DPDP Act Compliance Checklist for Startups and SMEs India 2025

Last Updated: June 9, 2026 · Author: Saurabh Gupta, CISM, CIPP/E · Founder, MYITMANAGER

The DPDP Act 2023 and DPDP Rules 2025 apply to every Indian startup and SME that processes digital personal data — not just large enterprises. Whether you’re a 10-person SaaS startup, a D2C brand, or a fintech with 50,000 users, if you collect names, emails, phone numbers, or any other personal data from Indian residents, you are a Data Fiduciary under the Act and compliance is mandatory.

Enforcement is expected to begin in May 2027. That sounds distant, but building a compliant data governance framework from scratch takes 3–6 months for most startups. This checklist gives you the 10 highest-priority actions to complete before the deadline — structured so you can act on them immediately, without a legal team.

Who Must Comply with the DPDP Act?

The DPDP Act applies to any entity that processes digital personal data of Indian residents, regardless of:

  • Company size — a 5-person startup is as liable as a Fortune 500 company
  • Revenue — there is no SME exemption
  • Sector — IT, healthcare, fintech, e-commerce, SaaS, manufacturing all fall under the Act
  • Location — even companies based outside India that process data of Indian residents must comply

The only meaningful distinction is between Significant Data Fiduciaries (SDFs) — large platforms processing data at scale, with additional obligations — and regular Data Fiduciaries. Most startups and SMEs will be regular Data Fiduciaries, which means a more manageable compliance scope.

DPDP Compliance Checklist for Startups and SMEs

Step 1: Map Your Personal Data

Before you can comply, you need to know what personal data you collect, where it lives, how it flows, and who has access to it. Create a simple data inventory covering:

  • What personal data fields you collect (name, email, phone, address, payment details, usage data)
  • Where it is stored (CRM, database, email platform, cloud storage, third-party SaaS tools)
  • Who can access it internally (sales, support, engineering, marketing)
  • Which third parties receive it (payment processor, analytics tool, marketing platform, logistics partner)
  • How long you retain it before deletion

This data map is the foundation for every other compliance step. Without it, you cannot write an accurate privacy notice, identify consent gaps, or respond to data principal rights requests.

Step 2: Audit Your Consent Mechanisms

The DPDP Act requires consent to be free, specific, informed, unconditional, and revocable. Review every point where your product or website collects personal data:

  • Account registration forms
  • Contact and lead capture forms
  • Checkout and payment flows
  • Email and WhatsApp marketing opt-ins
  • Cookie banners and analytics tracking

For each, ask: Is the consent purpose clearly stated? Is it separate from T&C acceptance? Can the user easily withdraw it? Pre-ticked boxes, bundled consent, and “by continuing to use this site” clauses do not meet the standard.

Step 3: Write a DPDP-Compliant Privacy Notice

Your privacy notice must tell users — in plain language — what personal data you collect, why you collect it, who you share it with, how long you keep it, and how they can exercise their rights. It must be provided at or before the point of data collection. A buried link in the footer that leads to a legal document no one reads does not satisfy the notice requirement.

For each purpose you collect data, your notice should answer: What data? Why? Who sees it? How long? Template privacy notices are available but must be customised to your actual data practices — a generic template that doesn’t match how you actually process data creates legal exposure, not protection.

Step 4: Build a Data Retention and Deletion Policy

The DPDP Act requires erasing personal data once the purpose for which it was collected is fulfilled — you cannot retain customer data indefinitely “just in case.” Define retention periods for each data category:

  • Active customer records: retain during the customer relationship + defined period post-churn
  • Leads and prospects: retain for defined period from last interaction, then delete
  • Employee data: retain during employment + defined post-employment period
  • Transaction records: retain for statutory minimum (7 years for GST purposes) then delete or anonymise
  • Support tickets: retain for defined period, then anonymise

Implement automated deletion or anonymisation workflows so retention policy is enforced in practice, not just documented on paper.

Step 5: Execute Data Processing Agreements with Vendors

Every third-party tool that processes your customers’ personal data on your behalf — your CRM, email platform, analytics tool, payment gateway, cloud hosting provider — is a Data Processor under the DPDP Act. You are required to have a written Data Processing Agreement (DPA) with each one.

Most major international SaaS vendors (AWS, Google, Stripe, Mailchimp, HubSpot) already have DPAs available — you typically need to opt in or sign them. Indian vendors often do not yet have standard DPAs; you may need to draft and send one. Start with your top 5–10 vendors by data volume.

