Connect on WhatsApp
Back to Insights
Technology, Media & Privacy (GDPR)

What Indian Websites Get Wrong About DPDP

By Akash Sinha|
What Indian Websites Get Wrong About DPDP

When was the last time you looked at your own website and asked: what happens to the data we collect?

Not in a vague, "we have a privacy policy" kind of way. Really asked. Like: if someone fills out your contact form right now, where does that information go? Who has access to it? How long do you keep it? What happens if there is a data breach? Can that person ask you to delete their information, and if they do, can you actually find and remove it from every system where it lives?

If you are pausing right now, you are not alone. Most Indian business owners cannot answer these questions confidently. And that is exactly the problem.

Here is the thing. India's Digital Personal Data Protection Act, 2023, and the Digital Personal Data Protection Rules, 2025, are not distant regulatory concepts that only affect tech giants. They affect your website. Today. Right now. Whether you are a solo founder running a SaaS product, a family business with an online store, or a consultancy with a simple contact page.

The Data Protection Board of India is already operational. The penalties are real. And the full enforcement deadline is May 13, 2027. That is less than a year away.

So let us talk about what this actually means for you, why most Indian websites are getting it wrong, and what you need to do about it. No legal jargon. No corporate buzzwords. Just a straight conversation about a law that affects your business more than you probably realise.

What Is the DPDP Act, Really?

The Short Version

The Digital Personal Data Protection Act, 2023 is India's first comprehensive law on how personal data is collected, used, stored, and shared. It got Presidential assent in August 2023, but for over two years it sat without operational rules. That changed on November 13, 2025, when the government finally notified the DPDP Rules, 2025.

Think of the Act as the constitution and the Rules as the operational manual. The Act says "protect personal data." The Rules say "here is exactly how, and here is what happens if you do not."

The law applies to every person or organization that processes digital personal data of individuals in India. That language is broad, and it is broad on purpose.

What This Means for You: If your website collects any information that can identify a person, the DPDP Act applies to you. There is no revenue threshold. No employee count cutoff. No "we are just a small business" exemption.

The Three Deadlines You Need to Know

The government rolled out enforcement in three phases. Here is what matters for your timeline:

PhaseDateWhat Happens
Phase 1November 13, 2025Data Protection Board becomes operational; it can now receive complaints and start inquiries
Phase 2November 13, 2026Consent Manager registration opens; new intermediaries that help users manage consent must register
Phase 3May 13, 2027Full compliance becomes enforceable; every Data Fiduciary must meet all obligations

What This Means for You: The Board is already watching. The May 2027 deadline is not when the law starts. It is when the grace period ends. If your website is not compliant by then, you are exposed to penalties that start at Rs. 50 Crore and go up to Rs. 250 Crore.

Here Is What Most Websites Get Completely Wrong

Misconception 1: "We Only Collect Basic Information"

This is the big one. The misconception that creates the most liability for Indian website owners.

Most business owners think DPDP compliance is about protecting sensitive data like Aadhaar numbers, bank account details, or medical records. They look at their website and think, "We just have a contact form. We only collect names, emails, and phone numbers. That is not sensitive data. This law does not really apply to us."

That thinking is wrong. Under the DPDP framework, there is no distinction between sensitive and non-sensitive personal data. All personal data is treated the same way. If it can identify an individual, it is regulated.

Let us look at what counts:

  • Email addresses from your newsletter sign-up, your lead magnet download, or your contact form
  • Phone numbers collected for OTP verification, callback requests, or WhatsApp updates
  • Names and addresses from delivery forms, billing pages, or event registrations
  • IP addresses captured by your analytics tool, your security firewall, or your advertising pixels
  • Location data from your map integration, your delivery tracking, or your geo-targeted content
  • Browsing behavior recorded by cookies, session trackers, heatmaps, and A/B testing tools
  • Payment details flowing through your payment gateway, subscription platform, or invoice system
  • Chat histories stored in your support widget, your CRM, or your helpdesk platform
  • Professional information from job applications, partnership inquiries, or B2B contact forms

Every single item on that list is personal data under the DPDP Act. And if your website collects any of them, you are a Data Fiduciary with legal obligations.

