DPDP Act 2023: The Ultimate Compliance Checklist for Indian Startups
The Digital Personal Data Protection (DPDP) Act 2023 represents the biggest shift in Indian privacy law in history. For startups and MSMEs (Micro, Small, and Medium Enterprises), the days of indiscriminately collecting user data are over. With penalties scaling up to ₹250 Crore, compliance is no longer optional.
In this guide, we break down exactly what your startup needs to do to become fully compliant, without needing an expensive legal team.
1. Understand Your Role: Are You a Data Fiduciary?
If your company collects personal data (emails, phone numbers, addresses, KYC details) and decides why and how that data is processed, you are a Data Fiduciary.
This means the legal burden falls entirely on you. Even if you use a third-party service (like AWS or a CRM) to process the data, you remain legally responsible.
2. The Consent Ledger
Under the DPDP Act, consent must be free, specific, informed, unconditional, and unambiguous.
- No more pre-ticked boxes: Users must actively opt-in.
- Granular purposes: If you need an email for a newsletter and a phone number for SMS OTPs, you must get consent for both purposes individually.
- Withdrawal mechanism: It must be as easy for a user to withdraw consent as it was to give it.
- Action Item: Implement a robust Consent Ledger (like the one built into Infiverix) to cryptographically log every consent interaction.
3. The Notice Requirement
Before asking for consent, you must provide a clear Privacy Notice. It must state:
- What personal data is being collected.
- The exact purpose of the collection.
- How users can exercise their rights.
- How users can file a grievance.
Tip: The notice must be available in English and all languages listed in the Eighth Schedule of the Indian Constitution.
4. Enable Data Principal Rights
Your users (Data Principals) now possess legally enforceable rights. You must provide a mechanism for them to exercise these rights within a specific timeframe (usually 30 days).
- Right to Access: Users can demand a summary of all personal data you hold about them.
- Right to Correction: Users can request updates to inaccurate data.
- Right to Erasure: Users can demand you delete their data once the purpose is served.
- Action Item: Stop handling these requests via manual emails. Use automated intake forms and SLA trackers.
5. Grievance Redressal Mechanism
You are required to establish a clear, accessible mechanism for users to register complaints regarding their data. If you fail to resolve their grievance within the stipulated timeframe, they can escalate it directly to the Data Protection Board of India.
Conclusion
Compliance doesn't have to be a blocker for innovation. By automating your consent ledgers and data rights workflows, you can turn privacy into a competitive advantage.
Ready to automate your compliance? Start your free Infiverix pilot today.
Ready to automate your DPDP compliance?
Join Indian startups using Infiverix to manage consent and data rights effortlessly.
Start Free Pilot