Startups · Compliance

DPDP Act Compliance: What Every Indian Startup Handling User Data Must Do

Vaksy Legal Desk · 18 July 2026 · 4 min read

The Digital Personal Data Protection Act, 2023 applies to any startup that collects personal data, regardless of user count. Compliance comes down to a handful of concrete steps: a plain-language consent flow, a published grievance officer, a breach response and notification plan, and working tools for users to access, correct, or erase their data.

The Law Everyone Assumes Applies Only to Big Tech

If your app collects a phone number at signup, asks for location to show nearby options, or stores an email address in a database, the Digital Personal Data Protection Act, 2023 already applies to you. It does not matter if you have 200 users or 2 million. The Act defines a "data fiduciary" as anyone who decides why and how personal data is processed, and a five-person startup fits that definition just as much as a listed company does.

Founders often push this to the "we'll deal with it after we raise the next round" pile. That is the wrong instinct. Retrofitting consent flows, grievance processes, and deletion mechanisms into a product that already has thousands of users and years of accumulated data is far more expensive and disruptive than building them in from day one. It is also the kind of thing investors and enterprise customers now ask about during diligence.

Consent Has to Actually Mean Something

The Act is specific about what counts as valid consent: it has to be free, specific, informed, unconditional, and unambiguous, given through a clear affirmative action. A pre-ticked checkbox does not qualify. Neither does a wall-of-text privacy policy that users scroll past to hit "Continue." You need a notice, in plain language, telling the user what data you are collecting, why, and what happens to it, before you collect it, not buried in a terms page they never open.

If you are collecting data for one purpose (say, verifying identity) and later want to use it for another (say, marketing), that needs fresh consent. Bundling everything into one broad "I agree" at signup and hoping it covers future use is exactly the pattern the Act is designed to stop. Startups that support withdrawal of consent as easily as they support giving it tend to have far fewer headaches later.

Appointing a Grievance Officer Is Not Optional

Every data fiduciary has to designate a grievance officer whose contact details are published where users can find them, typically in the privacy policy or app settings. This person is the point of contact when a user wants to know what data you hold on them, wants it corrected, or wants it deleted. For a small team, this might just be your founder or ops lead wearing an additional hat. What matters is that the channel exists and that requests actually get resolved, not that you have a large compliance department.

What Happens If Data Gets Breached

If personal data you hold is compromised, whether through a hack, a misconfigured database, or an employee mistake, the Act requires you to notify the Data Protection Board of India and the affected individuals. The exact format and timelines for this notification are laid out under the rules framework, and startups should confirm current timelines with an advisor rather than assume, since implementation details have continued to be refined. The safer approach is to build breach detection and an internal escalation process now, so you are not scrambling to figure out who to call while a breach is actively unfolding.

Rights Your Users Now Have, By Law

Data principals, meaning your users, have the right to know what personal data of theirs you are processing, to correct inaccurate or outdated data, to have it erased once it is no longer needed for the purpose it was collected for, and to a clear grievance redressal path if you do not respond. Building simple in-app tools for "download my data" and "delete my account" early saves you from manually fulfilling these requests one by one as your user base grows.

Penalties under the Act for failures like inadequate security safeguards or breach non-reporting run into the crores of rupees, scaled by the Data Protection Board depending on the severity and nature of the failure. That number alone should be reason enough to treat this as foundational architecture, not paperwork to file away for later.

Getting This Right From the Start

Most of this comes down to a handful of concrete steps: a plain-language consent flow, a published grievance contact, a breach response plan, and working access-correction-erasure tools. None of it needs a legal team on retainer, but it does need someone who understands how the Act applies to your specific product and data flows.

Vaksy can connect you with a verified advocate on the platform who can review your consent flows, privacy policy, and data handling practices for your specific setup, and explain it all in the language you're most comfortable working in.

Get this reviewed for your case. General guides don't know your state, your facts, or your deadline. Vaksy matches you with a verified advocate on the platform who can review your situation and draft what you need, in your own language.

Talk to a Vaksy advocate →

New here? See how talking to a lawyer on Vaksy works →