Readiness assessment
The Act
The DPDP Act, explainedThe DPDP Rules 2025

Ch IPreliminary

S.1 Short title and commencementS.2 DefinitionsS.3 Application and scope

Ch IIObligations of Data Fiduciary

S.4 Grounds for processingS.5 NoticeS.6 ConsentS.7 Certain legitimate usesS.8 Data Fiduciary obligationsS.9 Children’s dataS.10 Significant Data Fiduciary

Ch IIIRights and duties of Data Principal

S.11 Right to accessS.12 Correction and erasureS.13 Grievance redressalS.14 Right to nominateS.15 Duties of the Data Principal

Ch IVSpecial provisions

S.16 Transfer outside IndiaS.17 Exemptions

Ch VData Protection Board of India

S.18 Establishment of the BoardS.19 Composition of the BoardS.20 Salary and term of officeS.21 DisqualificationsS.22 Resignation and vacanciesS.23 Proceedings of the BoardS.24 Officers and employeesS.25 Members as public servantsS.26 Powers of the Chairperson

Ch VIBoard powers and procedure

S.27 Powers and functions of the BoardS.28 Procedure followed by the Board

Ch VIIAppeal and dispute resolution

S.29 Appeal to the Appellate TribunalS.30 Tribunal orders as a decreeS.31 Alternate dispute resolutionS.32 Voluntary undertaking

Ch VIIIPenalties

S.33 Penalties and the ScheduleS.34 Penalties to Consolidated Fund

Ch IXMiscellaneous

S.35 Good-faith protectionS.36 Power to call for informationS.37 Blocking of accessS.38 Consistency with other lawsS.39 Bar of jurisdictionS.40 Power to make rulesS.41 Laying of rules before ParliamentS.42 Power to amend the ScheduleS.43 Power to remove difficultiesS.44 Amendments to other Acts
Industries
Implementation
Training
Resources
About
Readiness assessment

DPDP Act by role

DPDP Act for Founders and Startups in India

You are building a company, and the DPDP Act now applies to you as a Data Fiduciary. Here is the practical minimum to get compliant without slowing down.

Understand. Check. Connect.

We match you with the right DPDP implementation partner, only when you ask.

At a glance

Founders and startups become Data Fiduciaries under India's DPDP Act the moment they collect personal data from users, customers or employees. The practical priorities are to know what data you hold, get your privacy notice and consent right, publish a contact point, apply basic security, and set retention. Full compliance is expected by 13 May 2027. Most of it can be covered with editable templates; bring in help only where risk is high.

What the DPDP Act means for you

If you collect any personal data, name, email, phone, payment or usage data, your startup is a Data Fiduciary under the DPDP Act, with real obligations and penalties for getting it wrong. The good news is that for most early-stage companies the core is achievable with a few well-drafted documents and sensible defaults. The goal is to build privacy in now, while your data footprint is small, rather than retrofitting it after you scale.

Your priorities

Know what you collect

Map the personal data you hold and why. This record of processing is the foundation everything else builds on.

Notice and consent

Publish a clear privacy notice and collect free, specific, unbundled consent that is as easy to withdraw as to give.

Basic security

Apply reasonable safeguards: access control, encryption where it matters, and a simple breach plan.

Retention and rights

Keep data only as long as you need it, and be ready to handle access, correction and erasure requests.

Where to start

Map your data

List what you collect, where it lives and why. Start with the record-of-processing template.

Fix notice and consent

Publish a compliant notice and clean up your signup consent flow.

Name a contact

Publish a point of contact for data questions and grievances.

Set retention and security

Decide how long you keep data, and lock down who can access it.

Tools and help

Move fast with ready-made resources, or get expert help where it matters:

Frequently asked questions

Does the DPDP Act apply to a small startup?
Yes. Size does not exempt you. Any organisation that decides why and how to process personal data is a Data Fiduciary, with the core duties of notice, consent, security, retention and rights.
What is the cheapest way to get compliant?
Start with the free readiness assessment, then use editable templates for your notice, consent, record of processing and retention. Bring in a partner only for high-risk or complex areas.
When do I need to comply?
Full compliance is expected by 13 May 2027, but starting now is far cheaper than retrofitting privacy once you have scaled.

See where you stand

Take the free readiness assessment for a picture tailored to your organisation, then choose a tool or a partner.

Start free readiness assessmentSee the Compliance Toolkit

This page is educational and not legal advice. Confirm against the enacted Act and the DPDP Rules, or take professional advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.