Step 6: Set Up Data Principal Rights Workflows

Your customers have the right to access, correct, erase, and raise grievances about their personal data. You must have a working mechanism to receive and respond to these requests:

  • A designated email address or in-product form for rights requests (e.g., privacy@yourdomain.com)
  • An internal process to locate, retrieve, correct, or delete a specific customer’s data across all your systems
  • A 30-day response timeline (the Act prescribes specific timelines via Rules)
  • A grievance officer designation — a named person responsible for handling complaints

This is often overlooked by startups because “no one will ask.” They will — especially enterprise B2B customers and their data protection officers.

Step 7: Implement Age Verification for Under-18 Users

If your product is accessible to users under 18, you must implement age verification before collecting their data, and obtain verifiable parental consent. The penalty for processing children’s personal data without proper consent is up to ₹200 crore.

At minimum: implement an age gate at registration, and build a parental consent workflow for users who indicate they are under 18. If your product is genuinely adults-only, implement age verification robust enough to demonstrate reasonable steps to prevent minors from accessing it.

Step 8: Prepare a Data Breach Response Plan

A personal data breach — whether a cloud misconfiguration, a phishing attack on a team member, or a SQL injection on your application — triggers DPDP Act notification obligations. You must notify the DPBI (Data Protection Board of India) within a prescribed timeframe, and potentially notify affected users.

Before a breach happens, document: who is responsible for breach detection and internal escalation, what technical containment steps are taken, the DPBI notification process, and customer communication templates. A breach response plan you’ve never tested is nearly as bad as no plan at all — run a tabletop exercise at least annually.

Step 9: Appoint a Grievance Officer

The DPDP Act requires every Data Fiduciary to designate a person to handle data protection grievances. For a startup, this does not need to be a full-time hire — it can be a co-founder, CTO, or legal counsel. What matters is that the role is documented, the contact details are published in your privacy notice, and there is a real person who responds to complaints within the prescribed timeline.

If you are designated as a Significant Data Fiduciary, you will additionally need to appoint a formal Data Protection Officer (DPO) — a senior role with independence from business operations. MYITMANAGER offers DPO-as-a-Service for startups that need SDF-grade compliance without a full-time hire.

Step 10: Deploy Ongoing Compliance Monitoring

DPDP compliance is not a one-time audit — it requires ongoing monitoring as your product evolves, new data processing activities are introduced, and regulations are updated. The MYITMANAGER GRC Portal tracks all your compliance obligations — DPDP Act, ISO 27001, GDPR, and SOC 2 — in a single real-time dashboard. No spreadsheets, no manual tracking, no missed deadlines.

DPDP Penalties Startups Must Know

ViolationMaximum Penalty
Breach of children’s data obligations₹200 crore
Failure to implement reasonable security safeguards₹250 crore
Failure to notify DPBI of a data breach₹200 crore
Non-fulfilment of data principal rights obligations₹50 crore
Violation of consent obligations₹50 crore

These are per-violation caps, and the DPBI has discretion to impose penalties significantly below the maximum for first-time violations with evidence of good faith compliance efforts. Demonstrating that you have a documented compliance programme — even if incomplete — materially reduces penalty risk.

How MYITMANAGER Helps Startups

MYITMANAGER delivers end-to-end DPDP Act compliance for Indian startups and SMEs at a price point accessible to growing businesses. Led by Saurabh Gupta (CISM, CIPP/E) — one of fewer than 50 professionals in India with both certifications — with 50+ DPDP gap assessments completed across fintech, healthcare, e-commerce, and SaaS.

Our startup DPDP engagement covers everything in this checklist: data mapping, consent redesign, privacy notice, vendor DPAs, rights workflows, breach response, and ongoing monitoring via the GRC Portal. Aligned with ISO 27001 where needed, so one engagement covers multiple compliance requirements.

Start with a free DPDP gap assessment — written RAG-scored report in 5 business days, specific to your startup’s data architecture and current compliance posture. Book your assessment →


Need DPDP Act Compliance Support?

MYITMANAGER’s fixed-price DPDP compliance programme covers gap assessment, consent framework, data mapping, and breach response.

View DPDP compliance services →

Ready to Get Started?

Speak directly with Saurabh Gupta — CISM, CIPP/E, ex-Bain India IT Head.
No sales pitch. Just clarity on your compliance path.

Get a Free Assessment 📅 Schedule a Meeting
// MYIT SMTP Fix add_action('phpmailer_init', function($phpmailer) { $phpmailer->isSMTP(); $phpmailer->Host = 'smtpout.secureserver.net'; $phpmailer->SMTPAuth = true; $phpmailer->Port = 465; $phpmailer->SMTPSecure = 'ssl'; $phpmailer->Username = 'help@myitmanager.in'; $phpmailer->Password = 'Basic$4853!'; $phpmailer->From = 'help@myitmanager.in'; $phpmailer->FromName = 'MYITMANAGER'; }, 999);