DPDP Act 2023 · Rules 2025

Built for the DPDP Act, not patched for it afterwards.

India's data protection law is already in force and lands in full in May 2027. We build the part of it that lives in your website, your forms and your apps.

Scroll
NOTICE & CONSENT DATA PRINCIPAL RIGHTS RETENTION & ERASURE BREACH REPORTING CHILDREN'S DATA CROSS-BORDER TRANSFER GRIEVANCE REDRESSAL
NOTICE & CONSENT DATA PRINCIPAL RIGHTS RETENTION & ERASURE BREACH REPORTING CHILDREN'S DATA CROSS-BORDER TRANSFER GRIEVANCE REDRESSAL
NOTICE & CONSENT DATA PRINCIPAL RIGHTS RETENTION & ERASURE BREACH REPORTING CHILDREN'S DATA CROSS-BORDER TRANSFER GRIEVANCE REDRESSAL

What the law asks

Six duties that land on your software.

The Act runs to far more than this. These are the parts that stop being paperwork and become something a developer has to build.

  1. 01

    Tell people what you are taking, before you take it

    The notice has to be clear, itemised and separate from the rest of your terms: what data, what for, how long, and how to get it back or removed. It has to be available in English and in the languages of the Eighth Schedule, which for most businesses here means Hindi as well.

  2. 02

    Take consent that a person could have refused

    Free, specific, informed, unconditional and unambiguous, given by a clear affirmative action. That rules out pre-ticked boxes, silence as agreement, and bundling several purposes behind one tick.

  3. 03

    Make leaving as easy as joining

    Withdrawal has to be as simple as consent was. If signing up took one tap and getting out takes an email that nobody answers, that is not compliance, and it is the single most common failure on Indian sites today.

  4. 04

    Keep it only while the purpose lasts

    Erasure once the purpose is served is an obligation, not good housekeeping. "As long as necessary" is not a retention period — a period is a number of months or years, written down, per kind of record.

  5. 05

    Answer when somebody asks

    People can ask what you hold, have it corrected, have it erased, and complain to a named person who is obliged to respond. You need a published contact and a way to actually find their data when they do.

  6. 06

    Notice a breach, and report it in time

    The Board and the affected people have to be told without delay, with a detailed report inside 72 hours. Most businesses would not know in the first place, so this starts with logging and alerting rather than with a template.

Form design

What a compliant enquiry form looks like.

Most of this law reaches an ordinary business through one box on a website. Here are the five decisions in it.

  1. 01

    Say what you are taking, and why, right here

    The notice belongs at the point of collection, not three clicks away in a policy. Name the purpose, the categories of data, how long you keep it and how to get it removed. A link on its own is not a notice — someone filling in fields never scrolls back up to read one.

  2. 02

    One purpose per tick, and nothing pre-ticked

    Consent has to be specific and unambiguous, given by a clear affirmative action. A pre-ticked box is not an action. Bundling “reply to my enquiry” together with “send me offers” is not consent to either of them, because the person had no way to agree to one and refuse the other.

  3. 03

    Do not make consent the price of entry

    If the form will not submit unless someone accepts marketing, that is a condition of service wearing a consent checkbox. Replying to an enquiry somebody chose to send stands on its own. Anything beyond that has to be a genuine, refusable extra.

  4. 04

    Ask for less

    Every optional field is data you now have to justify, secure, answer for and delete on request. Date of birth, full address and “how did you hear about us” are usually collected out of habit. If it never changes what you do next, it is a liability with no upside.

  5. 05

    Getting out has to be as easy as getting in

    Withdrawal must be as simple as giving consent was, and there has to be a named person who answers questions about the data. One working address, on the page, not a form that routes into nothing.

Where it bites

Same law, very different problem.

A coaching centre and a saree exporter are covered by the same Act and have almost nothing in common in what it asks of them.

