DPDPA Compliance Checklist for Startups
India's Digital Personal Data Protection Act, 2023 is now law. Here's a pragmatic, startup-friendly checklist covering consent, data fiduciary duties, breach reporting, and DPO triggers.
The Digital Personal Data Protection Act, 2023 (DPDPA) is India's first comprehensive data protection law. Unlike GDPR's 99 articles, the DPDPA is relatively short — but the operational implications for startups are significant. This checklist breaks down what a typical Indian startup needs to do, in priority order.
1. Determine If DPDPA Applies To You
DPDPA applies to processing of digital personal data within India, and to processing outside India that targets data principals in India. If your startup has Indian users, customers, or employees — DPDPA applies.
2. Identify Your Role: Data Fiduciary vs Data Processor
- Data Fiduciary — determines the purpose and means of processing (usually you, the startup).
- Data Processor — processes data on behalf of a fiduciary (e.g., your cloud provider, email service, analytics vendor).
You're almost certainly a Data Fiduciary. Map every third-party processor you use (AWS, Stripe, Mixpanel, Slack, etc.).
3. Build a Data Inventory
You cannot protect what you don't know you have. Document:
- What personal data you collect (email, phone, location, biometric, etc.)
- Where it's stored (S3 bucket, Postgres table, vendor X)
- Who has access (which team, which vendor)
- Retention period (how long you keep it)
- Legal basis (consent, legitimate use, legal obligation)
4. Implement a Consent Mechanism
DPDPA requires a specific, informed, and unambiguous consent for processing personal data. The consent notice must be:
- Available in English and any Indian language your users speak
- Clear about what data is collected and why
- Withdrawable as easily as it was given
A pre-ticked checkbox is NOT valid consent.
5. Publish a Privacy Policy
Your privacy policy must disclose:
- What personal data is collected
- The purpose of processing
- The rights of the data principal
- How to grievance-redress
- The contact of your Grievance Officer
6. Appoint a Grievance Officer
Every Data Fiduciary must publish the name and contact of a Grievance Officer. The officer must acknowledge complaints within 24 hours and resolve within 21 days (or such period as prescribed).
7. Implement Data Principal Rights
DPDPA grants data principals the right to:
- Access their data
- Correct and complete it
- Erase it
- Nominate (in case of death/incapacity)
- Withdraw consent
Build a self-service portal or documented email workflow for each of these.
8. Reasonable Security Safeguards
Section 8(5) requires "reasonable security safeguards" — the DPDPA doesn't prescribe specific controls, but the Standard Reasonable Security Practices (to be notified) will likely align with ISO 27001 / SOC 2 baselines:
- Encryption at rest and in transit (AES-256-GCM, TLS 1.3)
- Access control (RBAC, MFA)
- Audit logging (immutable, tamper-evident)
- Vulnerability management (continuous SAST + DAST)
- Incident response plan
9. Breach Notification
If a personal data breach occurs, you must notify:
- The Data Protection Board (within 72 hours)
- Each affected data principal (without undue delay)
Document the breach: nature, scope, mitigation steps, remediation plan.
10. Data Retention & Deletion
You must delete personal data once the purpose for collection is no longer served and consent is withdrawn (or retention is not required by law). Automate deletion in your DB schema — soft-delete for the first 30 days, then hard-delete.
11. Cross-Border Transfers
DPDPA restricts transfers to countries on a negative list (to be notified by the Central Government). Until the list is published, default to storing Indian personal data within India.
12. Children's Data
If you process data of anyone under 18:
- Verifiable parental consent is mandatory
- No behavioral tracking or targeted advertising
- No processing likely to cause detriment to the child
13. Special Categories: Significant Data Fiduciaries
If the government notifies you as a Significant Data Fiduciary (based on volume, sensitivity, risk), additional duties kick in:
- Appoint a Data Protection Officer (DPO)
- Conduct annual Data Protection Impact Assessments (DPIAs)
- Annual financial audit by an independent auditor
14. Continuous Monitoring & Evidence Collection
Compliance isn't a one-time checkbox. You need ongoing evidence that controls are operating. GuardianX's compliance module auto-collects evidence for ISO 27001, SOC 2, and DPDPA — SAST/DAST scan results, patch audit trails, access reviews, and incident timelines, all exportable for an auditor.
Summary Checklist
1. Confirm DPDPA applicability 2. Map data inventory 3. Implement consent + withdrawal 4. Publish privacy policy + Grievance Officer 5. Build data principal rights workflow 6. Apply reasonable security safeguards (encryption, MFA, audit, vuln mgmt) 7. Document breach response runbook 8. Automate retention & deletion 9. Stay within cross-border rules 10. Collect continuous compliance evidence
Startups that bake DPDPA into their product from day one avoid painful retrofits. The cost of compliance is far lower than the cost of a ₹250 crore penalty.
Sign up for GuardianX
Run a full SAST + DAST + patch-generation VAPT scan on your codebase in under 5 minutes. No credit card required.