Overview
The Digital Personal Data Protection Act, 2023 applies to every business that processes digital personal data — there is no turnover, headcount or user-count threshold. If you collect an email address or a phone number from someone in India, you are a Data Fiduciary under the Act.
Here is the part most compliance pages will not tell you: as of today almost none of it is enforceable yet. The DPDP Rules were notified in November 2025, but only the institutional provisions — the Data Protection Board, definitions, procedure — are in force. The obligations that actually affect your business (notice, consent, security safeguards, breach reporting, individual rights) and the penalties behind them commence in May 2027. Consent Manager registration opens a little earlier, in November 2026.
That is runway, not a reason to ignore it. Two things make starting in 2026 the right call rather than the cautious one. First, MeitY consulted in January 2026 on compressing the window to November 2026; that has not been notified, but the deadline may move toward you, not away. Second, the work itself is slow — a data map, a consent rebuild and re-papering every processor contract is a two-to-three-quarter programme in most businesses, and investors and enterprise customers are already asking about DPDP readiness in diligence long before the Board can fine anyone.
CapEasy runs this as a business-compliance engagement, not a security audit. Most firms ranking for DPDP are infosec practices selling enterprise programmes; a 12-person SaaS company does not need the same thing a bank does. We scope to what the Act actually asks of a company your size.
Who it’s for
- SaaS, D2C, marketplace and app businesses collecting customer data — the profile most exposed and least served by enterprise privacy vendors
- Startups being asked about DPDP readiness in investor diligence or enterprise procurement, well ahead of the legal deadline
- Companies handling data of users under 18, where the Act is materially stricter than most founders expect
- Businesses outside India offering goods or services to Indian users — the Act reaches them under section 3(b)
- Founders who have read a GDPR-shaped checklist and want to know what actually differs under Indian law
Eligibility & requirements
- Notice and consent: a standalone notice in clear language, itemising the data and the purpose, with withdrawal as easy as giving consent — and the option for the individual to read it in English or any of the 22 scheduled languages
- No legitimate-interest fallback: unlike GDPR, anything outside a closed statutory list of legitimate uses needs consent. This is where privacy programmes copied from Europe break
- Security safeguards: encryption or masking, access control, logging and monitoring, backups, one-year log retention, and equivalent obligations pushed down to your processors by contract
- Breach notification: tell affected individuals without delay, tell the Board without delay and file a detailed report within 72 hours — with no severity threshold, so every breach is reportable. CERT-In’s separate 6-hour reporting already applies today
- Children’s data: a child is anyone under 18. Verifiable parental consent is required, and tracking, behavioural monitoring and targeted advertising to children are prohibited outright — consent cannot cure that
- Erasure and retention: delete when consent is withdrawn or the purpose is served, with 48 hours’ notice to the individual before erasure
- Grievance redressal: a published mechanism and a named contact, responding within 90 days
How CapEasy handles it
- Data map first. We inventory every system holding personal data and trace flows, purposes, recipients, processors and cross-border movement. Every other deliverable is guesswork without it
- Lawful-basis assessment — classify each processing activity as consent-based or falling inside the statutory list of legitimate uses, and flag anything currently relying on a basis the Act does not recognise
- Consent architecture — granular per-purpose consent replacing bundled acceptance, withdrawal as easy as giving, and auditable consent logs
- Notice drafting — a standalone notice that meets the Rules, plus the language-option mechanism
- Processor and vendor contracts — the Act requires a valid contract with every processor and equivalent safeguards passed down, including a breach window tight enough for you to hit your own 72 hours
- Retention schedule and erasure mechanics, reconciled with the longer retention other Indian laws impose on tax, company and payroll records
- Breach playbook — a runbook covering detection, containment, the individual and Board intimations and the 72-hour report, reconciled with CERT-In’s 6-hour clock, and tested rather than filed
- Grievance function — a named contact, published means, and tracking against the 90-day cap
Documents you’ll typically need
- A list of systems, tools and vendors that touch customer or employee data (CRM, analytics, payments, support desk, cloud storage, payroll)
- Your current privacy policy, terms and any consent or cookie banners
- Existing contracts with vendors that process data on your behalf
- Sign-up and onboarding flows — screenshots or access — so consent capture can be reviewed as users actually experience it
- Details of any data stored or processed outside India
- Whether any of your users are under 18, and how age is currently established
CapEasy is a private consultancy and is not affiliated with any government authority. We help you assess eligibility and prepare and file your application; eligibility and approval depend on your specifics and the relevant department’s discretion.



