The Digital Personal Data Protection Act, 2023 (the DPDP Act) is India's first dedicated law for personal data. It gives people rights over their data, makes every company that collects it accountable for how it is used and protected, and sets up a Data Protection Board with the power to impose penalties of up to ₹250 crore. The DPDP Rules, notified in November 2025, phase the obligations in over 18 months, with the core duties (security safeguards, breach reporting, notices, retention) applying by May 2027.
Most explainers treat the DPDP Act as a consent law. I read it as a security engineer, because that is what I am: I hold an M.Tech in Cybersecurity from NIT Kurukshetra, my research on attribute-based access control has been cited 30+ times, and I have built products on Indian infrastructure as a six-time technical co-founder. From that angle the Act says something founders miss: India has decided that losing people's data is a bigger failure than collecting it without asking.
I am not a lawyer, and this is not legal advice. It is how the law translates into engineering work. For your specific obligations, talk to a privacy lawyer; for how to build them into your product, that is where I come in.
Why India needed a data protection law
India needed the DPDP Act because it had become one of the largest digital economies in the world while protecting personal data with rules written in 2011 that covered only a narrow slice of data and had no dedicated regulator. The gap between how much data Indian companies held and how little they were accountable for kept widening.
Before the Act, the legal baseline was Section 43A of the IT Act and the 2011 "SPDI" rules. They applied mainly to a short list of "sensitive" data (passwords, financial and health information, biometrics), asked for "reasonable security practices" without saying much about what that meant, and left individuals to pursue compensation through a slow adjudication process. There was no duty to tell people their data had been breached, no general right to have your data deleted, and no regulator whose job was personal data.
Three things made that untenable.
Privacy became a fundamental right. In 2017 a nine-judge bench of the Supreme Court held in Justice K.S. Puttaswamy v. Union of India that privacy is a fundamental right under the Constitution, and noted that the state should put a data protection framework in place. What followed was six years of drafting: the Justice Srikrishna committee report in 2018, the Personal Data Protection Bill of 2019, its withdrawal in 2022, and finally the much shorter DPDP Act, passed in August 2023.
India's digital public infrastructure put everyone's data online at once. Aadhaar, UPI, DigiLocker, and the account aggregator framework moved hundreds of millions of people into digital identity and payments within a few years. That is a remarkable achievement, and it also means that for most Indians, a large share of their life now exists as records in databases they have never seen, run by companies they have never heard of.
Breaches kept happening, and nobody had to tell you. The ransomware attack on AIIMS Delhi in late 2022 took one of the country's largest hospitals back to paper records for days. In 2023, reports surfaced of personal details linked to the CoWIN vaccination platform being served through a Telegram bot. Digital lending apps that took contact-list access and used it to harass borrowers and their families became a problem big enough for the RBI to issue specific guidelines. Under the old regime, in most of these situations, the affected people had no legal right to be told what had happened to their data.
Why the DPDP Act is a security law, not just a privacy law
Read the penalty schedule and the priorities are clear: the largest penalty in the Act, up to ₹250 crore, is for failing to take reasonable security safeguards to prevent a personal data breach. Failing to notify a breach, and failing to meet the obligations around children's data, can each cost up to ₹200 crore. Most other violations are capped at ₹50 crore.
The biggest fine in India's data protection law is not for collecting data without consent. It is for failing to protect it.
That ordering matters for how you prioritise engineering work. A missing consent checkbox is a problem. An unencrypted database behind a shared admin password is a much bigger one, and the Act prices it that way.
As a security researcher, three ideas in the Act matter more to me than the rest.
- Data minimisation shrinks the blast radius. The Act ties processing to a specified purpose and expects data to be erased when that purpose is served. Every field you do not collect is a field that cannot leak. This is the cheapest security control there is, and the law now makes it mandatory rather than advisable.
- Accountability follows the data, including to your vendors. The data fiduciary (the company that decides why and how data is processed) is responsible even when a processor (your cloud host, your SMS provider, your analytics tool, your model provider) handles the data. You cannot outsource the liability, only the work.
- Breaches become visible. Mandatory notification to the Board and to affected people changes the incentive. Companies that could previously absorb a breach quietly now have to disclose it, which makes prevention a business decision rather than an engineering nice-to-have.
What the DPDP Rules actually require from engineering
The DPDP Rules turn the Act's broad duties into concrete technical requirements: specific security safeguards, a breach reporting process with a 72-hour deadline, logs kept for at least a year, erasure with advance notice, and verifiable parental consent for children. Here is how the main rules translate into work on your stack.
