Beyond Precedent
Technology, Data Privacy & AI

DPDP Compliance Checklist for Indian Startups: Preparing Before the May 2027 Deadline

By Remote Lawyer  |  Jul 25, 2026
DPDP Compliance Checklist for Indian Startups: Preparing Before the May 2027 Deadline

The Digital Personal Data Protection Act, 2023 received presidential assent in August 2023, but sat largely dormant until the Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025 on 13 November 2025. That notification set a phased rollout: the Data Protection Board of India became operational immediately, the Consent Manager registration framework opens on 13 November 2026, and every data fiduciary, including early-stage startups, must be fully compliant by 13 May 2027. For founders who have treated privacy as a “later” problem, later now has a date on the calendar.

Unlike sector-specific rules founders may already know, such as the RBI’s KYC norms, the DPDP Act applies horizontally to any entity that determines the purpose and means of processing digital personal data of individuals in India, with no exemption keyed to revenue, funding stage or headcount. A two-person SaaS startup collecting email addresses through a signup form is a “data fiduciary” in the same way a bank is. That breadth is why compliance with the DPDP Act becomes pertinent not only for large enterprises but also early stage startups.

Compliance Checklist

The compliance with the DPDP Act should not only be on paper but should organically be built in to your product, processes and workflow. In this checklist, we will focus on the practical aspects of complying with the DPDP Act:

  1. Map what you collect and why. Start with a data inventory: which personal data is collected, through which app or website flows, why it is needed, where it is stored, and which vendors such as analytics tools, payment gateways and cloud hosts touch it. The Act defines “personal data” broadly, as any data about an identifiable individual, so this exercise should cover HR and vendor data, not only customer data.
  2. Rebuild consent as a first-class flow. Section 6 of the Act requires consent to be free, specific, informed, unconditional and unambiguous, given through clear affirmative action, and limited to the personal data necessary for the stated purpose. Pre-ticked boxes, bundled consent for unrelated purposes, and vague “we may use your data to improve services” language will not hold up. Every consent request must be accompanied by a notice specifying the data being collected and the purpose, and consent must be as easy to withdraw as it was to give. Affirmative action signifying explicit consent is mandatory.
  3. Rewrite the privacy notice. Copy-pasting a generic international privacy policy will not satisfy the Rules. The Digital Personal Data Protection Rules, 2025 specify itemized content for the notice: what data is collected, why, how to withdraw consent, how to file a complaint with the Data Protection Board, and how to exercise data-principal rights. Notices work best layered, with a short summary alongside a fuller version, rather than as one dense legal document.
  4. Build a genuine grievance and rights mechanism. Data principals have the right to access a summary of their personal data and processing activities, correct or update inaccurate data, have data erased once it is no longer necessary for the stated purpose, and nominate another individual to exercise their rights in the event of death or incapacity. Startups need a working intake channel, even a monitored email address or in-app form, with defined turnaround times, rather than a clause in the privacy policy that merely promises these rights exist.
  5. Get vendor contracts in order. Any processing carried out through a third party, including cloud storage, email marketing tools, analytics SDKs and payment processors, needs a data processing agreement that flows down the fiduciary’s obligations. The Act holds the data fiduciary, not the processor, liable for breaches, which makes contractual indemnities and security commitments from vendors more important than before. All obligations on data fiduciaries should flow down to data processors and an indemnity provision should be included in the data processing agreement.
  6. Put a breach-response plan on paper. On becoming aware of a personal data breach, a data fiduciary must, without delay, notify affected data principals in intelligible terms and separately inform the Data Protection Board. A fuller report covering the nature and extent of the breach, its cause, and remedial steps taken must follow within 72 hours, extendable only on a written request to the Board, as this Medianama analysis of the breach-notification rule explains. Startups should have an internal escalation path and a template notification ready before an incident happens, not after.
  7. Fix retention and deletion practices. Personal data must be erased once the purpose for which it was collected is no longer being served, unless retention is otherwise required by law. Set retention schedules now, particularly for former users and abandoned signups sitting in old databases. For data fiduciaries other than significant data fiduciaries retention up to one year is permitted.
  8. Watch for the Significant Data Fiduciary trigger. The government can designate any fiduciary as a Significant Data Fiduciary based on the volume and sensitivity of data processed, risk to data principals, and potential impact on sovereignty, electoral integrity or public order. Significant Data Fiduciary status brings materially heavier obligations, including an India-resident Data Protection Officer reporting to the board of directors, an independent data auditor, annual data protection impact assessments, and algorithmic due diligence, as this Trilegal analysis of the Act sets out. A fast-growing startup should track this threshold rather than assume it applies only to large technology companies.
  9. Take the penalty exposure seriously. The Act’s schedule prescribes civil penalties of up to Rs 250 crore for failing to implement reasonable security safeguards and up to Rs 200 crore for failing to notify the Board or affected individuals of a breach, among other heads, imposed by the Data Protection Board after an inquiry, as this Shardul Amarchand Mangaldas note on enforcement of the Rules describes. These penalties are not tied to turnover, which makes the cost of ignoring compliance disproportionate for an early-stage company relative to its revenue.

Conclusion

The Data Protection Board is already operational and can act on complaints today, even though the full compliance deadline is 13 May 2027, and the Consent Manager framework, described in this Hogan Lovells briefing, opens for registration in November 2026. Startups raising funding in this window should expect data protection questions in investor due diligence well before the deadline. Getting consent, notice and vendor-contract basics right now is materially cheaper than a retrofit under regulatory or investor pressure later.

The DPDP Act rewards startups that build privacy into their product from the outset rather than bolting it on later. None of the steps above require an enterprise compliance budget. They require a founder or in-house counsel willing to sit down with the text of the Act and the Rules and match it against how the product actually collects and uses data. Done early, that exercise is among the cheapest insurance a startup will buy this year.