India’s Digital Personal Data Protection (DPDP) Act, 2023, read with the DPDP Rules, is the country’s first comprehensive privacy law. If your startup collects so much as an email address from a person in India, it applies to you — and unlike the frameworks it replaces, it carries penalties measured in crores.
This checklist turns the statute into work you can put in a sprint. Ten steps, in the order we would actually do them, with the traps that catch small teams.
First: which role are you?
Almost every obligation in the Act attaches to a role, so establishing yours settles most questions about what you owe.
| Role | Who it is | What it means for you |
|---|---|---|
| Data Fiduciary | You decide why and how personal data is processed | Nearly every startup with users. Carries the full obligation set below. |
| Data Processor | You process data on someone else’s instructions | Typical for B2B SaaS. Obligations flow through your contract with the fiduciary. |
| Significant Data Fiduciary | Designated by the government on volume and sensitivity | Adds a Data Protection Officer in India, an independent audit and impact assessments. |
| Data Principal | The individual the data is about | Your users. They hold the rights you must build channels for. |
Most early-stage companies are fiduciaries for their own users and processors for their B2B clients simultaneously. Both sets of duties apply at once.
1. Map the personal data you hold
You cannot protect what you cannot see. Build a data inventory before anything else: what you collect, where it lives, who can reach it, which third parties receive it, and how long you keep it. One spreadsheet is enough to start.
Do not forget the places data leaks out of the product: analytics tools, support inboxes, CRM exports, spreadsheets on laptops, WhatsApp groups where the sales team shares customer numbers, and backups nobody has opened in a year. In our experience these informal copies, not the production database, are where the real exposure sits.
2. Fix consent and notice
Consent must be free, specific, informed, unconditional and unambiguous, given by clear affirmative action. Your notice must be itemised, in plain language, available in English and the Eighth Schedule languages, and must state the purpose plus how to exercise rights and complain to the Data Protection Board.
- Pre-ticked boxes fail. So does consent bundled into terms of service.
- One purpose, one consent. Marketing email is not the same purpose as order fulfilment.
- Withdrawal must be as easy as giving it. If signup is one click, so is opt-out.
- Log it. You must be able to show when consent was given, for what, and on which notice version.
The consent log is the item teams skip and regulators ask for first. Store the timestamp, the purpose, the notice version and the mechanism — not just a boolean column called marketing_opt_in.
3. Build the data-principal rights channels
People can ask for access to their data, correction, completion, updating, erasure, and they can nominate someone to act for them if they die or become incapacitated. You need a published route for each, a named grievance officer, and a stated response time you actually meet.
Practically: one email address that reaches a real person, a documented internal runbook for fulfilling each request type, and a log of requests and outcomes. A deletion request that cannot reach the backups and the analytics warehouse is not fulfilled.
4. Put reasonable security safeguards in place
The Rules expect technical and organisational measures: encryption at rest and in transit, access control, logging and monitoring, secure development practice, and a way to detect unauthorised access. The Act does not enumerate a fixed list, which means the standard is judged after the fact against what a reasonable organisation would have done.
- Encrypt personal data at rest, and never log it in plaintext to your application logs
- Enforce multi-factor authentication on every admin, hosting and email account
- Make every read of sensitive data attributable to a person, not to a shared service account
- Scan dependencies continuously — an unpatched CVE is the clearest example of an unreasonable safeguard
- Separate production from staging, with no real personal data in test environments
A penetration test is the fastest way to find these gaps before an attacker or the Board does. See how we scope and price VAPT, and the LoansBaba build for what encrypted-on-receipt KYC handling looks like in practice.
5. Write the breach playbook before you need it
On a personal data breach you must notify affected individuals without delay, and report to the Data Protection Board, with a detailed report following within 72 hours. Seventy-two hours is not long enough to decide who is in charge.
- Name the incident lead and the deputy, with phone numbers, before an incident
- Pre-draft the user notification and the Board report so you are editing, not writing
- Know in advance how you will determine scope — which logs answer “whose data?”