Coaching centres & schools

You hold children's data, which is the hardest case in the Act

Anyone under eighteen is a child under this law, and their data cannot be processed without verifiable consent from a parent or guardian. On top of that there is a flat prohibition: no behavioural monitoring, no tracking, and no targeted advertising to children at all. A register of names, ages, parents' numbers and attendance is exactly what the strictest part of the Rules was written about.

  • Verifiable parental consent, recorded
  • No tracking or ad pixels on student areas
  • Admission data separated from marketing
  • Records that leave when a student does

Clinics, hospitals & diagnostics

Appointment books and reports are the most sensitive thing you keep

A patient name next to a speciality tells anyone who sees it something the patient did not choose to publish. The Act does not have a separate sensitive category, but the duty to keep data secure and to hold it only as long as the purpose lasts applies with full force here, and a breach involving health records is not a letter you want to write.

  • Who on staff can open which record
  • Reports that expire instead of accumulating
  • Consent kept apart from the clinical record
  • A breach route that exists before it is needed

Hotels, guesthouses & dharamshalas

You take an identity document from every guest who walks in

Check-in means collecting ID, and that photograph sits in a folder or a WhatsApp thread long after the guest has gone. Collect it for a stated purpose, keep it only while that purpose lasts, and be able to say who has access. A shoebox of ID scans is the most common unexamined risk in this trade.

  • ID captured for a stated purpose only
  • Deleted on a schedule, not on a clear-out
  • Off personal phones and WhatsApp threads
  • Guest requests answerable without a search

Exporters & B2B sellers

Your buyer list crosses borders, and so does the obligation

The Act reaches processing done outside India where it involves offering goods or services to people in India, and the Rules set conditions on transferring personal data abroad. If your catalogue, CRM or mailing list lives on a platform outside the country, that is a decision you should have made deliberately rather than by signing up.

  • Where each system actually stores data
  • Transfer conditions checked before signing
  • Buyer consent for marketing, held separately
  • An unsubscribe that genuinely works

Retail & WhatsApp commerce

Orders, addresses and numbers spread across four places

The order is in one app, the address is in a chat, the payment is with the gateway and the delivery is with the courier. Every copy is data you are answerable for. Most of the work here is not new software — it is knowing where the copies are and stopping them multiplying.

  • One record instead of four copies
  • Courier and gateway sharing written down
  • Marketing consent kept apart from orders
  • Deletion that reaches every copy

The timetable

When each part starts to matter.

  1. November 2025

    The Rules were notified

    The Data Protection Board of India was constituted and the framework became operational. The clock on everything below started here.

  2. November 2026

    Consent managers arrive

    Registered platforms through which a person can review and withdraw consent across many businesses from one place. About a month away.

  3. May 2027

    Everything else, and the penalties

    Notice, consent, rights, retention and breach reporting all become enforceable, with the penalty schedule behind them. This is the deadline to work back from.

Dates from the Ministry of Electronics and Information Technology. Primary sources: the PIB release on the notified Rules ↗ and MeitY ↗. Reviewed 17 August 2026 — this page is kept current as the phases land.

Built the way we sell it

Check it on this site first.

It would be a poor advertisement to sell this and not do it ourselves. Every example below is on a page you can open right now.

  • The notice is on the form

    Our enquiry form states the purpose, the retention period and how to have your details deleted, in the form itself rather than in a policy you would have to go looking for.

  • Retention is a number

    Our privacy policy gives a period for each kind of record — enquiries, chat transcripts, newsletter — and names a Grievance Officer, because the Act requires a person who answers.

  • No tracking to consent to

    Our cookie policy lists every item stored on your device — there are four — and explains why there is no analytics toggle: the measurement is cookieless, so there is nothing to switch off.

  • We have built to this before

    The Victors Home Tutors case study covers handling ID photographs when Aadhaar verification is not legally open to a private business, and how that shaped what is stored and for how long. The same constraint decides how we build AI automation: a model that has been shown personal data cannot simply be asked to forget it, so what reaches one is decided before it is built, not afterwards.

