"We're a small startup — does this law really apply to us?" Yes. Every word of it. The Digital Personal Data Protection Act, 2023 has no revenue threshold, no employee count minimum, and no small business exemption. If your business collects a name, email, phone number, or any other data about an Indian resident — you are a Data Fiduciary with full legal obligations. This guide explains exactly what startups and SMEs must do, when they must do it, and how to make compliance achievable without an enterprise budget.
Bottom line: You have until May 2027 — but waiting until the last month guarantees scrambled, expensive, and incomplete compliance. Businesses building compliance now have the advantage.
- Does DPDPA apply to your startup or SME?
- The compliance timeline — what's due when
- Why startups face unique compliance challenges
- Why early compliance is a business advantage
- The 8 core obligations every startup must meet
- What startups are NOT required to do (yet)
- The most common DPDPA mistakes startups make
- Practical compliance roadmap — 90 days
- How much does DPDPA compliance cost for a startup?
- DPDPA compliance and fundraising / enterprise sales
1. Does DPDPA Apply to Your Startup or SME?
The most important thing to understand about the DPDP Act is its scope — it is deliberately broad and applies to virtually every business that has any digital presence serving Indian users.
The DPDPA applies to you if: Your business processes digital personal data of Indian residents — whether you are a sole proprietor, a 3-person startup, a 50-person SME, or a 5,000-person enterprise. The law makes no distinction based on size.
Ask yourself these questions:
If you answered yes to even one of the above — the DPDPA applies to you in full. There is no partial application, no startup grace period on core obligations, and no size-based exemption on the penalty schedule.
2. The Compliance Timeline — What's Due When
The DPDP Rules 2025 were notified on 13 November 2025 and introduced a phased compliance timeline. Understanding this timeline is critical for planning your compliance roadmap:
The "18 months" myth: Many startups think they have 18 months to do nothing. Wrong. The 18-month window is for building systems and processes — not for delaying action. The Board is operational today and can act on complaints about ongoing violations. Starting compliance in April 2027 means you will be non-compliant for the entirety of your operational history to date.
3. Why Startups Face Unique DPDPA Compliance Challenges
The DPDPA was drafted with large enterprises in mind — but the compliance burden falls equally on startups that often lack the resources to absorb it. Understanding these challenges helps you plan realistically:
No Dedicated Legal Budget
Most startups have no in-house legal team. DPDPA compliance requires legal drafting (privacy policies, consent notices, vendor DPAs), legal analysis, and ongoing monitoring — all areas where startups typically have zero internal capacity.
Fast-Moving Data Practices
Startups pivot constantly — new features, new data types, new vendors, new markets. Every change can create a new DPDPA compliance requirement. A static compliance programme becomes outdated within months.
Third-Party Tool Dependency
The average startup uses 15-40 SaaS tools — Razorpay, HubSpot, Intercom, Firebase, Mixpanel, AWS, Twilio, and more. Every one of these tools processes your users' personal data, requiring vendor DPAs and compliance oversight.
Unknown User Demographics
Most startups don't know if users under 18 are accessing their platform. Under DPDPA, ignorance is no defence — if your platform could be accessed by minors, you need age verification, regardless of whether you know they're using it.
4. Why Early Compliance is a Business Advantage — Not Just a Legal Obligation
Most startups think of compliance as a cost. The smart ones treat it as a competitive asset. Here's why DPDPA compliance early pays dividends far beyond legal protection:
5. The 8 Core Obligations Every Startup and SME Must Meet
Regardless of size, every Data Fiduciary must meet these eight obligations under the DPDP Act and DPDP Rules 2025:
Valid Consent Before Collecting Any Data
Before collecting any personal data, you must provide a clear privacy notice and obtain free, specific, informed, and unambiguous consent. This means every contact form, sign-up flow, and data collection point needs a properly drafted consent mechanism.
- Add a privacy notice to every form on your website and app
- Remove all pre-ticked consent checkboxes
- Provide a clear, accessible withdrawal mechanism
- Get fresh consent for each distinct processing purpose
Publish a DPDPA-Compliant Privacy Policy
Your Privacy Policy must be updated to comply with DPDP Rules 2025 (Rule 3). It must clearly state what data you collect, why, who you share it with, how long you keep it, and how users can exercise their rights — in plain language.
Implement Basic Security Safeguards
Section 8(4) requires "reasonable security safeguards." For a startup this means — at minimum — HTTPS on all pages, encrypted databases, strong passwords and MFA for admin access, and limiting who in your team can access customer data.
Appoint and Publish a Grievance Officer
You must designate a Grievance Officer — a named person users can contact about privacy concerns. For a startup, this can be a founder, co-founder, or any team member. Their name and email must be published on your website and in your Privacy Policy.
