Long-form Regulatory Guide #1
- Robin Marwaha
- Dec 10, 2025
- 3 min read
Updated: Dec 17, 2025

Educational only. This is not legal advice. DPDP rules and guidance keep evolving; always check the latest notifications and consult your lawyer / DPO.
Why the DPDP Act matters for you
If your product collects names, emails, phone numbers, KYC docs, location, cookies or device IDs from users in India, the Digital Personal Data Protection Act, 2023 (DPDP Act) applies to you. cookieyes.com+5MeitY+5PRS Legislative Research+5
Investors are starting to ask:
“What happens if a user asks for their data to be deleted?”
“Where is your consent stored?”
“Who is responsible for data breaches?”
If your answer is “Umm… our developer handles that”, you’ve just created a new risk line item in DD.
Key concepts in plain English
Under the DPDP Act and 2025 Rules: cookieyes.com+5MeitY+5Press Information Bureau+5
Data Principal – your end user; the person the data is about.
Data Fiduciary – your startup; you decide why and how the data is processed.
Data Processor – vendors who process data on your behalf (cloud, CRM, analytics, payroll, etc.).
Consent – must be free, specific, informed, unambiguous and revocable.
Significant Data Fiduciary (SDF) – large/high-risk players who have stricter duties (like independent audits).
The law also creates a Data Protection Board of India with powers to monitor compliance and levy penalties, including large ones (up to hundreds of crores for serious, repeated violations). VISION IAS+3PRS Legislative Research+3Press Information Bureau+3
Step 1 – Map your data flows
Before you write a single policy, answer:
What personal data do we collect?Names, emails, phone numbers, PAN/Aadhaar (if any), IPs, device IDs, behaviour events, etc.
Where does it come from?Signup forms, lead forms, third-party integrations, cookies, offline onboarding.
Where is it stored?App DB, data warehouse, Google Sheets, CRM, founder’s personal laptop (be honest).
Who else touches it?Cloud providers, marketing tools, payment gateways, outsourced CX.
Draw a simple flowchart and keep it in your internal wiki. That becomes the backbone of your DPDP story.
Step 2 – Fix the consent and notice layer
Under the DPDP Act, you can process personal data primarily on the basis of consent (or specific “legitimate use” grounds). Consent must be: cookieyes.com+3MeitY+3dlapiperdataprotection.com+3
Free – not forced or bundled
Specific – for clearly stated purposes
Informed – user knows what, why, how long, and who to contact
Unambiguous – no pre-ticked boxes
Revocable – user can withdraw easily
Practically, this means:
Every form that collects personal data should link to a concise notice: what you collect, why, how long you keep it, and a grievance/contact email.
No pre-ticked “I agree to everything” boxes.
A simple way in the product or via email to withdraw consent and unsubscribe.
For apps or pan-India products, notice should be accessible in English and at least one other Indian language, as guidance around multi-language notices emerges. dlapiperdataprotection.com+2https://www.taxmann.com+2
Step 3 – Implement user rights & grievance
The Act gives Data Principals rights to: dlapiperdataprotection.com+4MeitY+4PRS Legislative Research+4
Access a summary of their personal data
Correct inaccurate data
Ask for erasure of data that is no longer needed for the stated purpose or law
Know who else (which processors/other fiduciaries) their data was shared with
Use a grievance mechanism and escalate to the Board if unhappy
For a startup, that translates to:
A working grievance email (e.g. privacy@yourstartup.com) and a simple form.
An internal SLA (e.g. respond within 7 days, resolve within 30, matching the spirit of the law and eventual Rules).
A basic internal process:
Identify the user
Pull their data from systems
Edit or delete where legally allowed
Log the action
Document this process. Investors love seeing even a scrappy internal wiki page describing how you’ll handle rights requests.
Step 4 – Governance, breaches and SDF risk
Even if you’re small today, show that you’re thinking like a serious Data Fiduciary.
Appoint an internal privacy owner (doesn’t have to be a full-blown DPO yet).
Maintain a one-page “Breach Response Plan”:
Who gets alerted internally
How you contain the incident
When you notify users and the Board (once formats are prescribed) Press Information Bureau+1
If you ever grow into an SDF (large scale, sensitive data, or notified sectors), you’ll likely need independent audits and more formal processes. Laying foundations now makes future DD much easier.
A simple DPDP checklist for founders
Have we mapped what personal data we collect and where it flows?
Do our forms and flows have clear notices and non-bundled consent?
Can a user see, correct or delete their data without heroics from the tech team?
Do we know whom to email internally when there’s a privacy complaint?
Do our contracts with vendors mention data protection obligations?
Is there a short, written breach playbook?
Reminder: This guide is general information, not legal advice. The DPDP Act and Rules are still being refined – always check the latest MeitY / DPBI notifications and consult your counsel.




Comments