Built for the DPDP Act, not patched for it afterwards.
India's data protection law is already in force and lands in full in May 2027. We build the part of it that lives in your website, your forms and your apps.
NOTICE & CONSENT DATA PRINCIPAL RIGHTS RETENTION & ERASURE BREACH REPORTING CHILDREN'S DATA CROSS-BORDER TRANSFER GRIEVANCE REDRESSAL
NOTICE & CONSENT DATA PRINCIPAL RIGHTS RETENTION & ERASURE BREACH REPORTING CHILDREN'S DATA CROSS-BORDER TRANSFER GRIEVANCE REDRESSAL
NOTICE & CONSENT DATA PRINCIPAL RIGHTS RETENTION & ERASURE BREACH REPORTING CHILDREN'S DATA CROSS-BORDER TRANSFER GRIEVANCE REDRESSAL
What the law asks
Six duties that land on your software.
The Act runs to far more than this. These are the parts that stop being paperwork and become something a developer has to build.
01
Tell people what you are taking, before you take it
The notice has to be clear, itemised and separate from the rest of your terms: what data, what for, how long, and how to get it back or removed. It has to be available in English and in the languages of the Eighth Schedule, which for most businesses here means Hindi as well.
02
Take consent that a person could have refused
Free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. That rules out pre-ticked boxes, silence as agreement, and bundling several purposes behind one tick.
03
Make leaving as easy as joining
Withdrawal has to be as simple as consent was. If signing up took one tap and getting out takes an email that nobody answers, that is not compliance, and it is the single most common failure on Indian sites today.
04
Keep it only while the purpose lasts
Erasure once the purpose is served is an obligation, not good housekeeping. "As long as necessary" is not a retention period — a period is a number of months or years, written down, per kind of record.
05
Answer when somebody asks
People can ask what you hold, have it corrected, have it erased, and complain to a named person who is obliged to respond. You need a published contact and a way to actually find their data when they do.
06
Notice a breach, and report it in time
The Board and the affected people have to be told without delay, with a detailed report inside 72 hours. Most businesses would not know in the first place, so this starts with logging and alerting rather than with a template.
Form design
What a compliant enquiry form looks like.
Most of this law reaches an ordinary business through one box on a website. Here are the five decisions in it.
Enquiry form
Name
Phone
04Date of birth
01
02
03
05
01
Say what you are taking, and why, right here
The notice belongs at the point of collection, not three clicks away in a policy. Name the purpose, the categories of data, how long you keep it and how to get it removed. A link on its own is not a notice — someone filling in fields never scrolls back up to read one.
02
One purpose per tick, and nothing pre-ticked
Consent has to be specific and unambiguous, given by a clear affirmative action. A pre-ticked box is not an action. Bundling “reply to my enquiry” together with “send me offers” is not consent to either of them, because the person had no way to agree to one and refuse the other.
03
Do not make consent the price of entry
If the form will not submit unless someone accepts marketing, that is a condition of service wearing a consent checkbox. Replying to an enquiry somebody chose to send stands on its own. Anything beyond that has to be a genuine, refusable extra.
04
Ask for less
Every optional field is data you now have to justify, secure, answer for and delete on request. Date of birth, full address and “how did you hear about us” are usually collected out of habit. If it never changes what you do next, it is a liability with no upside.
05
Getting out has to be as easy as getting in
Withdrawal must be as simple as giving consent was, and there has to be a named person who answers questions about the data. One working address, on the page, not a form that routes into nothing.
Where it bites
Same law, very different problem.
A coaching centre and a saree exporter are covered by the same Act and have almost nothing in common in what it asks of them.
Coaching centres & schools
You hold children's data, which is the hardest case in the Act
Anyone under eighteen is a child under this law, and their data cannot be processed without verifiable consent from a parent or guardian. On top of that there is a flat prohibition: no behavioural monitoring, no tracking, and no targeted advertising to children at all. A register of names, ages, parents' numbers and attendance is exactly what the strictest part of the Rules was written about.
Verifiable parental consent, recorded
No tracking or ad pixels on student areas
Admission data separated from marketing
Records that leave when a student does
Clinics, hospitals & diagnostics
Appointment books and reports are the most sensitive thing you keep
A patient name next to a speciality tells anyone who sees it something the patient did not choose to publish. The Act does not have a separate sensitive category, but the duty to keep data secure and to hold it only as long as the purpose lasts applies with full force here, and a breach involving health records is not a letter you want to write.
Who on staff can open which record
Reports that expire instead of accumulating
Consent kept apart from the clinical record
A breach route that exists before it is needed
Hotels, guesthouses & dharamshalas
You take an identity document from every guest who walks in
Check-in means collecting ID, and that photograph sits in a folder or a WhatsApp thread long after the guest has gone. Collect it for a stated purpose, keep it only while that purpose lasts, and be able to say who has access. A shoebox of ID scans is the most common unexamined risk in this trade.