Create a Data Retention Policy
You cannot hold personal data forever. You must document how long each type of data is kept and actually delete it when that period expires. For a startup, this means deciding — and writing down — your retention rules for customer data, lead data, employee data, and marketing lists.
- Active customers: retain while account is active + 1 year
- Unsuccessful leads: delete after 6 months of no engagement
- Employee data: retain as required by labour/tax law
- Marketing lists: delete if unsubscribed/inactive for 12 months
Sign Data Processing Agreements with Vendors
Every SaaS tool, cloud provider, and analytics platform that processes your users' data is a Data Processor — and you need a signed DPA with each of them. Many large vendors (AWS, Google, Razorpay) have standard DPAs available; you just need to execute them.
Honour Data Principal Rights
Your users have legally enforceable rights to access, correct, and delete their personal data. You must have a working process to respond to these requests — even if you receive them rarely, the mechanism must exist and function.
Breach Response — Know What to Do Before It Happens
Under Rule 7, you must notify the Data Protection Board within 72 hours of discovering a breach, and notify all affected users without undue delay. Without a prepared response plan, 72 hours is not enough time to even understand what happened, let alone report it properly.
6. What Startups Are NOT Required to Do (Yet)
Good news — there are certain obligations that apply only to Significant Data Fiduciaries (SDFs), a special category designated by the government for large-scale, high-risk processors. Most startups and SMEs will not qualify as SDFs, which means:
Important caveat: As your startup scales, you may grow into SDF territory. The government has not yet announced SDF designation criteria but is expected to focus on volume of data processed, type of data (health, financial, biometric), and national security relevance. Build your compliance programme with growth in mind.
7. The Most Common DPDPA Mistakes Startups Make
8. Practical Compliance Roadmap — 90 Days for Startups
- List every type of personal data your business collects
- List every vendor/tool that processes your user data
- Map the journey of each data type — collection → storage → use → deletion
- Identify which forms, pages, and flows collect data without proper consent notices
- Check if children under 18 can access your platform without age verification
- Draft or update your Privacy Policy (custom — not a template)
- Draft consent notices for every data collection form
- Create a Cookie Policy and consent banner if not already present
- Designate a Grievance Officer and publish details on website
- Create a simple data retention schedule document
- Execute DPAs with top 5 vendors handling user data
- Verify HTTPS is enforced on all pages
- Enable MFA on all admin accounts
- Implement role-based access — limit who can see customer data
- Build or verify account deletion functionality in your product
- Draft a simple breach response plan with notification templates
- Brief your team on DPDPA obligations relevant to their role
- Assemble investor due diligence data room: Privacy Policy, DPAs, Grievance Officer details, retention schedule
- Update app store Data Safety / Privacy Nutrition Label
- Set a 6-month calendar reminder to review and update compliance
9. How Much Does DPDPA Compliance Cost for a Startup?
This is the question every founder asks. The honest answer: it depends entirely on how you approach it.
| Approach | What You Get | Estimated Cost | Risk Level |
|---|---|---|---|
| DIY / Template | Generic documents that may not reflect your practices or meet DPDPA standards | ₹0 | Very High |
| Startup Package | Custom privacy policy, consent notices, grievance setup, basic vendor DPAs, compliance certificate | ₹25K–75K | Low |
| Growth Package | Everything in Startup + app compliance, 5 vendor DPAs, consent framework, breach plan, investor pack | ₹75K–1.5L | Very Low |
| Ongoing DPO Service | Outsourced DPO, ongoing compliance, rights handling, breach response, quarterly reports | ₹15K–50K/mo | Minimal |
Perspective check: The cheapest DPDPA compliance package costs less than one month of a junior hire's salary. The cheapest DPDPA penalty is ₹50 crore. The ROI calculation is not complicated.
10. DPDPA Compliance and Fundraising / Enterprise Sales
For growth-stage startups, DPDPA compliance has become a commercial gate — not just a legal one. Here is what you need documented for the two most common use cases:
Start Now — Not in May 2027
The startups that build DPDPA compliance into their operations now will have investor-ready documentation, enterprise-contract-eligible status, and a compliance foundation that scales with their growth — at a fraction of the cost of emergency remediation later.
The startups that wait until May 2027 will be competing for the same legal resources as thousands of other non-compliant businesses — all trying to achieve compliance in the same 90-day window. Costs will spike, timelines will compress, and compliance quality will suffer.
Our Startup DPDPA Compliance Packages are specifically designed for lean teams and startup budgets — fixed price, fast delivery, and everything you need to be investor-ready and legally protected.