What is the DPDP Act? A founder's guide
The Digital Personal Data Protection Act is India's data protection law. It was enacted in 2023, and its Rules were notified in November 2025. It governs how companies collect, store, and use the personal data of Indian users. Almost every company holding Indian user data has obligations under it, and full enforcement applies from 13 May 2027.
Two roles you need to understand
The Act introduces two roles. A Data Fiduciary is any company that decides why and how personal data is processed. That is most product companies. A Data Principal is the individual whose data is being processed, which means your users. The Act gives Data Principals rights and places duties on Data Fiduciaries.
The core duties
The core duties are straightforward to state and harder to build. You need explicit, verifiable consent before processing personal data. You need a plain-language notice at the point of collection. You must honour user rights to access, correction, and erasure. You must report personal data breaches. You must delete data you no longer need. And you remain responsible for every vendor that touches that data on your behalf.
Who enforces it
The Act is made by MeitY, the Ministry of Electronics and Information Technology. Enforcement sits with the Data Protection Board of India, a body empowered to investigate breaches and impose penalties. Those penalties run high, up to INR 250 crore for inadequate security safeguards.
No size exemption
There is no size exemption. A two-person startup and a listed company both carry obligations if they process Indian personal data. The difference is that larger or higher-risk entities can be classified as Significant Data Fiduciaries with extra duties.
"Most founders assume a privacy policy covers it. It does not. The Act asks for systems, not statements."
Where to start
Map what personal data your product collects, where it flows, and which third parties receive it. That map shows you the gap between what the Act requires and what your product does today.
Next step
Find out how compliant your product is.
Ten questions covering consent, data rights, security, and breach readiness. Takes two minutes.
Start the readiness check →Written by Smoketrees Digital LLP, a product engineering studio based in Bengaluru. We implement DPDP compliance directly into codebases for Indian product companies.