Reasonable security safeguards (Rule 6). The rules list the measures expected at minimum: protecting personal data through encryption, obfuscation, masking, or virtual tokens; access controls over the systems that process it; visibility into access through logs and monitoring so that unauthorised access can be detected and investigated; retaining those logs for at least a year; backups and measures for continuity if data is compromised; and contracts that require your processors to take safeguards too. If you have read my startup security checklist, most of this will look familiar, because it is the same baseline, now with legal weight behind it.
Breach intimation (Rule 7). When a personal data breach happens, you must inform each affected person without delay, in plain language, explaining what happened, the likely consequences, what you are doing about it, what they can do to protect themselves, and who to contact. You must also inform the Data Protection Board without delay, followed by a detailed report within 72 hours covering the facts, the cause, the mitigation, and the notifications you have sent. This sits alongside the existing CERT-In directions, which already require cyber incidents to be reported to CERT-In within six hours. In practice that means one incident process with three clocks.
Retention and erasure (Rule 8). Personal data must be erased once the purpose is served or consent is withdrawn, unless the law requires you to keep it. Large e-commerce, gaming, and social media platforms get defined retention periods after a user's last activity, and people must be told at least 48 hours before their data is erased so they can log in and keep their account. Separately, logs of processing must be retained for at least a year. Engineering takeaway: you need to know where every copy of a person's data lives, including backups, analytics, and logs, or you cannot erase it.
Children's data. Anyone under 18 is a child under the Act, and processing their data needs verifiable consent from a parent or guardian, with limited exemptions such as healthcare and education providers acting within their role. Tracking, behavioural monitoring, and targeted advertising directed at children are prohibited. For edtech, gaming, and consumer apps, this is an onboarding and identity problem, not a checkbox.
Consent notices and Consent Managers. Notices must be clear, standalone, and itemised, telling people what data you collect and for what purpose, and consent must be as easy to withdraw as it was to give. Consent Managers, India-based entities registered with the Board, will let people give, manage, and withdraw consent across services from one place. Their registration regime starts in November 2026, a year after the Rules were notified.
Significant Data Fiduciaries. Companies the government notifies as Significant Data Fiduciaries (based on the volume and sensitivity of data, and risk to people and the state) carry more: a Data Protection Officer based in India, an independent data auditor, periodic data protection impact assessments and audits, and due diligence that the algorithms and software they use do not put people's rights at risk. The government can also restrict certain categories of their data from leaving India.
The timeline: what applies when
The Rules were notified in November 2025 and phase in over 18 months.
- November 2025: the Data Protection Board provisions took effect, so the enforcement machinery could be set up.
- November 2026 (next month, as I write this): the Consent Manager registration regime begins.
- May 2027: the core obligations apply, including notices, consent, security safeguards, breach intimation, retention and erasure, children's data, and data principal rights.
MeitY has also consulted on bringing some of these dates forward, particularly for Significant Data Fiduciaries. Treat May 2027 as the latest possible date, not the planning target. Retrofitting encryption, logging, erasure, and a breach process into a live product takes months, and the calendar is shorter than it looks.
Where the DPDP Act is weaker, and the criticisms worth knowing
The Act is a big step forward, but it is not the strongest data protection law in the world, and a fair reading has to include its gaps. These are the criticisms I hear most often from privacy researchers and practitioners; you do not have to agree with all of them to plan around them.
- Broad government exemptions. Section 17 lets the central government exempt its own agencies from the Act on grounds such as national security and public order. Critics argue this is too wide; the government's position is that it mirrors exemptions found in other data protection laws.
- "Reasonable" is not defined in depth. Rule 6 lists categories of safeguards but not standards. That flexibility helps startups, and it also means there is no clear bar until the Board starts deciding cases.
- No compensation for individuals. Penalties go to the government, not to the people whose data was breached. Earlier drafts had a compensation route; the final Act does not.
- Board independence. Members of the Data Protection Board are appointed by the central government, which critics say limits its independence when the government itself is the data fiduciary.
- No separate category for sensitive data. Unlike GDPR and the earlier Indian drafts, the Act treats health, financial, and biometric data under the same general rules as everything else, apart from children's data and Significant Data Fiduciaries.
- The RTI amendment. The Act amended the Right to Information Act in a way transparency advocates say makes it easier to refuse information that involves personal data.
From a security perspective, the practical upshot is simple. Do not build to the weakest reading of the law. Build to the baseline a competent auditor would expect, because that is what the Board will eventually use to judge "reasonable."
