacy-by-design reviews

Penalty exposure

Financial penalties can be substantial, but the operational cost of weak data governance is often larger: breach response, customer churn, enterprise sales delays and emergency re-engineering. A measured programme reduces all four.

Common startup mistakes

  • Copying a privacy policy without matching product behaviour
  • Collecting analytics and support data indefinitely
  • Assuming a cloud provider carries the startup's compliance obligation
  • Having no tested way to find and delete one person's data
  • Treating security safeguards as an annual penetration test only

Frequently asked questions

Does the Act apply to small startups?

Size alone does not remove obligations. The applicability and risk depend on the digital personal data processed and the startup's role.

Is consent always required?

Consent is central, but the law also defines certain legitimate uses. Each purpose should be assessed rather than relying on a blanket assumption.

What should we do first?

Build the data inventory. Without knowing what data exists and where it flows, every policy and control is guesswork.

Related Topics & Tags

#DPDP Act#startup compliance#India privacy#data protection#30-60-90 roadmap

Have Questions? Get in Touch!

Whether you need an architecture review, a penetration test, or a security programme built from scratch — let's talk about where you are and what comes next.

Contact Me