Home Services Penetration Testing Work About Research Contact Cyber Range BytePatch Labs Our Security Posture Call +91 98836 53673 WhatsApp
Blog / Data Privacy

DPDP Act Compliance Checklist for Indian Startups (2026)

By Mayank Minda·27 June 2026·7 min read

India’s Digital Personal Data Protection (DPDP) Act, 2023, read with the DPDP Rules, is the country’s first comprehensive privacy law. If your startup collects so much as an email address from a person in India, it applies to you — and unlike the frameworks it replaces, it carries penalties measured in crores.

This checklist turns the statute into work you can put in a sprint. Ten steps, in the order we would actually do them, with the traps that catch small teams.

First: which role are you?

Almost every obligation in the Act attaches to a role, so establishing yours settles most questions about what you owe.

RoleWho it isWhat it means for you
Data FiduciaryYou decide why and how personal data is processedNearly every startup with users. Carries the full obligation set below.
Data ProcessorYou process data on someone else’s instructionsTypical for B2B SaaS. Obligations flow through your contract with the fiduciary.
Significant Data FiduciaryDesignated by the government on volume and sensitivityAdds a Data Protection Officer in India, an independent audit and impact assessments.
Data PrincipalThe individual the data is aboutYour users. They hold the rights you must build channels for.

Most early-stage companies are fiduciaries for their own users and processors for their B2B clients simultaneously. Both sets of duties apply at once.

1. Map the personal data you hold

You cannot protect what you cannot see. Build a data inventory before anything else: what you collect, where it lives, who can reach it, which third parties receive it, and how long you keep it. One spreadsheet is enough to start.

Do not forget the places data leaks out of the product: analytics tools, support inboxes, CRM exports, spreadsheets on laptops, WhatsApp groups where the sales team shares customer numbers, and backups nobody has opened in a year. In our experience these informal copies, not the production database, are where the real exposure sits.

2. Fix consent and notice

Consent must be free, specific, informed, unconditional and unambiguous, given by clear affirmative action. Your notice must be itemised, in plain language, available in English and the Eighth Schedule languages, and must state the purpose plus how to exercise rights and complain to the Data Protection Board.

  • Pre-ticked boxes fail. So does consent bundled into terms of service.
  • One purpose, one consent. Marketing email is not the same purpose as order fulfilment.
  • Withdrawal must be as easy as giving it. If signup is one click, so is opt-out.
  • Log it. You must be able to show when consent was given, for what, and on which notice version.

The consent log is the item teams skip and regulators ask for first. Store the timestamp, the purpose, the notice version and the mechanism — not just a boolean column called marketing_opt_in.

3. Build the data-principal rights channels

People can ask for access to their data, correction, completion, updating, erasure, and they can nominate someone to act for them if they die or become incapacitated. You need a published route for each, a named grievance officer, and a stated response time you actually meet.

Practically: one email address that reaches a real person, a documented internal runbook for fulfilling each request type, and a log of requests and outcomes. A deletion request that cannot reach the backups and the analytics warehouse is not fulfilled.

4. Put reasonable security safeguards in place

The Rules expect technical and organisational measures: encryption at rest and in transit, access control, logging and monitoring, secure development practice, and a way to detect unauthorised access. The Act does not enumerate a fixed list, which means the standard is judged after the fact against what a reasonable organisation would have done.

  • Encrypt personal data at rest, and never log it in plaintext to your application logs
  • Enforce multi-factor authentication on every admin, hosting and email account
  • Make every read of sensitive data attributable to a person, not to a shared service account
  • Scan dependencies continuously — an unpatched CVE is the clearest example of an unreasonable safeguard
  • Separate production from staging, with no real personal data in test environments

A penetration test is the fastest way to find these gaps before an attacker or the Board does. See how we scope and price VAPT, and the LoansBaba build for what encrypted-on-receipt KYC handling looks like in practice.

5. Write the breach playbook before you need it

On a personal data breach you must notify affected individuals without delay, and report to the Data Protection Board, with a detailed report following within 72 hours. Seventy-two hours is not long enough to decide who is in charge.

  • Name the incident lead and the deputy, with phone numbers, before an incident
  • Pre-draft the user notification and the Board report so you are editing, not writing
  • Know in advance how you will determine scope — which logs answer “whose data?”
  • Rehearse it once. A tabletop exercise costs an afternoon and finds the gaps cheaply

If you want to feel the clock, our incident response simulator runs four real deadlines at once, including the CERT-In notification.