What Indian startups should build before May 2027
If you process personal data of people in India, the DPDP Act applies to you, whatever your size, and it also applies to companies outside India that offer goods or services to people in India. The Act lets the government exempt notified startups and classes of companies from some obligations, but no startup should plan its security around an exemption that may never cover it. Here is the order I would work in.
- Map your personal data. What you collect, why, where it is stored (including backups, logs, analytics, and third-party tools), and who can access it. Every other obligation depends on this document.
- Cut what you do not need. Remove fields, stop logging personal data you never use, and set retention periods. Less data is less risk and less compliance work.
- Put the Rule 6 baseline in place. Encryption at rest and in transit, access control with one identity per person and MFA, logging and monitoring retained for at least a year, tested backups, and security clauses in your processor contracts.
- Build the rights workflows. Access, correction, erasure (with the 48-hour notice where it applies), consent withdrawal, and a grievance contact, all working end to end rather than handled by email.
- Write the breach process now. One runbook covering CERT-In's six hours, the Board's 72 hours, and plain-language notices to affected users, with named owners.
- Rewrite your consent notices so they are itemised, specific, and available in the languages your users actually use.
- Handle children properly if there is any chance minors use your product: age signals, verifiable parental consent, and no tracking or targeted ads.
- Check your AI stack. If you send personal data to an LLM provider, you are using a processor. Know what you send, whether it is retained, and where it is processed, and keep personal data out of prompts and prompt logs unless the feature needs it.
If you are also regulated elsewhere, DPDP stacks on top: RBI rules for payments and lending (covered on my fractional CTO for fintech page), health data expectations (see fractional CTO for healthcare), and GDPR if you serve users in Europe.
Who should own DPDP compliance at a startup
DPDP compliance is split between legal and engineering, and at most startups the engineering half is the larger one. A lawyer can write your notices and review your contracts. Someone technical has to build the data map, the encryption, the logging, the erasure path, and the breach process, and keep them working as the product changes.
That is part of the work I do as a fractional CTO in India, for Indian founders and for foreign founders building products for Indian users: designing these obligations into the architecture from the start, or retrofitting them before they turn into a funding diligence problem. If you only need a periodic review of your design decisions, the technical advisor engagement covers that; if you need someone accountable for the work, that is a fractional CTO engagement.
Frequently asked questions
Why was the DPDP Act introduced? Because India's previous framework, Section 43A of the IT Act and the 2011 SPDI rules, covered only a narrow set of sensitive data, had no dedicated regulator, and did not require companies to tell people about breaches. The Supreme Court's 2017 Puttaswamy judgment recognised privacy as a fundamental right, and the scale of India's digital economy and repeated large breaches made a comprehensive law necessary.
When does the DPDP Act come into force for businesses? The DPDP Rules were notified in November 2025 with an 18-month phase-in. The Data Protection Board provisions applied immediately, the Consent Manager regime starts in November 2026, and the core obligations, including security safeguards and breach notification, apply by May 2027. The government has consulted on bringing some dates forward, so check the latest notifications.
What is the maximum penalty under the DPDP Act? Up to ₹250 crore for failing to take reasonable security safeguards to prevent a personal data breach. Failing to notify a breach and breaching children's data obligations can each cost up to ₹200 crore, and most other violations up to ₹50 crore.
What security measures does the DPDP Act require? Rule 6 of the DPDP Rules expects encryption, obfuscation, masking, or tokenisation of personal data; access controls; logging and monitoring to detect unauthorised access; retention of logs for at least a year; backups and continuity measures; and contracts requiring processors to take safeguards. It does not name specific standards, so build to what a competent auditor would expect.
How fast do you have to report a data breach under DPDP? You must inform affected individuals and the Data Protection Board without delay, and send the Board a detailed report within 72 hours. Separately, CERT-In's directions require cyber incidents to be reported to CERT-In within six hours.
Does the DPDP Act apply to startups and companies outside India? Yes. It applies to any organisation processing digital personal data in India, and to organisations outside India that process personal data in connection with offering goods or services to people in India. The government can exempt notified startups from some obligations, but security safeguards and breach notification are not the place to rely on that.
If you are building for Indian users and want a straight read on how far your product is from DPDP-ready, book a 30-minute call and walk me through your stack. I will tell you what I would fix first.
Written By
Kunal Vohra
Technical Co-Founder & Fractional CTO
I've co-founded 6+ startups across India, the UAE, and the US, spanning AI, Web3, fintech, and cybersecurity. I write about the technical and strategic decisions that determine whether a startup thrives or stalls.
Comments
Loading comments…