08
DPDP
India's data protection law applies to almost every business that has customers. Most have done nothing about it.
12
Obligations tracked
7
Statutory forms
0
Things you do
What this covers
The Digital Personal Data Protection Act applies to any business processing the personal data of people in India. That is not a technology-company obligation - it is a customer-list obligation, and it covers a cafe with a loyalty programme as much as a SaaS platform.
The requirements are not exotic. You need a lawful basis for what you collect, a notice telling people what you are doing with it, a way for them to withdraw consent, a named grievance officer, a retention limit, and a plan for what happens if data leaks. Children's data needs verifiable parental consent.
Separately, CERT-In directions require Indian entities to report cyber incidents within a prescribed window and retain logs for 180 days. These two frameworks are often confused. They are different, and both apply.
The calendar
Every obligation, with dates.
| What it is | Form | When | Who it applies to |
|---|---|---|---|
| Consent and lawful basis | - | Before collection | Any personal data of people in India |
| Privacy notice | - | At the point of collection | Every data fiduciary |
| Consent withdrawal mechanism | - | Continuous | Every data fiduciary |
| Grievance officer | - | Named and published | Every data fiduciary |
| Data principal rights process | - | Within prescribed timelines | Access, correction, erasure requests |
| Retention and deletion policy | - | Continuous | Every data fiduciary |
| Children's data - parental consent | - | Before collection | Users under 18 |
| Personal data breach notification | - | Within the prescribed window | Every breach |
| Processor and vendor agreements | - | Before sharing data | Every sub-processor |
| Cyber incident reporting | CERT-In | Within the prescribed window | Every body corporate |
| Log retention | CERT-In | 180 days | Every body corporate |
| Significant data fiduciary obligations | - | If notified | DPIA, audit, data protection officer |
Consent and lawful basis
Form · -
When · Before collection
Any personal data of people in India
Privacy notice
Form · -
When · At the point of collection
Every data fiduciary
Consent withdrawal mechanism
Form · -
When · Continuous
Every data fiduciary
Grievance officer
Form · -
When · Named and published
Every data fiduciary
Data principal rights process
Form · -
When · Within prescribed timelines
Access, correction, erasure requests
Retention and deletion policy
Form · -
When · Continuous
Every data fiduciary
Children's data - parental consent
Form · -
When · Before collection
Users under 18
Personal data breach notification
Form · -
When · Within the prescribed window
Every breach
Processor and vendor agreements
Form · -
When · Before sharing data
Every sub-processor
Cyber incident reporting
Form · CERT-In
When · Within the prescribed window
Every body corporate
Log retention
Form · CERT-In
When · 180 days
Every body corporate
Significant data fiduciary obligations
Form · -
When · If notified
DPIA, audit, data protection officer
Our side
What we do.
- Map what personal data you actually hold, where it sits, and who you share it with
- Determine your lawful basis for each category
- Draft the privacy notice, consent language and cookie disclosures
- Build the consent withdrawal and rights-request process
- Appoint and publish a grievance officer, and run the response workflow
- Draft the data retention and deletion policy
- Put processor agreements in place with every vendor that touches your data
- Draft the breach response plan and run the notification if one happens
- Assess whether CERT-In log retention applies to your infrastructure and check you are meeting it
- Reassess when you launch a product, add a vendor, or begin serving users under 18
If you miss it
The DPDP Act carries financial penalties at a scale that is unusual for Indian regulation, with the highest tier attaching to a failure to take reasonable security safeguards to prevent a breach. The practical exposure arrives earlier than the regulator does, though: enterprise customers now ask for your privacy posture in procurement, and a startup that cannot answer loses the deal long before it hears from anyone official.
Digital Personal Data Protection Act, 2023 · Information Technology Act, 2000 · CERT-In Directions, 2022
Process
How it runs.
- 01
We map the data
What you collect, why, where it lives, who else can see it. Most founders have never written this down.
- 02
We build the paperwork
Notice, consent, retention, grievance officer, processor agreements. All of it, drafted for your product.
- 03
We keep it aligned
When you add a vendor or launch a feature that collects something new, the map updates.
Questions founders ask
If you hold names, emails or phone numbers of people in India, yes. Turnover and headcount do not exempt you.
No, though they share concepts. If you also serve EU users, GDPR applies in parallel and its requirements are stricter in places. We will tell you which applies where.
No. A notice is one requirement of several. Consent mechanics, a grievance officer, retention limits and processor agreements are separate obligations.
No, and we will never tell you it is. Those are contractual certifications your customers require. DPDP is law. We track both, but they are different things.
Notification obligations run on short timelines, and CERT-In's window is shorter still. We draft the response plan in advance, because the middle of an incident is the wrong time to work out who to tell.
Related
Compliance you do not have to think about.
Tell us your CIN and what you are worried about. We will tell you exactly what applies to your company.
Every filing under this service is reviewed and signed by a practising Company Secretary or Chartered Accountant engaged on your account.
