top of page
  • LinkedIn
Search

Long-form Regulatory Guide #1

Updated: Dec 17, 2025


DPDP Act discussion
Educational only. This is not legal advice. DPDP rules and guidance keep evolving; always check the latest notifications and consult your lawyer / DPO.

Why the DPDP Act matters for you

If your product collects names, emails, phone numbers, KYC docs, location, cookies or device IDs from users in India, the Digital Personal Data Protection Act, 2023 (DPDP Act) applies to you. cookieyes.com+5MeitY+5PRS Legislative Research+5

Investors are starting to ask:

  • “What happens if a user asks for their data to be deleted?”

  • “Where is your consent stored?”

  • “Who is responsible for data breaches?”

If your answer is “Umm… our developer handles that”, you’ve just created a new risk line item in DD.

Key concepts in plain English

Under the DPDP Act and 2025 Rules: cookieyes.com+5MeitY+5Press Information Bureau+5

  • Data Principal – your end user; the person the data is about.

  • Data Fiduciary – your startup; you decide why and how the data is processed.

  • Data Processor – vendors who process data on your behalf (cloud, CRM, analytics, payroll, etc.).

  • Consent – must be free, specific, informed, unambiguous and revocable.

  • Significant Data Fiduciary (SDF) – large/high-risk players who have stricter duties (like independent audits).

The law also creates a Data Protection Board of India with powers to monitor compliance and levy penalties, including large ones (up to hundreds of crores for serious, repeated violations). VISION IAS+3PRS Legislative Research+3Press Information Bureau+3

Step 1 – Map your data flows

Before you write a single policy, answer:

  1. What personal data do we collect?Names, emails, phone numbers, PAN/Aadhaar (if any), IPs, device IDs, behaviour events, etc.

  2. Where does it come from?Signup forms, lead forms, third-party integrations, cookies, offline onboarding.

  3. Where is it stored?App DB, data warehouse, Google Sheets, CRM, founder’s personal laptop (be honest).

  4. Who else touches it?Cloud providers, marketing tools, payment gateways, outsourced CX.

Draw a simple flowchart and keep it in your internal wiki. That becomes the backbone of your DPDP story.

Step 2 – Fix the consent and notice layer

Under the DPDP Act, you can process personal data primarily on the basis of consent (or specific “legitimate use” grounds). Consent must be: cookieyes.com+3MeitY+3dlapiperdataprotection.com+3

  • Free – not forced or bundled

  • Specific – for clearly stated purposes

  • Informed – user knows what, why, how long, and who to contact

  • Unambiguous – no pre-ticked boxes

  • Revocable – user can withdraw easily

Practically, this means:

  • Every form that collects personal data should link to a concise notice: what you collect, why, how long you keep it, and a grievance/contact email.

  • No pre-ticked “I agree to everything” boxes.

  • A simple way in the product or via email to withdraw consent and unsubscribe.

  • For apps or pan-India products, notice should be accessible in English and at least one other Indian language, as guidance around multi-language notices emerges. dlapiperdataprotection.com+2https://www.taxmann.com+2

Step 3 – Implement user rights & grievance

The Act gives Data Principals rights to: dlapiperdataprotection.com+4MeitY+4PRS Legislative Research+4

  • Access a summary of their personal data

  • Correct inaccurate data

  • Ask for erasure of data that is no longer needed for the stated purpose or law

  • Know who else (which processors/other fiduciaries) their data was shared with

  • Use a grievance mechanism and escalate to the Board if unhappy

For a startup, that translates to:

  • A working grievance email (e.g. privacy@yourstartup.com) and a simple form.

  • An internal SLA (e.g. respond within 7 days, resolve within 30, matching the spirit of the law and eventual Rules).

  • A basic internal process:

    • Identify the user

    • Pull their data from systems

    • Edit or delete where legally allowed

    • Log the action

Document this process. Investors love seeing even a scrappy internal wiki page describing how you’ll handle rights requests.

Step 4 – Governance, breaches and SDF risk

Even if you’re small today, show that you’re thinking like a serious Data Fiduciary.

  • Appoint an internal privacy owner (doesn’t have to be a full-blown DPO yet).

  • Maintain a one-page “Breach Response Plan”:

    • Who gets alerted internally

    • How you contain the incident

    • When you notify users and the Board (once formats are prescribed) Press Information Bureau+1

If you ever grow into an SDF (large scale, sensitive data, or notified sectors), you’ll likely need independent audits and more formal processes. Laying foundations now makes future DD much easier.

A simple DPDP checklist for founders

  •  Have we mapped what personal data we collect and where it flows?

  •  Do our forms and flows have clear notices and non-bundled consent?

  •  Can a user see, correct or delete their data without heroics from the tech team?

  •  Do we know whom to email internally when there’s a privacy complaint?

  •  Do our contracts with vendors mention data protection obligations?

  •  Is there a short, written breach playbook?

Reminder: This guide is general information, not legal advice. The DPDP Act and Rules are still being refined – always check the latest MeitY / DPBI notifications and consult your counsel.

 
 
 

Comments


Let’s Audit Your Readiness

Guruvion – due diligence and governance advisory for Indian founders

Phone
+91 8368996538

Email
team@guruvion.com

Address
512, Ocus Quantum,Ocus Quantum Internal Rd, Sector 51,
Gurugram, Haryana 122018, India

  • LinkedIn

Subscribe to get exclusive updates

Nothing on this site is investment, tax or legal advice. It is operational and educational guidance for founders. Please read the Disclaimer and Terms & Conditions before acting on anything here.

© 2025 Guruvion. All rights reserved.

bottom of page