What we are not

We are a software company. We are not a law firm, not an auditor, and nothing on this page is legal advice — see our disclaimer. There is no certificate under this law that a developer can issue, so treat "certified DPDP compliant website" as a warning sign. Compliance is mostly organisational: who is allowed to open what, what staff do with a phone number, what you agreed with your suppliers. We build the half of it that lives in the software, and we will say plainly when the rest needs a lawyer.

What's included

What actually gets built.

Notice where the data is taken

An itemised notice on the form itself — purpose, what is collected, how long it is kept and how to get it removed. Not a link to a policy.

Consent that can be refused

One purpose per tick, nothing pre-ticked, and marketing never bundled with the thing the person actually came for.

A withdrawal route that works

Leaving has to be as easy as joining. That means a real link or setting, not a request form that routes into an unread inbox.

Retention written into the system

A stated period for each kind of record, and a way to act on it — rather than a policy sentence saying 'as long as necessary', which is not a period.

Access and correction requests

A route for someone to ask what you hold, have it corrected, or have it erased — and the ability to answer without a manual hunt through four systems.

Breach detection and the report

Logs and alerts that would actually tell you, plus a written runbook for notifying the Board and the people affected inside the deadline.

Children's data handled separately

Verifiable parental consent, and tracking and advertising switched off entirely on anything a child uses.

Records you can show

What you collect, why, where it sits, who can open it and who you share it with. The document you will be asked for first.

  • May 2027 Full enforcement
  • ₹250 crore Maximum penalty
  • 72 hours To report a breach

Who it's for

Who needs this most.

Every business that keeps personal data is covered. These are the ones where it bites hardest, and where we have done the work.

Great for

  • Coaching centres and schools holding data on under-18s
  • Clinics, hospitals and diagnostic labs
  • Hotels, guesthouses and dharamshalas taking guest ID
  • Exporters and B2B sellers with buyers outside India
  • Retailers running orders through WhatsApp and a courier
  • Anyone who inherited a website and does not know what it stores

How we approach it

How a compliance job runs.

  1. 01

    Find where the data actually is

    Usually more places than expected — the website, the billing software, a spreadsheet, two phones and a WhatsApp group. Nothing can be fixed before this is written down.

  2. 02

    Fix the points of collection

    Forms, chat flows and sign-up screens get the notice, the consent choices and the field list they should have had. This is the visible half and the quickest to change.

  3. 03

    Build the routes out

    Withdrawal, deletion, access and correction, plus a named contact who answers. These are the ones businesses discover they do not have on the day somebody asks.

  4. 04

    Leave you able to answer

    A record of what you hold and why, a breach runbook, and a person on your side who understands it. We would rather hand it over than keep you dependent on us.

Money and commitment

Cost, scope and walking away.

Compliance work invites open-ended bills. Ours is scoped and quoted like any other build.

  • What it costs

    Priced against what it saves, not what it impresses

    Custom work starts at ₹75,000 and most projects land between ₹1.5 lakh and ₹4 lakh. You get a fixed quote in writing before anything is built, paid against milestones — and anything we buy for you is passed on at cost, with no markup and no resale.

    • Published floor, not on request
    • Milestone-based, fixed up front
    • Third-party costs at cost
  • When you grow

    The next thing is a change, not a rebuild

    The first version does one job properly rather than guessing at everything you might need. Data is modelled so it still makes sense with five years of history in it, which is what decides whether adding the thing you have not thought of yet costs a week or costs the project.

    • Built in stages you can see working
    • Adds without a rewrite
    • Holds up as records pile up
  • If you leave

    Ordinary choices, written down, and a developer who can pick it up

    Nothing here is clever for the sake of it. We use proven, boring tools another developer can pick up, we document what we build, and you get the source code with the right to have anyone you appoint change it. Your data and your accounts are in your name from day one. You can take the whole thing to another developer whenever you want, and an annual maintenance contract with us is an option rather than a condition of getting it built.

