Why the DPDP Act matters for startups now
India's Digital Personal Data Protection Act, 2023 changes how every startup that handles digital personal data must design products, choose vendors and respond to incidents. Compliance is not a privacy-policy exercise. It is an operating model spanning product, engineering, security, legal and customer support.
The seven core obligations
- Know your data: inventory personal data, purposes, systems, owners and processors.
- Provide clear notice: explain what is collected, why, and how people exercise rights.
- Use valid consent or another permitted basis: keep evidence and make withdrawal as easy as giving consent.
- Limit and delete: collect only what is needed and enforce retention schedules.
- Protect data: apply reasonable security safeguards proportionate to risk.
- Handle rights: provide reliable correction, access and erasure workflows.
- Prepare for breaches: detect, contain, investigate and notify through a rehearsed process.
A 30-60-90 day roadmap
Days 1–30: discover and prioritise
- Create a data inventory and system map
- Identify high-risk stores, public exposure and privileged access
- Review notices, consent capture and third-party trackers
- Assign accountable owners across product, security and legal
Days 31–60: implement controls
- Build withdrawal, correction and deletion workflows
- Apply retention rules and verify deletion in backups and vendors
- Strengthen access control, encryption, logging and vulnerability management
- Update processor contracts and vendor review criteria
Days 61–90: prove and rehearse
- Test rights requests end to end
- Run a personal-data breach tabletop exercise
- Review evidence and remediate control gaps
- Establish recurring audits and privacy-by-design reviews
Penalty exposure
Financial penalties can be substantial, but the operational cost of weak data governance is often larger: breach response, customer churn, enterprise sales delays and emergency re-engineering. A measured programme reduces all four.
Common startup mistakes
- Copying a privacy policy without matching product behaviour
- Collecting analytics and support data indefinitely
- Assuming a cloud provider carries the startup's compliance obligation
- Having no tested way to find and delete one person's data
- Treating security safeguards as an annual penetration test only
Frequently asked questions
Does the Act apply to small startups?
Size alone does not remove obligations. The applicability and risk depend on the digital personal data processed and the startup's role.
Is consent always required?
Consent is central, but the law also defines certain legitimate uses. Each purpose should be assessed rather than relying on a blanket assumption.
What should we do first?
Build the data inventory. Without knowing what data exists and where it flows, every policy and control is guesswork.
Related Topics & Tags
Related Articles
View allIndia's DPDP Act: A Practical Technical Readiness Checklist for CISOs
With India's Digital Personal Data Protection (DPDP) Act enforceable across sectors, compliance requires translating legal obligations into tangible technical safeguards and data governance architectures.
SOC 2 Type II vs. ISO 27001: Which Security Framework Should You Target First?
Navigating security compliance certifications can overwhelm technology leaders. Analyze the structural differences, audit processes, and business positioning between SOC 2 Type II and ISO/IEC 27001:2022.
DPDP Act and Website Compliance: What Indian Sites Must Fix
A pragmatic mapping of India's Digital Personal Data Protection Act to the concrete changes a website needs: consent, notices, retention, breach reporting and vendor controls.