What This Means for You: That simple contact form on your homepage? It is a regulated data collection point. That Google Analytics script tracking visitor behavior? Regulated. That Intercom chatbot logging customer conversations? Also regulated. The scope is far broader than most website owners realize.

Misconception 2: "Our Privacy Policy Covers Us"

Here is a scenario we see all the time. A business owner spends Rs. 5,000 on a generic privacy policy template, posts it on a footer link, and considers the job done.

A privacy policy is a disclosure document. It tells users, in broad terms, what you do with their data. The DPDP Rules require something entirely different. They require a standalone notice at the exact point where data is collected. This notice must be in plain language, separate from your terms of service, and presented before the user submits their information.

Let us say you have a contact form with three fields: name, email, and phone number. Under DPDP, you need a notice at or near that form explaining:

  • What specific data you are collecting and why you need each item
  • How long you will keep it
  • Whether anyone else will have access to it
  • How the user can withdraw consent or request deletion

A link to your privacy policy in the footer does not satisfy this requirement. Neither does a blanket "by submitting this form, you agree to our terms" checkbox.

What This Means for You: Every form, every cookie banner, every app permission request, and every checkout flow on your website needs its own clear, specific notice. Your privacy policy is necessary but it is not sufficient.

Misconception 3: "Our Third-Party Tools Handle Compliance"

This one is particularly dangerous because it sounds so reasonable.

You use Stripe for payments. Google Analytics for tracking. Mailchimp for newsletters. Cloudflare for security. Intercom for support. These are big, reputable companies. Surely they handle data protection compliance so you do not have to?

No. Under the DPDP framework, you are the Data Fiduciary. Your vendors are Data Processors. You remain legally responsible for everything they do with your users' data. If your email marketing platform has a breach and exposes your subscriber list, you are the one who must notify the Data Protection Board within 72 hours. If your analytics provider shares data in ways you did not anticipate, you are the one facing regulatory action.

Your contracts with every third-party tool must include DPDP-specific clauses requiring them to maintain reasonable security safeguards and to notify you of any breach within a timeline that allows you to meet your own 72-hour notification obligation.

What This Means for You: Go through every tool connected to your website. Your hosting provider. Your CDN. Your CRM. Your payment gateway. Your live chat. Your analytics. Your advertising pixels. If your contract with any of them does not address data protection obligations, that contract needs to be reviewed.

Misconception 4: "We Are Too Small for Anyone to Notice"

The DPDP Act does not have a small business exemption. It does not say "this applies only to companies with 50 or more employees" or "this applies only to businesses with revenue above Rs. 1 Crore." It applies to any entity that processes digital personal data of individuals in India.

A solo founder running a consultancy from a co-working space in Indiranagar is a Data Fiduciary. A family-owned bakery with an online order form is a Data Fiduciary. A freelance photographer with a portfolio website and a contact page is a Data Fiduciary.

The Data Protection Board does not have a "ignore small businesses" policy. Its mandate is to protect Data Principals. If a user complains that their data was mishandled, the Board will investigate regardless of the size of the business involved.

What This Means for You: Your size does not protect you. Your lack of awareness does not protect you. The only thing that protects you is compliance.

What the DPDP Rules Actually Require

The Seven Obligations Every Website Owner Must Understand

The DPDP Rules create seven core obligations. You do not need to memorize the section numbers. You just need to understand what they mean for your daily operations.

1. Notice and Consent Before you collect any personal data, you must give the user a clear notice explaining what you are collecting and why. Consent must be free, specific, informed, and unambiguous. The user must know exactly what they are agreeing to. And crucially, withdrawing consent must be as easy as giving it. If someone can subscribe to your newsletter with one click, they must be able to unsubscribe and have their data deleted with equal ease.

2. Purpose Limitation You can only use data for the purpose you collected it for. If you collected an email address for newsletter delivery, you cannot start sending promotional SMS messages to that same address without fresh consent. If you collected a phone number for delivery tracking, you cannot use it for telemarketing.

3. Data Minimization Collect only what you absolutely need. This challenges the common habit of asking for extra information "just in case." If your contact form asks for date of birth, marital status, or company size when none of these are relevant to your interaction, you are violating this principle.

4. Accuracy Keep the data you hold accurate and current. If a customer tells you their email has changed and you keep sending communications to the old address, you are not meeting this obligation.

