Chandrasekar Rathinam logo
Back to all articles
Compliance6 Aug 20269 min read

DPDP Act and Website Compliance: What Indian Sites Must Fix

A pragmatic mapping of India's Digital Personal Data Protection Act to the concrete changes a website needs: consent, notices, retention, breach reporting and vendor controls.

Chandrasekar Rathinam

Chandrasekar Rathinam

Cyber Security Consultant · Chennai

Share:

Start with the data your website actually collects

List every form field, cookie, analytics event, support transcript, account attribute and server log that can identify a person. Include data sent to payment, CRM, analytics, email and hosting vendors.

Make notices specific

A generic privacy policy is not enough. At collection points, explain the purpose, the data involved, relevant sharing, retention and how a person can withdraw consent or exercise rights.

Fix consent mechanics

Do not pre-tick optional marketing choices or bundle unrelated purposes. Record what notice and choice the person saw, and ensure withdrawal propagates to downstream systems.

Engineer deletion

Deletion must work across primary databases, search indexes, analytics exports, support tools and processors. Document justified retention and automate expiry wherever possible.

Strengthen safeguards

  • Enforce strong authentication and least privilege
  • Encrypt sensitive data in transit and at rest
  • Patch internet-facing systems and test them regularly
  • Centralise security logs and alert on suspicious access
  • Maintain tested backups and incident playbooks

Govern vendors

Know which processors receive personal data, review their security, define deletion and breach duties contractually, and monitor material changes.

Prepare for incidents

Build a breach process that can determine affected people and data quickly. Rehearse escalation, containment, evidence preservation and notification decisions before an incident.

Related Topics & Tags

#DPDP Act#website compliance#privacy notice#consent#data retention

Have Questions? Get in Touch!

Whether you need an architecture review, a penetration test, or a security programme built from scratch — let's talk about where you are and what comes next.

Contact Me