ID captured for a stated purpose only
Deleted on a schedule, not on a clear-out
Off personal phones and WhatsApp threads
Guest requests answerable without a search
Exporters & B2B sellers
Your buyer list crosses borders, and so does the obligation
The Act reaches processing done outside India where it involves offering goods or services to people in India, and the Rules set conditions on transferring personal data abroad. If your catalogue, CRM or mailing list lives on a platform outside the country, that is a decision you should have made deliberately rather than by signing up.
Where each system actually stores data
Transfer conditions checked before signing
Buyer consent for marketing, held separately
An unsubscribe that genuinely works
Retail & WhatsApp commerce
Orders, addresses and numbers spread across four places
The order is in one app, the address is in a chat, the payment is with the gateway and the delivery is with the courier. Every copy is data you are answerable for. Most of the work here is not new software — it is knowing where the copies are and stopping them multiplying.
One record instead of four copies
Courier and gateway sharing written down
Marketing consent kept apart from orders
Deletion that reaches every copy
The timetable
When each part starts to matter.
November 2025
The Rules were notified
The Data Protection Board of India was constituted and the framework became operational. The clock on everything below started here.
November 2026
Consent managers arrive
Registered platforms through which a person can review and withdraw consent across many businesses from one place. About a month away.
May 2027
Everything else, and the penalties
Notice, consent, rights, retention and breach reporting all become enforceable, with the penalty schedule behind them. This is the deadline to work back from.
Dates from the Ministry of Electronics and Information Technology. Primary sources: the PIB release on the notified Rules ↗ and MeitY ↗. Reviewed 17 August 2026 — this page is kept current as the phases land.
Built the way we sell it
Check it on this site first.
It would be a poor advertisement to sell this and not do it ourselves. Every example below is on a page you can open right now.
The notice is on the form
Our enquiry form states the purpose, the retention period and how to have your details deleted, in the form itself rather than in a policy you would have to go looking for.
Retention is a number
Our privacy policy gives a period for each kind of record — enquiries, chat transcripts, newsletter — and names a Grievance Officer, because the Act requires a person who answers.
No tracking to consent to
Our cookie policy lists every item stored on your device — there are four — and explains why there is no analytics toggle: the measurement is cookieless, so there is nothing to switch off.
We have built to this before
The Victors Home Tutors case study covers handling ID photographs when Aadhaar verification is not legally open to a private business, and how that shaped what is stored and for how long. The same constraint decides how we build AI automation: a model that has been shown personal data cannot simply be asked to forget it, so what reaches one is decided before it is built, not afterwards.
What we are not
We are a software company. We are not a law firm, not an auditor, and nothing on this page is legal advice — see our disclaimer. There is no certificate under this law that a developer can issue, so treat "certified DPDP compliant website" as a warning sign. Compliance is mostly organisational: who is allowed to open what, what staff do with a phone number, what you agreed with your suppliers. We build the half of it that lives in the software, and we will say plainly when the rest needs a lawyer.
What's included
What actually gets built.
01
Notice where the data is taken
An itemised notice on the form itself — purpose, what is collected, how long it is kept and how to get it removed. Not a link to a policy.
02
Consent that can be refused
One purpose per tick, nothing pre-ticked, and marketing never bundled with the thing the person actually came for.
03
A withdrawal route that works
Leaving has to be as easy as joining. That means a real link or setting, not a request form that routes into an unread inbox.
04
Retention written into the system
A stated period for each kind of record, and a way to act on it — rather than a policy sentence saying 'as long as necessary', which is not a period.
05
Access and correction requests
A route for someone to ask what you hold, have it corrected, or have it erased — and the ability to answer without a manual hunt through four systems.
06
Breach detection and the report
Logs and alerts that would actually tell you, plus a written runbook for notifying the Board and the people affected inside the deadline.
07
Children's data handled separately
Verifiable parental consent, and tracking and advertising switched off entirely on anything a child uses.
08
Records you can show
What you collect, why, where it sits, who can open it and who you share it with. The document you will be asked for first.
May 2027Full enforcement
₹250 croreMaximum penalty
72 hoursTo report a breach
Who it's for
Who needs this most.
Every business that keeps personal data is covered. These are the ones where it bites hardest, and where we have done the work.
Great for
Coaching centres and schools holding data on under-18s
Clinics, hospitals and diagnostic labs
Hotels, guesthouses and dharamshalas taking guest ID
Exporters and B2B sellers with buyers outside India
Retailers running orders through WhatsApp and a courier
Anyone who inherited a website and does not know what it stores
How we approach it
How a compliance job runs.
01
Find where the data actually is
Usually more places than expected — the website, the billing software, a spreadsheet, two phones and a WhatsApp group. Nothing can be fixed before this is written down.
02
Fix the points of collection
Forms, chat flows and sign-up screens get the notice, the consent choices and the field list they should have had. This is the visible half and the quickest to change.
