Virtual CFO & Compliance

DPDP Act Compliance for Startups & SMEs

Get ready for India’s Digital Personal Data Protection Act before the obligations bite in 2027 — data mapping, consent and notice architecture, processor contracts and a breach playbook, built for a startup rather than an enterprise.

Why founders pick CapEasy

5.0★ across 335+ Google reviews

2,700+ founders served across India

Overview

The Digital Personal Data Protection Act, 2023 applies to every business that processes digital personal data — there is no turnover, headcount or user-count threshold. If you collect an email address or a phone number from someone in India, you are a Data Fiduciary under the Act.

Here is the part most compliance pages will not tell you: as of today almost none of it is enforceable yet. The DPDP Rules were notified in November 2025, but only the institutional provisions — the Data Protection Board, definitions, procedure — are in force. The obligations that actually affect your business (notice, consent, security safeguards, breach reporting, individual rights) and the penalties behind them commence in May 2027. Consent Manager registration opens a little earlier, in November 2026.

That is runway, not a reason to ignore it. Two things make starting in 2026 the right call rather than the cautious one. First, MeitY consulted in January 2026 on compressing the window to November 2026; that has not been notified, but the deadline may move toward you, not away. Second, the work itself is slow — a data map, a consent rebuild and re-papering every processor contract is a two-to-three-quarter programme in most businesses, and investors and enterprise customers are already asking about DPDP readiness in diligence long before the Board can fine anyone.

CapEasy runs this as a business-compliance engagement, not a security audit. Most firms ranking for DPDP are infosec practices selling enterprise programmes; a 12-person SaaS company does not need the same thing a bank does. We scope to what the Act actually asks of a company your size.

Who it’s for

  • SaaS, D2C, marketplace and app businesses collecting customer data — the profile most exposed and least served by enterprise privacy vendors
  • Startups being asked about DPDP readiness in investor diligence or enterprise procurement, well ahead of the legal deadline
  • Companies handling data of users under 18, where the Act is materially stricter than most founders expect
  • Businesses outside India offering goods or services to Indian users — the Act reaches them under section 3(b)
  • Founders who have read a GDPR-shaped checklist and want to know what actually differs under Indian law

Eligibility & requirements

  • Notice and consent: a standalone notice in clear language, itemising the data and the purpose, with withdrawal as easy as giving consent — and the option for the individual to read it in English or any of the 22 scheduled languages
  • No legitimate-interest fallback: unlike GDPR, anything outside a closed statutory list of legitimate uses needs consent. This is where privacy programmes copied from Europe break
  • Security safeguards: encryption or masking, access control, logging and monitoring, backups, one-year log retention, and equivalent obligations pushed down to your processors by contract
  • Breach notification: tell affected individuals without delay, tell the Board without delay and file a detailed report within 72 hours — with no severity threshold, so every breach is reportable. CERT-In’s separate 6-hour reporting already applies today
  • Children’s data: a child is anyone under 18. Verifiable parental consent is required, and tracking, behavioural monitoring and targeted advertising to children are prohibited outright — consent cannot cure that
  • Erasure and retention: delete when consent is withdrawn or the purpose is served, with 48 hours’ notice to the individual before erasure
  • Grievance redressal: a published mechanism and a named contact, responding within 90 days

How CapEasy handles it

  1. Data map first. We inventory every system holding personal data and trace flows, purposes, recipients, processors and cross-border movement. Every other deliverable is guesswork without it
  2. Lawful-basis assessment — classify each processing activity as consent-based or falling inside the statutory list of legitimate uses, and flag anything currently relying on a basis the Act does not recognise
  3. Consent architecture — granular per-purpose consent replacing bundled acceptance, withdrawal as easy as giving, and auditable consent logs
  4. Notice drafting — a standalone notice that meets the Rules, plus the language-option mechanism
  5. Processor and vendor contracts — the Act requires a valid contract with every processor and equivalent safeguards passed down, including a breach window tight enough for you to hit your own 72 hours
  6. Retention schedule and erasure mechanics, reconciled with the longer retention other Indian laws impose on tax, company and payroll records
  7. Breach playbook — a runbook covering detection, containment, the individual and Board intimations and the 72-hour report, reconciled with CERT-In’s 6-hour clock, and tested rather than filed
  8. Grievance function — a named contact, published means, and tracking against the 90-day cap

Documents you’ll typically need

  • A list of systems, tools and vendors that touch customer or employee data (CRM, analytics, payments, support desk, cloud storage, payroll)
  • Your current privacy policy, terms and any consent or cookie banners
  • Existing contracts with vendors that process data on your behalf
  • Sign-up and onboarding flows — screenshots or access — so consent capture can be reviewed as users actually experience it
  • Details of any data stored or processed outside India
  • Whether any of your users are under 18, and how age is currently established

CapEasy is a private consultancy and is not affiliated with any government authority. We help you assess eligibility and prepare and file your application; eligibility and approval depend on your specifics and the relevant department’s discretion.

Frequently asked

DPDP Act Compliance for Startups & SMEs — questions founders ask

Partly. The Act and the DPDP Rules were notified in November 2025, but only the institutional provisions — the Data Protection Board, definitions and procedure — are live. Notice, consent, security, breach reporting, individual rights and the penalties commence in May 2027, with Consent Manager registration opening in November 2026. MeitY has consulted on moving the main date forward to November 2026; that has not been notified.

Yes. There is no turnover, revenue, headcount or user-count threshold — if you collect personal data from people in India, you are a Data Fiduciary. The Act allows the government to exempt startups from a handful of obligations, but it has not done so, and even that exemption would leave consent, security, breach reporting, grievance handling and children’s-data duties intact.

Up to ₹250 crore for failing to maintain reasonable security safeguards, up to ₹200 crore each for failing to report a breach or breaching children’s-data obligations, and up to ₹50 crore for any other contravention. For a small company the realistic exposure is the residual head, not the headline — and none of it is enforceable until the penalty provisions commence.

No, and it is worth being precise about the difference. A Consent Manager is a separately licensed role — a company incorporated in India with at least ₹2 crore net worth, independently certified and registered with the Data Protection Board — running a neutral platform through which individuals manage consent. We provide Data Fiduciary compliance services: we help your business meet its own obligations. We do not hold, broker or manage consent on behalf of individuals, and we make no claim to Board registration.

Only if the government designates you a Significant Data Fiduciary, and none have been designated yet. Every other business simply publishes the business contact details of a person who can answer questions about how it processes personal data.

Affected individuals must be told without delay, and the Board must receive an initial intimation without delay followed by a detailed report within 72 hours. There is no severity threshold — every personal data breach is reportable. CERT-In’s separate 6-hour cyber-incident reporting applies today and is unaffected.

Your CapEasy experts

Connect with us

Talk to the people who handle this work every day — no call centre, no hand-offs.

Ayush Joshi

Ayush Joshi

Co-Founder

Ex-OYO and Tenaciousfly. 7+ years in business development, strategic acquisitions, financing and debt syndication.

Aditya Jain

Aditya Jain

Co-Founder

Ex-Bank of America. 4+ years in investment banking, EU & Indian compliances, ESG compliances, and project management.

Manav Raval

Virtual CFO & Tax Specialist

Section 80-IAC, tax planning and startup compliance. Previously at Toyota Motor Corporation and Jaguar Land Rover.

Ayush Faldu

Virtual CFO & Tax Specialist

Financial strategy, budgeting and cash flow — a CFO’s judgement, monthly.

Book a free consultation.

An honest assessment of where you are and what comes next — no cost, no pressure, no inflated promises.