- Rehearse it once. A tabletop exercise costs an afternoon and finds the gaps cheaply
If you want to feel the clock, our incident response simulator runs four real deadlines at once, including the CERT-In notification.
6. Handle children’s data carefully
Processing data of anyone under 18 requires verifiable parental consent. Behavioural tracking and targeted advertising directed at children are barred outright. If children can sign up to your product, you need age assurance and a parental consent flow, and you need to be able to show how the verification worked.
7. Set retention periods and delete on schedule
Define how long you keep each class of data and erase it when the purpose ends, unless a law requires you to keep it. Retention is the obligation most often written into a policy and never implemented in code.
Make it a scheduled job, not a manual quarterly ritual. And check that deletion actually reaches every copy: the primary database, read replicas, search indexes, object storage, analytics, and backups as they roll off.
8. Get your processor agreements in order
When you outsource processing — hosting, email delivery, analytics, a support desk, a payment gateway — you remain the fiduciary. The Act requires a valid contract with each processor, and you are answerable for their failures.
- List every vendor that touches personal data, including the ones bought on a card by one team
- Confirm each has a written data processing agreement, not just terms of service
- Check where they store data and who they sub-process to
- Apply heavier due diligence to anyone touching financial or identity documents
9. Know what a failure costs
| Contravention | Maximum penalty |
|---|---|
| Failure to take reasonable security safeguards | ₹250 crore |
| Failure to notify a personal data breach | ₹200 crore |
| Breach of obligations relating to children’s data | ₹200 crore |
| Breach of additional Significant Data Fiduciary duties | ₹150 crore |
| Breach of a data principal’s own duties | ₹10,000 |
| Other contraventions | ₹50 crore |
Note which line is largest. The heaviest penalty in the Act attaches to inadequate security safeguards — not to paperwork. For most startups the fine is also not the worst outcome: enterprise customers ask about breaches in every security questionnaire from then on.
10. A realistic first 30 days
| Week | Focus | Output |
|---|---|---|
| Week 1 | Discovery | Data inventory, vendor list, role determination |
| Week 2 | Consent and notice | Rewritten privacy notice, consent log schema, opt-out path |
| Week 3 | Security | MFA everywhere, dependency scan, encryption gaps closed, access review |
| Week 4 | Process | Grievance officer named, rights runbook, breach playbook, retention jobs |
Thirty days gets a small team to defensible. It does not get you to finished — retention automation and processor agreements usually run into a second month.
Frequently asked questions
Does the DPDP Act apply to my startup if we are tiny?
Yes. There is no revenue or headcount threshold. The Act applies to processing of digital personal data within India, and to processing outside India that involves offering goods or services to people in India. Size affects whether you are designated a Significant Data Fiduciary, not whether the Act applies.
How is this different from GDPR?
The structure is familiar but narrower. DPDP has no separate category of sensitive personal data, no general right to data portability or objection, and a consent-first legal basis model with “legitimate uses” in place of GDPR’s six lawful bases. If you already comply with GDPR you are most of the way there, but consent notices, children’s data and the breach timeline all need rework.
Do we need a Data Protection Officer?
Only Significant Data Fiduciaries must appoint a DPO based in India. Everyone else must publish the contact details of a person who answers questions on data processing — usually titled a grievance officer. Name someone real either way.
Can we store data outside India?
Generally yes. DPDP permits cross-border transfer except to countries the government restricts by notification. This is more permissive than earlier drafts, but sector regulators — RBI for payments in particular — impose their own localisation rules that still bind you.
What is the single highest-value thing to do first?
Turn on multi-factor authentication across admin, hosting and email, then run a dependency scan. Both are same-day, both are free, and both sit directly under the heaviest penalty in the Act. Our free security scorecard will tell you in three minutes which of the ten basics you are missing.
We turn DPDP compliance into something you can ship — security audits, breach-readiness and privacy-by-design build. Read our full briefing or get a security review.
This article is general information, not legal advice. For your specific obligations, consult a qualified professional.