03
Build the routes out
Withdrawal, deletion, access and correction, plus a named contact who answers. These are the ones businesses discover they do not have on the day somebody asks.
04
Leave you able to answer
A record of what you hold and why, a breach runbook, and a person on your side who understands it. We would rather hand it over than keep you dependent on us.
Money and commitment
Cost, scope and walking away.
Compliance work invites open-ended bills. Ours is scoped and quoted like any other build.
What it costs
Priced against what it saves, not what it impresses
Custom work starts at ₹75,000 and most projects land between ₹1.5 lakh and ₹4 lakh. You get a fixed quote in writing before anything is built, paid against milestones — and anything we buy for you is passed on at cost, with no markup and no resale.
Published floor, not on request
Milestone-based, fixed up front
Third-party costs at cost
When you grow
The next thing is a change, not a rebuild
The first version does one job properly rather than guessing at everything you might need. Data is modelled so it still makes sense with five years of history in it, which is what decides whether adding the thing you have not thought of yet costs a week or costs the project.
Built in stages you can see working
Adds without a rewrite
Holds up as records pile up
If you leave
Ordinary choices, written down, and a developer who can pick it up
Nothing here is clever for the sake of it. We use proven, boring tools another developer can pick up, we document what we build, and you get the source code with the right to have anyone you appoint change it. Your data and your accounts are in your name from day one. You can take the whole thing to another developer whenever you want, and an annual maintenance contract with us is an option rather than a condition of getting it built.
Documented on handover
Any developer can change it
Source code, data and accounts
Not sure which of these you need? Most people are not, on the first call. Tell us what your team does by hand and we will tell you what it would take — including when the answer is that you do not need software yet.
Almost certainly. The Act applies to anyone who decides why and how personal data is processed — that is what a Data Fiduciary is — and it makes no exemption for turnover or headcount. If your website has an enquiry form, or you keep customer numbers in a spreadsheet, you are in scope. The obligations scale with what you hold, but they do not switch off because you are small.
When do I actually have to be ready?
The Rules were notified in November 2025 and phase in over eighteen months. Provisions covering consent managers arrive in November 2026, and the substantive obligations along with the penalty schedule take effect in May 2027. That is the date worth working back from. Nothing about it requires waiting — the changes are the same ones that make a form easier to trust.
What are the penalties?
The schedule to the Act runs up to ₹250 crore for a single class of breach. Realistically the Data Protection Board's attention is on serious failures rather than small businesses with an untidy form, but the exposure is written into the statute and it is not a number to plan around. The more likely cost for most businesses here is an angry customer with a complaint that has nowhere to go.
Do you provide legal advice or a compliance certificate?
No, and be careful of anyone who offers a website that is 'certified compliant'. We are a software company, not a law firm and not an auditor. We build the part of compliance that lives in your website, your software and your apps, and we will tell you plainly when a question needs a lawyer. There is no certificate under this law that a developer can issue.
Is a cookie banner enough?
No. A banner is one narrow piece and most Indian sites have one that does nothing — a notice with no actual choice behind it. The obligations that matter are about the personal data you collect and keep: the enquiry form, the booking, the customer list, the ID photograph. A banner on top of an unchanged system is decoration.
We collect student details for a coaching centre. What changes?
The most, unfortunately. Anyone under eighteen is a child under this law, which means verifiable consent from a parent or guardian before you process their data, and a complete prohibition on behavioural tracking or targeted advertising aimed at them. In practice that means separating admission records from anything marketing touches, and taking ad and analytics pixels off student-facing areas.
What happens if we have a data breach?
You must tell the Data Protection Board and the people affected without delay, and follow up with a detailed report — what happened, how many people, what you have done about it — inside 72 hours. The hard part is not the form. It is that most businesses have no way of knowing a breach happened at all, which is why detection and logging come before the runbook.
Can you fix a website somebody else built?
Usually yes, and it is most of this work. We look at what you collect and where it goes before proposing anything, and often the answer is a set of changes to the forms and the retention rules rather than a rebuild. We take on maintenance for software we did not write, so this is familiar ground.
Straight answers on cost
What you pay for, and what you keep.
Good work should not come with a guessing game attached. Four things we put in writing on every project.
No markup on anything we buy for you
Domains, hosting, paid plugins, stock assets, ad spend — you pay the provider directly, at their price. We do not resell them and we take no cut.
A fixed quote before anything starts
You see the number and the scope in writing first. Out-of-scope work is quoted and agreed separately — never done and then invoiced as a surprise.
What you keep is agreed before we start
A website or design job transfers to you outright. Software, apps and AI work come with the source code and the right to have any developer change it. A managed system gives you your data, your accounts, and a working copy you keep if you leave.
Prices are published, not quoted on request
Our plans and what they include are on the pricing page. You can work out roughly what your project costs before you ever speak to us.