DPDP Compliance Checklist for Indian Startups
The Digital Personal Data Protection Act 2023 (DPDP Act) introduces compliance obligations for any Indian business that collects or processes personal data digitally, including startups at an early stage. This checklist walks through the key compliance steps, from understanding whether the Act applies to your business through to implementing consent mechanisms, vendor agreements, and data subject rights processes.
[Image placeholder: Startup founder reviewing a data compliance checklist on a laptop, conveying systematic approach to privacy and regulatory compliance, real photo to replace at launch]
Step 1: Confirm Whether and How the DPDP Act Applies to Your Business
The DPDP Act applies to the processing of digital personal data within India, and to processing outside India if it is in connection with offering goods or services to persons in India. “Personal data” covers any data that can identify an individual, including names, email addresses, phone numbers, device IDs, and user behaviour data linked to an identifiable person. Any entity that determines the purpose and means of processing personal data is a “Data Fiduciary” and is subject to the Act. This means virtually all startups that have a user base or collect customer information are Data Fiduciaries. Limited exemptions apply for personal or domestic use, processing of data made publicly available by the individual, and certain government functions. Businesses designated as “Significant Data Fiduciaries” by the government will face additional obligations, including mandatory appointment of a Data Protection Officer and an independent data auditor.
Step 2: Map Your Data Flows
Before implementing any compliance measures, document what personal data your business collects, why, and where it goes. A data map should record: the categories of personal data collected (e.g., name, email, payment information, location, health data); the purposes for which each category is collected; the lawful basis for processing (consent or legitimate use); the third parties (vendors, cloud providers, analytics tools, payment gateways) that process data on your behalf; where data is stored (including any cross-border transfers); and how long data is retained. This data inventory is the foundation of all subsequent compliance work, you cannot implement appropriate safeguards or respond to Data Principal requests without knowing what data you hold and where it is.
Step 3: Implement Valid Consent Mechanisms
The DPDP Act requires consent that is “free, specific, informed, unconditional, and unambiguous”, expressed through a clear affirmative action. This means: pre-ticked boxes do not constitute valid consent; consent cannot be bundled with general Terms & Conditions; each purpose of processing requires separate consent; and consent must be as easy to withdraw as it is to give. Before collecting personal data, you must provide a “notice” to the Data Principal specifying the personal data to be collected, the purpose, how to exercise rights, and contact details for grievances. The notice must be in plain language, and, where feasible, in a language of the Constitution of India specified by the user. Keep records of when consent was given and for what purpose, as you will need to produce these if challenged.
Step 4: Update Your Privacy Policy
Your Privacy Policy must align with the DPDP Act’s notice requirements and be accessible to users before they provide personal data. It should set out: the categories of personal data collected; the purposes of processing; who the data is shared with (and for what purpose); how long data is retained; how Data Principals can exercise their rights (correction, erasure, nomination); how to lodge a grievance; and the contact details of the Data Protection Officer (if one has been appointed). The policy must be written in plain, non-legal language. If your privacy policy currently uses generic or vague language about data collection, it needs to be substantially rewritten for DPDP Act compliance.
Step 5: Put Data Processing Agreements with Vendors in Place
Any third party that processes personal data on your behalf, including cloud hosting providers, analytics tools, email marketing platforms, payment gateways, and customer support tools, is a “Data Processor” under the DPDP Act. You remain responsible as the Data Fiduciary for how your Data Processors handle the data. You must have a contract (Data Processing Agreement or DPA) with each Data Processor that specifies: the scope and purpose of processing; security obligations the processor must meet; requirements for handling data breaches; restrictions on sub-processing and cross-border transfers; and what the processor must do when the contract ends (delete or return the data). Review your existing vendor contracts against these requirements and put DPAs in place where they are missing.
Step 6: Implement Security Safeguards and a Breach Response Process
The DPDP Act requires Data Fiduciaries to implement “reasonable security safeguards” to prevent personal data breaches. While the government will specify security standards in the rules, current good practice for startups includes: encryption of personal data at rest and in transit; access controls and role-based permissions so employees only access data they need; regular security audits and vulnerability assessments; and a documented incident response plan. If a personal data breach occurs, you will be required to notify the Data Protection Board of India and the affected Data Principals, the rules will specify timelines and the form of notification. Build an incident response process now so you are not creating one in a crisis.
Step 7: Prepare to Handle Data Principal Rights Requests
Data Principals (users whose data you process) have several rights under the DPDP Act: the right to know what personal data is held about them and to access it; the right to correct inaccurate or incomplete data; the right to erasure of their data when the original purpose is fulfilled or consent is withdrawn; and the right to nominate a person to exercise these rights in the event of death or incapacity. You must have a process to receive, authenticate, and respond to these requests within the timeframe prescribed in the rules. A grievance redressal mechanism must also be in place, with a designated point of contact. If requests are not handled correctly, Data Principals can escalate to the Data Protection Board.
Need Help with DPDP Compliance?
Y&A Legal advises startups on DPDP Act compliance, from initial data mapping and privacy policy drafting through to DPAs, consent mechanism review, and compliance audits. See our DPDP Compliance Services and DPDP Audit & Readiness Assessment, or chat with us directly on WhatsApp.
Frequently Asked Questions
Which businesses are covered by the DPDP Act 2023?
The DPDP Act applies to any entity that processes digital personal data within India, and to processing outside India if it relates to offering goods or services to persons in India. This is a broad definition that covers virtually all digital businesses, e-commerce platforms, SaaS companies, apps, websites, and any business with a digital customer touchpoint. There is no revenue or size threshold for applicability. Small startups that collect user data (even just email addresses) are Data Fiduciaries and must comply. The government may, by notification, exempt certain categories of Data Fiduciaries from specific obligations.
What are the penalties under the DPDP Act?
The DPDP Act provides for financial penalties imposed by the Data Protection Board of India for contraventions. The maximum penalties range from ₹50 crore (for failing to notify a data breach to the Board or affected Data Principals) to ₹250 crore (for failing to implement adequate security safeguards). The Board adjudicates complaints and can impose penalties after an inquiry process. Penalties are cumulative, a single incident can result in multiple penalty heads. The Act does not provide for criminal liability (unlike some other jurisdictions).
What is the difference between a Data Fiduciary and a Data Processor?
A Data Fiduciary is the entity that determines the purpose and means of processing personal data, in most cases, this is your startup. A Data Processor is any entity that processes personal data on behalf of a Data Fiduciary, for example, your cloud hosting provider, email platform, or analytics tool. The distinction matters because the primary compliance obligations under the DPDP Act fall on the Data Fiduciary, not the Data Processor, though the Data Fiduciary must ensure its Data Processors also meet the Act’s requirements through contractual obligations.
When does the DPDP Act come fully into force?
The DPDP Act 2023 received presidential assent in August 2023 but operates primarily through rules that the central government has been notifying in phases. The core provisions and the Data Protection Board framework are in the process of being operationalised. Businesses should not wait for rules to be finalised before beginning compliance work, the data mapping, privacy policy, consent mechanism, and vendor contract review steps in this checklist can be completed now and will form the foundation of full compliance once all rules are in force. Legal advice on current requirements is recommended given the evolving nature of the rules.
Related Guides
Related Services
Written by Yuvraj Rana, Advocate & Co-Founder, Y&A Legal
