Readiness assessment

DPDP by role

DPDP Act for Founders and Startups in India

You are building a company, and the DPDP Act now applies to you as a Data Fiduciary. Here is the practical minimum to get compliant without slowing down.

At a glance

Founders and startups become Data Fiduciaries under India's DPDP Act the moment they collect personal data from users, customers or employees. The practical priorities are to know what data you hold, get your privacy notice and consent right, publish a contact point, apply basic security, and set retention. Full compliance is expected by 13 May 2027. Most of it can be covered with editable templates; bring in help only where risk is high.

What the DPDP Act means for you

If you collect any personal data, name, email, phone, payment or usage data, your startup is a Data Fiduciary under the DPDP Act, with real obligations and penalties for getting it wrong. The good news is that for most early-stage companies the core is achievable with a few well-drafted documents and sensible defaults. The goal is to build privacy in now, while your data footprint is small, rather than retrofitting it after you scale.

Your priorities

Know what you collect

Map the personal data you hold and why. This record of processing is the foundation everything else builds on.

Notice and consent

Publish a clear privacy notice and collect free, specific, unbundled consent that is as easy to withdraw as to give.

Basic security

Apply reasonable safeguards: access control, encryption where it matters, and a simple breach plan.

Retention and rights

Keep data only as long as you need it, and be ready to handle access, correction and erasure requests.

Where to start

Map your data

List what you collect, where it lives and why. Start with the record-of-processing template.

Fix notice and consent

Publish a compliant notice and clean up your signup consent flow.

Name a contact

Publish a point of contact for data questions and grievances.

Set retention and security

Decide how long you keep data, and lock down who can access it.

Tools and help

Move fast with ready-made resources, or get expert help where it matters:

Frequently asked questions

Does the DPDP Act apply to a small startup?
Yes. Size does not exempt you. Any organisation that decides why and how to process personal data is a Data Fiduciary, with the core duties of notice, consent, security, retention and rights.
What is the cheapest way to get compliant?
Start with the free readiness assessment, then use editable templates for your notice, consent, record of processing and retention. Bring in a partner only for high-risk or complex areas.
When do I need to comply?
Full compliance is expected by 13 May 2027, but starting now is far cheaper than retrofitting privacy once you have scaled.

See where you stand

Take the free readiness assessment for a picture tailored to your organisation, then choose a tool or a partner.

Start free readiness assessmentSee the Compliance Toolkit

This page is educational and not legal advice. Confirm against the enacted Act and the DPDP Rules, or take professional advice. dpdpactindia.in is an independent resource and is not affiliated with the Government of India.