6. Handle children’s data carefully

Processing data of anyone under 18 requires verifiable parental consent. Behavioural tracking and targeted advertising directed at children are barred outright. If children can sign up to your product, you need age assurance and a parental consent flow, and you need to be able to show how the verification worked.

7. Set retention periods and delete on schedule

Define how long you keep each class of data and erase it when the purpose ends, unless a law requires you to keep it. Retention is the obligation most often written into a policy and never implemented in code.

Make it a scheduled job, not a manual quarterly ritual. And check that deletion actually reaches every copy: the primary database, read replicas, search indexes, object storage, analytics, and backups as they roll off.

8. Get your processor agreements in order

When you outsource processing — hosting, email delivery, analytics, a support desk, a payment gateway — you remain the fiduciary. The Act requires a valid contract with each processor, and you are answerable for their failures.

  • List every vendor that touches personal data, including the ones bought on a card by one team
  • Confirm each has a written data processing agreement, not just terms of service
  • Check where they store data and who they sub-process to
  • Apply heavier due diligence to anyone touching financial or identity documents

9. Know what a failure costs

ContraventionMaximum penalty
Failure to take reasonable security safeguards₹250 crore
Failure to notify a personal data breach₹200 crore
Breach of obligations relating to children’s data₹200 crore
Breach of additional Significant Data Fiduciary duties₹150 crore
Breach of a data principal’s own duties₹10,000
Other contraventions₹50 crore

Note which line is largest. The heaviest penalty in the Act attaches to inadequate security safeguards — not to paperwork. For most startups the fine is also not the worst outcome: enterprise customers ask about breaches in every security questionnaire from then on.

10. A realistic first 30 days

WeekFocusOutput
Week 1DiscoveryData inventory, vendor list, role determination
Week 2Consent and noticeRewritten privacy notice, consent log schema, opt-out path
Week 3SecurityMFA everywhere, dependency scan, encryption gaps closed, access review
Week 4ProcessGrievance officer named, rights runbook, breach playbook, retention jobs

Thirty days gets a small team to defensible. It does not get you to finished — retention automation and processor agreements usually run into a second month.

Frequently asked questions

Does the DPDP Act apply to my startup if we are tiny?

Yes. There is no revenue or headcount threshold. The Act applies to processing of digital personal data within India, and to processing outside India that involves offering goods or services to people in India. Size affects whether you are designated a Significant Data Fiduciary, not whether the Act applies.

How is this different from GDPR?

The structure is familiar but narrower. DPDP has no separate category of sensitive personal data, no general right to data portability or objection, and a consent-first legal basis model with “legitimate uses” in place of GDPR’s six lawful bases. If you already comply with GDPR you are most of the way there, but consent notices, children’s data and the breach timeline all need rework.

Do we need a Data Protection Officer?

Only Significant Data Fiduciaries must appoint a DPO based in India. Everyone else must publish the contact details of a person who answers questions on data processing — usually titled a grievance officer. Name someone real either way.

Can we store data outside India?

Generally yes. DPDP permits cross-border transfer except to countries the government restricts by notification. This is more permissive than earlier drafts, but sector regulators — RBI for payments in particular — impose their own localisation rules that still bind you.

What is the single highest-value thing to do first?

Turn on multi-factor authentication across admin, hosting and email, then run a dependency scan. Both are same-day, both are free, and both sit directly under the heaviest penalty in the Act. Our free security scorecard will tell you in three minutes which of the ten basics you are missing.

Want a head start?

We turn DPDP compliance into something you can ship — security audits, breach-readiness and privacy-by-design build. Read our full briefing or get a security review.

Read the DPDP whitepaper → Cyber security services

This article is general information, not legal advice. For your specific obligations, consult a qualified professional.

Keep reading

Related guides

Inside a Dark Web Leaked Database Where your stolen data goes after a breach, step by step. OWASP Top 10 Explained The ten risks behind most real breaches, and the fixes for each. Dark Web Threat Intelligence How to monitor for leaked corporate credentials, legally.

Seen in practice: LoansBaba — KYC documents encrypted on receipt, retention decided before launch

One email a month

What actually changed in Indian security this month.

New DPDP rulings, breaches worth learning from, and the one thing we would fix first if it were your stack. Written by the people doing the work — not a content team.

No spam, no sharing your address, unsubscribe in one click. Prefer a reader? RSS feed.