Back to Home Page

DPDP Act Compliance for Startups and E-Commerce Businesses in India

Customer data powers modern businesses. Startups, Software-as-a-Service (SaaS) platforms, mobile applications, e-commerce sellers, marketplaces, agencies, and online service providers collect personal data every day.

The Digital Personal Data Protection (DPDP) Act, 2023 creates India’s principal framework for processing digital personal data. The notified Digital Personal Data Protection Rules, 2025 provide additional operational detail and introduce a phased commencement structure.

Compliance is not limited to publishing a privacy policy. Businesses must understand what data they collect, why they collect it, where it goes, who processes it, how long it is retained, and how individuals can exercise their rights.

Important: The DPDP framework is being implemented in phases. This article explains the compliance approach relevant to businesses in 2026 based on the DPDP Act, 2023, the notified DPDP Rules, 2025, and available government material. Businesses should verify the latest notifications, sector-specific requirements, and commencement status before taking action.

What Is the DPDP Act, 2023?

The Digital Personal Data Protection Act, 2023 regulates the processing of digital personal data in India. It applies to organisations that determine the purpose and means of processing personal data, as well as organisations that process data on their behalf.

The Act generally refers to these parties as:

  • Data Principal: The individual to whom the personal data relates.
  • Data Fiduciary: The person or organisation deciding why and how personal data is processed.
  • Data Processor: A person or organisation processing personal data for a Data Fiduciary.
  • Significant Data Fiduciary (SDF): A Data Fiduciary that may be notified as significant based on factors such as the volume and sensitivity of data, risk to individuals, impact on sovereignty or integrity, and other prescribed considerations.

A startup may be a Data Fiduciary for its customers and a Data Processor for another company at the same time. The correct classification depends on the actual role performed in each relationship.

What Is the Compliance Position in 2026?

The DPDP Rules, 2025 were notified by the Ministry of Electronics and Information Technology (MeitY) through Gazette Notification G.S.R. 846(E). The Rules provide for phased commencement.

As a general overview:

  • Certain introductory, institutional, and procedural rules came into force upon publication.
  • The rule concerning consent managers is scheduled to commence one year after Gazette publication.
  • Several substantive operational rules are scheduled to commence eighteen months after publication, including rules relating to notices, security safeguards, breach response, children’s data, rights, and certain Data Fiduciary obligations.

As of 2026, most businesses should treat the period as a compliance-readiness window. Organisations should not wait for the final enforcement stage to begin preparing. Data mapping, contract revision, security controls, rights-handling processes, and vendor review often require significant time.

Businesses should review the latest materials on the MeitY official website and the DPDP Act, 2023 page.

Privacy Notices Must Be Clear and Purpose-Specific

A privacy notice explains how a business collects and uses personal data. It should be written in clear language and made available at the relevant point of collection.

A practical notice should address:

  • The categories of personal data collected.
  • The purpose of collection and processing.
  • The method of providing and withdrawing consent, where consent is the applicable basis.
  • The manner in which individuals may exercise their rights.
  • Contact details for grievance or privacy-related communication.
  • The categories of processors or vendors receiving the data.
  • Retention or deletion practices, where relevant.
  • Cross-border processing or transfer information, where applicable.

A single generic policy copied from another website may not accurately describe the business. A SaaS company, online marketplace, coaching platform, and D2C seller will generally have different data flows and purposes.

Consent, Legitimate Uses and User Choice

Consent should be informed, specific, clear, and capable of being withdrawn through a reasonably accessible method. Businesses should avoid forced consent, bundled permissions, pre-selected choices, or confusing user interfaces.

The DPDP Act also recognises certain legitimate uses in specified circumstances. A business should not assume that every processing activity qualifies as a legitimate use. The relevant purpose, facts, notices, and applicable provisions must be assessed individually.

Consent records should be maintained in a manner that enables the business to demonstrate:

  • When consent was collected.
  • What the individual was told.
  • What purpose was accepted.
  • Which version of the notice applied.
  • Whether consent was later withdrawn.
  • What action was taken after withdrawal.

A consent manager is not automatically required for every startup. Organisations intending to operate as consent managers may have separate registration and compliance requirements under the notified framework.

Children’s Data Requires Additional Care

The DPDP framework contains enhanced protections for children. Businesses handling children’s data should review requirements relating to verifiable parental consent and restrictions on activities such as tracking, behavioural monitoring, or targeted advertising.

This is particularly relevant for:

  • Educational applications.
  • Gaming platforms.
  • Social media and community products.
  • Children’s product stores.
  • EdTech and online learning businesses.
  • Family-focused healthcare or wellness platforms.