5. Storage Limitation Delete data once the purpose is fulfilled, unless the law requires you to keep it longer. You cannot retain user information indefinitely because it might be useful someday. You need clear retention periods and automated deletion workflows.

6. Reasonable Security Safeguards Implement technical measures to protect data. Encryption. Access controls. Event logging. Regular security reviews. This is where the biggest penalty, Rs. 250 Crore, applies.

7. Breach Notification If there is a data breach, you must notify the Data Protection Board and affected users within 72 hours. The notification must explain what happened, what data was affected, what you have done, and what users should do to protect themselves.

What This Means for You: These seven obligations are not theoretical legal concepts. They are operational requirements that touch every part of your website. Your forms. Your cookies. Your analytics. Your payment flow. Your support chat. Your email marketing. Every single one needs to be reviewed against these seven standards.

Special Rules for Websites Serving Children

If your platform is used by or directed at individuals under 18, additional rules kick in. You must obtain verifiable parental or lawful guardian consent before processing any child's personal data. You cannot track children for behavioral advertising. You cannot run targeted ads at users you know or should know are minors.

This matters for EdTech platforms, gaming websites, children's content apps, and any site with a significant under-18 user base. The Rules do allow limited exemptions, such as processing necessary for child protection or email account creation, but these exemptions are narrow and strictly defined.

What This Means for You: If your website serves children or teenagers, you need a clear age verification mechanism and a parental consent workflow. A simple "I am over 18" checkbox is not enough.

The Penalties: Why This Is Not a Paper Tiger

The DPDP Act includes a penalty schedule that should get every website owner's attention:

ViolationMaximum Penalty
Failure to implement reasonable security safeguardsRs. 250 Crore
Failure to notify the Board or users of a data breachRs. 200 Crore
Violations of children's data protection rulesRs. 200 Crore
Failure to meet Significant Data Fiduciary obligationsRs. 150 Crore
Any other violation by a Data FiduciaryRs. 50 Crore

Rs. 50 Crore is the minimum penalty tier for a Data Fiduciary violation. For a small business or startup, that is not a fine. That is an extinction event.

The Data Protection Board does have discretion. It considers the nature of the breach, how many people were affected, your history of compliance, and how quickly you fixed the problem. But the statutory maximums create a ceiling so high that even a fraction of the penalty would destroy most small businesses.

What This Means for You: The question is not "will I get caught?" The question is "if something goes wrong, can my business survive the consequences?" For most small businesses, the answer is no. Compliance is not optional. It is survival.

Why Most Articles About DPDP Miss the Point

If you have read other articles about DPDP compliance, you have probably noticed a pattern. They use phrases like "journey toward compliance" and "framework for data governance." They talk about "embedding privacy-by-design principles" and "establishing robust audit trails." They sound like they were written by consultants billing by the hour.

Here is what those articles rarely tell you:

  • That the contact form on your website is a regulated data collection point right now
  • That your newsletter subscriber list is subject to the same rules as a hospital's patient database
  • That your Google Analytics setup probably violates the data minimization principle
  • That your privacy policy, however well-drafted, does not satisfy the notice requirement
  • That your contracts with third-party tools are probably silent on DPDP obligations
  • That you have less than a year to fix all of this

The DPDP Act is not a distant regulatory framework for large corporations to contemplate. It is a present legal obligation for every Indian website that processes personal data. The articles that frame it as a strategic initiative for enterprises are talking to the wrong audience. The audience that needs this information most is the small business owner who thinks a privacy policy and an SSL certificate are enough.

What This Means for You: Do not wait for a consultant to sell you a "DPDP compliance framework." Start with the basics. Audit your website. Review your contracts. Fix your consent flows. The law is not waiting for you to be ready.

What You Should Do Next

A Practical Checklist

You do not need a Fortune 500 budget to get your website compliant. You need a methodical approach that starts with the highest-risk areas.

Step 1: Audit Every Data Collection Point Go through your website page by page. Identify every form, every cookie, every tracking script, every third-party integration. Write down what data is collected, where it goes, how long it stays, and who can access it. This inventory is the foundation of everything that follows.

Step 2: Review Your Vendor Contracts Pull up your agreements with every third-party service connected to your website. Your hosting provider. Your email platform. Your payment gateway. Your analytics tool. Your support chat. Check whether these contracts include DPDP-specific data protection clauses and breach notification timelines. If they do not, they need to be amended.