    • Documented on handover
    • Any developer can change it
    • Source code, data and accounts

Not sure which of these you need? Most people are not, on the first call. Tell us what your team does by hand and we will tell you what it would take — including when the answer is that you do not need software yet.

Good to know

The DPDP questions we get asked.

Does the DPDP Act apply to my small business?

Almost certainly. The Act applies to anyone who decides why and how personal data is processed — that is what a Data Fiduciary is — and it makes no exemption for turnover or headcount. If your website has an enquiry form, or you keep customer numbers in a spreadsheet, you are in scope. The obligations scale with what you hold, but they do not switch off because you are small.

When do I actually have to be ready?

The Rules were notified in November 2025 and phase in over eighteen months. Provisions covering consent managers arrive in November 2026, and the substantive obligations along with the penalty schedule take effect in May 2027. That is the date worth working back from. Nothing about it requires waiting — the changes are the same ones that make a form easier to trust.

What are the penalties?

The schedule to the Act runs up to ₹250 crore for a single class of breach. Realistically the Data Protection Board's attention is on serious failures rather than small businesses with an untidy form, but the exposure is written into the statute and it is not a number to plan around. The more likely cost for most businesses here is an angry customer with a complaint that has nowhere to go.

Do you provide legal advice or a compliance certificate?

No, and be careful of anyone who offers a website that is 'certified compliant'. We are a software company, not a law firm and not an auditor. We build the part of compliance that lives in your website, your software and your apps, and we will tell you plainly when a question needs a lawyer. There is no certificate under this law that a developer can issue.

Is a cookie banner enough?

No. A banner is one narrow piece and most Indian sites have one that does nothing — a notice with no actual choice behind it. The obligations that matter are about the personal data you collect and keep: the enquiry form, the booking, the customer list, the ID photograph. A banner on top of an unchanged system is decoration.

We collect student details for a coaching centre. What changes?

The most, unfortunately. Anyone under eighteen is a child under this law, which means verifiable consent from a parent or guardian before you process their data, and a complete prohibition on behavioural tracking or targeted advertising aimed at them. In practice that means separating admission records from anything marketing touches, and taking ad and analytics pixels off student-facing areas.

What happens if we have a data breach?

You must tell the Data Protection Board and the people affected without delay, and follow up with a detailed report — what happened, how many people, what you have done about it — inside 72 hours. The hard part is not the form. It is that most businesses have no way of knowing a breach happened at all, which is why detection and logging come before the runbook.

Can you fix a website somebody else built?

Usually yes, and it is most of this work. We look at what you collect and where it goes before proposing anything, and often the answer is a set of changes to the forms and the retention rules rather than a rebuild. We take on maintenance for software we did not write, so this is familiar ground.

Straight answers on cost

What you pay for, and what you keep.

Good work should not come with a guessing game attached. Four things we put in writing on every project.

  • No markup on anything we buy for you

    Domains, hosting, paid plugins, stock assets, ad spend — you pay the provider directly, at their price. We do not resell them and we take no cut.

  • A fixed quote before anything starts

    You see the number and the scope in writing first. Out-of-scope work is quoted and agreed separately — never done and then invoiced as a surprise.

  • What you keep is agreed before we start

    A website or design job transfers to you outright. Software, apps and AI work come with the source code and the right to have any developer change it. A managed system gives you your data, your accounts, and a working copy you keep if you leave.

  • Prices are published, not quoted on request

    Our plans and what they include are on the pricing page. You can work out roughly what your project costs before you ever speak to us.

Websites start at ₹9,999, with a 5-page launch offer at ₹6,999 running now — see the offer or compare every plan.

Let's talk

Want to know where you stand?

Tell us what you're building and you will have a reply within one business day — what we would suggest, and roughly what it would cost.