Age-gating, parental verification, marketing controls, and internal escalation procedures should be designed before launch. Businesses should also consider whether their product design encourages children to submit unnecessary information.

Secure data flow from customer consent to storage, vendor processing and deletion for an Indian digital business

Data Processing Contracts and Vendor Due Diligence

Many businesses share personal data with cloud providers, payment gateways, logistics partners, Customer Relationship Management (CRM) platforms, marketing agencies, analytics vendors, call centres, and Information Technology (IT) support providers.

A Data Fiduciary should understand:

  • What data the vendor receives.
  • Why the vendor processes it.
  • Whether the vendor may appoint sub-processors.
  • Where the information is stored or accessed.
  • What security controls apply.
  • How incidents must be reported.
  • How data will be returned or deleted.
  • Whether the vendor may use the data for its own purposes.

Written Data Processing Agreements (DPAs) should be aligned with the actual relationship. A basic confidentiality clause may not be sufficient. Vendor agreements should address confidentiality, security safeguards, incident cooperation, audit or assurance rights, deletion, sub-processing, access control, and assistance with individual requests.

Security Safeguards and Breach Response

Security safeguards should be proportionate to the nature and volume of personal data. They may include:

  • Role-based access controls.
  • Multi-factor authentication.
  • Encryption where appropriate.
  • Secure software development practices.
  • Vulnerability testing and patch management.
  • Backup and recovery controls.
  • Logging and monitoring.
  • Employee awareness training.
  • Device and credential management.
  • Incident response procedures.

A breach plan should identify who investigates an incident, who preserves evidence, who communicates with vendors, who assesses legal impact, and who manages communications with affected individuals or authorities when required.

The DPDP Rules contain operational provisions concerning breach reporting. Businesses should verify the applicable commencement status and reporting requirements rather than relying on informal summaries or outdated articles.

Retention, Deletion and Data Lifecycle Management

Businesses should not retain personal data indefinitely without a documented reason. Retention should be connected to the purpose of collection, contractual requirements, legal obligations, accounting needs, fraud prevention, dispute management, and other legitimate business requirements.

A practical data lifecycle should cover:

  1. Collection.
  2. Use.
  3. Sharing.
  4. Archival, where justified.
  5. Deletion or anonymisation.
  6. Verification of deletion from relevant systems and vendors.

Deletion processes should include production databases, backups, shared drives, email systems, CRM tools, and vendor platforms where technically and legally appropriate.

Cross-Border Transfers and Sector-Specific Compliance

The DPDP Act and Rules should not be read in isolation. Businesses may also be subject to sector-specific requirements involving banking, payments, insurance, healthcare, telecommunications, employment, advertising, consumer protection, or information technology.

Cross-border data transfers should be assessed against:

  • The DPDP framework and applicable government restrictions.
  • Regulatory requirements applicable to the industry.
  • Contractual commitments to customers or enterprise clients.
  • Cloud and sub-processor locations.
  • Security and access-control arrangements.
  • Data localisation requirements, where applicable.

A business should not make a broad statement that “data is never transferred outside India” unless its systems, vendors, support teams, and backups have been properly checked.

E-Commerce Marketplace Responsibilities

An e-commerce marketplace may process data as a Data Fiduciary, while sellers, delivery partners, payment providers, and technology vendors may have separate roles.

Marketplace businesses should review:

  • Customer account and order information.
  • Seller and buyer onboarding data.
  • Payment and refund information.
  • Delivery and location data.
  • Marketing and recommendation systems.
  • Customer support recordings.
  • Fraud detection and risk scoring.
  • Data sharing with sellers and logistics providers.
  • Deletion and account-closure workflows.

The marketplace should clearly identify which entity controls each processing activity. The privacy notice, seller agreement, consumer terms, data-processing contracts, and internal data map should not contradict one another.

Employee, Applicant and Contractor Data

DPDP compliance also covers many internal data flows. Employers and startups should review personal data collected from:

  • Employees.
  • Job applicants.
  • Consultants.
  • Interns.
  • Contractors.
  • Directors and authorised signatories.

Relevant records may include identity documents, payroll information, bank details, attendance data, performance records, health information, background verification reports, and access logs.

Employee data should be collected for defined purposes, accessed only by authorised personnel, retained appropriately, and protected through suitable administrative and technical controls.