Step 3: Redesign Your Consent Flows Replace generic privacy policy links with specific notices at each data collection point. Make consent granular. Give users clear withdrawal mechanisms. Ensure that requesting data deletion is as easy as submitting the data in the first place.

Step 4: Set Data Retention Rules Decide how long you need each type of data. Build automated deletion workflows. Document your retention schedules. Do not keep data indefinitely because you might need it later.

Step 5: Prepare for Breaches Before They Happen Create a response plan. Who detects the breach? Who assesses it? Who notifies the Board? Who communicates with users? Draft your notification templates now, while you have time to think clearly. Test your plan.

Step 6: Train Your Team Everyone who touches customer data needs to understand the basics. Your developer who installs analytics scripts. Your marketer who manages email campaigns. Your support staff who handles user requests. Most data breaches are caused by human error, not sophisticated hacking.

What You Can Handle Yourself vs. What Needs a Lawyer

Not everything requires legal counsel. Here is a practical split:

TaskHandle InternallyGet Legal Help
Data collection auditYesNo
Drafting consent noticesYes (with guidance)Recommended for first version
Vendor contract reviewNoYes
Data retention workflow setupYes (technical team)No
Breach response planningPartiallyYes
Cross-border transfer assessmentNoYes
Responding to user data requestsYes (trained staff)If disputed or complex

For most small businesses, the smart approach is to handle the operational and technical work internally while engaging a lawyer for contract review, notice drafting, and regulatory strategy.

The Hidden Opportunity

Why Compliance Is Becoming a Competitive Advantage

Here is something most articles do not talk about. DPDP compliance is not just about avoiding penalties. It is becoming a business differentiator.

Enterprise customers are increasingly asking vendors about data governance. If your SaaS product processes their customer data and you cannot demonstrate compliance, you will lose to a competitor who can. Venture capital investors now treat data protection as a governance metric during due diligence. A clean compliance record signals operational maturity.

The EY India report from early 2026 estimated that DPDP compliance would unlock a Rs. 10,000 Crore market over three years. That market exists because thousands of Indian businesses need practical, affordable guidance. The firms that get compliant early will have a measurable advantage over those that scramble in the second quarter of 2027.

What This Means for You: Treat DPDP compliance as an investment, not a cost. The businesses that are ready by May 2027 will win contracts, close funding rounds, and build trust with customers. The ones that are not ready will be explaining to investors why their data practices were never addressed.

A Quick Word on the November 2026 and May 2027 Deadlines

You have probably noticed that we keep coming back to these two dates. Here is why they matter in practical terms.

November 13, 2026, is when Consent Manager registration opens. Consent Managers are intermediaries that help users manage their consent across multiple platforms through a single dashboard. If your business model involves processing data across platforms or if you want to streamline user consent management, this date matters for your integration strategy.

May 13, 2027, is when the full weight of the Rules becomes enforceable. From this date, every obligation we have discussed in this article becomes legally binding. Every Data Fiduciary must have their notice and consent mechanisms in place. Every Data Fiduciary must have their security safeguards operational. Every Data Fiduciary must have their breach response plan tested and ready.

What This Means for You: Do not plan to start your compliance work in April 2027. Typical website compliance programs require 6 to 12 months to complete audit, implement changes, and test systems. If you have not started by late 2026, you are already behind.

How Vera Causa Legal Can Help

At Vera Causa Legal, we work with startups, SMEs, and mid-size firms to build DPDP compliance programs that are legally sound and practically implementable. Our Startup Hub helps early-stage companies establish governance foundations, including data protection policies and consent architectures that work for lean teams, while our Corporate Advisory practice supports growing firms through vendor contract review, regulatory compliance strategy, and breach response planning.

If you are not sure whether your website is DPDP-ready, the first step is a compliance assessment. We audit your data collection points, review your vendor contracts, identify your highest-risk areas, and give you a prioritized action plan.

The DPDP compliance window is open. The Data Protection Board is operational. The November 2026 and May 2027 deadlines are not moving. The only question is whether your website will be ready.

Strategic Legal Counsel

Discuss the implications of this briefing for your specific corporate or cross-border operations.

Request Private Consultation