India's Digital Personal Data Protection Act 2023 (DPDP Act) received assent on 11 August 2023. It establishes a framework for processing digital personal data, with the company deciding the purpose and means of processing generally acting as the Data Fiduciary. The Act defines the architecture, but the operating detail depends heavily on rules and notifications. The DPDP Rules had not been notified as of 5 August 2026, so every startup should treat implementation timelines and thresholds as VERIFY items. (DPDP Act ss.2, 4, 40, 66.)
What the Act covers
Personal data means data about an individual who is identifiable by or in relation to that data. That can include names, contact details, identifiers and online identifiers when they identify an individual. A Data Fiduciary is the person who determines why and how personal data is processed. A Data Processor processes it on the Fiduciary's behalf, such as a cloud, analytics or payments vendor. The individual is the Data Principal. (DPDP Act s.2(i), s.2(j), s.2(k), s.2(t).)
The Act's consent model requires consent to be free, specific, informed, unconditional and unambiguous, signified by clear affirmative action. Notice must explain the data and purpose, withdrawal, and grievance route. A Consent Manager is a registered body that helps Data Principals give, manage, review and withdraw consent. (DPDP Act ss.2(e), 5, 6.)
The seven-step startup checklist
1. Map your data
List each category of personal data, the purpose for collecting it, where it is stored, who receives it, and how long it is needed. This creates an internal data register and makes later correction, erasure and breach work possible. The Fiduciary must not retain data once the purpose is no longer being served, subject to the period to be prescribed in the rules. (DPDP Act s.8(7).)
2. Rewrite the notice
Your privacy notice should say what data is collected and why, how consent can be withdrawn, and how a person can contact the Grievance Officer. Write it in clear language and provide the prescribed language options. The notice obligation applies before or at collection. (DPDP Act ss.5, 6.)
3. Build a real consent flow
Use a clear affirmative action for each purpose. Do not hide data consent inside unrelated terms, and provide a withdrawal path that is as easy as the giving path. For a child, obtain verifiable parental consent before processing. A child is a person under 18 for this purpose. (DPDP Act ss.6, 6(4), 9.)
Whether pre-ticked boxes, bundled consent, or a particular age-verification mechanism will satisfy the final rules remains a VERIFY item. The Act supplies the principle; the rules are expected to supply operational detail. (DPDP Act ss.6, 9, 40.)
4. Review vendors
Cloud, analytics, payroll, CRM, support and payment vendors may be Data Processors. Review contracts for purpose limitation, security safeguards, assistance with rights requests, deletion and incident escalation. The Fiduciary remains responsible for processing done for its purposes, and must implement reasonable security safeguards. (DPDP Act ss.2(j), 8(5).)
The Act does not impose a blanket requirement that all personal data remain in India. Transfers are allowed except to countries or territories restricted by Central Government notification. Check the current notification position before relying on an overseas architecture. (DPDP Act s.16(1).)
5. Create grievance handling
Publish a Grievance Officer contact and a process for receiving and resolving requests. Data Principals have a right to grievance redressal and can approach the Data Protection Board if the Fiduciary's process does not resolve the issue. The Act also gives rights to information, correction, erasure, nomination and withdrawal of consent. (DPDP Act ss.11, 12, 13, 14, 6(4).)
6. Add a children's gate
If your service is likely to be used by people under 18, build age assurance and a parental-consent path. The Act prohibits tracking or behavioural monitoring of children and targeted advertising directed at children. If the product is not designed for minors, document the restriction and test the gate. (DPDP Act s.9.)
7. Prepare a breach plan
Define detection, containment, investigation, Board notification and affected-person notification. The Act requires reasonable security safeguards and notification of a personal data breach to the Board and each affected Data Principal. The exact period for Board notification was not prescribed as of 5 August 2026; do not copy a 72-hour deadline into your policy as if it were a notified statutory rule. (DPDP Act s.8(5), s.8(6), s.40.)
Significant Data Fiduciaries
The Central Government may designate a Data Fiduciary as a Significant Data Fiduciary based on factors including the volume and sensitivity of data, risk to Data Principals, national security, public order and sovereign integrity. An SDF may have to appoint an India-resident Data Protection Officer, an independent auditor and conduct periodic Data Protection Impact Assessments. The Act does not provide a simple startup turnover or user-count threshold; designation criteria and notifications remain VERIFY items. (DPDP Act s.10.)
Penalties
The Act permits penalties up to ₹250 crore for failure to take reasonable security safeguards resulting in a personal data breach. Failure to notify the Board and Data Principals can attract up to ₹200 crore; children's-data non-compliance can attract up to ₹200 crore; SDF non-compliance up to ₹150 crore; and other breaches up to ₹50 crore. These are statutory maximums, not automatic invoices. (DPDP Act s.66(1)(a), (b), (c), (d), (f).)
What remains unknown
Rules are needed for retention periods, breach-notification mechanics, Consent Manager specifications, age verification, SDF criteria and potentially transfer restrictions. Maintain a versioned compliance register with an owner for each VERIFY item. When MeitY notifies rules, compare them against your notice, consent UX, vendor contracts, retention settings and response plan. (DPDP Act ss.8(6), 8(7), 9, 10, 16, 40.)
The safest next step is a documented Act-level baseline, followed by a rule-update review. HRA can review your privacy policy, consent flow, processor agreements and breach plan against the DPDP Act 2023 and the rules when notified.
What to put in the register
For each data field, record the collection surface, purpose, lawful basis, vendor access, storage location, deletion trigger and responsible owner. Link each purpose to the notice wording and the product screen where consent is collected. This makes it easier to honour a correction or erasure request rather than searching through several systems. (DPDP Act ss.5, 6, 8(7), 12.)
Keep an evidence trail for consent: version of notice, timestamp, affirmative action, purpose selected and withdrawal event. The Act does not prescribe one database schema, but a company that cannot explain what it told a Data Principal will struggle to demonstrate clear, specific and informed consent. (DPDP Act s.6.)
Assign owners before launch
The founder or product lead should own the data map, engineering should own access controls and deletion jobs, legal or compliance should own notices and vendor terms, and an incident lead should own the breach plan. Review the register whenever a new analytics tool, marketing pixel, support workflow or AI feature is introduced. A new processor can change the risk profile even when the customer-facing product looks unchanged. (DPDP Act ss.2(j), 8(5), 10.)
Do not wait for a regulator inquiry to discover that consent withdrawal is only a support email, that a former customer remains in five exports, or that a vendor has no incident escalation clause. Those are precisely the operational gaps a short Act-level starter review can identify. (DPDP Act ss.6(4), 8(5), 8(7), 13.)
Ready to decide your structure?
Structure + Setup Plan — ₹4,999 flat. A 60-minute CA call, a written recommendation citing the Act, and your exact incorporation checklist. Government fees and filing execution are separate.