Practical DPDP Compliance Checklist for 2026

Businesses can begin with the following checklist:

  • Identify all personal data collected through websites, applications, forms, calls, cookies, and offline channels.
  • Classify the organisation’s role as Data Fiduciary, Data Processor, or both.
  • Create a data inventory and processing map.
  • Review and customise the privacy notice.
  • Document consent and withdrawal mechanisms.
  • Identify applicable legitimate-use grounds.
  • Review children’s data and age-verification risks.
  • Prepare a rights and grievance-handling workflow.
  • Review vendor contracts and sub-processor arrangements.
  • Implement reasonable security safeguards.
  • Create an incident and breach-response plan.
  • Establish retention and deletion schedules.
  • Assess cross-border data access and storage.
  • Check sector-specific laws and regulatory directions.
  • Determine whether Significant Data Fiduciary obligations may become relevant.
  • Train employees handling personal data.
  • Maintain an evidence file showing compliance decisions and implementation.

Common DPDP Compliance Mistakes

Common mistakes include:

  • Treating a privacy policy as the complete compliance programme.
  • Copying a generic policy without mapping actual data flows.
  • Collecting excessive information “just in case.”
  • Using consent for purposes that are not properly explained.
  • Ignoring vendors and cloud platforms.
  • Failing to document consent withdrawal.
  • Retaining former customer or employee data indefinitely.
  • Assuming processors have no compliance responsibilities.
  • Neglecting children’s data risks.
  • Treating the DPDP Act as the only applicable data law.
  • Waiting until enforcement begins to prepare.

A privacy policy alone is not sufficient. Effective compliance requires documentation, contracts, security, governance, training, and operational processes.

Indian e-commerce founders and legal professionals reviewing cybersecurity and customer data compliance

How VS IPR & LEGAL ADVISORS LLP Can Help

DPDP compliance often overlaps with corporate law, technology contracts, intellectual property, startup advisory, GST, employment documentation, and e-commerce operations.

VS IPR & LEGAL ADVISORS LLP provides a one-roof legal approach that can assist businesses with:

  • DPDP readiness assessments.
  • Privacy policies and website terms.
  • Data Processing Agreements.
  • Vendor and technology contracts.
  • Consent and grievance workflows.
  • Intellectual property protection.
  • Startup and company registration.
  • Corporate law advisory.
  • GST and business compliance support.
  • Ongoing legal and regulatory strategy.

Expert Team

Mr. Sanjay Trivedi

Mr. Sanjay Trivedi, legal and corporate law advisor

Mr. Vipul Bhatt

Mr. Vipul Bhatt, legal and corporate law advisor

Mr. Harsh Mehta

Mr. Harsh Mehta, legal and corporate law advisor speaking at a professional forum

Protect Your Business Before Data Risk Becomes a Dispute

If your startup, SaaS platform, mobile application, agency, marketplace, or e-commerce business collects customer or employee data, begin with a structured assessment.

Review your data flows, identify your legal role, update your contracts, and build practical compliance processes. Let’s talk about your DPDP readiness. Call us today or leave a message to schedule a consultation.

Consult VS IPR & LEGAL ADVISORS LLP or contact the firm.

VS IPR & LEGAL ADVISORS LLP
B-005 & 6 SURYA KIRAN BUILDING, AWADHUT NAGAR, NEAR ANAND JUICE CENTER, DAHISAR-EAST, MUMBAI 400068, MAHARASHTRA.
EMAIL: PROCESS.VSLEGAL@GMAIL.COM | LEGAL@VSIPR.COM
TEL: +91 8898979393 | +91 9326362813 | +91 8652519622

This article is for general information and does not constitute legal advice. DPDP applicability and commencement should be verified against the latest official notifications, rules, corrigenda, and sector-specific requirements.

Frequently Asked Questions

Is a privacy policy mandatory for every startup?

A business should assess its obligations based on its role, data processing activities, applicable provisions, and sector requirements. A privacy policy or notice is an important part of compliance, but it is not a substitute for contracts, security safeguards, rights-handling procedures, and governance.

Does the DPDP Act apply only to large e-commerce companies?

No. Startups, SaaS companies, agencies, mobile-app businesses, marketplaces, and other organisations may be covered depending on their processing activities and role as a Data Fiduciary or Data Processor.

Must every company appoint a Data Protection Officer?

Not necessarily. Specific obligations may depend on whether the organisation is notified as a Significant Data Fiduciary or falls under another applicable requirement. Businesses should assess their status instead of assuming that one appointment model applies to every organisation.

What should a startup do first?

The first steps should usually include data mapping, role classification, privacy notice review, vendor assessment, consent analysis, and creation of a breach-response and grievance-handling process.

Leave a Reply